diff options
| author | Richard Cheng <icheng@nvidia.com> | 2026-07-21 18:00:26 +0800 |
|---|---|---|
| committer | Will Deacon <will@kernel.org> | 2026-07-21 15:21:11 +0000 |
| commit | 285f90a4d1141c7594f2368e19cbb307388eff30 (patch) | |
| tree | f5bc3679f2885a238766832df37d4ce7e1ac21a0 | |
| parent | b877075d0baa22c225842c2f19e3ea0a9cbcbe39 (diff) | |
| download | linux-285f90a4d1141c7594f2368e19cbb307388eff30.tar.gz linux-285f90a4d1141c7594f2368e19cbb307388eff30.tar.bz2 linux-285f90a4d1141c7594f2368e19cbb307388eff30.zip | |
arm64/mm: Check the requested PFN range during memory removal
prevent_memory_remove_notifier() advances pfn while scanning the requested
range for early memory. When the loop completes, pfn is at or beyond
end_pfn. Passing it to can_unmap_without_split() therefore checks a range
after the one being offlined.
Consequently, a valid request can be rejected based on the following
range, while a request that would split a leaf mapping can be accepted if
the shifted range can be unmapped without a split. This was observed with
CXL DAX memory, where the final memory block was incorrectly allowed to
be offlined.
Pass arg->start_pfn into can_unmap_without_split() so it checks the
requested range.
Fixes: 95a58852b0e5 ("arm64/mm: Reject memory removal that splits a kernel leaf mapping")
Signed-off-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
| -rw-r--r-- | arch/arm64/mm/mmu.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c index a25d8beacc83..18a8b0d3714e 100644 --- a/arch/arm64/mm/mmu.c +++ b/arch/arm64/mm/mmu.c @@ -2194,7 +2194,7 @@ static int prevent_memory_remove_notifier(struct notifier_block *nb, } } - if (!can_unmap_without_split(pfn, arg->nr_pages)) + if (!can_unmap_without_split(arg->start_pfn, arg->nr_pages)) return NOTIFY_BAD; return NOTIFY_OK; |