mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk, Youquan Song <youquan.song@intel.com>,
	Andi Kleen <andi@firstfloor.org>
Subject: [10/45] thp: add compound tail page _mapcount when mapped
Date: Fri, 16 Dec 2011 11:40:17 -0800	[thread overview]
Message-ID: <20111216194208.378007069@clark.kroah.org> (raw)
In-Reply-To: <20111216194603.GA15028@kroah.com>

3.0-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Youquan Song <youquan.song@intel.com>

commit b6999b19120931ede364fa3b685e698a61fed31d upstream.

With the 3.2-rc kernel, IOMMU 2M pages in KVM works.  But when I tried
to use IOMMU 1GB pages in KVM, I encountered an oops and the 1GB page
failed to be used.

The root cause is that 1GB page allocation calls gup_huge_pud() while 2M
page calls gup_huge_pmd.  If compound pages are used and the page is a
tail page, gup_huge_pmd() increases _mapcount to record tail page are
mapped while gup_huge_pud does not do that.

So when the mapped page is relesed, it will result in kernel oops
because the page is not marked mapped.

This patch add tail process for compound page in 1GB huge page which
keeps the same process as 2M page.

Reproduce like:
1. Add grub boot option: hugepagesz=1G hugepages=8
2. mount -t hugetlbfs -o pagesize=1G hugetlbfs /dev/hugepages
3. qemu-kvm -m 2048 -hda os-kvm.img -cpu kvm64 -smp 4 -mem-path /dev/hugepages
	-net none -device pci-assign,host=07:00.1

  kernel BUG at mm/swap.c:114!
  invalid opcode: 0000 [#1] SMP
  Call Trace:
    put_page+0x15/0x37
    kvm_release_pfn_clean+0x31/0x36
    kvm_iommu_put_pages+0x94/0xb1
    kvm_iommu_unmap_memslots+0x80/0xb6
    kvm_assign_device+0xba/0x117
    kvm_vm_ioctl_assigned_device+0x301/0xa47
    kvm_vm_ioctl+0x36c/0x3a2
    do_vfs_ioctl+0x49e/0x4e4
    sys_ioctl+0x5a/0x7c
    system_call_fastpath+0x16/0x1b
  RIP  put_compound_page+0xd4/0x168

Signed-off-by: Youquan Song <youquan.song@intel.com>
Reviewed-by: Andrea Arcangeli <aarcange@redhat.com>
Cc: Andi Kleen <andi@firstfloor.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 arch/x86/mm/gup.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/arch/x86/mm/gup.c
+++ b/arch/x86/mm/gup.c
@@ -201,6 +201,8 @@ static noinline int gup_huge_pud(pud_t p
 	do {
 		VM_BUG_ON(compound_head(page) != head);
 		pages[*nr] = page;
+		if (PageTail(page))
+			get_huge_page_tail(page);
 		(*nr)++;
 		page++;
 		refs++;



  parent reply	other threads:[~2011-12-16 19:54 UTC|newest]

