mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2 0/2] mm/mremap: fix two issues with MREMAP_DONTUNMAP
@ 2026-09-30 18:47 Lorenzo Stoakes (ARM)
  2026-09-30 18:47 ` [PATCH v2 1/2] mm/mremap: fix locked_vm leak from MREMAP_DONTUNMAP self-merge Lorenzo Stoakes (ARM)
                   ` (3 more replies)
  0 siblings, 4 replies; 7+ messages in thread
From: Lorenzo Stoakes (ARM) @ 2026-09-30 18:47 UTC (permalink / raw)
  To: Andrew Morton, Liam R. Howlett, Vlastimil Babka, Jann Horn,
	Pedro Falcato, Brian Geffon, Minchan Kim, Kiryl Shutsemau
  Cc: linux-mm, linux-kernel, Anirudh Srinivasan, Lorenzo Stoakes (ARM),
	stable, Jose A. Perez de Azpillaga

The MREMAP_DONTUNMAP feature is highly unusual in that it permits mremap()
operations that keep the original VMA in place.

Historically this has led to a lot of bugs where non-obvious interactions
occur between existing mremap() operations and the original VMA.

Commit 397432cab17b ("mm/mremap: account mm->locked_vm correctly for
MREMAP_DONTUNMAP") fixed an accidentally introduced bug around
mm->locked_vm accounting, but this wasn't the only issue.

And thus history repeats itself, as it turns out that mm->locked_vm
accounting is broken by MREMAP_DONTUNMAP yet again by two further cases,
and has been broken ever since the feature was introduced.

Both relate to the fact that VMA_LOCKED_BIT is cleared on the source
VMA (it has to be as all page tables are moved):

1. If an unfaulted VMA_LOCKONFAULT_BIT anonymous VMA self-merges it
   clears the VMA_LOCKED_BIT flag and permanently leaks mm->locked_vm
   pages.

2. If a partial mremap() is performed on a locked VMA there is a leak equal
   to the number of pages not copied.

(Both for MREMAP_DONTUNMAP operations only)

Both issues can be fixed by treating the source range as distinct from the
destination range, which is the definition of what MREMAP_DONTUNMAP does so
is appropriate.

In case 1, simply disallow the self-merge, keeping adjacent source and
destination VMAs distinct.

In case 2, split the source range ahead of time if the VMA is mlock()'d, so
accounting is always correct.

Both changes were tested locally and confirmed to fix the issues.

For the purposes of a backport, the fixes are kept distinct, a follow-up
series can add self-tests.

Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
---
v2:
* Added tags (thanks everybody!)
* Updated 2/2 to avoid splitting the VMA if the VMA was not mlock()'d. It
  is only meaningful and necessary to perform the split in this case. This
  also fixes the proc_maps_race selftests that broke, as reported by
  Anirudh.

v1:
https://lore.kernel.org/r/20260920-fix-dontunmap-partial-self-merge-v1-0-6ffb556f8f8b@kernel.org

---
Lorenzo Stoakes (ARM) (2):
      mm/mremap: fix locked_vm leak from MREMAP_DONTUNMAP self-merge
      mm/mremap: fix locked_vm leak by splitting VMA for MREMAP_DONTUNMAP

 mm/mremap.c                   | 70 ++++++++++++++++++++++++++++++++-----------
 mm/vma.c                      | 21 +++++++++++--
 mm/vma.h                      |  7 ++++-
 tools/testing/vma/tests/vma.c | 10 +++----
 4 files changed, 81 insertions(+), 27 deletions(-)
---
base-commit: a3d0117e02bfa1c3bb6c50e7afe42bbecdbb3459
change-id: 20260920-fix-dontunmap-partial-self-merge-74a98b1d5a65

Cheers,
-- 
Lorenzo Stoakes (ARM) <ljs@kernel.org>


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-10-01  8:10 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 18:47 [PATCH v2 0/2] mm/mremap: fix two issues with MREMAP_DONTUNMAP Lorenzo Stoakes (ARM)
2026-09-30 18:47 ` [PATCH v2 1/2] mm/mremap: fix locked_vm leak from MREMAP_DONTUNMAP self-merge Lorenzo Stoakes (ARM)
2026-09-30 18:47 ` [PATCH v2 2/2] mm/mremap: fix locked_vm leak by splitting VMA for MREMAP_DONTUNMAP Lorenzo Stoakes (ARM)
2026-09-30 19:15 ` [PATCH v2 0/2] mm/mremap: fix two issues with MREMAP_DONTUNMAP Anirudh Srinivasan
2026-10-01  8:10   ` Lorenzo Stoakes (ARM)
2026-09-30 22:21 ` Andrew Morton
2026-10-01  8:05   ` Lorenzo Stoakes (ARM)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®