[PATCH] riscv: patch: fix handling of bpf-jit execmem addresses

Alexei Starovoitov alexei.starovoitov at gmail.com
Thu Sep 24 14:48:21 PDT 2026


On Thu, Sep 17, 2026 at 6:32 PM Pu Lehui <pulehui at huawei.com> wrote:
>
>
> On 2026/9/14 19:56, Wei-Jie Hung wrote:
> > Commit 8718e5a3090b ("riscv: patch: skip fixmap mapping when kernel text
> > is already writable") gated the core_kernel_text() branch of patch_map()
> > on CONFIG_STRICT_KERNEL_RWX, and explicitly left the vmalloc branch
> > unchanged. That branch has a separate problem.
> >
> > That branch only creates a temporary writable fixmap alias when
> > CONFIG_STRICT_MODULE_RWX is enabled, and otherwise assumes the target is
> > directly writable and returns the address unchanged. That assumption no
> > longer holds: bpf_prog_pack_alloc calls set_memory_rox() on every pack
> > unconditionally in alloc_new_pack(), independently of any
> > CONFIG_STRICT_*_RWX option, so BPF text in the vmalloc area is read-only
> > regardless of what CONFIG_STRICT_MODULE_RWX says.
> >
> > With CONFIG_STRICT_MODULE_RWX=n, patch_map() returns the read-only
> > address directly, the subsequent copy_to_kernel_nofault() takes a
> > page fault and returns -EFAULT. bpf_arch_text_copy() turns that into
> > -EINVAL, which propagates through bpf_jit_binary_pack_finalize() to the
> > WARN_ON() in bpf_int_jit_compile() and leaves the program un-JITed.
> >
> > Note that BPF cannot be fixed the way kprobes was in
> > commit bdc46e507b59 ("riscv: mm: make EXECMEM_KPROBES writable without
> > CONFIG_STRICT_MODULE_RWX"). EXECMEM_BPF is already PAGE_KERNEL, i.e.
> > writable at allocation time; the read-only mapping is established
> > afterwards by generic code in alloc_new_pack(), which arch code cannot
> > influence. The only place this can be handled is patch_map().
> >
> > This is the same problem that was fixed on arm64 by commit b1480ed230ac
> > ("arm64: patching: fix handling of execmem addresses"), and the fix is
> > the same: CONFIG_EXECMEM is what actually tracks whether the vmalloc
> > area can hold executable memory that needs a temporary alias to be
> > written. CONFIG_BPF_JIT, CONFIG_KPROBES and CONFIG_MODULES all select
> > it.
> >
> > Note that this is not limited to CONFIG_MODULES=n. Unlike arm64, riscv
> > selects CONFIG_ARCH_OPTIONAL_KERNEL_RWX, so CONFIG_STRICT_MODULE_RWX can
> > be disabled with CONFIG_MODULES=y as well, and the bug is reachable in
> > that configuration too.
> >
> > The !CONFIG_MMU build is unaffected: it has its own __patch_insn_set()
> > and __patch_insn_write() implementations and never calls patch_map().
> >
> > Fixes: 2c9e5d4a0082 ("bpf: remove CONFIG_BPF_JIT dependency on CONFIG_MODULES of")
> > Signed-off-by: Wei-Jie Hung <imbigking12 at gmail.com>
> > ---
> > Based on riscv/fixes (b94cec5761d2).

Not clear what tree this patch suppose to go to.
If it's bpf-next then pls respin with correct subj,

pw-bot: cr

>
> Reviewed-by: Pu Lehui <pulehui at huawei.com>
> Tested-by: Pu Lehui <pulehui at huawei.com>

and keep tags.
Thanks everyone.



More information about the linux-riscv mailing list