From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk,
Xiao Guangrong <xiaoguangrong@linux.vnet.ibm.com>,
Avi Kivity <avi@redhat.com>,
Marcelo Tosatti <mtosatti@redhat.com>,
Paul Gortmaker <paul.gortmaker@windriver.com>,
Andrea Arcangeli <aarcange@redhat.com>
Subject: [ 56/70] mm: mmu_notifier: fix freed page still mapped in secondary MMU
Date: Tue, 07 Aug 2012 04:28:51 +0100 [thread overview]
Message-ID: <20120807032804.224482411@decadent.org.uk> (raw)
In-Reply-To: <20120807032755.803571133@decadent.org.uk>
3.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiao Guangrong <xiaoguangrong@linux.vnet.ibm.com>
commit 3ad3d901bbcfb15a5e4690e55350db0899095a68 upstream.
mmu_notifier_release() is called when the process is exiting. It will
delete all the mmu notifiers. But at this time the page belonging to the
process is still present in page tables and is present on the LRU list, so
this race will happen:
CPU 0 CPU 1
mmu_notifier_release: try_to_unmap:
hlist_del_init_rcu(&mn->hlist);
ptep_clear_flush_notify:
mmu nofifler not found
free page !!!!!!
/*
* At the point, the page has been
* freed, but it is still mapped in
* the secondary MMU.
*/
mn->ops->release(mn, mm);
Then the box is not stable and sometimes we can get this bug:
[ 738.075923] BUG: Bad page state in process migrate-perf pfn:03bec
[ 738.075931] page:ffffea00000efb00 count:0 mapcount:0 mapping: (null) index:0x8076
[ 738.075936] page flags: 0x20000000000014(referenced|dirty)
The same issue is present in mmu_notifier_unregister().
We can call ->release before deleting the notifier to ensure the page has
been unmapped from the secondary MMU before it is freed.
Signed-off-by: Xiao Guangrong <xiaoguangrong@linux.vnet.ibm.com>
Cc: Avi Kivity <avi@redhat.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>
Cc: Paul Gortmaker <paul.gortmaker@windriver.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
mm/mmu_notifier.c | 45 +++++++++++++++++++++++----------------------
1 file changed, 23 insertions(+), 22 deletions(-)
diff --git a/mm/mmu_notifier.c b/mm/mmu_notifier.c
index 9a611d3..862b608 100644
--- a/mm/mmu_notifier.c
+++ b/mm/mmu_notifier.c
@@ -33,6 +33,24 @@
void __mmu_notifier_release(struct mm_struct *mm)
{
struct mmu_notifier *mn;
+ struct hlist_node *n;
+
+ /*
+ * RCU here will block mmu_notifier_unregister until
+ * ->release returns.
+ */
+ rcu_read_lock();
+ hlist_for_each_entry_rcu(mn, n, &mm->mmu_notifier_mm->list, hlist)
+ /*
+ * if ->release runs before mmu_notifier_unregister it
+ * must be handled as it's the only way for the driver
+ * to flush all existing sptes and stop the driver
+ * from establishing any more sptes before all the
+ * pages in the mm are freed.
+ */
+ if (mn->ops->release)
+ mn->ops->release(mn, mm);
+ rcu_read_unlock();
spin_lock(&mm->mmu_notifier_mm->lock);
while (unlikely(!hlist_empty(&mm->mmu_notifier_mm->list))) {
@@ -46,23 +64,6 @@ void __mmu_notifier_release(struct mm_struct *mm)
* mmu_notifier_unregister to return.
*/
hlist_del_init_rcu(&mn->hlist);
- /*
- * RCU here will block mmu_notifier_unregister until
- * ->release returns.
- */
- rcu_read_lock();
- spin_unlock(&mm->mmu_notifier_mm->lock);
- /*
- * if ->release runs before mmu_notifier_unregister it
- * must be handled as it's the only way for the driver
- * to flush all existing sptes and stop the driver
- * from establishing any more sptes before all the
- * pages in the mm are freed.
- */
- if (mn->ops->release)
- mn->ops->release(mn, mm);
- rcu_read_unlock();
- spin_lock(&mm->mmu_notifier_mm->lock);
}
spin_unlock(&mm->mmu_notifier_mm->lock);
@@ -284,16 +285,13 @@ void mmu_notifier_unregister(struct mmu_notifier *mn, struct mm_struct *mm)
{
BUG_ON(atomic_read(&mm->mm_count) <= 0);
- spin_lock(&mm->mmu_notifier_mm->lock);
if (!hlist_unhashed(&mn->hlist)) {
- hlist_del_rcu(&mn->hlist);
-
/*
* RCU here will force exit_mmap to wait ->release to finish
* before freeing the pages.
