Re: [PATCH] x86/mm/fault: Test _PAGE_RW, not pte_write(), in spurious_kernel_fault_check()

From: Dave Hansen

Date: Thu Oct 01 2026 - 12:48:52 EST


On 10/1/26 09:12, Hitesh Murali via B4 Relay wrote:
> Kernel read-only mappings are created without Dirty since commit
> f788b71768ff ("x86/mm: Remove _PAGE_DIRTY from kernel RO pages"), but a
> store made while _PAGE_RW is temporarily set leaves Dirty behind, and the
> kernel does not clear it again. A later normal store to such an entry
> raises a protection fault, which is then classified as spurious. The
> store is restarted, faults again, and the CPU makes no progress.

I'm having a really hard time parsing through this changelog. Was this
all from the LLM?

Can this issue actually be triggered in a normal kernel? The root of
this problem is that PTE-modifying kernel code is leaving _PAGE_DIRTY
behind during a RW=>RO transition. We have code to prevent that from
happening.

So are the out-of-tree modules just being naughty and directly
manipulating page tables? Care to post your "small GPL test modules"?

Yeah, there still might be a buglet in spurious fault detection that
would surface in the face of _other_ kernel bugs, but it'd be extra low
priority.