mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org,
	"Naoya Horiguchi" <n-horiguchi@ah.jp.nec.com>,
	"SunDong" <sund_sky@126.com>,
	"Andrea Arcangeli" <aarcange@redhat.com>,
	"Michal Hocko" <mhocko@suse.com>,
	"Linus Torvalds" <torvalds@linux-foundation.org>,
	"Hugh Dickins" <hughd@google.com>,
	"Mel Gorman" <mgorman@techsingularity.net>,
	"David Rientjes" <rientjes@google.com>
Subject: [PATCH 3.2 13/60] mm: hugetlbfs: skip shared VMAs when unmapping private pages to satisfy a fault
Date: Sun, 15 Nov 2015 01:45:45 +0000	[thread overview]
Message-ID: <lsq.1447551945.838302538@decadent.org.uk> (raw)
In-Reply-To: <lsq.1447551944.536641563@decadent.org.uk>

3.2.73-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Mel Gorman <mgorman@techsingularity.net>

commit 2f84a8990ebbe235c59716896e017c6b2ca1200f upstream.

SunDong reported the following on

  https://bugzilla.kernel.org/show_bug.cgi?id=103841

	I think I find a linux bug, I have the test cases is constructed. I
	can stable recurring problems in fedora22(4.0.4) kernel version,
	arch for x86_64.  I construct transparent huge page, when the parent
	and child process with MAP_SHARE, MAP_PRIVATE way to access the same
	huge page area, it has the opportunity to lead to huge page copy on
	write failure, and then it will munmap the child corresponding mmap
	area, but then the child mmap area with VM_MAYSHARE attributes, child
	process munmap this area can trigger VM_BUG_ON in set_vma_resv_flags
	functions (vma - > vm_flags & VM_MAYSHARE).

There were a number of problems with the report (e.g.  it's hugetlbfs that
triggers this, not transparent huge pages) but it was fundamentally
correct in that a VM_BUG_ON in set_vma_resv_flags() can be triggered that
looks like this

	 vma ffff8804651fd0d0 start 00007fc474e00000 end 00007fc475e00000
	 next ffff8804651fd018 prev ffff8804651fd188 mm ffff88046b1b1800
	 prot 8000000000000027 anon_vma           (null) vm_ops ffffffff8182a7a0
	 pgoff 0 file ffff88106bdb9800 private_data           (null)
	 flags: 0x84400fb(read|write|shared|mayread|maywrite|mayexec|mayshare|dontexpand|hugetlb)
	 ------------
	 kernel BUG at mm/hugetlb.c:462!
	 SMP
	 Modules linked in: xt_pkttype xt_LOG xt_limit [..]
	 CPU: 38 PID: 26839 Comm: map Not tainted 4.0.4-default #1
	 Hardware name: Dell Inc. PowerEdge R810/0TT6JF, BIOS 2.7.4 04/26/2012
	 set_vma_resv_flags+0x2d/0x30

The VM_BUG_ON is correct because private and shared mappings have
different reservation accounting but the warning clearly shows that the
VMA is shared.

When a private COW fails to allocate a new page then only the process
that created the VMA gets the page -- all the children unmap the page.
If the children access that data in the future then they get killed.

The problem is that the same file is mapped shared and private.  During
the COW, the allocation fails, the VMAs are traversed to unmap the other
private pages but a shared VMA is found and the bug is triggered.  This
patch identifies such VMAs and skips them.

Signed-off-by: Mel Gorman <mgorman@techsingularity.net>
Reported-by: SunDong <sund_sky@126.com>
Reviewed-by: Michal Hocko <mhocko@suse.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Cc: David Rientjes <rientjes@google.com>
Reviewed-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 mm/hugetlb.c | 8 ++++++++
 1 file changed, 8 insertions(+)

--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -2502,6 +2502,14 @@ static int unmap_ref_private(struct mm_s
 			continue;
 
 		/*
+		 * Shared VMAs have their own reserves and do not affect
+		 * MAP_PRIVATE accounting but it is possible that a shared
+		 * VMA is using the same page so check and skip such VMAs.
+		 */
+		if (iter_vma->vm_flags & VM_MAYSHARE)
+			continue;
+
+		/*
 		 * Unmap the page from other VMAs without their own reserves.
 		 * They get marked to be SIGKILLed if they fault in these
 		 * areas. This is because a future no-page fault on this VMA


  parent reply	other threads:[~2015-11-15  2:08 UTC|newest]