*/
rcu_read_lock();
- spin_unlock(&mm->mmu_notifier_mm->lock);
+
/*
* exit_mmap will block in mmu_notifier_release to
* guarantee ->release is called before freeing the
@@ -302,8 +300,11 @@ void mmu_notifier_unregister(struct mmu_notifier *mn, struct mm_struct *mm)
if (mn->ops->release)
mn->ops->release(mn, mm);
rcu_read_unlock();
- } else
+
+ spin_lock(&mm->mmu_notifier_mm->lock);
+ hlist_del_rcu(&mn->hlist);
spin_unlock(&mm->mmu_notifier_mm->lock);
+ }
/*
* Wait any running method to finish, of course including
next prev parent reply other threads:[~2012-08-07 3:47 UTC|newest]
Thread overview: 75+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-08-07 3:27 [ 00/70] 3.2.27-stable review Ben Hutchings
2012-08-07 3:27 ` [ 01/70] sched: Fix race in task_group() Ben Hutchings
2012-08-07 3:27 ` [ 02/70] floppy: Cleanup disk->queue before caling put_disk() if add_disk() was never called Ben Hutchings
2012-08-07 22:49 ` Herton Ronaldo Krzesinski
2012-08-08 0:40 ` Ben Hutchings
2012-08-08 13:02 ` Herton Ronaldo Krzesinski
2012-08-07 3:27 ` [ 03/70] xen: mark local pages as FOREIGN in the m2p_override Ben Hutchings
2012-08-07 3:27 ` [ 04/70] [media] lirc_sir: make device registration work Ben Hutchings
2012-08-07 3:28 ` [ 05/70] stable: update references to older 2.6 versions for 3.x Ben Hutchings
2012-08-07 3:28 ` [ 06/70] ALSA: hda - add dock support for Thinkpad X230 Tablet Ben Hutchings
2012-08-07 3:28 ` [ 07/70] cfg80211: fix interface combinations check for ADHOC(IBSS) Ben Hutchings
2012-08-07 3:28 ` [ 08/70] m68k: Correct the Atari ALLOWINT definition Ben Hutchings
2012-08-07 3:28 ` [ 09/70] [media] ene_ir: Fix driver initialisation Ben Hutchings
2012-08-07 3:28 ` [ 10/70] nfsd4: our filesystems are normally case sensitive Ben Hutchings
2012-08-07 3:28 ` [ 11/70] random: Use arch_get_random_int instead of cycle counter if avail Ben Hutchings
2012-08-07 3:28 ` [ 12/70] random: Use arch-specific RNG to initialize the entropy store Ben Hutchings
2012-08-07 3:28 ` [ 13/70] random: Adjust the number of loops when initializing Ben Hutchings
2012-08-07 3:28 ` [ 14/70] random: make add_interrupt_randomness() do something sane Ben Hutchings
2012-08-07 3:28 ` [ 15/70] random: use lockless techniques in the interrupt path Ben Hutchings
2012-08-07 3:28 ` [ 16/70] random: create add_device_randomness() interface Ben Hutchings
2012-08-07 3:28 ` [ 17/70] usb: feed USB device information to the /dev/random driver Ben Hutchings
2012-08-07 3:28 ` [ 18/70] net: feed /dev/random with the MAC address when registering a device Ben Hutchings
2012-08-07 3:28 ` [ 19/70] random: use the arch-specific rng in xfer_secondary_pool Ben Hutchings
2012-08-07 3:28 ` [ 20/70] random: add new get_random_bytes_arch() function Ben Hutchings
2012-08-07 3:28 ` [ 21/70] rtc: wm831x: Feed the write counter into device_add_randomness() Ben Hutchings
2012-08-07 3:28 ` [ 22/70] mfd: wm831x: Feed the device UUID " Ben Hutchings
2012-08-07 3:28 ` [ 23/70] ASoC: wm8994: Ensure there are enough BCLKs for four channels Ben Hutchings
2012-08-07 3:28 ` [ 24/70] futex: Test for pi_mutex on fault in futex_wait_requeue_pi() Ben Hutchings
2012-08-07 3:28 ` [ 25/70] futex: Fix bug in WARN_ON for NULL q.pi_state Ben Hutchings
2012-08-07 3:28 ` [ 26/70] futex: Forbid uaddr == uaddr2 in futex_wait_requeue_pi() Ben Hutchings
2012-08-07 3:28 ` [ 27/70] video/smscufx: fix line counting in fb_write Ben Hutchings
2012-08-07 3:28 ` [ 28/70] Input: synaptics - handle out of bounds values from the hardware Ben Hutchings
2012-08-07 3:28 ` [ 29/70] ALSA: hda - Fix invalid D3 of headphone DAC on VT202x codecs Ben Hutchings
2012-08-07 3:28 ` [ 30/70] ALSA: mpu401: Fix missing initialization of irq field Ben Hutchings
2012-08-07 3:28 ` [ 31/70] x86, nops: Missing break resulting in incorrect selection on Intel Ben Hutchings
2012-08-07 3:28 ` [ 32/70] s390/mm: downgrade page table after fork of a 31 bit process Ben Hutchings
2012-08-07 3:28 ` [ 33/70] [IA64] Redefine ATOMIC_INIT and ATOMIC64_INIT to drop the casts Ben Hutchings
