mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Nick Piggin <npiggin@suse.de>
To: Andrew Morton <akpm@linux-foundation.org>
Cc: Dave Airlie <airlied@gmail.com>,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org,
	benh@kernel.crashing.org
Subject: Re: [patch 0/6] fault vs truncate/invalidate race fix
Date: Tue, 27 Feb 2007 09:50:25 +0100	[thread overview]
Message-ID: <20070227085025.GA2710@wotan.suse.de> (raw)
In-Reply-To: <20070226213204.14f8b584.akpm@linux-foundation.org>

On Mon, Feb 26, 2007 at 09:32:04PM -0800, Andrew Morton wrote:
> > On Tue, 27 Feb 2007 15:36:03 +1100 "Dave Airlie" <airlied@gmail.com> wrote:
> > >
> > > I've also got rid of the horrible populate API, and integrated nonlinear pages
> > > properly with the page fault path.
> > >
> > > Downside is that this adds one more vector through which the buffered write
> > > deadlock can occur. However this is just a very tiny one (pte being unmapped
> > > for reclaim), compared to all the other ways that deadlock can occur (unmap,
> > > reclaim, truncate, invalidate). I doubt it will be noticable. At any rate, it
> > > is better than data corruption.
> > >
> > > I hope these can get merged (at least into -mm) soon.
> > 
> > Have these been put into mm?
> 
> Not yet - I need to get back on the correct continent, review the code,
> stuff like that.  It still hurts that this work makes the write() deadlock
> harder to hit,

s/harder/easier of course...

I think there is good reason to assume the buffered write page lock
deadlocks would not occur in "normal" programs (or very very few),
because it would require writing from the same page you are writing to,
or 2 processes writing from the page the other is writing to. If any
innocent users do hit this, at least it is not data corrupting, and is
relatively easy to trace back to the kernel.

In the case of local DoS exploits, the deadlocks already present in the
buffered write path are already trivial to exploit...  locking the page
in the fault path doesn't make the deadlock exploit any more possible.

So the downside to merging is that we _may_ get some additional deadlocks.

What is being fixed is silent data corruption that has been reported by
several different users of the SLES kernel (because we have assertions
there to catch it), and can be triggered by DIO or NFS, or anything using
vmtruncate_range or invalidate_inode_pages2 on regular files. Or even a
regular truncate with nonlinear pages. These are known problems on
production workloads.

That's my argument for merging these. I think it's reasonable, but I'm
open to debate.

I did get some page fault performance numbers at one stage. Nothing
really exciting seemed to happen IIRC, but I can do another set of tests
if you want?

> and we haven't worked out how to fix that.

To be fair, I have 2 ways to fix it. Unfortunately one is slow and the
other requires cooperation from filesystem developers. perform_write() is
still on track, but it is going to take a reasonable amount of time and
effort to convert filesystems. I just can't see any gain in holding these
patches back until that all happens.

Thanks,
Nick

      parent reply	other threads:[~2007-02-27  8:50 UTC|newest]

