Re: [PATCH] bpf, arm64: Fix text_mutex critical section in bpf_arch_text_poke()

From: Matthew Wood

Date: Fri Oct 02 2026 - 07:41:45 EST


On Fri, Oct 2, 2026 at 12:21 PM Alexei Starovoitov
<alexei.starovoitov@xxxxxxxxx> wrote:
>
> On Thu, Oct 01, 2026 at 09:40 PM Matthew Wood <thepacketgeek@xxxxxxxxx> wrote:
> > + /* pages of the bpf prog pack are shared between progs, so the
> > + * set_memory_rw()/set_memory_ro() window below must be serialized
> > + * against other pokers too.
> > + */
> > + mutex_lock(&text_mutex);
> > +
> > if (plt_target) {
> > /* non-zero plt_target indicates we're patching a bpf prog,
> > * which is read only.
> > */
> > - if (set_memory_rw(PAGE_MASK & ((uintptr_t)&plt->target), 1))
> > - return -EFAULT;
> > + if (set_memory_rw(PAGE_MASK & ((uintptr_t)&plt->target), 1)) {
> > + ret = -EFAULT;
> > + goto out;
> > + }
> > WRITE_ONCE(plt->target, plt_target);
> > set_memory_ro(PAGE_MASK & ((uintptr_t)&plt->target), 1);
>
> The lock hides the crash, but set_memory_rw() is the actual problem.
> The page is shared, so it makes 64K of other progs writable and
> executable at the same time.
> Use aarch64_insn_write_literal_u64(&plt->target, plt_target) instead.
> That's how ftrace_rec_set_ops() and arch_static_call_transform()
> update 64-bit literals in the text.
> It's atomic and writes via fixmap under patch_lock, just like
> aarch64_insn_patch_text_nosync() below.
> No need to change page permissions and no need to move text_mutex.
>
> pw-bot: cr

Thank you both for the quick review! This
aarch64_insn_write_literal_u64 makes sense,
I'll test and submit an update shortly.

Regards,
Matthew