[PATCH] ARM: hibernate: flush TLB after switching to idmap

From: Chongchong Ding

Date: Wed Sep 30 2026 - 02:19:19 EST


On 32-bit ARM, hibernate switches to the identity mapping to copy pages.
The idmap keeps an early RW snapshot of kernel mappings, so
STRICT_KERNEL_RWX text/rodata can be written during restore.

cpu_switch_mm() does not drop the global TLB entries from swapper.
copy_page() can therefore still hit the old RO translations and fail to
restore kernel RO sections.

Flush the local BTB and TLB after installing the idmap, matching
setup_mm_for_reboot() and the cpu_suspend() resume path.

Signed-off-by: Chongchong Ding <chongchong.ding@xxxxxxxxxxx>
---
arch/arm/kernel/hibernate.c is only compiled when CONFIG_HIBERNATION is
enabled, and none of the 32-bit ARM defconfigs enable it, so the ARM
hibernation code has never been covered by the regular build tests. This
bug was found while enabling the option for build coverage.
---
arch/arm/kernel/hibernate.c | 12 ++++++++++++
1 file changed, 12 insertions(+)

diff --git a/arch/arm/kernel/hibernate.c b/arch/arm/kernel/hibernate.c
index 231a76af09a0..1c7c1cb6dade 100644
--- a/arch/arm/kernel/hibernate.c
+++ b/arch/arm/kernel/hibernate.c
@@ -21,6 +21,7 @@
#include <asm/suspend.h>
#include <asm/page.h>
#include <asm/sections.h>
+#include <asm/tlbflush.h>
#include <asm/uaccess.h>
#include "reboot.h"

@@ -93,6 +94,17 @@ static void notrace arch_restore_image(void *unused)
if (IS_ENABLED(CONFIG_CPU_TTBR0_PAN))
uaccess_save_and_enable();
cpu_switch_mm(idmap_pgd, &init_mm);
+ local_flush_bp_all();
+
+#ifdef CONFIG_CPU_HAS_ASID
+ /*
+ * The identity mapping has no clean ASID and may clash with entries
+ * left behind by the previous page tables. Without this flush,
+ * copy_page() can translate through the stale read-only kernel
+ * mappings instead of the writable aliases in the idmap.
+ */
+ local_flush_tlb_all();
+#endif
for (pbe = restore_pblist; pbe; pbe = pbe->next)
copy_page(pbe->orig_address, pbe->address);


---
base-commit: 551c722f40809618230001baccf219193e22fc5a
change-id: 20260928-hibernate-tlb-flush-f2c1c5315625

Best regards,
--
Chongchong Ding <chongchong.ding@xxxxxxxxxxx>