From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lf1-f44.google.com (mail-lf1-f44.google.com [209.85.167.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CAA3940DFCE for ; Sun, 22 Mar 2026 14:49:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774190996; cv=none; b=OLFUCwKDA79GjYo8z7d69yRXdlSBLCTHP95glLxhnpqBrgc7wxD/8DPY0MXIphbGgaILT6JYfpmDaKWfr/xZZgad4ocYVqzEf/HQrEjKSqg4/tK6KLGZpMZFo2/8mN13Fh3pIuk4+imkKC5/3mUoxKBN8TYT1l4WvBBJ845hX0Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774190996; c=relaxed/simple; bh=3YbFZkJuOyi+LdoLctpkTjvu2PpEv6jscoL4hXV7t68=; h=From:Date:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=dQcguWqvluRtyo7wy4O+TbaIrZSruMKp7FlQLHNK2kpbqIDG7fEiQheuQeRPzgQIp7URWCVc+jUV9cW4I5Cn0DYFHJnVujGnZ7fFXkUu5Aumwqxqb5oe4w1lTO2NRUXYWku8S0XhxpWmBo4d9c7yE7uBQ3cNUvElv1Y8Plt824E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=N9ILSufH; arc=none smtp.client-ip=209.85.167.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="N9ILSufH" Received: by mail-lf1-f44.google.com with SMTP id 2adb3069b0e04-5a142464316so3634636e87.1 for ; Sun, 22 Mar 2026 07:49:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1774190993; x=1774795793; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:date:from:from:to:cc:subject:date:message-id:reply-to; bh=rlTFfUPhBocGaxMerdSh1BiMW+L3wVNprEAxKNc1b7Y=; b=N9ILSufHCqOrpT2haRSU3L8LJ5vRJE7gzpaMENpKjgDhtxOAPrFpuNwSiZQOlyY1p0 6VlK0v3Y3zC4R/rLcuq8+2Jo67uSHfn9DyRk0Xljup/JsoM8UFpBYZngoXLckVPxXGiz 4wWMsX0eYagArbIrv1dhNsy5Gk9cUMpGagpIam6pUbu8e9vmp6agesMqTDNu0DxsE3iB N87gmAoVMeAkEx82ENq5lqHRoa1a1tm0uOaWMkkT37HAe8BOhDlhlZxUoy33uR3ib04P hxT8N2M6X8IbXHQdVww7pPhWjJ/J835EGlnWxrUVLRsAsvT/ScyZ9oBzIOnEtbSV8C5t RLBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1774190993; x=1774795793; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:date:from:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=rlTFfUPhBocGaxMerdSh1BiMW+L3wVNprEAxKNc1b7Y=; b=TjlDAsRhjjNFnnqONkMOwupCVC5ry2D/1I/7Gq4nfxVG1w5Vjwkq4CcokbJ1JoikSB jB311gFXqgKsQnRqvYqbd7YHfNnpjEdVbVxzueBqEPFp1cuqoWQNhTSloiaaStJU+fUa a2j+QHetO2HkeTgeOFl0HP1Fm5ujkMxzGBLXdznA/w9vWMI31bVC/qtXy2Y/zlJ6uBZt t8+xknGTM3kv/dmyQuriEYA9NhPeAM6UAJ7FRH75qLUJWkH9L9ag5rgwC/UUQS8LUn8y 1dkkCpZdd9X6FHyqb/yDeGG92/9HeuEFXgazaVAqPPzvfHEEskzAf+C7fPS8jF/lxoc5 K86A== X-Forwarded-Encrypted: i=1; AJvYcCW+mreFXuYWY6YG5vQ9LDO47w4b2YfeRMGQDrGR8CJgithdZzgAYx+qqaKW3oFhHxcVS3sTy7dsmKPxfq8=@vger.kernel.org X-Gm-Message-State: AOJu0YzyNUhwrQ3raH/KJ7mZY8ONwL4d7o+WUfdwecuKcmQO9JZg4pEw 9TvM+Zm6jXNo16qcnB/Lo+/63O9HH2e0yA32bjjqAMmR6sI05pYSsBbp X-Gm-Gg: ATEYQzyAhLQOrlbxUXZzo99blMp/MFzRBU2OKTsohkGunBq74TFD3RTRvUEa36XywI5 LH8Zas3kOQn7GSFPV2Y5D2eiACYaYElN/hQ5scEJvuun9ePypppsJq9/NSytgaSURCFp6OFpNfG cMG19zfRh97MbzbRZMq79ChjMB7w+nF+6XaQo7hvruAPPPSw/C7CTWZ9vEpr3WKTQoyPNTQTY4c 2v2rqupvJYueOpCmgDxY7mUO2eCbcnjrQpIqSkeE70CsD3jiTSz3+UaShkkiDOHvpKSwoG1G2JV afswRXJSZ8o/1syomK1LjLiYUZs5MhbQNJu90hFwGIUW0IwgZwAQ/2fv7bCuZA5bjObNOhcGX8Y xSBB1fsjRzgwUbnaLN/jMvw7ZS23zSL4hG/ryiXt3nmV4JWhn9j0jvvHgX1GXutA= X-Received: by 2002:a05:6512:3c82:b0:5a2:7c1c:749 with SMTP id 2adb3069b0e04-5a285b641eemr2701104e87.39.1774190992739; Sun, 22 Mar 2026 07:49:52 -0700 (PDT) Received: from pc636 ([2001:9b1:d5a0:a500::800]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5a2852071edsm1784683e87.49.2026.03.22.07.49.