Thread overview: 64+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-11-15  1:45 [PATCH 3.2 00/60] 3.2.73-rc1 review Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 06/60] m68k: Define asmlinkage_protect Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 53/60] skbuff: Fix skb checksum partial check Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 19/60] USB: Add reset-resume quirk for two Plantronics usb headphones Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 12/60] genirq: Fix race in register_irq_proc() Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 50/60] sched: declare pid_alive as inline Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 25/60] ALSA: synth: Fix conflicting OSS device registration on AWE32 Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 10/60] MIPS: dma-default: Fix 32-bit fall back to GFP_DMA Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 45/60] md/raid1: ensure device failure recorded before write request returns Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 22/60] drivers/tty: require read access for controlling terminal Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 37/60] ASoC: wm8904: Correct number of EQ registers Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 39/60] drm/nouveau/gem: return only valid domain when there's only one Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 49/60] mvsas: Fix NULL pointer dereference in mvs_slot_task_free Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 27/60] 3w-9xxx: don't unmap bounce buffered commands Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 31/60] iommu/vt-d: fix range computation when making room for large pages Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 07/60] x86/xen: Do not clip xen_e820_map to xen_e820_map_entries when sanitizing map Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 30/60] crypto: ahash - ensure statesize is non-zero Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 29/60] ALSA: hda - Fix inverted internal mic on Lenovo G50-80 Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 38/60] IB/cm: Fix rb-tree duplicate free and use-after-free Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 34/60] xhci: Switch Intel Lynx Point LP ports to EHCI on shutdown Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 35/60] xhci: Add spurious wakeup quirk for LynxPoint-LP controllers Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 05/60] ath9k: declare required extra tx headroom Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 33/60] xhci: handle no ping response error properly Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 47/60] md/raid10: ensure device failure recorded before write request returns Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 40/60] powerpc/rtas: Validate rtas.entry before calling enter_rtas() Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 03/60] regmap: debugfs: Ensure we don't underflow when printing access masks Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 59/60] KEYS: Fix race between key destruction and finding a keyring by name Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 23/60] ppp: don't override sk->sk_state in pppoe_flush_dev() Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 02/60] module: Fix locking in symbol_put_addr() Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 08/60] UBI: Validate data_size Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 55/60] asix: Don't reset PHY on if_up for ASIX 88772 Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 28/60] xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing) Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 57/60] Failing to send a CLOSE if file is opened WRONLY and server reboots on a 4.x mount Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 54/60] ethtool: Use kcalloc instead of kmalloc for ethtool_get_strings Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 11/60] x86/process: Add proper bound checks in 64bit get_wchan() Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 48/60] md/raid10: don't clear bitmap bit when bad-block-list write fails Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 46/60] md/raid1: " Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 01/60] Revert "KVM: MMU: fix validation of mmio page fault" Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 18/60] iio: accel: sca3000: memory corruption in sca3000_read_first_n_hw_rb() Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 51/60] net: add length argument to skb_copy_and_csum_datagram_iovec Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 60/60] KEYS: Fix crash when attempt to garbage collect an uninstantiated keyring Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 17/60] clocksource: Fix abs() usage w/ 64bit values Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 43/60] dm btree remove: fix a bug when rebalancing nodes after removal Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 56/60] asix: Do full reset during ax88772_bind Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 32/60] xhci: don't finish a TD if we get a short transfer event mid TD Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 41/60] mm: make sendfile(2) killable Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 21/60] tty: fix stall caused by missing memory barrier in drivers/tty/n_tty.c Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 52/60] skbuff: Fix skb checksum flag on skb pull Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 16/60] md/raid0: apply base queue limits *before* disk_stack_limits Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 36/60] crypto: api - Only abort operations on fatal signal Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 58/60] KVM: x86: work around infinite loop in microcode when #AC is delivered Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 24/60] iwlwifi: dvm: fix D3 firmware PN programming Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 42/60] ppp: fix pppoe_dev deletion condition in pppoe_release() Ben Hutchings
2015-11-15  1:45 ` Ben Hutchings [this message]
2015-11-15  1:45 ` [PATCH 3.2 15/60] md/raid0: update queue parameter in a safer location Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 44/60] dm btree: fix leak of bufio-backed block in btree_split_beneath error path Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 04/60] regmap: debugfs: Don't bother actually printing when calculating max length Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 26/60] sched/core: Fix TASK_DEAD race in finish_task_switch() Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 20/60] usb: Add device quirk for Logitech PTZ cameras Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 14/60] [SMB3] Do not fall back to SMBWriteX in set_file_size error cases Ben Hutchings
2015-11-15  1:45 ` [PATCH 3.2 09/60] UBI: return ENOSPC if no enough space available Ben Hutchings
2015-11-15  2:29 ` [PATCH 3.2 00/60] 3.2.73-rc1 review Ben Hutchings
2015-11-15 13:42 ` Guenter Roeck
2015-11-16 11:11   ` Ben Hutchings

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=lsq.1447551945.838302538@decadent.org.uk \
    --to=ben@decadent.org.uk \
    --cc=aarcange@redhat.com \
    --cc=akpm@linux-foundation.org \
    --cc=hughd@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mgorman@techsingularity.net \
    --cc=mhocko@suse.com \
    --cc=n-horiguchi@ah.jp.nec.com \
    --cc=rientjes@google.com \
    --cc=stable@vger.kernel.org \
    --cc=sund_sky@126.com \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®