Re: [PATCH] bpf, arm64: Fix text_mutex critical section in bpf_arch_text_poke()

From: Alexei Starovoitov

Date: Fri Oct 02 2026 - 07:22:11 EST


On Thu, Oct 01, 2026 at 09:40 PM Matthew Wood <thepacketgeek@xxxxxxxxx> wrote:
> + /* pages of the bpf prog pack are shared between progs, so the
> + * set_memory_rw()/set_memory_ro() window below must be serialized
> + * against other pokers too.
> + */
> + mutex_lock(&text_mutex);
> +
> if (plt_target) {
> /* non-zero plt_target indicates we're patching a bpf prog,
> * which is read only.
> */
> - if (set_memory_rw(PAGE_MASK & ((uintptr_t)&plt->target), 1))
> - return -EFAULT;
> + if (set_memory_rw(PAGE_MASK & ((uintptr_t)&plt->target), 1)) {
> + ret = -EFAULT;
> + goto out;
> + }
> WRITE_ONCE(plt->target, plt_target);
> set_memory_ro(PAGE_MASK & ((uintptr_t)&plt->target), 1);

The lock hides the crash, but set_memory_rw() is the actual problem.
The page is shared, so it makes 64K of other progs writable and
executable at the same time.
Use aarch64_insn_write_literal_u64(&plt->target, plt_target) instead.
That's how ftrace_rec_set_ops() and arch_static_call_transform()
update 64-bit literals in the text.
It's atomic and writes via fixmap under patch_lock, just like
aarch64_insn_patch_text_nosync() below.
No need to change page permissions and no need to move text_mutex.

pw-bot: cr