From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0F81EC77B7D for ; Mon, 15 May 2023 23:07:17 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 8D244900003; Mon, 15 May 2023 19:07:17 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 8824C900002; Mon, 15 May 2023 19:07:17 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 74B40900003; Mon, 15 May 2023 19:07:17 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 645B4900002 for ; Mon, 15 May 2023 19:07:17 -0400 (EDT) Received: from smtpin06.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay03.hostedemail.com (Postfix) with ESMTP id 2E48CA0E91 for ; Mon, 15 May 2023 23:07:17 +0000 (UTC) X-FDA: 80794027314.06.6BFC7E5 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by imf23.hostedemail.com (Postfix) with ESMTP id 43953140012 for ; Mon, 15 May 2023 23:07:14 +0000 (UTC) Authentication-Results: imf23.hostedemail.com; dkim=pass header.d=gmail.com header.s=20221208 header.b=kuHveEzN; spf=pass (imf23.hostedemail.com: domain of lstoakes@gmail.com designates 209.85.128.52 as permitted sender) smtp.mailfrom=lstoakes@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1684192035; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=6j/nsOgHTR4HSwmATJ+gjDXbPDspqE4tDffur2pBUW8=; b=maI7vO7WKl7wHH5O2RH0a3lSfHGzoZf/XZylPw9zv01XfFnVzX8THyUeKdy+uS7qFiKBX9 a3JhmpaUXeL43OoLPv2UL7z/v7WIsXGE8E07DNMf4VZzuUz7skInH/C+aDLJKoludrTxCQ 41omV/12WWSlZ0mc1RKLDSTPbgB6aXA= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1684192035; a=rsa-sha256; cv=none; b=BwmEXfSKJb7TvXRXRlX3nooJlBgMc6bZ5SkA2Uuq2W9JF2ktHlKJf7ya6QeOWZMqukV9NY iEmxDowNO3tSsbtPfT59vT8ajthcG+iyhCg6QpdKv5DNMDT1Zi07e1ahfxt0wX8I4Iq+Gx +SvU+q5L7j+WHhb0y0jeMwkB6ujaSUg= ARC-Authentication-Results: i=1; imf23.hostedemail.com; dkim=pass header.d=gmail.com header.s=20221208 header.b=kuHveEzN; spf=pass (imf23.hostedemail.com: domain of lstoakes@gmail.com designates 209.85.128.52 as permitted sender) smtp.mailfrom=lstoakes@gmail.com; dmarc=pass (policy=none) header.from=gmail.com Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-3f50020e0f8so5572535e9.0 for ; Mon, 15 May 2023 16:07:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1684192033; x=1686784033; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=6j/nsOgHTR4HSwmATJ+gjDXbPDspqE4tDffur2pBUW8=; b=kuHveEzNq4//+GGfS7POo3gtgBRRd++3cNEtMqG8NuA81QDSNRW4tUfJ7y4mBm2mp0 nITD5lFF5swL0tse+s7SsztgD3/pnMOCM8yANNmc0fYGOnP+gMD2m/uDJyvuhzHzVKlx HaQeUS9pVMsPL0fcr9OXh86qsgI8SIbKumC4XUU5Qz0a8TSekVPIlnw7NWfpv0O+EqP0 tRQL5K2eusLdp0AUhkwUREta6hBmPPypEPYjfUtTTxJZUZ9lDth0Fny8DdtsDpM+R9Zo 98s7YgZGojwckrAMdYq6a9Evt9JnythOHCOdpx+YCHFYiuaSAHWcuAYSZ3d8/ukocali tnIg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1684192033; x=1686784033; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=6j/nsOgHTR4HSwmATJ+gjDXbPDspqE4tDffur2pBUW8=; b=NtwIpMz1IBev2Vf8cobYWvWlmg0rhtenAmB5CWtv8f0zf3Pxg8wvEZ+QtgVCZLIrye