From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3440E7717D for ; Fri, 13 Dec 2024 06:12:57 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 212986B007B; Fri, 13 Dec 2024 01:12:57 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 1C2A86B0082; Fri, 13 Dec 2024 01:12:57 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 08A4C6B0083; Fri, 13 Dec 2024 01:12:57 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id DE1486B007B for ; Fri, 13 Dec 2024 01:12:56 -0500 (EST) Received: from smtpin09.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay03.hostedemail.com (Postfix) with ESMTP id 77C04A0CF0 for ; Fri, 13 Dec 2024 06:12:56 +0000 (UTC) X-FDA: 82888916082.09.D98D42C Received: from out30-99.freemail.mail.aliyun.com (out30-99.freemail.mail.aliyun.com [115.124.30.99]) by imf29.hostedemail.com (Postfix) with ESMTP id 37AFD120005 for ; Fri, 13 Dec 2024 06:12:16 +0000 (UTC) Authentication-Results: imf29.hostedemail.com; dkim=pass header.d=linux.alibaba.com header.s=default header.b=YuqKY98v; dmarc=pass (policy=none) header.from=linux.alibaba.com; spf=pass (imf29.hostedemail.com: domain of baolin.wang@linux.alibaba.com designates 115.124.30.99 as permitted sender) smtp.mailfrom=baolin.wang@linux.alibaba.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1734070362; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=OMF8uXbZ/IeLfhBi6aXh2FshojNwRAvQ2cThwJdSi28=; b=h0yQnRxP/MsqzutScqhSEg3eeNw4WWlJInVZ+TQFofv9ft37ItRyI/hDRgSycU2jFVUop0 4/wiOZI8zVMESVrg8gWQ7NNqoCRXLO3zSFpJAwyRn15OkE+JLoE7tJBN0aI+zs0LaOo2X+ fcwLTWIyCxXn8EhyIAcL7KJwQx/fPoA= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1734070362; a=rsa-sha256; cv=none; b=M6Q+VY/XuSJQyZY5tFmH62vrdLXOPKJr5g6P4aZJfPKasPGMmn6zw7n7oADAwff57HrwZP 7KxyU1NVqF50egQMrpU8t1NHBKjA5SqmQMMjb/Grn73//AI1RmKb3CC7EZlH95D2q8ZKt6 kPs966mHL9eycMHkBBaQPCy3jPAM6Mg= ARC-Authentication-Results: i=1; imf29.hostedemail.com; dkim=pass header.d=linux.alibaba.com header.s=default header.b=YuqKY98v; dmarc=pass (policy=none) header.from=linux.alibaba.com; spf=pass (imf29.hostedemail.com: domain of baolin.wang@linux.alibaba.com designates 115.124.30.99 as permitted sender) smtp.mailfrom=baolin.wang@linux.alibaba.com DKIM-Signature:v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1734070369; h=Message-ID:Date:MIME-Version:Subject:To:From:Content-Type; bh=OMF8uXbZ/IeLfhBi6aXh2FshojNwRAvQ2cThwJdSi28=; b=YuqKY98vtYYDuIhF/Zr1dqjptHZ0qtzYtSRjl/yxlRzUWvpN60yAgTJbSGSL4wJH9w0vbzyOYUoKxy5UTxycSsSdqavusJ3H4pccy12+c2PN7sAjOaGahRtD2lMyLUu9rODreL4ZnGpDrUl9+JWi1Bp9A57c+PqHuyWu9NcgvQQ= Received: from 30.74.144.152(mailfrom:baolin.wang@linux.alibaba.com fp:SMTPD_---0WLNyEWR_1734070368 cluster:ay36) by smtp.aliyun-inc.com; Fri, 13 Dec 2024 14:12:48 +0800 Message-ID: <1f8b523e-d68f-4382-8b1e-2475eb47ae81@linux.alibaba.com> Date: Fri, 13 Dec 2024 14:12:47 +0800 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v3 1/5] Xarray: Do not return sibling entries from xas_find_marked() To: Kemeng Shi , akpm@linux-foundation.org, willy@infradead.org Cc: linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org References: <20241213122523.12764-1-shikemeng@huaweicloud.com> <20241213122523.12764-2-shikemeng@huaweicloud.com> From: Baolin Wang In-Reply-To: <20241213122523.12764-2-shikemeng@huaweicloud.