Skip to content

Commit ce2bba8

Browse files
leitaoakpm00
authored andcommitted
mm/kfence: add reboot notifier to disable KFENCE on shutdown
During system shutdown, KFENCE can cause IPI synchronization issues if it remains active through the reboot process. To prevent this, register a reboot notifier that disables KFENCE and cancels any pending timer work early in the shutdown sequence. This is only necessary when CONFIG_KFENCE_STATIC_KEYS is enabled, as this configuration sends IPIs that can interfere with shutdown. Without static keys, no IPIs are generated and KFENCE can safely remain active. The notifier uses maximum priority (INT_MAX) to ensure KFENCE shuts down before other subsystems that might still depend on stable memory allocation behavior. This fixes a late kexec CSD lockup[1] when kfence is trying to IPI a CPU that is busy in a IRQ-disabled context printing characters to the console. Link: https://lkml.kernel.org/r/20251127-kfence-v2-1-daeccb5ef9aa@debian.org Link: https://lkml.kernel.org/r/20251126-kfence-v1-1-5a6e1d7c681c@debian.org Link: https://lore.kernel.org/all/sqwajvt7utnt463tzxgwu2yctyn5m6bjwrslsnupfexeml6hkd@v6sqmpbu3vvu/ [1] Fixes: 0ce20dd ("mm: add Kernel Electric-Fence infrastructure") Signed-off-by: Breno Leitao <leitao@debian.org> Reviewed-by: Marco Elver <elver@google.com> Cc: Alexander Potapenko <glider@google.com> Cc: Dmitriy Vyukov <dvyukov@google.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
1 parent f3b566d commit ce2bba8

1 file changed

Lines changed: 24 additions & 0 deletions

File tree

mm/kfence/core.c

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@
2626
#include <linux/panic_notifier.h>
2727
#include <linux/random.h>
2828
#include <linux/rcupdate.h>
29+
#include <linux/reboot.h>
2930
#include <linux/sched/clock.h>
3031
#include <linux/seq_file.h>
3132
#include <linux/slab.h>
@@ -820,6 +821,25 @@ static struct notifier_block kfence_check_canary_notifier = {
820821
static struct delayed_work kfence_timer;
821822

822823
#ifdef CONFIG_KFENCE_STATIC_KEYS
824+
static int kfence_reboot_callback(struct notifier_block *nb,
825+
unsigned long action, void *data)
826+
{
827+
/*
828+
* Disable kfence to avoid static keys IPI synchronization during
829+
* late shutdown/kexec
830+
*/
831+
WRITE_ONCE(kfence_enabled, false);
832+
/* Cancel any pending timer work */
833+
cancel_delayed_work_sync(&kfence_timer);
834+
835+
return NOTIFY_OK;
836+
}
837+
838+
static struct notifier_block kfence_reboot_notifier = {
839+
.notifier_call = kfence_reboot_callback,
840+
.priority = INT_MAX, /* Run early to stop timers ASAP */
841+
};
842+
823843
/* Wait queue to wake up allocation-gate timer task. */
824844
static DECLARE_WAIT_QUEUE_HEAD(allocation_wait);
825845

@@ -901,6 +921,10 @@ static void kfence_init_enable(void)
901921
if (kfence_check_on_panic)
902922
atomic_notifier_chain_register(&panic_notifier_list, &kfence_check_canary_notifier);
903923

924+
#ifdef CONFIG_KFENCE_STATIC_KEYS
925+
register_reboot_notifier(&kfence_reboot_notifier);
926+
#endif
927+
904928
WRITE_ONCE(kfence_enabled, true);
905929
queue_delayed_work(system_unbound_wq, &kfence_timer, 0);
906930

0 commit comments

Comments
 (0)