From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-9.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI, SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5438EC433DF for ; Wed, 19 Aug 2020 21:00:39 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id BF40A20658 for ; Wed, 19 Aug 2020 21:00:38 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="Ze+CBBwV" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org BF40A20658 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=linux.ibm.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 2D7D28D005B; Wed, 19 Aug 2020 17:00:37 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 288B58D0057; Wed, 19 Aug 2020 17:00:37 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 176688D005B; Wed, 19 Aug 2020 17:00:37 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0153.hostedemail.com [216.40.44.153]) by kanga.kvack.org (Postfix) with ESMTP id F31538D0057 for ; Wed, 19 Aug 2020 17:00:36 -0400 (EDT) Received: from smtpin28.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay05.hostedemail.com (Postfix) with ESMTP id AFC67181AEF07 for ; Wed, 19 Aug 2020 21:00:36 +0000 (UTC) X-FDA: 77168536872.28.stone75_2d087c92702b Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin28.hostedemail.com (Postfix) with ESMTP id 7AD6F6D65 for ; Wed, 19 Aug 2020 21:00:36 +0000 (UTC) X-HE-Tag: stone75_2d087c92702b X-Filterd-Recvd-Size: 5968 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) by imf48.hostedemail.com (Postfix) with ESMTP for ; Wed, 19 Aug 2020 21:00:35 +0000 (UTC) Received: from pps.filterd (m0098421.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 07JKWXot181172; Wed, 19 Aug 2020 17:00:30 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=date : from : to : cc : subject : message-id : references : mime-version : content-type : in-reply-to; s=pp1; bh=R4rXw64wavA2Oiy2dvEogrKVyn9FrOYN4omW0UQg8Dk=; b=Ze+CBBwVZxazL7yA5TZjb9lefZD2Kc0RZakf4dp/8DH9fxzJomnBgpXRKQa8zaVHprFb +sUwkAiYLKpivuQsnHR9ph0Eo0rllEt62A6rUmwhFSmeuAbE1r3GreyeLTlje1+Wv5kZ AzhCG1A0HTSzvZyXVpGMJ5ZzWsmRa/Lr82MNbs5wMBmsaQSvBdCJ9TybOifGvDch7zRy zOn+FWs4s3E+bbFDCBi/1UgBuuuOb/4jAbKWcXrgpMzyj5avN9CTL1ptHDgXc0R/Zo2F OU2DwJJGKhikKUNq2pr80FqdonYXSOQQuBNy5CcgLTiA4yG6rrLvdan4TVIhv83R9TZt nw== Received: from ppma06ams.nl.ibm.com (66.31.33a9.ip4.static.sl-reverse.com [169.51.49.102]) by mx0a-001b2d01.pphosted.com with ESMTP id 331an61dt6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2020 17:00:30 -0400 Received: from pps.filterd (ppma06ams.nl.ibm.com [127.0.0.1]) by ppma06ams.nl.ibm.com (8.16.0.42/8.16.0.42) with SMTP id 07JKq74o022935; Wed, 19 Aug 2020 21:00:29 GMT Received: from b06cxnps3074.portsmouth.uk.ibm.com (d06relay09.portsmouth.uk.ibm.com [9.149.109.194]) by ppma06ams.nl.ibm.com with ESMTP id 330tbvs1bp-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 19 Aug 2020 21:00:28 +0000 Received: from d06av23.portsmouth.uk.ibm.com (d06av23.portsmouth.uk.ibm.com [9.149.105.59]) by b06cxnps3074.portsmouth.uk.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 07JL0Qlh14221728 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 19 Aug 2020 21:00:26 GMT Received: from d06av23.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 74519A4059; Wed, 19 Aug 2020 21:00:26 +0000 (GMT) Received: from d06av23.