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Stat-Signature: irqstgwzwdiushyc4y5rtnq9x3pu74z7 X-Rspamd-Queue-Id: 37AFD120005 X-Rspam-User: X-Rspamd-Server: rspam01 X-HE-Tag: 1734070336-926397 X-HE-Meta: U2FsdGVkX1+aW62P+k9wfp91JVhn1PC1j3/v4VCH4wdnKzOK0g8yR5gf9hck6y5jqNowGTv+bmsfbUhphwgAUtPGjLZGB/ymx26mQxwW91yhy1cU5jGAponPOhWiiFIOro3YYYKFUh/xdbC1FounS+wiDCGPguihPqYL0u1JKhT8e1tSLSvgMExu2urutlxDNsg3L8LsnNcvlTjwlfj7nxTwrV0zRIpHSD9DBueDjXCTsPqXvpvpxGmCpWv9Y/ZkRb2tvEoAeLU8zfpd7jczs+ULBFghAdsy+z79RDmmr7pCX/Uh1ia9PDFe7h56ziXJ2ZM8kTskkpdhBSJSGxBH75I0wkbYqD6qxfYY9+VWFkRyuyCcFJfE1JQqZkLk13+qXQe2HtER/1VXI/GkfbMZJ+wmdcGa0qTJjlexkXkTf6tAcs//P8pgEbAFW3I0FngBE+iL/WNktT2h0Qxnk5OZ60EqvLvRJDKYihZ1WqMDrB+CToAjShiOeU/VJ30XLn6pXZ1NphPjwCZA4MyQsiXC74oOsD2dp0szZJJgcJguy6a1paiWYv4pgpLj15Y8G4b/f/huhHoah7cppzWx5B6buBfne8zB2lOeIhqe4c4wDRqywQqmt0kSsjSJeQazBeUcvcLktDHzYnoh7YLK3zwxRAdgqI21/aCNQ8NPDbvocpaujgHX1NA4tFB3LcjRyOrGYFF0wdVyVxWLxAJ9faF1wtpuEt+0iNVi03q5S8fNSSXx0qtH+Zv1U+84RKMlxoPdjb/vUy7bW8dsCTNAHDxchy0cneZ4pb3OZIjPaUdZToWoYXhXBvFj5oyz6ZdxPqJo5LJYCgShJ/3hz2wynZdpfcpxrB+AJeRVhtWQ7BMBzrySRWtVnnqUqy5k/UzA/d905kHM1s4SgPiCf+1FAqo7PRx4F3wQxweL89pzoG1jjHnqdYavMjcJ8M/AjQYpuhb73cdaMyFslpte5N1oC7I UlDXHz6u N6u5iKEznXKXmtw443JQbkbk/BfstGcOvGSAJhNE0SJ5zwPe1SRiiXbniP7lCIoUeSt/6qbYy1e7xsbYZU7RekgIwCztEnr3IJgfMSQaWu9TPVM5vl5jHjLVoEgRHl20fLrxh1jo5adIkLoVl49m0rEtzz5duAZhx08gqRr3mUPhl1OTBKj4lwUZiKY+qavFw8o379I/gOmp9CHJZ8lVfCdIxGV+VS9xI5cSl5GT162D+1lWh4MXWiKnZrWY0pV7KOK5ThIzpdVLv9jSgmYVIv6gmov9uOP/WY+ykxhDrLK+HPE8= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000932, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On 2024/12/13 20:25, Kemeng Shi wrote: > Similar to issue fixed in commit cbc02854331ed ("XArray: Do not return > sibling entries from xa_load()"), we may return sibling entries from > xas_find_marked as following: > Thread A: Thread B: > xa_store_range(xa, entry, 6, 7, gfp); > xa_set_mark(xa, 6, mark) > XA_STATE(xas, xa, 6); > xas_find_marked(&xas, 7, mark); > offset = xas_find_chunk(xas, advance, mark); > [offset is 6 which points to a valid entry] > xa_store_range(xa, entry, 4, 7, gfp); > entry = xa_entry(xa, node, 6); > [entry is a sibling of 4] > if (!xa_is_node(entry)) > return entry; > > Skip sibling entry like xas_find() does to protect caller from seeing > sibling entry from xas_find_marked() or caller may use sibling entry > as a valid entry and crash the kernel. > > Besides, load_race() test is modified to catch mentioned issue and modified > load_race() only passes after this fix is merged. > > Here is an example how this bug could be triggerred in tmpfs which > enables large folio in mapping: > Let's take a look at involved racer: > 1. How pages could be created and dirtied in shmem file. > write > ksys_write > vfs_write > new_sync_write > shmem_file_write_iter > generic_perform_write > shmem_write_begin > shmem_get_folio > shmem_allowable_huge_orders > shmem_alloc_and_add_folios > shmem_alloc_folio > __folio_set_locked > shmem_add_to_page_cache > XA_STATE_ORDER(..., index, order) > xax_store() > shmem_write_end > folio_mark_dirty() > > 2. How dirty pages could be deleted in shmem file. > ioctl > do_vfs_ioctl > file_ioctl > ioctl_preallocate > vfs_fallocate > shmem_fallocate > shmem_truncate_range > shmem_undo_range > truncate_inode_folio > filemap_remove_folio > page_cache_delete > xas_store(&xas, NULL); > > 3. How dirty pages could be lockless searched > sync_file_range > ksys_sync_file_range > __filemap_fdatawrite_range > filemap_fdatawrite_wbc Seems not a good example, IIUC, tmpfs doesn't support writeback (mapping_can_writeback() will return false), right? > do_writepages > writeback_use_writepage > writeback_iter > writeback_get_folio > filemap_get_folios_tag > find_get_entry > folio = xas_find_marked() > folio_try_get(folio) >