[PATCH 0/5] x86/mm/pat: CPA fixes

From: Mike Rapoport (Microsoft)

Date: Tue Jul 28 2026 - 09:13:59 EST


There are a couple of CPA fixes floating around:

Denis Lunev fixed races between split and collapse of the large mappings:

https://lore.kernel.org/all/20260715183453.2381141-1-den@xxxxxxxxxx

Lorenzo Stoakes fixed UAF caused by races between CPA and ptdump:

https://lore.kernel.org/all/20260723-series-vmap-race-fix-v6-0-8cc77dcc0018@xxxxxxxxxx

and an issue with stale page tables in IOMMU:

https://lore.kernel.org/all/20260721-fix-cpa-kernel-pagetables-v2-1-2b255deed710@xxxxxxxxxx

Mike Rapoport fixed a check of RW attribute in lookup_address_in_pgd_attr()
used for the verification of RWX:

https://lore.kernel.org/all/20260715144519.934289-1-rppt@xxxxxxxxxx

Some of the fixes got merged into x86 tree, some of them got merged into mm
tree and some are still hanging in the air.

Beside the fixes there was a supposed simplification of cpa_lock locking
that looked like removal of an optimization for DEBUG_PAGEALLOC, but it
turned out that it was not an optimization but rather a correctness
guard because with DEBUG_PAGEALLOC the locks could be taken in an atomic
context and couldn't use plain spin_lock()/spin_unlock().

The changes here are collected from all these fixes into a sinlge coherent
set on top of tip/x86/mm:

* update to cpa_lock handling with DEBUG_PAGEALLOC
* fix for races between CPA and ptdumpi causing UAF
* fix for stale page tables in IOMMU
* update to the fix of the race between split and collapse of large
mappings
* fix for effective RW computation in lookup_address_in_pgd_attr()

Signed-off-by: Mike Rapoport (Microsoft) <rppt@xxxxxxxxxx>
---
Lorenzo Stoakes (ARM) (3):
x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
x86/mm/pat: allocate split page tables as kernel page tables

Mike Rapoport (Microsoft) (2):
x86/mm/pat: introcude cpa_lock() and cpa_unlock()
x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()

arch/x86/mm/pat/set_memory.c | 95 +++++++++++++++++++++++++++++++-------------
include/linux/mmap_lock.h | 2 +
2 files changed, 70 insertions(+), 27 deletions(-)
---
base-commit: a5a162fe1ae130e3d2ceefef3f43afe3773c1d56
change-id: 20260727-cpa-fixes-d3c73c075672

--
Sincerely yours,
Mike.