From: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
To: Hugh Dickins <hughd@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
David Rientjes <rientjes@google.com>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
Naoya Horiguchi <nao.horiguchi@gmail.com>
Subject: Re: [PATCH v2 3/3] mm/hugetlb: add migration entry check in hugetlb_change_protection
Date: Tue, 12 Aug 2014 14:55:44 -0400 [thread overview]
Message-ID: <20140812185544.GC8975@nhori.bos.redhat.com> (raw)
In-Reply-To: <alpine.LSU.2.11.1408091611150.15311@eggly.anvils>
On Sat, Aug 09, 2014 at 04:12:09PM -0700, Hugh Dickins wrote:
> On Fri, 1 Aug 2014, Naoya Horiguchi wrote:
>
> > There is a race condition between hugepage migration and change_protection(),
> > where hugetlb_change_protection() doesn't care about migration entries and
> > wrongly overwrites them. That causes unexpected results like kernel crash.
> >
> > This patch adds is_hugetlb_entry_(migration|hwpoisoned) check in this
> > function and skip all such entries.
> >
> > Signed-off-by: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
> > Cc: <stable@vger.kernel.org> # [3.12+]
> > ---
> > mm/hugetlb.c | 8 +++++++-
> > 1 file changed, 7 insertions(+), 1 deletion(-)
> >
> > diff --git mmotm-2014-07-22-15-58.orig/mm/hugetlb.c mmotm-2014-07-22-15-58/mm/hugetlb.c
> > index 863f45f63cd5..1da7ca2e2a02 100644
> > --- mmotm-2014-07-22-15-58.orig/mm/hugetlb.c
> > +++ mmotm-2014-07-22-15-58/mm/hugetlb.c
> > @@ -3355,7 +3355,13 @@ unsigned long hugetlb_change_protection(struct vm_area_struct *vma,
> > spin_unlock(ptl);
> > continue;
> > }
> > - if (!huge_pte_none(huge_ptep_get(ptep))) {
> > + pte = huge_ptep_get(ptep);
> > + if (unlikely(is_hugetlb_entry_migration(pte) ||
> > + is_hugetlb_entry_hwpoisoned(pte))) {
>
> Another instance of this pattern. Oh well, perhaps we have to continue
> this way while backporting fixes, but the repetition irritates me.
Yes, I thought about the repetition too, so at some point (hopefully
in this patchset?) it would be nice to fix up all the similar code.
> Or use is_swap_pte() as follow_hugetlb_page() does?
>
> More importantly, the regular change_pte_range() has to
> make_migration_entry_read() if is_migration_entry_write():
> why is that not necessary here?
It's necessary for migration entry. For hwpoison entry, just unlocking is ok.
(I focused on avoiding bug and thought not enough about proper fixing, sorry.)
> And have you compared hugetlb codepaths with normal codepaths, to see
> if there are other huge places which need to check for a migration entry
> now? If you have checked, please reassure us in the commit message:
> we would prefer not to have these fixes coming in one by one.
I've not checked all hugetlb codepaths, so will do this.
(for example free_pgtables() may need a check of migration pmd entry.)
> (I first thought __unmap_hugepage_range() would need it, but since
> zap_pte_range() only checks it for rss stats, and hugetlb does not
> participate in rss stats, it looks like no need.)
You catch the point. I thought that is_hugetlb_entry_migration() check
is necessary in __unmap_hugepage_range(), but didn't include it in this
patch just because it's not related to this specific problem.
But it's an inefficient manner of kernel development, so I'll include
it in the next version.
Thanks,
Naoya Horiguchi
> Hugh
>
> > + spin_unlock(ptl);
> > + continue;
> > + }
> > + if (!huge_pte_none(pte)) {
> > pte = huge_ptep_get_and_clear(mm, address, ptep);
> > pte = pte_mkhuge(huge_pte_modify(pte, newprot));
> > pte = arch_make_huge_pte(pte, vma, NULL, 0);
> > --
> > 1.9.3
>
--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org. For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
next prev parent reply other threads:[~2014-08-12 19:26 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-08-01 17:37 [PATCH v2 1/3] mm/hugetlb: take refcount under page table lock in follow_huge_pmd() Naoya Horiguchi
2014-08-01 17:37 ` [PATCH v2 2/3] mm/hugetlb: use get_page_unless_zero() in hugetlb_fault() Naoya Horiguchi
2014-08-09 23:11 ` Hugh Dickins
2014-08-12 18:55 ` Naoya Horiguchi
2014-08-01 17:37 ` [PATCH v2 3/3] mm/hugetlb: add migration entry check in hugetlb_change_protection Naoya Horiguchi
2014-08-09 23:12 ` Hugh Dickins
2014-08-12 18:55 ` Naoya Horiguchi [this message]
2014-08-01 21:53 ` [PATCH v2 1/3] mm/hugetlb: take refcount under page table lock in follow_huge_pmd() Andrew Morton
2014-08-01 21:58 ` Naoya Horiguchi
2014-08-04 15:50 ` [PATCH] mm/hugetlb: remove unused argument of follow_huge_(pmd|pud) Naoya Horiguchi
2014-08-04 15:29 ` [PATCH v2 1/3] mm/hugetlb: take refcount under page table lock in follow_huge_pmd() Naoya Horiguchi
2014-08-09 23:01 ` Hugh Dickins
2014-08-12 18:55 ` Naoya Horiguchi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140812185544.GC8975@nhori.bos.redhat.com \
--to=n-horiguchi@ah.jp.nec.com \
--cc=akpm@linux-foundation.org \
--cc=hughd@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=nao.horiguchi@gmail.com \
--cc=rientjes@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox