From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk, Youquan Song <youquan.song@intel.com>
Subject: [14/53] thp: set compound tail page _count to zero
Date: Fri, 16 Dec 2011 11:45:11 -0800 [thread overview]
Message-ID: <20111216194556.292933403@clark.kroah.org> (raw)
In-Reply-To: <20111216194613.GA18395@kroah.com>
3.1-stable review patch. If anyone has any objections, please let me know.
------------------
From: Youquan Song <youquan.song@intel.com>
commit 58a84aa92723d1ac3e1cc4e3b0ff49291663f7e1 upstream.
Commit 70b50f94f1644 ("mm: thp: tail page refcounting fix") keeps all
page_tail->_count zero at all times. But the current kernel does not
set page_tail->_count to zero if a 1GB page is utilized. So when an
IOMMU 1GB page is used by KVM, it wil result in a kernel oops because a
tail page's _count does not equal zero.
kernel BUG at include/linux/mm.h:386!
invalid opcode: 0000 [#1] SMP
Call Trace:
gup_pud_range+0xb8/0x19d
get_user_pages_fast+0xcb/0x192
? trace_hardirqs_off+0xd/0xf
hva_to_pfn+0x119/0x2f2
gfn_to_pfn_memslot+0x2c/0x2e
kvm_iommu_map_pages+0xfd/0x1c1
kvm_iommu_map_memslots+0x7c/0xbd
kvm_iommu_map_guest+0xaa/0xbf
kvm_vm_ioctl_assigned_device+0x2ef/0xa47
kvm_vm_ioctl+0x36c/0x3a2
do_vfs_ioctl+0x49e/0x4e4
sys_ioctl+0x5a/0x7c
system_call_fastpath+0x16/0x1b
RIP gup_huge_pud+0xf2/0x159
Signed-off-by: Youquan Song <youquan.song@intel.com>
Reviewed-by: Andrea Arcangeli <aarcange@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
mm/hugetlb.c | 1 +
mm/page_alloc.c | 2 +-
2 files changed, 2 insertions(+), 1 deletion(-)
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -576,6 +576,7 @@ static void prep_compound_gigantic_page(
__SetPageHead(page);
for (i = 1; i < nr_pages; i++, p = mem_map_next(p, page, i)) {
__SetPageTail(p);
+ set_page_count(p, 0);
p->first_page = page;
}
}
--- a/mm/page_alloc.c
+++ b/mm/page_alloc.c
@@ -355,8 +355,8 @@ void prep_compound_page(struct page *pag
__SetPageHead(page);
for (i = 1; i < nr_pages; i++) {
struct page *p = page + i;
-
__SetPageTail(p);
+ set_page_count(p, 0);
p->first_page = page;
}
}
next prev parent reply other threads:[~2011-12-16 19:48 UTC|newest]
Thread overview: 54+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-12-16 19:46 [00/53] 3.1.6-stable review Greg KH
2011-12-16 19:44 ` [01/53] ALSA: sis7019 - give slow codecs more time to reset Greg KH
2011-12-16 19:44 ` [02/53] ALSA: hda/realtek - Fix Oops in alc_mux_select() Greg KH
2011-12-16 19:45 ` [03/53] ALSA: hda - Fix GPIO LED setup for IDT 92HD75 codecs Greg KH
2011-12-16 19:45 ` [04/53] alarmtimers: Fix time comparison Greg KH
2011-12-16 19:45 ` [05/53] ARM: davinci: da850 evm: change audio edma event queue to EVENTQ_0 Greg KH
2011-12-16 19:45 ` [06/53] arm: mx23: recognise stmp378x as mx23 Greg KH
2011-12-16 19:45 ` [07/53] ARM: at91: fix clock conid for atmel_tcb.1 on 9260/9g20 Greg KH
2011-12-16 19:45 ` [08/53] ARM: at91: Fix USB AT91 gadget registration Greg KH
2011-12-16 19:45 ` [09/53] ARM: davinci: dm646x evm: wrong register used in setup_vpif_input_channel_mode Greg KH
2011-12-16 19:45 ` [10/53] ASoC: Provide a more complete DMA driver stub Greg KH
2011-12-16 19:45 ` [11/53] drivers/rtc/rtc-s3c.c: fix driver clock enable/disable balance issues Greg KH
2011-12-16 19:45 ` [12/53] fs/proc/meminfo.c: fix compilation error Greg KH
2011-12-16 19:45 ` [13/53] thp: add compound tail page _mapcount when mapped Greg KH
2011-12-16 19:45 ` Greg KH [this message]
2011-12-16 19:45 ` [15/53] lockdep, kmemcheck: Annotate ->lock in lockdep_init_map() Greg KH