e4Un9VuA5yquvKf3P8VM7d3gAtBPy3ojcpKh22fkcZ5q/j818FZGpwkqtiVq8tqfq3Fe HsOrRtHlutD04Q1adxV82wM1S6m2xd+qkNnE6LcgKmsTOiDCdm3eXGreFzRRZuv6sD0+ 4LHDjEHhDqusijtIzkE+Ton44UMf/PSkITy/9NXtQu624pBw6gFENONOg+DescJz4jsm yU325kuM3SLIUgfUFrjpQUwL8x4dYtyd8pTHU82MsVD1YDj7SdmeIcJC0rcj5nPUIojg JK6A== X-Gm-Message-State: AC+VfDxaeCFo5mQHmatO7Fb7w7AXKPSlYcVqS/+Mc2x+bkdAOVPV6eSJ o2Z3uzI9FmCR3LMGekinXUA= X-Google-Smtp-Source: ACHHUZ7e4XGwKLFeai3EYTdxhXJNrtTXJ3tfSWzkgKRlHyGnyxzT9D47ODs5gApWq4D66xu28G9ijA== X-Received: by 2002:adf:dfc7:0:b0:307:c0c4:1094 with SMTP id q7-20020adfdfc7000000b00307c0c41094mr14016148wrn.34.1684192033343; Mon, 15 May 2023 16:07:13 -0700 (PDT) Received: from localhost ([2a00:23c5:dc8c:8701:1663:9a35:5a7b:1d76]) by smtp.gmail.com with ESMTPSA id q6-20020adfcd86000000b00307a83ea722sm505531wrj.58.2023.05.15.16.07.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 May 2023 16:07:12 -0700 (PDT) Date: Tue, 16 May 2023 00:07:11 +0100 From: Lorenzo Stoakes To: Peter Xu Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrew Morton , Mike Rapoport , Mark Rutland , "Liam R . Howlett" , Alexander Viro , Christian Brauner Subject: Re: [PATCH v2] mm: userfaultfd: avoid passing an invalid range to vma_merge() Message-ID: <20abea10-5307-498b-b9df-8f0b2fed1701@lucifer.local> References: <20230515193232.67552-1-lstoakes@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Rspamd-Queue-Id: 43953140012 X-Rspam-User: X-Rspamd-Server: rspam06 X-Stat-Signature: dbxqunw9457etnhq9m3qbqk7aqi1uhbt X-HE-Tag: 1684192034-517977 X-HE-Meta: U2FsdGVkX1+cCj7JXSlabdhtfEPCvp2wxGLZ7Ozv6zxyXDp9cmughXuHyUvUo5PLNUTqDwJbiupKMJhKE1yA+maYMKzSt1uXGV9ts0EtQklPtIsNBT4pcExEFqBMYqQNdaxVQbu5PzpJndWQOhtqORNDXUm2n6b7ZZcxOcDcg+H+kvbazNA0g8lsZfZoPP69bUwQDsxEJ86A6JkRaCOcH0RF4ChiAabQzkGdCclMKpwXkKSiNUkaePXuRnY55A71u58YnBkhv/9OlSznkQ9hdEy8xEmIJUPd8BcJHsonXlLpINxF8oV89tg2emPqC31y8nMQQV7pwAyHSGEqzMYxWb4HC6ZERDEh5LkbP7ly3Hax5NhilbW6jd+aUm3YvLgBrNAEkwv6Q8T9ETCwx+TNC57oQ+6gOXWRaRiJ0LUPpj9YsVx4j22z9j7wiUXqhhiHWkD8TZyjikGSdQp8LXN/20UQxMlG/QheTXNNU6lY5gvNHtr4hJaiPNwrZijm1VQdGlA60FBw678Yaaz0lyVgEPgbqVa0VGBb5PTO1VnixZtkWSNWJvwgZpwoITxwiIF3hBu2dn+RJIO+6NrNyWwhoeB9JIaRPl86qATyxSyiZJ3S5gh4k53dNZP52yRdcSpiNUIsvO2pDumGOh4Y/lTrgqc7Rn9n2OpgOIS5kbUflawi555zqH+SMr+erd59UsIvM6ArUuz9TpUGM0kseBKi/82F6YdBvGzS4pycf6PbRrT/XbIpyRaopp7ClnaIde9ucLKLt4rY3aO2z4syHPA+VsnsXmirZgxNJpoY+nkDpywcS57hx7n13tgA7lPxpyFYNJRowJBk2R8g7rvIq3Po6suG3aziageQyrT0Wn4Wz4YTjC36BZWWgu/6a8f7gd+CxLmaAq6mq9dY/FdBtiCgjGYBFIu0BfJvxyvAIvw+GuPwMJt7wDWKqGbIXDFmej+xvukte5CzJl7L06cNYbH HFJlwevU 