From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-10.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH, MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id E54A4C433C1 for ; Wed, 24 Mar 2021 23:20:32 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 68D9561A1E for ; Wed, 24 Mar 2021 23:20:32 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 68D9561A1E Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=linux-foundation.org Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id F386C6B006E; Wed, 24 Mar 2021 19:20:31 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id F0E986B0070; Wed, 24 Mar 2021 19:20:31 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id DFE6C6B0071; Wed, 24 Mar 2021 19:20:31 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0050.hostedemail.com [216.40.44.50]) by kanga.kvack.org (Postfix) with ESMTP id C66246B006E for ; Wed, 24 Mar 2021 19:20:31 -0400 (EDT) Received: from smtpin01.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay05.hostedemail.com (Postfix) with ESMTP id 8046B183E4B63 for ; Wed, 24 Mar 2021 23:20:31 +0000 (UTC) X-FDA: 77956339062.01.ADC7CE6 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by imf18.hostedemail.com (Postfix) with ESMTP id B6DB72000241 for ; Wed, 24 Mar 2021 23:20:30 +0000 (UTC) Received: by mail.kernel.org (Postfix) with ESMTPSA id EE88661A0F; Wed, 24 Mar 2021 23:20:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linux-foundation.org; s=korg; t=1616628028; bh=DfPvVvnnPDOnWWAUCw/MMTu0BV/F1aFcs7Ds2Ng04gc=; h=Date:From:To:Cc:Subject:In-Reply-To:References:From; b=mW4k3bZ+pK+Ysg7gscjEg94zbFO6h0wM0OI3WLRbjquYaGsdT9B6FGHJRwncMqk2o 3AmNZ3T7z2vK3kNKvl8TLZ6peKzmZHK9JXI2g/lDl6mAWf9awteRaHy4z57jtli3B4 Qg8KK7bbMeg+voQ1gLv3FOPPfzwy3S3GzuUFAHWY= Date: Wed, 24 Mar 2021 16:20:27 -0700 From: Andrew Morton To: Axel Rasmussen Cc: Alexander Viro , Andrea Arcangeli , Hugh Dickins , Jerome Glisse , Joe Perches , Lokesh Gidra , Mike Rapoport , Peter Xu , Shaohua Li , Shuah Khan , Wang Qing , linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, linux-kselftest@vger.kernel.org, Brian Geffon , Cannon Matthews , "Dr . David Alan Gilbert" , David Rientjes , Michel Lespinasse , Mina Almasry , Oliver Upton Subject: Re: [PATCH] userfaultfd/shmem: fix minor fault page leak Message-Id: <20210324162027.cc723b545ff62b1ad6f5223e@linux-foundation.org> In-Reply-To: <20210322204836.1650221-1-axelrasmussen@google.com> References: <20210322204836.1650221-1-axelrasmussen@google.com> X-Mailer: Sylpheed 3.5.1 (GTK+ 2.24.32; x86_64-pc-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Server: rspam03 X-Rspamd-Queue-Id: B6DB72000241 X-Stat-Signature: jrckzkpf8hs4cew7qnzp5jjesdpi6qj8 Received-SPF: none (linux-foundation.org>: No applicable sender policy available) receiver=imf18; identity=mailfrom; envelope-from=""; helo=mail.kernel.org; client-ip=198.145.29.99 X-HE-DKIM-Result: pass/pass X-HE-Tag: 1616628030-88851 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Mon, 22 Mar 2021 13:48:35 -0700 Axel Rasmussen wrote: > This fix is analogous to Peter Xu's fix for hugetlb [0]. If we don't > put_page() after getting the page out of the page cache, we leak the > reference. > > The fix can be verified by checking /proc/meminfo and running the > userfaultfd selftest in shmem mode. Without the fix, we see MemFree / > MemAvailable steadily decreasing with each run of the test. With the > fix, memory is correctly freed after the test program exits. > > Fixes: 00da60b9d0a0 ("userfaultfd: support minor fault handling for shmem") Confused. The affected code: > --- a/mm/shmem.c > +++ b/mm/shmem.c > @@ -1831,6 +1831,7 @@ static int shmem_getpage_gfp(struct inode *inode, pgoff_t index, > > if (page && vma && userfaultfd_minor(vma)) { > unlock_page(page); > + put_page(page); > *fault_type = handle_userfault(vmf, VM_UFFD_MINOR); > return 0; > } Is added by Peter's "page && vma && userfaultfd_minor". I assume that "Fixes:" is incorrect?