2011-12-16 19:45 ` [16/53] ptp: Fix clock_getres() implementation Greg KH
2011-12-16 19:45 ` [17/53] mm: Ensure that pfn_valid() is called once per pageblock when reserving pageblocks Greg KH
2011-12-16 19:45 ` [18/53] mm: vmalloc: check for page allocation failure before vmlist insertion Greg KH
2011-12-16 19:45 ` [19/53] fix apparmor dereferencing potentially freed dentry, sanitize __d_path() API Greg KH
2011-12-16 19:45 ` [20/53] TOMOYO: Fix pathname handling of disconnected paths Greg KH
2011-12-16 19:45 ` [21/53] target: Reject SCSI data overflow for fabrics using transport_generic_map_mem_to_cmd Greg KH
2011-12-16 19:45 ` [22/53] iscsi-target: Fix residual count hanlding + remove iscsi_cmd->residual_count Greg KH
2011-12-16 19:45 ` [23/53] target: Handle 0 correctly in transport_get_sectors_6() Greg KH
2011-12-16 19:45 ` [24/53] target: Fix page length in emulated INQUIRY VPD page 86h Greg KH
2011-12-16 19:45 ` [25/53] iscsi-target: Add missing F_BIT for iscsi_tm_rsp Greg KH
2011-12-16 19:45 ` [26/53] target/file: walk properly over sg list Greg KH
2011-12-16 19:45 ` [27/53] percpu: fix chunk range calculation Greg KH
2011-12-16 19:45 ` [28/53] cifs: check for NULL last_entry before calling cifs_save_resume_key Greg KH
2011-12-16 19:45 ` [29/53] linux/log2.h: Fix rounddown_pow_of_two(1) Greg KH
2011-12-16 19:45 ` [30/53] hwmon: (jz4740) fix signedness bug Greg KH
2011-12-16 19:45 ` [31/53] ARM: 7204/1: arch/arm/kernel/setup.c: initialize arm_dma_zone_size earlier Greg KH
2011-12-16 19:45 ` [32/53] mmc: mxcmmc: fix falling back to PIO Greg KH
2011-12-16 19:45 ` [33/53] xen/pm_idle: Make pm_idle be default_idle under Xen Greg KH
2011-12-16 19:45 ` [34/53] x86, hpet: Immediately disable HPET timer 1 if rtc irq is masked Greg KH
2011-12-16 19:45 ` [35/53] jbd/jbd2: validate sb->s_first in journal_get_superblock() Greg KH
2011-12-16 19:45 ` [36/53] hfs: fix hfs_find_init() sb->ext_tree NULL ptr oops Greg KH
2011-12-16 19:45 ` [37/53] drm/radeon/kms: cleanup atombios_adjust_pll() Greg KH
2011-12-16 19:45 ` [38/53] drm/radeon/kms: rework DP bridge checks Greg KH
2011-12-16 19:45 ` [39/53] drm/radeon/kms: fix DP setup on TRAVIS bridges Greg KH
2011-12-16 19:45 ` [40/53] xen: only limit memory map to maximum reservation for domain 0 Greg KH
2011-12-16 19:45 ` [41/53] ext4: fix ext4_end_io_dio() racing against fsync() Greg KH
2011-12-16 19:45 ` [42/53] ext4: display the correct mount option in /proc/mounts for [no]init_itable Greg KH
2011-12-16 19:45 ` [43/53] ext4: avoid hangs in ext4_da_should_update_i_disksize() Greg KH
2011-12-16 19:45 ` [44/53] ext4: avoid potential hang in mpage_submit_io() when blocksize < pagesize Greg KH
2011-12-16 19:45 ` [45/53] ext4: handle EOF correctly in ext4_bio_write_page() Greg KH
2011-12-16 19:45 ` [46/53] fuse: fix fuse_retrieve Greg KH
2011-12-16 19:45 ` [47/53] fuse: fix llseek bug Greg KH
2011-12-16 19:45 ` [48/53] staging: r8712u: Add new USB ID Greg KH
2011-12-16 19:45 ` [49/53] drm/radeon/kms: add some new pci ids Greg KH
2011-12-16 19:45 ` [50/53] ibft: Fix finding IBFT ACPI table on UEFI Greg KH
2011-12-16 19:45 ` [51/53] USB: cdc-acm: add IDs for Motorola H24 HSPA USB module Greg KH
2011-12-16 19:45 ` [52/53] usb: option: Add Huawei E398 controlling interfaces Greg KH
2011-12-16 19:45 ` [53/53] USB: option: Removing one bogus and adding some new Huawei combinations Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20111216194556.292933403@clark.kroah.org \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=youquan.song@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®