Received: by 2002:a05:6a10:af89:0:0:0:0 with SMTP id iu9csp3623755pxb; Mon, 24 Jan 2022 13:46:27 -0800 (PST) X-Google-Smtp-Source: ABdhPJzDHg5j54NLp4zzwO0TNT/PiQB3raty6NFD93EhS4+4aM34ejC61jqic6eKeCtZB7hlSBpF X-Received: by 2002:a17:902:ea10:b0:14a:f84a:bfa0 with SMTP id s16-20020a170902ea1000b0014af84abfa0mr15987594plg.163.1643060786817; Mon, 24 Jan 2022 13:46:26 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1643060786; cv=none; d=google.com; s=arc-20160816; b=witoI13oxJOttJyzf2TwOqG7fmhi6p7o26A/+pT2jP6yey3kPiLv+TIN36TpPp4mzt Z/aLz1fLEHEjnceBC2GKRi8dxUeYVDOjOW6zP8mIs2VOWBRP8BEz+CRqtLphYVbs+la6 pVbXMVnP8wNS/58F20JzfEZLMzGE9g0uf9ZrpBYX+wWF5bgY0rqZKs2HB31RzMSOdbaz wpZ3aXFnybZwSSOVW93WWcfYX8IGnUjDNBED2Al/pIGUE2ZmbgWHanqm4ZqjxCxXk4zv 8H7MlJ7vrF/uF2CTlhw86H+iqxpOL3U3S/Svo/2lu4tQOPbNPIphgRo5FRvWkRnvOAys 4PdQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=SnZ3lAqQL6pRx/aY5rBEDTlRvgYgbwPK4C4WDgxdIfs=; b=BZziyGLq1XLxjRej/JhPX1QZnZUQFtA4Vkaw6iTDYL+sisw0gQL7bNztQk349aQA5f FX+s2vIxrEu11R5dPbzfjxLCVB8L3xJLA0AQXbvZGZ+pyu27qTqI7GBudDuvChVD14f1 5f49qlCMofV9cyVW+bFhYdA6hfzZ4cHFYWmzxjhpX9iH9NN10aToucpYAdJan6VCtaWe 1bYHTHjQS9eL2n8TG8A1uuNYrXOoLleZOOzZYDoDYgj1mvaFLf0WTDVw6+wx2Oe1VzyN ndKLoEXqH27wd7IULVndTb0+gzeQGaGF7O9FiPEED3Kx+JUXahmzIyMYqQH7rDzGiGX2 7xpg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=iGk+uYmv; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id lb3si451891pjb.143.2022.01.24.13.46.14; Mon, 24 Jan 2022 13:46:26 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=iGk+uYmv; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1452693AbiAXV0N (ORCPT + 99 others); Mon, 24 Jan 2022 16:26:13 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44226 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1392299AbiAXUvB (ORCPT ); Mon, 24 Jan 2022 15:51:01 -0500 Received: from ams.source.kernel.org (ams.source.kernel.org [IPv6:2604:1380:4601:e00::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 47D93C054301; Mon, 24 Jan 2022 11:58:11 -0800 (PST) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ams.source.kernel.org (Postfix) with ESMTPS id E2EB8B8119D; Mon, 24 Jan 2022 19:58:10 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 482BFC340E7; Mon, 24 Jan 2022 19:58:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1643054289; bh=zfEYjZPtuQKLUiQd334jkr6Im+SBhh1cinJVAghTffk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=iGk+uYmvtZFi1jsS+ey3VHhnNu0DE0Nnt2bWheyfr5U9GD4t/jYuO/1HCOhI9qeyx OYIvsq1BHZEKc6LGDth1U1mw2Pd58lUAHp1FD6sSrPp6pGGjcAB4q7BXGLVJqzuhWC lx8riCaBkEx0VBo/KpguFiImrO7RqghkHzTdWOzo= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Joerg Roedel , Borislav Petkov , Sasha Levin Subject: [PATCH 5.10 340/563] x86/mm: Flush global TLB when switching to trampoline page-table Date: Mon, 24 Jan 2022 19:41:45 +0100 Message-Id: <20220124184036.186221874@linuxfoundation.org> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20220124184024.407936072@linuxfoundation.org> References: <20220124184024.407936072@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Joerg Roedel [ Upstream commit 71d5049b053876afbde6c3273250b76935494ab2 ] Move the switching code into a function so that it can be re-used and add a global TLB flush. This makes sure that usage of memory which is not mapped in the trampoline page-table is reliably caught. Also move the clearing of CR4.PCIDE before the CR3 switch because the cr4_clear_bits() function will access data not mapped into the trampoline page-table. Signed-off-by: Joerg Roedel Signed-off-by: Borislav Petkov Link: https://lore.kernel.org/r/20211202153226.22946-4-joro@8bytes.org Signed-off-by: Sasha Levin --- arch/x86/include/asm/realmode.h | 1 + arch/x86/kernel/reboot.c | 12 ++---------- arch/x86/realmode/init.c | 26 ++++++++++++++++++++++++++ 3 files changed, 29 insertions(+), 10 deletions(-) diff --git a/arch/x86/include/asm/realmode.h b/arch/x86/include/asm/realmode.h index 5db5d083c8732..331474b150f16 100644 --- a/arch/x86/include/asm/realmode.h +++ b/arch/x86/include/asm/realmode.h @@ -89,6 +89,7 @@ static inline void set_real_mode_mem(phys_addr_t mem) } void reserve_real_mode(void); +void load_trampoline_pgtable(void); #endif /* __ASSEMBLY__ */ diff --git a/arch/x86/kernel/reboot.c b/arch/x86/kernel/reboot.c index 798a6f73f8946..df3514835b356 100644 --- a/arch/x86/kernel/reboot.c +++ b/arch/x86/kernel/reboot.c @@ -113,17 +113,9 @@ void __noreturn machine_real_restart(unsigned int type) spin_unlock(&rtc_lock); /* - * Switch back to the initial page table. + * Switch to the trampoline page table. */ -#ifdef CONFIG_X86_32 - load_cr3(initial_page_table); -#else - write_cr3(real_mode_header->trampoline_pgd); - - /* Exiting long mode will fail if CR4.PCIDE is set. */ - if (boot_cpu_has(X86_FEATURE_PCID)) - cr4_clear_bits(X86_CR4_PCIDE); -#endif + load_trampoline_pgtable(); /* Jump to the identity-mapped low memory code */ #ifdef CONFIG_X86_32 diff --git a/arch/x86/realmode/init.c b/arch/x86/realmode/init.c index 3313bffbecd4d..1a702c6a226ec 100644 --- a/arch/x86/realmode/init.c +++ b/arch/x86/realmode/init.c @@ -17,6 +17,32 @@ u32 *trampoline_cr4_features; /* Hold the pgd entry used on booting additional CPUs */ pgd_t trampoline_pgd_entry; +void load_trampoline_pgtable(void) +{ +#ifdef CONFIG_X86_32 + load_cr3(initial_page_table); +#else + /* + * This function is called before exiting to real-mode and that will + * fail with CR4.PCIDE still set. + */ + if (boot_cpu_has(X86_FEATURE_PCID)) + cr4_clear_bits(X86_CR4_PCIDE); + + write_cr3(real_mode_header->trampoline_pgd); +#endif + + /* + * The CR3 write above will not flush global TLB entries. + * Stale, global entries from previous page tables may still be + * present. Flush those stale entries. + * + * This ensures that memory accessed while running with + * trampoline_pgd is *actually* mapped into trampoline_pgd. + */ + __flush_tlb_all(); +} + void __init reserve_real_mode(void) { phys_addr_t mem; -- 2.34.1