Thread overview: 47+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-12-16 19:46 [00/45] 3.0.14-stable review Greg KH
2011-12-16 19:40 ` [01/45] ALSA: sis7019 - give slow codecs more time to reset Greg KH
2011-12-16 19:40 ` [02/45] ALSA: hda/realtek - Fix Oops in alc_mux_select() Greg KH
2011-12-16 19:40 ` [03/45] alarmtimers: Fix time comparison Greg KH
2011-12-16 19:40 ` [04/45] ARM: davinci: da850 evm: change audio edma event queue to EVENTQ_0 Greg KH
2011-12-16 19:40 ` [05/45] arm: mx23: recognise stmp378x as mx23 Greg KH
2011-12-16 19:40 ` [06/45] ARM: at91: fix clock conid for atmel_tcb.1 on 9260/9g20 Greg KH
2011-12-16 19:40 ` [07/45] ARM: davinci: dm646x evm: wrong register used in setup_vpif_input_channel_mode Greg KH
2011-12-16 19:40 ` [08/45] ASoC: Provide a more complete DMA driver stub Greg KH
2011-12-16 19:40 ` [09/45] fs/proc/meminfo.c: fix compilation error Greg KH
2011-12-16 19:40 ` Greg KH [this message]
2011-12-16 19:40 ` [11/45] thp: set compound tail page _count to zero Greg KH
2011-12-16 19:40 ` [12/45] ptp: Fix clock_getres() implementation Greg KH
2011-12-16 19:40 ` [13/45] mm: Ensure that pfn_valid() is called once per pageblock when reserving pageblocks Greg KH
2011-12-16 19:40 ` [14/45] mm: vmalloc: check for page allocation failure before vmlist insertion Greg KH
2011-12-16 19:40 ` [15/45] fix apparmor dereferencing potentially freed dentry, sanitize __d_path() API Greg KH
2011-12-16 19:40 ` [16/45] target: Handle 0 correctly in transport_get_sectors_6() Greg KH
2011-12-16 19:40 ` [17/45] intel-iommu: fix return value of iommu_unmap() API Greg KH
2011-12-16 19:40 ` [18/45] intel-iommu: set iommu_superpage on VM domains to lowest common denominator Greg KH
2011-12-16 19:40 ` [19/45] intel-iommu: fix superpage support in pfn_to_dma_pte() Greg KH
2011-12-16 19:40 ` [20/45] percpu: fix chunk range calculation Greg KH
2011-12-16 19:40 ` [21/45] iwlwifi: do not re-configure HT40 after associated Greg KH
2011-12-16 19:40 ` [22/45] mac80211: fix race condition caused by late addBA response Greg KH
2011-12-16 19:40 ` [23/45] linux/log2.h: Fix rounddown_pow_of_two(1) Greg KH
2011-12-16 19:40 ` [24/45] hwmon: (jz4740) fix signedness bug Greg KH
2011-12-16 19:40 ` [25/45] mmc: mxcmmc: fix falling back to PIO Greg KH
2011-12-16 19:40 ` [26/45] x86, hpet: Immediately disable HPET timer 1 if rtc irq is masked Greg KH
2011-12-16 19:40 ` [27/45] jbd/jbd2: validate sb->s_first in journal_get_superblock() Greg KH
2011-12-16 19:40 ` [28/45] Make TASKSTATS require root access Greg KH
2011-12-16 19:40 ` [29/45] hfs: fix hfs_find_init() sb->ext_tree NULL ptr oops Greg KH
2011-12-16 19:40 ` [30/45] hwmon: (coretemp) Fix oops on CPU offlining Greg KH
2011-12-16 22:19   ` Yu, Fenghua
2011-12-16 19:40 ` [31/45] xfs: fix nfs export of 64-bit inodes numbers on 32-bit kernels Greg KH
2011-12-16 19:40 ` [32/45] xfs: avoid synchronous transactions when deleting attr blocks Greg KH
2011-12-16 19:40 ` [33/45] md/raid5: fix bug that could result in reads from a failed device Greg KH
2011-12-16 19:40 ` [34/45] xen: only limit memory map to maximum reservation for domain 0 Greg KH
2011-12-16 19:40 ` [35/45] ext4: display the correct mount option in /proc/mounts for [no]init_itable Greg KH
2011-12-16 19:40 ` [36/45] ext4: avoid hangs in ext4_da_should_update_i_disksize() Greg KH
2011-12-16 19:40 ` [37/45] ext4: avoid potential hang in mpage_submit_io() when blocksize < pagesize Greg KH
2011-12-16 19:40 ` [38/45] ext4: handle EOF correctly in ext4_bio_write_page() Greg KH
2011-12-16 19:40 ` [39/45] fuse: fix fuse_retrieve Greg KH
2011-12-16 19:40 ` [40/45] staging: r8712u: Add new USB ID Greg KH
2011-12-16 19:40 ` [41/45] drm/radeon/kms: add some new pci ids Greg KH
2011-12-16 19:40 ` [42/45] ibft: Fix finding IBFT ACPI table on UEFI Greg KH
2011-12-16 19:40 ` [43/45] USB: cdc-acm: add IDs for Motorola H24 HSPA USB module Greg KH
2011-12-16 19:40 ` [44/45] usb: option: Add Huawei E398 controlling interfaces Greg KH
2011-12-16 19:40 ` [45/45] USB: option: Removing one bogus and adding some new Huawei combinations Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20111216194208.378007069@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=andi@firstfloor.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=youquan.song@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®