2012-08-07 3:28 ` [ 34/70] dm thin: reduce endio_hook pool size Ben Hutchings
2012-08-07 3:28 ` [ 35/70] dm thin: fix memory leak in process_prepared_mapping error paths Ben Hutchings
2012-08-07 3:28 ` [ 36/70] random: mix in architectural randomness in extract_buf() Ben Hutchings
2012-08-07 3:28 ` [ 37/70] asus-wmi: use ASUS_WMI_METHODID_DSTS2 as default DSTS ID Ben Hutchings
2012-08-07 3:28 ` [ 38/70] virtio-blk: Use block layer provided spinlock Ben Hutchings
2012-08-07 3:28 ` [ 39/70] s390/mm: fix fault handling for page table walk case Ben Hutchings
2012-08-07 3:28 ` [ 40/70] nfs: skip commit in releasepage if were freeing memory for fs-related reasons Ben Hutchings
2012-08-07 3:28 ` [ 41/70] md/raid1: dont abort a resync on the first badblock Ben Hutchings
2012-08-07 3:28 ` [ 42/70] pcdp: use early_ioremap/early_iounmap to access pcdp table Ben Hutchings
2012-08-07 3:28 ` [ 43/70] lib/vsprintf.c: kptr_restrict: fix pK-error in SysRq show-all-timers(Q) Ben Hutchings
2012-08-07 3:28 ` [ 44/70] nilfs2: fix deadlock issue between chcp and thaw ioctls Ben Hutchings
2012-08-07 3:28 ` [ 45/70] SUNRPC: return negative value in case rpcbind client creation error Ben Hutchings
2012-08-07 3:28 ` [ 46/70] ARM: 7466/1: disable interrupt before spinning endlessly Ben Hutchings
2012-08-07 3:28 ` [ 47/70] ARM: 7467/1: mutex: use generic xchg-based implementation for ARMv6+ Ben Hutchings
2012-08-07 3:28 ` [ 48/70] ARM: 7476/1: vfp: only clear vfp state for current cpu in vfp_pm_suspend Ben Hutchings
2012-08-07 3:28 ` [ 49/70] ARM: 7477/1: vfp: Always save VFP state in vfp_pm_suspend on UP Ben Hutchings
2012-08-07 3:28 ` [ 50/70] ARM: 7478/1: errata: extend workaround for erratum #720789 Ben Hutchings
2012-08-07 3:28 ` [ 51/70] ARM: Fix undefined instruction exception handling Ben Hutchings
2012-08-07 3:28 ` [ 52/70] USB: echi-dbgp: increase the controller wait time to come out of halt Ben Hutchings
2012-08-07 3:28 ` [ 53/70] ASoC: wm8962: Allow VMID time to fully ramp Ben Hutchings
2012-08-07 3:28 ` [ 54/70] mm/page_alloc.c: remove pageblock_default_order() Ben Hutchings
2012-08-07 3:28 ` [ 55/70] mm: setup pageblock_order before its used by sparsemem Ben Hutchings
2012-08-07 3:28 ` Ben Hutchings [this message]
2012-08-07 3:28 ` [ 57/70] mm: hugetlbfs: close race during teardown of hugetlbfs shared page tables Ben Hutchings
2012-08-07 3:28 ` [ 58/70] ALSA: snd-usb: fix clock source validity index Ben Hutchings
2012-08-07 3:28 ` [ 59/70] ALSA: hda - Support dock on Lenovo Thinkpad T530 with ALC269VC Ben Hutchings
2012-08-07 3:28 ` [ 60/70] ore: Fix out-of-bounds access in _ios_obj() Ben Hutchings
2012-08-07 3:28 ` [ 61/70] m68k: Make sys_atomic_cmpxchg_32 work on classic m68k Ben Hutchings
2012-08-07 3:28 ` [ 62/70] drm/i915: prefer wide & slow to fast & narrow in DP configs Ben Hutchings
2012-08-07 3:28 ` [ 63/70] rt2x00: Add support for BUFFALO WLI-UC-GNM2 to rt2800usb Ben Hutchings
2012-08-07 3:28 ` [ 64/70] drop_monitor: fix sleeping in invalid context warning Ben Hutchings
2012-08-07 3:29 ` [ 65/70] drop_monitor: Make updating data->skb smp safe Ben Hutchings
2012-08-07 3:29 ` [ 66/70] drop_monitor: prevent init path from scheduling on the wrong cpu Ben Hutchings
2012-08-07 3:29 ` [ 67/70] drop_monitor: dont sleep in atomic context Ben Hutchings
2012-08-07 3:29 ` [ 68/70] pch_uart: Fix missing break for 16 byte fifo Ben Hutchings
2012-08-07 3:29 ` [ 69/70] pch_uart: Fix rx error interrupt setting issue Ben Hutchings
2012-08-07 3:29 ` [ 70/70] pch_uart: Fix parity " Ben Hutchings
2012-08-07 3:49 ` [ 00/70] 3.2.27-stable review Ben Hutchings
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120807032804.224482411@decadent.org.uk \
--to=ben@decadent.org.uk \
--cc=aarcange@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=avi@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mtosatti@redhat.com \
--cc=paul.gortmaker@windriver.com \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=xiaoguangrong@linux.vnet.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®