mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Hugh Dickins <hugh@veritas.com>
To: Andrew Morton <akpm@osdl.org>
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH 01/21] mm: hugetlb truncation fixes
Date: Sun, 25 Sep 2005 16:47:33 +0100 (BST)	[thread overview]
Message-ID: <Pine.LNX.4.61.0509251646380.3490@goblin.wat.veritas.com> (raw)
In-Reply-To: <Pine.LNX.4.61.0509251644100.3490@goblin.wat.veritas.com>

hugetlbfs allows truncation of its files (should it?), but hugetlb.c
often forgets that: crashes and misaccounting ensue.

copy_hugetlb_page_range better grab the src page_table_lock since we
don't want to guess what happens if concurrently truncated.
unmap_hugepage_range rss accounting must not assume the full range was
mapped.  follow_hugetlb_page must guard with page_table_lock and be
prepared to exit early.

Restyle copy_hugetlb_page_range with a for loop like the others there.

Signed-off-by: Hugh Dickins <hugh@veritas.com>
---

 mm/hugetlb.c |   35 +++++++++++++++++++++--------------
 1 files changed, 21 insertions(+), 14 deletions(-)

--- 2.6.14-rc2/mm/hugetlb.c	2005-09-22 12:32:03.000000000 +0100
+++ mm01/mm/hugetlb.c	2005-09-24 19:26:24.000000000 +0100
@@ -273,21 +273,22 @@ int copy_hugetlb_page_range(struct mm_st
 {
 	pte_t *src_pte, *dst_pte, entry;
 	struct page *ptepage;
-	unsigned long addr = vma->vm_start;
-	unsigned long end = vma->vm_end;
+	unsigned long addr;
 
-	while (addr < end) {
+	for (addr = vma->vm_start; addr < vma->vm_end; addr += HPAGE_SIZE) {
 		dst_pte = huge_pte_alloc(dst, addr);
 		if (!dst_pte)
 			goto nomem;
+		spin_lock(&src->page_table_lock);
 		src_pte = huge_pte_offset(src, addr);
-		BUG_ON(!src_pte || pte_none(*src_pte)); /* prefaulted */
-		entry = *src_pte;
-		ptepage = pte_page(entry);
-		get_page(ptepage);
-		add_mm_counter(dst, rss, HPAGE_SIZE / PAGE_SIZE);
-		set_huge_pte_at(dst, addr, dst_pte, entry);
-		addr += HPAGE_SIZE;
+		if (src_pte && !pte_none(*src_pte)) {
+			entry = *src_pte;
+			ptepage = pte_page(entry);
+			get_page(ptepage);
+			add_mm_counter(dst, rss, HPAGE_SIZE / PAGE_SIZE);
+			set_huge_pte_at(dst, addr, dst_pte, entry);
+		}
+		spin_unlock(&src->page_table_lock);
 	}
 	return 0;
 
@@ -322,8 +323,8 @@ void unmap_hugepage_range(struct vm_area
 
 		page = pte_page(pte);
 		put_page(page);
+		add_mm_counter(mm, rss,  - (HPAGE_SIZE / PAGE_SIZE));
 	}
-	add_mm_counter(mm, rss,  -((end - start) >> PAGE_SHIFT));
 	flush_tlb_range(vma, start, end);
 }
 
@@ -402,6 +403,7 @@ int follow_hugetlb_page(struct mm_struct
 	BUG_ON(!is_vm_hugetlb_page(vma));
 
 	vpfn = vaddr/PAGE_SIZE;
+	spin_lock(&mm->page_table_lock);
 	while (vaddr < vma->vm_end && remainder) {
 
 		if (pages) {
@@ -414,8 +416,13 @@ int follow_hugetlb_page(struct mm_struct
 			 * indexing below to work. */
 			pte = huge_pte_offset(mm, vaddr & HPAGE_MASK);
 