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E36D0A4085; Wed, 19 Aug 2020 21:00:25 +0000 (GMT) Received: from linux.ibm.com (unknown [9.145.34.219]) by d06av23.portsmouth.uk.ibm.com (Postfix) with ESMTPS; Wed, 19 Aug 2020 21:00:25 +0000 (GMT) Date: Thu, 20 Aug 2020 00:00:24 +0300 From: Mike Rapoport To: "Matthew Wilcox (Oracle)" Cc: linux-mm@kvack.org, Andrew Morton , John Hubbard , Vlastimil Babka Subject: Re: [PATCH] mm/debug: Do not dereference i_ino blindly Message-ID: <20200819210024.GO969206@linux.ibm.com> References: <20200819185710.28180-1-willy@infradead.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20200819185710.28180-1-willy@infradead.org> X-TM-AS-GCONF: 00 X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.235,18.0.687 definitions=2020-08-19_13:2020-08-19,2020-08-19 signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 phishscore=0 adultscore=0 priorityscore=1501 spamscore=0 mlxscore=0 suspectscore=1 malwarescore=0 impostorscore=0 bulkscore=0 clxscore=1015 mlxlogscore=909 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2006250000 definitions=main-2008190163 X-Rspamd-Queue-Id: 7AD6F6D65 X-Spamd-Result: default: False [0.00 / 100.00] X-Rspamd-Server: rspam05 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Wed, Aug 19, 2020 at 07:57:10PM +0100, Matthew Wilcox (Oracle) wrote: > We check i_dentry is fetchable and i_ino is earlier in the struct > than i_ino, so it ought to work fine, but it's possible that struct > randomisation has reordered i_ino after i_dentry and the pointer is > just wild enough that i_dentry is fetchable and i_ino isn't. > > Also print the inode number if the dentry is invalid. > > Reported-by: Vlastimil Babka > Signed-off-by: Matthew Wilcox (Oracle) Reviewed-by: Mike Rapoport > --- > mm/debug.c | 12 +++++++----- > 1 file changed, 7 insertions(+), 5 deletions(-) > > diff --git a/mm/debug.c b/mm/debug.c > index ca8d1cacdecc..2a767865145c 100644 > --- a/mm/debug.c > +++ b/mm/debug.c > @@ -120,6 +120,7 @@ void __dump_page(struct page *page, const char *reason) > struct hlist_node *dentry_first; > struct dentry *dentry_ptr; > struct dentry dentry; > + unsigned long ino; > > /* > * mapping can be invalid pointer and we don't want to crash > @@ -136,21 +137,22 @@ void __dump_page(struct page *page, const char *reason) > goto out_mapping; > } > > - if (get_kernel_nofault(dentry_first, &host->i_dentry.first)) { > + if (get_kernel_nofault(dentry_first, &host->i_dentry.first) || > + get_kernel_nofault(ino, &host->i_ino)) { > pr_warn("aops:%ps with invalid host inode %px\n", > a_ops, host); > goto out_mapping; > } > > if (!dentry_first) { > - pr_warn("aops:%ps ino:%lx\n", a_ops, host->i_ino); > + pr_warn("aops:%ps ino:%lx\n", a_ops, ino); > goto out_mapping; > } > > dentry_ptr = container_of(dentry_first, struct dentry, d_u.d_alias); > if (get_kernel_nofault(dentry, dentry_ptr)) { > - pr_warn("aops:%ps with invalid dentry %px\n", a_ops, > - dentry_ptr); > + pr_warn("aops:%ps ino:%lx with invalid dentry %px\n", > + a_ops, ino, dentry_ptr); > } else { > /* > * if dentry is corrupted, the %pd handler may still > @@ -158,7 +160,7 @@ void __dump_page(struct page *page, const char *reason) > * corrupted struct page > */ > pr_warn("aops:%ps ino:%lx dentry name:\"%pd\"\n", > - a_ops, host->i_ino, &dentry); > + a_ops, ino, &dentry); > } > } > out_mapping: > -- > 2.28.0 > -- Sincerely yours, Mike.