mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 05:04:02 +02:00
show_pte() walks page tables locklessly and can run with interrupts
enabled. A concurrent teardown can free a table page while it is being
walked. It can also clear a parent entry after show_pte() checked it; the
regular pXd_offset() helpers then reread the cleared entry and can derive a
bogus lower-level pointer and fault again.
Use the lockless offset helpers with the saved parent entries, as
gup_fast() does, and pass the saved PMD to pte_offset_map().
For task page tables, arm64 selects MMU_GATHER_RCU_TABLE_FREE. Disable
local interrupts around the walk to hold off RCU-deferred table frees and
block the tlb_remove_table_sync_one() IPI until the walk is finished.
Place the IRQ guard after the header print. This does not make the output a
consistent snapshot, but prevents the task page-table walk from
dereferencing a released table page or deriving a pointer from a different
parent value.
Fixes:
|
||
|---|---|---|
| .. | ||
| cache.S | ||
| context.c | ||
| contpte.c | ||
| copypage.c | ||
| dma-mapping.c | ||
| extable.c | ||
| fault.c | ||
| fixmap.c | ||
| flush.c | ||
| gcs.c | ||
| hugetlbpage.c | ||
| init.c | ||
| ioremap.c | ||
| kasan_init.c | ||
| Makefile | ||
| mem_encrypt.c | ||
| mmap.c | ||
| mmu.c | ||
| mteswap.c | ||
| pageattr.c | ||
| pgd.c | ||
| physaddr.c | ||
| proc.S | ||
| ptdump_debugfs.c | ||
| ptdump.c | ||
| trans_pgd-asm.S | ||
| trans_pgd.c | ||