* [PATCH v2] selftests/mm: check MREMAP_DONTUNMAP mlock accounting
@ 2026-10-06 6:39 Jose A. Perez de Azpillaga
0 siblings, 0 replies; only message in thread
From: Jose A. Perez de Azpillaga @ 2026-10-06 6:39 UTC (permalink / raw)
To: Andrew Morton, David Hildenbrand, Shuah Khan
Cc: Jose A. Perez de Azpillaga, Lorenzo Stoakes, Liam R. Howlett,
Vlastimil Babka, Mike Rapoport, Suren Baghdasaryan, Michal Hocko,
linux-mm, linux-kselftest, linux-kernel
MREMAP_DONTUNMAP keeps the source VMA in place, but clears its mlock flags
while setting them on the destination VMA. The "mm/mremap: fix two issues
with MREMAP_DONTUNMAP" series fixed two cases where this leaked
mm->locked_vm:
- an unfaulted mlock-on-fault VMA moved behind itself self-merges, so the
single resulting VMA loses the flags without the accounting being
dropped;
- a partial mremap() moves only part of the range, leaving the pages which
are not moved accounted as locked in a VMA whose flags were cleared.
Add a test which mlock2()s a source mapping, moves all or part of it with
MREMAP_DONTUNMAP, unmaps everything and checks that VmLck is back to its
value from before, and run it for the self-merge case and for a partial
move with and without MLOCK_ONFAULT.
Verified on x86_64: the three cases fail on mm-unstable with the two fixes
reverted and pass with them applied.
Signed-off-by: Jose A. Perez de Azpillaga <azpijr@gmail.com>
---
v2:
- Reduce the churn (David): fold the three cases into one parameterised
test and drop the child process per case, comparing VmLck against its
value before each case instead.
- Use the file's BUG_ON() for setup failures and vm_util's
check_for_pattern() to read VmLck, call mlock2() directly.
- Verify against mm-unstable with the two fixes reverted rather than an
older -rc, now that the series is applied.
tools/testing/selftests/mm/mremap_dontunmap.c | 63 ++++++++++++++++++-
1 file changed, 62 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/mm/mremap_dontunmap.c b/tools/testing/selftests/mm/mremap_dontunmap.c
index 96ba537facf7..5ca33d9d42af 100644
--- a/tools/testing/selftests/mm/mremap_dontunmap.c
+++ b/tools/testing/selftests/mm/mremap_dontunmap.c
@@ -7,6 +7,7 @@
*/
#define _GNU_SOURCE
#include <sys/mman.h>
+#include <sys/syscall.h>
#include <linux/mman.h>
#include <errno.h>
#include <stdio.h>
@@ -15,6 +16,7 @@
#include <unistd.h>
#include "kselftest.h"
+#include "vm_util.h"
unsigned long page_size;
char *page_buffer;
@@ -335,6 +337,62 @@ static void mremap_dontunmap_partial_mapping_overwrite(void)
ksft_test_result_pass("%s\n", __func__);
}
+/* VmLck from /proc/self/status, which is mm->locked_vm in kB. */
+static unsigned long locked_vm_kb(void)
+{
+ unsigned long kb;
+ char buf[256];
+ FILE *fp;
+
+ fp = fopen("/proc/self/status", "r");
+ BUG_ON(!fp, "unable to open /proc/self/status");
+ BUG_ON(!check_for_pattern(fp, "VmLck:", buf, sizeof(buf)) ||
+ sscanf(buf, "VmLck: %lu kB", &kb) != 1, "unable to read VmLck");
+ fclose(fp);
+
+ return kb;
+}
+
+/*
+ * MREMAP_DONTUNMAP clears the mlock flags of the source VMA and sets them on
+ * the destination, and mm->locked_vm has to follow. mlock2() a source of
+ * num_pages and move its first move_pages to gap pages past its end:
+ *
+ * |------ source ------|... gap ...|-- dest --|
+ *
+ * then unmap everything and check that VmLck is back where it started. With
+ * no gap the destination is adjacent to the source and could merge with it,
+ * otherwise the gap is left PROT_NONE so that it cannot.
+ */
+static void mremap_dontunmap_mlock(const char *desc, unsigned long num_pages,
+ unsigned long move_pages, unsigned long gap,
+ int mlock_flags)
+{
+ unsigned long size = (num_pages + gap + move_pages) * page_size;
+ unsigned long locked = locked_vm_kb();
+ void *source, *dest;
+
+ source = mmap(NULL, size, PROT_NONE, MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
+ BUG_ON(source == MAP_FAILED, "mmap");
+ BUG_ON(mprotect(source, num_pages * page_size,
+ PROT_READ | PROT_WRITE) == -1, "mprotect");
+ dest = source + (num_pages + gap) * page_size;
+
+ if (syscall(__NR_mlock2, source, num_pages * page_size, mlock_flags)) {
+ ksft_test_result_skip("%s: %s: mlock2: %s\n", __func__, desc,
+ strerror(errno));
+ BUG_ON(munmap(source, size) == -1, "unable to unmap mappings");
+ return;
+ }
+
+ BUG_ON(mremap(source, move_pages * page_size, move_pages * page_size,
+ MREMAP_DONTUNMAP | MREMAP_MAYMOVE | MREMAP_FIXED,
+ dest) != dest, "mremap");
+
+ BUG_ON(munmap(source, size) == -1, "unable to unmap mappings");
+ ksft_test_result(locked_vm_kb() == locked, "%s: %s\n", __func__, desc);
+}
+
int main(void)
{
ksft_print_header();
@@ -348,7 +406,7 @@ int main(void)
ksft_finished();
}
- ksft_set_plan(5);
+ ksft_set_plan(8);
// Keep a page sized buffer around for when we need it.
page_buffer =
@@ -361,6 +419,9 @@ int main(void)
mremap_dontunmap_simple_fixed();
mremap_dontunmap_partial_mapping();
mremap_dontunmap_partial_mapping_overwrite();
+ mremap_dontunmap_mlock("onfault self-merge", 1, 1, 0, MLOCK_ONFAULT);
+ mremap_dontunmap_mlock("partial", 3, 2, 1, 0);
+ mremap_dontunmap_mlock("onfault partial", 3, 2, 1, MLOCK_ONFAULT);
BUG_ON(munmap(page_buffer, page_size) == -1,
"unable to unmap page buffer");
--
2.55.0
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-06 6:41 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 6:39 [PATCH v2] selftests/mm: check MREMAP_DONTUNMAP mlock accounting Jose A. Perez de Azpillaga
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®