4BC8nNInECuTfcYGKra7mz0Sps4ns59Ga1qTclyhWLfLtSobgJo53PsUaVruCUg6mlbtlqhwasT3B457Vmh3G42dmz3hgR4iW2QbG5WQBEwVVu7H1LPoIzjmRmq0JjJTvgA8aJqfGM+LHADwAscLlWzuGo0+hRP9IKDxyfHkXqSGUFp8Dudm+ylP98YpfQI/RWr2sfJYwWdZmDwYln230hGWtZal/tcmLeIxaA7KK+QgFw0NGfBnf4gX5ag5IfV+G0HYN7QSd2DE7AKsmqv4J7NXI0OCG8RvN7Ows20rDAwSP7I4XsgioWkrBygR/SyrnfxAWC9zQKvYNSGMH9S1xU+59v1QrGwK3j8rkmtBfe4M6S2oANN5F2vi0WKfwcCIEo2xGtNJ0h3ih9N2KaP6aCXH3rAz2KxyT5+wIgH11lfyhqh2k9M3j0EFBSWF8NNSJzON9Bxz3c+n28xQBJnM98UBbvQ== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Mon, May 15, 2023 at 11:04:27PM +0100, Lorenzo Stoakes wrote: [snip] > > Could you explain a bit why we don't need to merge in this case? > > > > I'm considering, for example, when we have: > > > > vma1(range 0-9, with uffd), vma2(range 10-19, no uffd) > > > > Then someone unregisters uffd on range (5-9), iiuc it should become: > > > > vma1(range 0-4, with uffd), vma2(range 5-19, no uffd) > > > > But if no merge here it's: > > > > vma1(range 0-4, with uffd), vma3(range 5-9, no uffd), vma2(range 10-19, no uffd) > > > > Maybe I missed something? > > > > There's something really, really wrong with this. It simply isn't valid to > invoke vma_merge() over an existing VMA that != prev where you're not > specifying addr = vma->vm_start, end == vma->vm_end. > > This seems like you're relying on:- > > *** > CCCCCNNNNN -> CCNNNNNNNN > > By specifying parameters that are compatible with N even though you're only > partially spanning C? > > This is crazy, and isn't how this should be used. vma_merge() is not > supposed to do partial merges. If it works (presumably it does) this is not > by design unless I've lost my mind and I (and others) have somehow not > noticed this?? > > I think you're right that now we'll end up with more fragmentation, but > what you're suggesting is not how vma_merge() is supposed to work. > > As I said above, giving vma_merge() invalid parameters is very dangerous as > you could end up merging over empty ranges in theory (and could otherwise > have corruption). > > I guess we should probably be passing 0 to the last parameter in > split_vma() here then to ensure we do a merge pass too. Will experiment > with this. > > I'm confused as to how the remove from case 8 is not proceeding. I'll look > into this some more... > > Happy to be corrected if I'm misconstruing this! > OK, so I wrote a small program to do perform exactly this case [0] and it seems that the outcome is the same before and after this patch - vma_merge() is clearly rejecting the case 8 merge (phew!) and in both instances you end up with 3 VMAs. So this patch doesn't change this behaviour and everything is as it was before. Ideally we'd let it go for another pass, so maybe we should change the split to add a new VMA _afterwards_. Will experiment with that, separately. But looks like the patch is good as it is. (if you notice something wrong with the repro, etc. do let me know!) [0]: https://gist.github.com/lorenzo-stoakes/a11a10f5f479e7a977fc456331266e0e [snip]