From: "Jose A. Perez de Azpillaga" <azpijr@gmail.com>
To: Andrew Morton <akpm@linux-foundation.org>,
David Hildenbrand <david@kernel.org>,
Shuah Khan <shuah@kernel.org>
Cc: "Jose A. Perez de Azpillaga" <azpijr@gmail.com>,
Lorenzo Stoakes <ljs@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
Vlastimil Babka <vbabka@kernel.org>,
Mike Rapoport <rppt@kernel.org>,
Suren Baghdasaryan <surenb@google.com>,
Michal Hocko <mhocko@suse.com>,
linux-mm@kvack.org, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v2] selftests/mm: check MREMAP_DONTUNMAP mlock accounting
Date: Tue, 6 Oct 2026 08:39:01 +0200 [thread overview]
Message-ID: <20261006064120.6796-1-azpijr@gmail.com> (raw)
MREMAP_DONTUNMAP keeps the source VMA in place, but clears its mlock flags
while setting them on the destination VMA. The "mm/mremap: fix two issues
with MREMAP_DONTUNMAP" series fixed two cases where this leaked
mm->locked_vm:
- an unfaulted mlock-on-fault VMA moved behind itself self-merges, so the
single resulting VMA loses the flags without the accounting being
dropped;
- a partial mremap() moves only part of the range, leaving the pages which
are not moved accounted as locked in a VMA whose flags were cleared.
Add a test which mlock2()s a source mapping, moves all or part of it with
MREMAP_DONTUNMAP, unmaps everything and checks that VmLck is back to its
value from before, and run it for the self-merge case and for a partial
move with and without MLOCK_ONFAULT.
Verified on x86_64: the three cases fail on mm-unstable with the two fixes
reverted and pass with them applied.
Signed-off-by: Jose A. Perez de Azpillaga <azpijr@gmail.com>
---
v2:
- Reduce the churn (David): fold the three cases into one parameterised
test and drop the child process per case, comparing VmLck against its
value before each case instead.
- Use the file's BUG_ON() for setup failures and vm_util's
check_for_pattern() to read VmLck, call mlock2() directly.
- Verify against mm-unstable with the two fixes reverted rather than an
older -rc, now that the series is applied.
tools/testing/selftests/mm/mremap_dontunmap.c | 63 ++++++++++++++++++-
1 file changed, 62 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/mm/mremap_dontunmap.c b/tools/testing/selftests/mm/mremap_dontunmap.c
index 96ba537facf7..5ca33d9d42af 100644
--- a/tools/testing/selftests/mm/mremap_dontunmap.c
+++ b/tools/testing/selftests/mm/mremap_dontunmap.c
@@ -7,6 +7,7 @@
*/
#define _GNU_SOURCE
#include <sys/mman.h>
+#include <sys/syscall.h>
#include <linux/mman.h>
#include <errno.h>
#include <stdio.h>
@@ -15,6 +16,7 @@
#include <unistd.h>
#include "kselftest.h"
+#include "vm_util.h"
unsigned long page_size;
char *page_buffer;
@@ -335,6 +337,62 @@ static void mremap_dontunmap_partial_mapping_overwrite(void)
ksft_test_result_pass("%s\n", __func__);
}
+/* VmLck from /proc/self/status, which is mm->locked_vm in kB. */
+static unsigned long locked_vm_kb(void)
+{
+ unsigned long kb;
+ char buf[256];
+ FILE *fp;
+
+ fp = fopen("/proc/self/status", "r");
+ BUG_ON(!fp, "unable to open /proc/self/status");
+ BUG_ON(!check_for_pattern(fp, "VmLck:", buf, sizeof(buf)) ||
+ sscanf(buf, "VmLck: %lu kB", &kb) != 1, "unable to read VmLck");
+ fclose(fp);
+
+ return kb;
+}
+
+/*
+ * MREMAP_DONTUNMAP clears the mlock flags of the source VMA and sets them on
+ * the destination, and mm->locked_vm has to follow. mlock2() a source of
+ * num_pages and move its first move_pages to gap pages past its end:
+ *
+ * |------ source ------|... gap ...|-- dest --|
+ *
+ * then unmap everything and check that VmLck is back where it started. With
+ * no gap the destination is adjacent to the source and could merge with it,
+ * otherwise the gap is left PROT_NONE so that it cannot.
+ */
+static void mremap_dontunmap_mlock(const char *desc, unsigned long num_pages,
+ unsigned long move_pages, unsigned long gap,
+ int mlock_flags)
+{
+ unsigned long size = (num_pages + gap + move_pages) * page_size;
+ unsigned long locked = locked_vm_kb();
+ void *source, *dest;
+
+ source = mmap(NULL, size, PROT_NONE, MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
+ BUG_ON(source == MAP_FAILED, "mmap");
+ BUG_ON(mprotect(source, num_pages * page_size,
+ PROT_READ | PROT_WRITE) == -1, "mprotect");
+ dest = source + (num_pages + gap) * page_size;
+
+ if (syscall(__NR_mlock2, source, num_pages * page_size, mlock_flags)) {
+ ksft_test_result_skip("%s: %s: mlock2: %s\n", __func__, desc,
+ strerror(errno));
+ BUG_ON(munmap(source, size) == -1, "unable to unmap mappings");
+ return;
+ }
+
+ BUG_ON(mremap(source, move_pages * page_size, move_pages * page_size,
+ MREMAP_DONTUNMAP | MREMAP_MAYMOVE | MREMAP_FIXED,
+ dest) != dest, "mremap");
+
+ BUG_ON(munmap(source, size) == -1, "unable to unmap mappings");
+ ksft_test_result(locked_vm_kb() == locked, "%s: %s\n", __func__, desc);
+}
+
int main(void)
{
ksft_print_header();
@@ -348,7 +406,7 @@ int main(void)
ksft_finished();
}
- ksft_set_plan(5);
+ ksft_set_plan(8);
// Keep a page sized buffer around for when we need it.
page_buffer =
@@ -361,6 +419,9 @@ int main(void)
mremap_dontunmap_simple_fixed();
mremap_dontunmap_partial_mapping();
mremap_dontunmap_partial_mapping_overwrite();
+ mremap_dontunmap_mlock("onfault self-merge", 1, 1, 0, MLOCK_ONFAULT);
+ mremap_dontunmap_mlock("partial", 3, 2, 1, 0);
+ mremap_dontunmap_mlock("onfault partial", 3, 2, 1, MLOCK_ONFAULT);
BUG_ON(munmap(page_buffer, page_size) == -1,
"unable to unmap page buffer");
--
2.55.0
reply other threads:[~2026-10-06 6:41 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006064120.6796-1-azpijr@gmail.com \
--to=azpijr@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=david@kernel.org \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=mhocko@suse.com \
--cc=rppt@kernel.org \
--cc=shuah@kernel.org \
--cc=surenb@google.com \
--cc=vbabka@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®