Thread overview: 99+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-02-21  4:49 Nick Piggin
2007-02-21  4:49 ` [patch 1/6] mm: debug check for the fault vs invalidate race Nick Piggin
2007-02-21  4:49 ` [patch 2/6] mm: simplify filemap_nopage Nick Piggin
2007-02-21  4:50 ` [patch 3/6] mm: fix fault vs invalidate race for linear mappings Nick Piggin
2007-03-07  6:36   ` Andrew Morton
2007-03-07  6:57     ` Nick Piggin
2007-03-07  7:08       ` Andrew Morton
2007-03-07  7:25         ` Nick Piggin
2007-02-21  4:50 ` [patch 4/6] mm: merge populate and nopage into fault (fixes nonlinear) Nick Piggin
2007-03-07  6:51   ` Andrew Morton
2007-03-07  7:08     ` Nick Piggin
2007-03-07  8:19       ` Nick Piggin
2007-03-07  8:27         ` Ingo Molnar
2007-03-07  8:35           ` Andrew Morton
2007-03-07  8:53             ` Ingo Molnar
2007-03-07  9:28               ` Nick Piggin
2007-03-07  9:44                 ` Bill Irwin
2007-03-07  9:49                   ` Nick Piggin
2007-03-07 10:02                     ` Nick Piggin
2007-03-12 23:01                       ` Blaisorblade
2007-03-13  1:19                         ` Nick Piggin
2007-03-17 12:17                           ` Blaisorblade
2007-03-18  2:50                             ` Nick Piggin
2007-03-18 13:09                               ` Jeff Dike
2007-03-19 12:04                               ` Bill Irwin
2007-03-19 20:44                               ` Blaisorblade
2007-03-20  6:00                                 ` Nick Piggin
2007-03-21 19:45                                   ` Blaisorblade
2007-03-08 12:39                   ` Blaisorblade
2007-03-07  9:29             ` Bill Irwin
2007-03-07  9:39               ` Andrew Morton
2007-03-07 10:09                 ` Bill Irwin
2007-03-07  8:38           ` Miklos Szeredi
2007-03-07  8:47             ` Andrew Morton
2007-03-07  8:51               ` Miklos Szeredi
2007-03-07  9:07                 ` Andrew Morton
2007-03-07  9:18                   ` Nick Piggin
2007-03-07  9:26                     ` Andrew Morton
2007-03-07  9:28                       ` Miklos Szeredi
2007-03-07  9:38                       ` Nick Piggin
2007-03-07  9:25                   ` Miklos Szeredi
2007-03-07  9:32                   ` Peter Zijlstra
2007-03-07  9:45                     ` Nick Piggin
2007-03-07 10:04                       ` Nick Piggin
2007-03-07 10:06                         ` Peter Zijlstra
2007-03-07 10:13                           ` Miklos Szeredi
2007-03-07 10:21                             ` Nick Piggin
2007-03-07 10:24                               ` Peter Zijlstra
2007-03-07 10:38                                 ` Nick Piggin
2007-03-07 10:47                                   ` Peter Zijlstra
2007-03-07 11:00                                     ` Nick Piggin
2007-03-07 11:48                                       ` Peter Zijlstra
2007-03-07 12:17                                         ` Nick Piggin
2007-03-07 12:41                                           ` Peter Zijlstra
2007-03-07 13:08                                             ` Nick Piggin
2007-03-07 13:19                                               ` Peter Zijlstra
2007-03-07 13:36                                                 ` Nick Piggin
2007-03-07 13:52                                                   ` Peter Zijlstra
2007-03-07 13:56                                                     ` Miklos Szeredi
2007-03-07 14:34                                                     ` Peter Zijlstra
2007-03-07 15:01                                                       ` Nick Piggin
2007-03-07 16:58                                                         ` [RFC][PATCH] mm: fix page_mkclean() vs non-linear vmas Peter Zijlstra
2007-03-07 18:00                                                           ` Linus Torvalds
2007-03-07 18:12                                                             ` Peter Zijlstra
2007-03-07 18:24                                                               ` Peter Zijlstra
2007-03-08 11:21                                                           ` Miklos Szeredi
2007-03-08 11:37                                                             ` Peter Zijlstra
2007-03-08 11:48                                                               ` Miklos Szeredi
2007-03-08 12:11                                                                 ` Peter Zijlstra
2007-03-08 12:19                                                                   ` Nick Piggin
2007-03-08 12:25                                                                     ` Miklos Szeredi
2007-03-08 11:58                                                             ` Nick Piggin
2007-03-08 12:09                                                               ` Miklos Szeredi
2007-03-07 15:10                                                     ` [patch 4/6] mm: merge populate and nopage into fault (fixes nonlinear) Jeff Dike
2007-03-07 13:53                                                   ` Miklos Szeredi
2007-03-07 14:50                                                     ` Nick Piggin
2007-03-07 12:22                                       ` Bill Irwin
2007-03-07 12:36                                         ` Nick Piggin
2007-03-07 10:30                             ` [rfc][patch 7/6] mm: merge page_mkwrite Nick Piggin
2007-03-07  8:59           ` [patch 4/6] mm: merge populate and nopage into fault (fixes nonlinear) Nick Piggin
2007-03-07  9:11             ` Nick Piggin
2007-03-07  9:22             ` Ingo Molnar
2007-03-07  9:32               ` Bill Irwin
2007-03-07  9:35                 ` Ingo Molnar
2007-03-07  9:50                   ` Bill Irwin
2007-03-07  9:52               ` Nick Piggin
2007-03-07  7:19     ` Bill Irwin
2007-03-07 10:05     ` Benjamin Herrenschmidt
2007-03-07 10:17       ` Nick Piggin
2007-03-07 10:46         ` Benjamin Herrenschmidt
2007-02-21  4:50 ` [patch 5/6] mm: merge nopfn into fault Nick Piggin
2007-02-21  5:13   ` Nick Piggin
2007-02-21  4:50 ` [patch 6/6] mm: remove legacy cruft Nick Piggin
2007-02-27  4:36 ` [patch 0/6] fault vs truncate/invalidate race fix Dave Airlie
2007-02-27  5:32   ` Andrew Morton
2007-02-27  6:26     ` Dave Airlie
2007-02-27  6:54       ` Benjamin Herrenschmidt
2007-03-18 23:13         ` Dave Airlie
2007-02-27  8:50     ` Nick Piggin [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20070227085025.GA2710@wotan.suse.de \
    --to=npiggin@suse.de \
    --cc=airlied@gmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=benh@kernel.crashing.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®