From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from shelob.surriel.com (shelob.surriel.com [96.67.55.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5613E3B9D97 for ; Tue, 11 Aug 2026 03:49:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=96.67.55.147 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786420188; cv=none; b=teDQsE2eRlAh6Bz4tlqouwp2Q7aQy6XSwnrPE0GdaeXYVTOvd5j8N+Gtd3wAP7TzMuKtCwJPVDwvi5RvZjibikSW98y37ebdztWzA6XwaO7BRRMdF9ZYC6QYcJOver67POf5skDwvyjPB+J3pbfZkrIkdF9jqQU8BCaD50tEUYo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786420188; c=relaxed/simple; bh=VIDAzp2vdvRYK3x4QlJq9hC41n+2Mcff7IQn0gYnESE=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=Dih7R5W4HbtbL2/GU1/tjt0ubVI8fESSryMdqzAQfAO0AhQpWs881dmj9rXNTk9UoHLJwyt2ed8QHJSCg4gLNNCagZcwzKvK1huA1LErjRQuv9w1cDryxmpZUXiDWH/sfz0En+z0eqQtiKtN6x5RYEq3RRkxxy+WeXWUvxMrdiY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=surriel.com; spf=pass smtp.mailfrom=surriel.com; dkim=pass (2048-bit key) header.d=surriel.com header.i=@surriel.com header.b=OFwNOTRM; arc=none smtp.client-ip=96.67.55.147 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=surriel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=surriel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=surriel.com header.i=@surriel.com header.b="OFwNOTRM" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=surriel.com ; s=mail; h=MIME-Version:Content-Transfer-Encoding:Content-Type:References: In-Reply-To:Date:Cc:To:From:Subject:Message-ID:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=HW3ljMdDkgUv1pkjZ70wXHJIMtblhGmLTYZIquDiu0Q=; b=OFwNOTRMOyjs4QUS7/ZcavY3W6 QlN5oyjXBul0J155btHf5kU4SSlDLpi10hp3Lgfohi4mB+eQ3d5lBQBs4ro5eaEnfTCMjWA5iBNKq n2PZCGhyUoefCSXHxlmXgN6SAWiFgvJus4q7l/Ef9xFfTijNhvrLVhknGiHpk2INt2hMmAlAX45lv bdcY7mGhSjFeP6HECJQtZUe7sysGX985QgLut42PyQr5Yj6qD5YMNK4632QhuRxd3BZbSqoeaBDsK iBvbn8KwGrQOHQX542GGq17HZ+NF2bhMnfx0eckEY5qPNn3kLZg8M7ORhK2p+vf5jUB64v3zBjgX/ zJqvuwRg==; Received: from [96.67.55.146] by shelob.surriel.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.97.1) (envelope-from ) id 1wtdUB-000000000f6-2KzG; Mon, 10 Aug 2026 23:49:07 -0400 Message-ID: <007c8bf2717346bdba791e1a5079f4d0abad41f5.camel@surriel.com> Subject: Re: [RFC v2 PATCH] mm/cma: don't release CMA pages still in use From: Rik van Riel To: "David Hildenbrand (Arm)" , Andrew Morton Cc: Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Chris Mason , linux-mm@kvack.org, linux-kernel@vger.kernel.org Date: Mon, 10 Aug 2026 23:49:07 -0400 In-Reply-To: <50b1dadb-37f1-48a0-adf6-c6ff8b704582@kernel.org> References: <20260810122737.030f8452@fangorn> <50b1dadb-37f1-48a0-adf6-c6ff8b704582@kernel.org> Autocrypt: addr=riel@surriel.com; prefer-encrypt=mutual; keydata=mQENBFIt3aUBCADCK0LicyCYyMa0E1lodCDUBf6G+6C5UXKG1jEYwQu49cc/gUBTTk33A eo2hjn4JinVaPF3zfZprnKMEGGv4dHvEOCPWiNhlz5RtqH3SKJllq2dpeMS9RqbMvDA36rlJIIo47 Z/nl6IA8MDhSqyqdnTY8z7LnQHqq16jAqwo7Ll9qALXz4yG1ZdSCmo80VPetBZZPw7WMjo+1hByv/ lvdFnLfiQ52tayuuC1r9x2qZ/SYWd2M4p/f5CLmvG9UcnkbYFsKWz8bwOBWKg1PQcaYHLx06sHGdY dIDaeVvkIfMFwAprSo5EFU+aes2VB2ZjugOTbkkW2aPSWTRsBhPHhV6dABEBAAG0HlJpayB2YW4gU mllbCA8cmllbEByZWRoYXQuY29tPokBHwQwAQIACQUCW5LcVgIdIAAKCRDOed6ShMTeg05SB/986o gEgdq4byrtaBQKFg5LWfd8e+h+QzLOg/T8mSS3dJzFXe5JBOfvYg7Bj47xXi9I5sM+I9Lu9+1XVb/ r2rGJrU1DwA09TnmyFtK76bgMF0sBEh1ECILYNQTEIemzNFwOWLZZlEhZFRJsZyX+mtEp/WQIygHV WjwuP69VJw+fPQvLOGn4j8W9QXuvhha7u1QJ7mYx4dLGHrZlHdwDsqpvWsW+3rsIqs1BBe5/Itz9o 6y9gLNtQzwmSDioV8KhF85VmYInslhv5tUtMEppfdTLyX4SUKh8ftNIVmH9mXyRCZclSoa6IMd635 Jq1Pj2/Lp64tOzSvN5Y9zaiCc5FucXtB9SaWsgdmFuIFJpZWwgPHJpZWxAc3VycmllbC5jb20+iQE +BBMBAgAoBQJSLd2lAhsjBQkSzAMABgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRDOed6ShMTe g4PpB/0ZivKYFt0LaB22ssWUrBoeNWCP1NY/lkq2QbPhR3agLB7ZXI97PF2z/5QD9Fuy/FD/jddPx KRTvFCtHcEzTOcFjBmf52uqgt3U40H9GM++0IM0yHusd9EzlaWsbp09vsAV2DwdqS69x9RPbvE/Ne fO5subhocH76okcF/aQiQ+oj2j6LJZGBJBVigOHg+4zyzdDgKM+jp0bvDI51KQ4XfxV593OhvkS3z 3FPx0CE7l62WhWrieHyBblqvkTYgJ6dq4bsYpqxxGJOkQ47WpEUx6onH+rImWmPJbSYGhwBzTo0Mm G1Nb1qGPG+mTrSmJjDRxrwf1zjmYqQreWVSFEt26tBpSaWsgdmFuIFJpZWwgPHJpZWxAZmIuY29tP okBPgQTAQIAKAUCW5LbiAIbIwUJEswDAAYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQznneko TE3oOUEQgAsrGxjTC1bGtZyuvyQPcXclap11Ogib6rQywGYu6/Mnkbd6hbyY3wpdyQii/cas2S44N cQj8HkGv91JLVE24/Wt0gITPCH3rLVJJDGQxprHTVDs1t1RAbsbp0XTksZPCNWDGYIBo2aHDwErhI omYQ0Xluo1WBtH/UmHgirHvclsou1Ks9jyTxiPyUKRfae7GNOFiX99+ZlB27P3t8CjtSO831Ij0Ip QrfooZ21YVlUKw0Wy6Ll8EyefyrEYSh8KTm8dQj4O7xxvdg865TLeLpho5PwDRF+/mR3qi8CdGbkE c4pYZQO8UDXUN4S+pe0aTeTqlYw8rRHWF9TnvtpcNzZw== Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.60.2 (3.60.2-1.fc44) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Mon, 2026-08-10 at 20:53 +0200, David Hildenbrand (Arm) wrote: > On 8/10/26 18:27, Rik van Riel wrote: > > When a driver calls dma_free_contiguous() before quiescing DMA, the > > page still has a reference from the device. put_page_testzero() > > there > > returns false, WARN fires, but the code proceeds to > > free_contig_frozen_range() putting a live page onto buddy and > > clearing > > the bitmap. Later cma_alloc() hands the same PFN to a new owner > > while > > the original holder still references it. >=20 > Hm, it rather sounds like it's really the drivers job to quiescing > DMA. Are you > aware of an in-tree driver that can trigger this, and if so, how? >=20 > Freeing memory through CMA, while the memory is still in use is > problematic for > CMA as you discovered :) I agree the driver should not be doing that.=C2=A0 I do not know of any driver that currently does it, but it has led to CVE-2025-37837 in the past, and there appear to have been other cases of this issue happening. > > + WARN(skipped, "%lu pages are still in use!\n", skipped); >=20 >=20 > We still issue a WARN, which itself is problematic. See "Do not WARN > lightly" in > Documentation/process/coding-style.rst. >=20 > So it's either >=20 > (a) This scenario is valid to be triggered. In that case, WARN is not > appropriate. >=20 > (b) This scenario is not valid to be triggered. In that case, this is > not a fix. If a driver does it with the current code, it can=C2=A0 cause free list corruption, with potential for temporary data exposure, until the system crashes. If we get rid of the free list corruption, it can continue to be a WARN, since it will no longer kill the system. If we continue to corrupt the free list when this happens, it should probably be a panic? A simpler fix may be to not free any of the memory, or the CMA address space, if there are still pages in use at cma_release() time. --=20 All Rights Reversed.