From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1757696AbdKOL1M (ORCPT ); Wed, 15 Nov 2017 06:27:12 -0500 Received: from mail-wm0-f66.google.com ([74.125.82.66]:35090 "EHLO mail-wm0-f66.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1756762AbdKOL1F (ORCPT ); Wed, 15 Nov 2017 06:27:05 -0500 X-Google-Smtp-Source: AGs4zMZBhWvHIKjNSGEhnKhhzU+hyVEdNVlukRP6zvcQVCWBYpO+tTLFedbwjQUyUIt0K65CwtBjXw== Date: Wed, 15 Nov 2017 14:27:02 +0300 From: "Kirill A. Shutemov" To: Thomas Gleixner Cc: "Kirill A. Shutemov" , Ingo Molnar , x86@kernel.org, "H. Peter Anvin" , Linus Torvalds , Andy Lutomirski , Nicholas Piggin , linux-mm@kvack.org, linux-kernel@vger.kernel.org Subject: Re: [PATCHv2 1/2] x86/mm: Do not allow non-MAP_FIXED mapping across DEFAULT_MAP_WINDOW border Message-ID: <20171115112702.e2m66wons37imtcj@node.shutemov.name> References: <20171114134322.40321-1-kirill.shutemov@linux.intel.com> <20171114202102.crpgiwgv2lu5aboq@node.shutemov.name> <20171114222718.76w4lmclf6wasbl3@node.shutemov.name> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: NeoMutt/20170609 (1.8.3) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Nov 15, 2017 at 12:00:46AM +0100, Thomas Gleixner wrote: > On Wed, 15 Nov 2017, Kirill A. Shutemov wrote: > > On Tue, Nov 14, 2017 at 09:54:52PM +0100, Thomas Gleixner wrote: > > > On Tue, 14 Nov 2017, Kirill A. Shutemov wrote: > > > > > > > On Tue, Nov 14, 2017 at 05:01:50PM +0100, Thomas Gleixner wrote: > > > > > @@ -198,11 +199,14 @@ arch_get_unmapped_area_topdown(struct fi > > > > > /* requesting a specific address */ > > > > > if (addr) { > > > > > addr = PAGE_ALIGN(addr); > > > > > + if (!mmap_address_hint_valid(addr, len)) > > > > > + goto get_unmapped_area; > > > > > + > > > > > > > > Here and in hugetlb_get_unmapped_area(), we should align the addr after > > > > the check, not before. Otherwise the alignment itself can bring us over > > > > the borderline as we align up. > > > > > > Hmm, then I wonder whether the next check against vm_start_gap() which > > > checks against the aligned address is correct: > > > > > > addr = PAGE_ALIGN(addr); > > > vma = find_vma(mm, addr); > > > > > > if (end - len >= addr && > > > (!vma || addr + len <= vm_start_gap(vma))) > > > return addr; > > > > I think the check is correct. The check is against resulting addresses > > that end up in vm_start/vm_end. In our case we want to figure out what > > user asked for. > > Well, but then checking just against the user supplied addr is only half of > the story. > > addr = boundary - PAGE_SIZE - PAGE_SIZE / 2; > len = PAGE_SIZE - PAGE_SIZE / 2; > > That fits, but then after alignment we end up with > > addr = boudary - PAGE_SIZE; > > and due to len > PAGE_SIZE this will result in a mapping which crosses the > boundary, right? So checking against the PAGE_ALIGN(addr) should be the > right thing to do. IIUC, this is only the case if 'len' is not aligned, right? >>From what I see we expect caller to align it (and mm/mmap.c does this, I haven't checked other callers). And hugetlb would actively reject non-aligned len. I *think* we should be fine with checking unaligned 'addr'. -- Kirill A. Shutemov