From: "Liam R. Howlett" <Liam.Howlett@oracle.com>
To: linux-mm@kvack.org, Andrew Morton <akpm@linux-foundation.org>
Cc: Suren Baghdasaryan <surenb@google.com>,
Vlastimil Babka <vbabka@suse.cz>,
Lorenzo Stoakes <lstoakes@gmail.com>,
Matthew Wilcox <willy@infradead.org>,
sidhartha.kumar@oracle.com,
"Paul E . McKenney" <paulmck@kernel.org>,
Bert Karwatzki <spasswolf@web.de>, Jiri Olsa <olsajiri@gmail.com>,
linux-kernel@vger.kernel.org, Kees Cook <kees@kernel.org>,
"Liam R. Howlett" <Liam.Howlett@oracle.com>
Subject: [PATCH v4 01/21] mm/mmap: Correctly position vma_iterator in __split_vma()
Date: Wed, 10 Jul 2024 15:22:30 -0400 [thread overview]
Message-ID: <20240710192250.4114783-2-Liam.Howlett@oracle.com> (raw)
In-Reply-To: <20240710192250.4114783-1-Liam.Howlett@oracle.com>
The vma iterator may be left pointing to the newly created vma. This
happens when inserting the new vma at the end of the old vma
(!new_below).
The incorrect position in the vma iterator is not exposed currently
since the vma iterator is repositioned in the munmap path and is not
reused in any of the other paths.
This has limited impact in the current code, but is required for future
changes.
Fixes: b2b3b886738f ("mm: don't use __vma_adjust() in __split_vma()")
Signed-off-by: Liam R. Howlett <Liam.Howlett@oracle.com>
Reviewed-by: Suren Baghdasaryan <surenb@google.com>
Reviewed-by: Lorenzo Stoakes <lstoakes@gmail.com>
---
mm/mmap.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/mm/mmap.c b/mm/mmap.c
index e42d89f98071..28a46d9ddde0 100644
--- a/mm/mmap.c
+++ b/mm/mmap.c
@@ -2414,7 +2414,7 @@ static void unmap_region(struct mm_struct *mm, struct ma_state *mas,
/*
* __split_vma() bypasses sysctl_max_map_count checking. We use this where it
* has already been checked or doesn't make sense to fail.
- * VMA Iterator will point to the end VMA.
+ * VMA Iterator will point to the original vma.
*/
static int __split_vma(struct vma_iterator *vmi, struct vm_area_struct *vma,
unsigned long addr, int new_below)
@@ -2483,6 +2483,9 @@ static int __split_vma(struct vma_iterator *vmi, struct vm_area_struct *vma,
/* Success. */
if (new_below)
vma_next(vmi);
+ else
+ vma_prev(vmi);
+
return 0;
out_free_mpol:
--
2.43.0
next prev parent reply other threads:[~2024-07-10 19:23 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-07-10 19:22 [PATCH v4 00/21] Avoid MAP_FIXED gap exposure Liam R. Howlett
2024-07-10 19:22 ` Liam R. Howlett [this message]
2024-07-10 19:22 ` [PATCH v4 02/21] mm/mmap: Introduce abort_munmap_vmas() Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 03/21] mm/mmap: Introduce vmi_complete_munmap_vmas() Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 04/21] mm/mmap: Extract the gathering of vmas from do_vmi_align_munmap() Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 05/21] mm/mmap: Introduce vma_munmap_struct for use in munmap operations Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 06/21] mm/mmap: Change munmap to use vma_munmap_struct() for accounting and surrounding vmas Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 07/21] mm/mmap: Extract validate_mm() from vma_complete() Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 08/21] mm/mmap: Inline munmap operation in mmap_region() Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 09/21] mm/mmap: Expand mmap_region() munmap call Liam R. Howlett
2024-07-11 14:16 ` Lorenzo Stoakes
2024-07-10 19:22 ` [PATCH v4 10/21] mm/mmap: Support vma == NULL in init_vma_munmap() Liam R. Howlett
2024-07-11 14:28 ` Lorenzo Stoakes
2024-07-11 16:04 ` Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 11/21] mm/mmap: Reposition vma iterator in mmap_region() Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 12/21] mm/mmap: Track start and end of munmap in vma_munmap_struct Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 13/21] mm/mmap: Clean up unmap_region() argument list Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 14/21] mm/mmap: Avoid zeroing vma tree in mmap_region() Liam R. Howlett
2024-07-11 15:25 ` Lorenzo Stoakes
2024-07-11 16:07 ` Liam R. Howlett
2024-07-16 12:46 ` kernel test robot
2024-07-17 17:42 ` Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 15/21] mm/mmap: Use PHYS_PFN " Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 16/21] mm/mmap: Use vms accounted pages " Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 17/21] mm/mmap: Drop arch_unmap() call from all archs Liam R. Howlett
2024-07-10 19:27 ` Dave Hansen
2024-07-10 21:02 ` LEROY Christophe
2024-07-10 23:26 ` Liam R. Howlett
2024-07-11 8:28 ` LEROY Christophe
2024-07-11 15:59 ` Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 18/21] mm/mmap: Move can_modify_mm() check down the stack Liam R. Howlett
2024-07-17 5:03 ` Jeff Xu
2024-07-17 14:07 ` Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 19/21] ipc/shm, mm: Drop do_vma_munmap() Liam R. Howlett
2024-07-10 19:22 ` [PATCH v4 20/21] mm/mmap: Move may_expand_vm() check in mmap_region() Liam R. Howlett
2024-07-11 15:38 ` Lorenzo Stoakes
2024-07-10 19:22 ` [PATCH v4 21/21] mm/mmap: Drop incorrect comment from vms_gather_munmap_vmas() Liam R. Howlett
2024-07-11 15:39 ` Lorenzo Stoakes
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240710192250.4114783-2-Liam.Howlett@oracle.com \
--to=liam.howlett@oracle.com \
--cc=akpm@linux-foundation.org \
--cc=kees@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=lstoakes@gmail.com \
--cc=olsajiri@gmail.com \
--cc=paulmck@kernel.org \
--cc=sidhartha.kumar@oracle.com \
--cc=spasswolf@web.de \
--cc=surenb@google.com \
--cc=vbabka@suse.cz \
--cc=willy@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®