[RFC PATCH v2 0/4] arm64: mm: Map fixmap page tables read-only

Kevin Brodsky kevin.brodsky at arm.com
Tue Sep 1 02:21:32 PDT 2026


On 27/08/2026 18:44, Ard Biesheuvel wrote:
> From: Ard Biesheuvel <ardb at kernel.org>
>
> This v2 now covers intermediate level page tables as well as the PTE
> level page table for the fixmap. The latter is a special case, as it
>
> a) is only accessed via the kernel image's mapping, and never via the
>    linear map (except for ptdump etc)
>
> b) must be accessible via a read-write mapping, as all manipulation of
>    read-only page table descriptors relies on the fixmap itself
>
> and so it is treated separately. The intermediate page tables may be
> shared with other mappings in the upper kernel/vmalloc region, so they
> must be updatable using the ordinary APIs.
>
> Build tested and boot tested on a Lenovo Yoga C630 using 16k pages.
>
> v1: https://lore.kernel.org/all/20260805104042.1107678-2-ardb+git@google.com/
>
> Cc: Ryan Roberts <ryan.roberts at arm.com>
> Cc: Anshuman Khandual <anshuman.khandual at arm.com>
> Cc: Kevin Brodsky <kevin.brodsky at arm.com>
> Cc: Liz Prucka <lizprucka at google.com>
> Cc: Seth Jenkins <sethjenkins at google.com>
> Cc: Kees Cook <kees at kernel.org>
> Cc: Jann Horn <jannh at google.com>
> Cc: linux-hardening at vger.kernel.org

Looks like the Cc's didn't propagate to the actual patches, fortunately
my lei filters did catch this series ;)

Either way I quite like this series, it's an elegant approach and it
should increase security without overhead, what's not to like!

I also considered it from the perspective of kpkeys protection [1] and I
think they should work together fine. The kpkeys series still allows
page table setters to write to all page tables, so if we get a fault
there it must be because the target is read only, and not because of a
pkey fault.

- Kevin

[1] https://lore.kernel.org/all/20260818-kpkeys-v9-0-743ad31b2c8f@arm.com/



More information about the linux-arm-kernel mailing list