-			/* hugetlb should be locked, and hence, prefaulted */
-			WARN_ON(!pte || pte_none(*pte));
+			/* the hugetlb file might have been truncated */
+			if (!pte || pte_none(*pte)) {
+				remainder = 0;
+				if (!i)
+					i = -EFAULT;
+				break;
+			}
 
 			page = &pte_page(*pte)[vpfn % (HPAGE_SIZE/PAGE_SIZE)];
 
@@ -433,7 +440,7 @@ int follow_hugetlb_page(struct mm_struct
 		--remainder;
 		++i;
 	}
-
+	spin_unlock(&mm->page_table_lock);
 	*length = remainder;
 	*position = vaddr;
 

  reply	other threads:[~2005-09-25 15:48 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-09-25 15:46 [PATCH 00/21] mm: page fault scalability prep Hugh Dickins
2005-09-25 15:47 ` Hugh Dickins [this message]
2005-09-25 15:48 ` [PATCH 02/21] mm: copy_pte_range progress fix Hugh Dickins
2005-09-25 15:49 ` [PATCH 03/21] mm: msync_pte_range progress Hugh Dickins
2005-09-25 15:49 ` [PATCH 04/21] mm: zap_pte_range dont dirty anon Hugh Dickins
2005-09-25 22:26   ` Andrew Morton
2005-09-26  6:02     ` Hugh Dickins
2005-09-26  6:14       ` Andrew Morton
2005-09-26  7:20         ` Hugh Dickins
2005-09-25 15:51 ` [PATCH 05/21] mm: anon is already wrprotected Hugh Dickins
2005-09-25 15:52 ` [PATCH 06/21] mm: vm_stat_account unshackled Hugh Dickins
2005-09-25 15:53 ` [PATCH 07/21] mm: remove_vma_list consolidation Hugh Dickins
2005-09-25 15:53 ` [PATCH 08/21] mm: unlink_file_vma, remove_vma Hugh Dickins
2005-09-25 15:54 ` [PATCH 09/21] mm: exit_mmap need not reset Hugh Dickins
2005-09-25 15:56 ` [PATCH 10/21] mm: page fault handlers tidyup Hugh Dickins
2005-09-25 15:57 ` [PATCH 11/21] mm: move_page_tables by extents Hugh Dickins
2005-09-25 15:59 ` [PATCH 12/21] mm: tlb_gather_mmu get_cpu_var Hugh Dickins
2005-09-25 16:01 ` [PATCH 13/21] mm: tlb_is_full_mm was obscure Hugh Dickins
2005-09-25 16:03 ` [PATCH 14/21] mm: tlb_finish_mmu forget rss Hugh Dickins
2005-09-25 16:06 ` [PATCH 15/21] mm: mm_init set_mm_counters Hugh Dickins
2005-09-25 16:07 ` [PATCH 16/21] mm: rss = file_rss + anon_rss Hugh Dickins
2005-09-25 16:08 ` [PATCH 17/21] mm: batch updating mm_counters Hugh Dickins
2005-09-26  7:25   ` Nick Piggin
2005-09-26  8:42     ` Hugh Dickins
2005-09-25 16:09 ` [PATCH 18/21] mm: dup_mmap use oldmm more Hugh Dickins
2005-09-25 16:10 ` [PATCH 19/21] mm: dup_mmap down new mmap_sem Hugh Dickins
2005-09-25 16:11 ` [PATCH 20/21] mm: sh64 hugetlbpage.c Hugh Dickins
2005-09-29  7:00   ` Paul Mundt
2005-09-25 16:15 ` [PATCH 21/21] mm: m68k kill stram swap Hugh Dickins
2005-09-28  0:05 ` [PATCH 00/21] mm: page fault scalability prep Christoph Lameter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.LNX.4.61.0509251646380.3490@goblin.wat.veritas.com \
    --to=hugh@veritas.com \
    --cc=akpm@osdl.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®