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 22 Mar 2026 07:49:52 -0700 (PDT) From: Uladzislau Rezki X-Google-Original-From: Uladzislau Rezki Date: Sun, 22 Mar 2026 15:49:50 +0100 To: shivamkalra98@zohomail.in Cc: Andrew Morton , Uladzislau Rezki , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Alice Ryhl , Danilo Krummrich Subject: Re: [PATCH v6 4/6] mm/vmalloc: protect /proc/vmallocinfo readers with READ_ONCE() Message-ID: References: <20260321-vmalloc-shrink-v6-0-062ca7b7ceb2@zohomail.in> <20260321-vmalloc-shrink-v6-4-062ca7b7ceb2@zohomail.in> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260321-vmalloc-shrink-v6-4-062ca7b7ceb2@zohomail.in> On Sat, Mar 21, 2026 at 11:35:49PM +0530, Shivam Kalra via B4 Relay wrote: > From: Shivam Kalra > > The /proc/vmallocinfo readers, specifically show_numa_info() and > vmalloc_info_show(), currently read v->nr_pages and the v->pages > array without any concurrent protection. > > In preparation for vrealloc() shrink support, where v->nr_pages can > be decreased and entries in the v->pages array can be nulled out > concurrently, these readers must be protected to prevent use-after-free > or NULL pointer dereferences. > > Update show_numa_info() to use READ_ONCE(v->nr_pages) and > READ_ONCE(v->pages[nr]), explicitly checking for NULL before > dereferencing the page. Similarly, update vmalloc_info_show() to > read nr_pages safely to avoid parsing a torn or inconsistent value. > > Signed-off-by: Shivam Kalra > --- > mm/vmalloc.c | 17 ++++++++++++----- > 1 file changed, 12 insertions(+), 5 deletions(-) > > diff --git a/mm/vmalloc.c b/mm/vmalloc.c > index 64f5d1088281..7658fdc087d2 100644 > --- a/mm/vmalloc.c > +++ b/mm/vmalloc.c > @@ -5204,7 +5204,7 @@ bool vmalloc_dump_obj(void *object) > static void show_numa_info(struct seq_file *m, struct vm_struct *v, > unsigned int *counters) > { > - unsigned int nr; > + unsigned int nr, nr_pages; > unsigned int step = 1U << vm_area_page_order(v); > > if (!counters) > @@ -5212,8 +5212,13 @@ static void show_numa_info(struct seq_file *m, struct vm_struct *v, > > memset(counters, 0, nr_node_ids * sizeof(unsigned int)); > > - for (nr = 0; nr < v->nr_pages; nr += step) > - counters[page_to_nid(v->pages[nr])] += step; > + nr_pages = READ_ONCE(v->nr_pages); > + for (nr = 0; nr < nr_pages; nr += step) { > + struct page *page = READ_ONCE(v->pages[nr]); > + > + if (page) > + counters[page_to_nid(page)] += step; > + } > for_each_node_state(nr, N_HIGH_MEMORY) > if (counters[nr]) > seq_printf(m, " N%u=%u", nr, counters[nr]); > @@ -5241,6 +5246,7 @@ static int vmalloc_info_show(struct seq_file *m, void *p) > struct vmap_area *va; > struct vm_struct *v; > unsigned int *counters; > + unsigned int nr_pages; > > if (IS_ENABLED(CONFIG_NUMA)) > counters = kmalloc_array(nr_node_ids, sizeof(unsigned int), GFP_KERNEL); > @@ -5270,8 +5276,9 @@ static int vmalloc_info_show(struct seq_file *m, void *p) > if (v->caller) > seq_printf(m, " %pS", v->caller); > > - if (v->nr_pages) > - seq_printf(m, " pages=%d", v->nr_pages); > + nr_pages = READ_ONCE(v->nr_pages); > + if (nr_pages) > + seq_printf(m, " pages=%d", nr_pages); > > if (v->phys_addr) > seq_printf(m, " phys=%pa", &v->phys_addr); > It is protected by the vn->busy.lock. When you update the page counter in the vrealloc, we should do it under the lock if i do not miss anything. -- Uladzislau Rezki