From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 661CAC3DA7F for ; Thu, 1 Aug 2024 02:43:03 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id D646E6B00A7; Wed, 31 Jul 2024 22:43:02 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id CECD56B00A8; Wed, 31 Jul 2024 22:43:02 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id B8DDE6B00AB; Wed, 31 Jul 2024 22:43:02 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 96CE86B00A7 for ; Wed, 31 Jul 2024 22:43:02 -0400 (EDT) Received: from smtpin02.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay07.hostedemail.com (Postfix) with ESMTP id 1CB4E16084E for ; Thu, 1 Aug 2024 02:43:02 +0000 (UTC) X-FDA: 82402129404.02.FD83FD6 Received: from out-181.mta0.migadu.com (out-181.mta0.migadu.com [91.218.175.181]) by imf13.hostedemail.com (Postfix) with ESMTP id F0AC32000E for ; Thu, 1 Aug 2024 02:42:58 +0000 (UTC) Authentication-Results: imf13.hostedemail.com; dkim=pass header.d=linux.dev header.s=key1 header.b=XRK+N5mA; dmarc=pass (policy=none) header.from=linux.dev; spf=pass (imf13.hostedemail.com: domain of muchun.song@linux.dev designates 91.218.175.181 as permitted sender) smtp.mailfrom=muchun.song@linux.dev ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1722480134; a=rsa-sha256; cv=none; b=zszFrwJZcJlR1YGmO9vET5f0mWWR0WdsVCNjSqM0USUjVz7QvsWZrEyPawqaKLXli921gd 1P5gdnmC5310x3sNdja+Ht8N+PBOl+l1G0lhsHfLr/86TVcQrZ1b+v2IYxU7iguhsVhSOF 2UC76/9aRUZLivE1XEAQFmcD5Dz11MI= ARC-Authentication-Results: i=1; imf13.hostedemail.com; dkim=pass header.d=linux.dev header.s=key1 header.b=XRK+N5mA; dmarc=pass (policy=none) header.from=linux.dev; spf=pass (imf13.hostedemail.com: domain of muchun.song@linux.dev designates 91.218.175.181 as permitted sender) smtp.mailfrom=muchun.song@linux.dev ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1722480134; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=6285+tUHdQTcg6DEPpwjsL4gMQQByjJdChORJZAXZcY=; b=BkL6oPXDWdUGNB9UN6ox1hWasfuh5D4d54EJEK+ORJxKMfFs3wgaYNqMBJm8h/ZKy+yXd7 Owgdzu9JHE1bXMOcSMmS5N5fDmpXOYSArP/1+mM/f+Ysi3eITW+PBEW+/TtoGorfg4XDhX lvBjToGErG5tJLSCpo8p8565kBpwJQc= Content-Type: text/plain; charset=us-ascii DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1722480176; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6285+tUHdQTcg6DEPpwjsL4gMQQByjJdChORJZAXZcY=; b=XRK+N5mAgJAg+xQTuOTTEkhPvx8G6KGCTxdq+vVwPOiLQ0sK3LIbA1qLXWyJaDE2ZsA1+z MTubxZqNpM62pddos+ThRRxA6+VfDymtFsTcboWvru1NYSEcXkn80aflZM0TkPO+FJIXrg gmfQK7ulc0WpLNz0oqP34mF6ZCW08f8= Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.600.62\)) Subject: Re: [PATCH] mm: list_lru: fix UAF for memory cgroup X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. From: Muchun Song In-Reply-To: <20240731132825.1fb29122d35997a425368b32@linux-foundation.org> Date: Thu, 1 Aug 2024 10:42:02 +0800 Cc: Muchun Song , Johannes Weiner , Nhat Pham , Linux Memory Management List , LKML , Vlastimil Babka , Shakeel Butt Content-Transfer-Encoding: quoted-printable Message-Id: <3AA53CB7-1E21-4B79-8BA9-B1F40D3E15DF@linux.dev> References: <20240718083607.42068-1-songmuchun@bytedance.com> <20240731132825.1fb29122d35997a425368b32@linux-foundation.org> To: Andrew Morton X-Migadu-Flow: FLOW_OUT X-Rspamd-Server: rspam12 X-Rspamd-Queue-Id: F0AC32000E X-Stat-Signature: 8y3d9ehea338f9ypqebief6ph8amk97i X-Rspam-User: X-HE-Tag: 1722480178-542932 X-HE-Meta: U2FsdGVkX18OqlzZU0/hlINtRDgruzKjtdRSXAAfDjcw3jFk4wYGsEWEIJQP19bUT/t9bCwF+v7v6tzRWJvw5bei0eWxnmgIC6vpFcQArUJvx+RjfDaQ0IRHk7ww/o3Ow/1Y6pt9hmiY72AMxMxXKwgRV+XxNPRIhJYusQERX3e8VcZd0jQ8Pw2ML1sXu9X3MuyjdpTWlandSd/vF0IBRPWKcl/FLxiBjsku6r3EaS5BT4/O39OLGnts+1hPYJrLn+1lc709x5xiYmlyBq19TkeFUUSLnwPVDJqnOzJ9tzsr6BdawAWkRwmOgtKMtDYupWJyhuBazDGgi3Vs9kmSLpL69Yc+RSPzuTEOWRLuFkKpURlUHPIk2I05m5XTNT+ko+h49VDxmzUwkERtkXGiAOw9NLv9eEZLYtrTO996Sow0XBs/86SixZqzdHhBN72NegvJ4PEDHO3/MJ9QoPnFKqH/ERo9qgqnsWGRFnVkSKMscTVzBjeDcnkW18QOf7xkZ2J7JP7OZKWmKGFbmvc88yb2pGLOi/Mj+brtWAW3uEG0MgXN+yKQRjS4LfW4VeX61QKiGU2ct0CUdxExAiT+kDhkn2/2r2WxDIAt41/Fx/a6CAUOP13F8espFOKF82CXCLvMD2xn8zcsCJJRoXLV+ogavECdmpcgH8LLQiMfBd06JvZNeA7VSNJtRB9mkRkmeEQwk1C0Svs1eg8VGg5LsPwonMCwutQDM+HDgQWjIYliEiwaeQzzPghzcRfFcDVI8OdlIYW0h3Kl1WqoockxFxQYixI3hMIddf/FZq03CEaccD8sHQ8THpqT87XDP2sX3IdwB9rDK/9bQGdCqJFRlYCWmOQHOBR9kRRFcsyBxB3mY3izZRktSiw1sonqSCM+iKtueSsSf3t6x42MfNeHNtvtfRjWhzeXmNk0cj93K3UKGgcMsrdDSQAD9y7LSKLjIqAmsc+ZE9+T91ZnauN wFZSB508 eX3VbteVbUsMFv74q2ANm/YnydStqySMiJB9okhMl1PVdxHkUGr1Li/kkZnshbOb0akvlHTG86CpR8ybFkLzMUxgnBMNJqp1bquYc4k5wPQrUvaPhWuk6aR3gvfISgRVu07dltWoHjDTTJLJZhRQ3/IIvndIVO+DfOF3tmCwxMyEALxZfi6BV47EhXIDwPJ79s03wVAq7P1hCIgx1Wn6YLLm/Vmsz4kcwxRxK0hDZSD5c5Q+v6j/edwB6xWcnvbM0ElZuMIsB5eUCo6Ic28Kk6KBm93JPsaqQEuct0+YMUWKm/DjiIUfmmSxUew6UtUWDLvLi X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: > On Aug 1, 2024, at 04:28, Andrew Morton = wrote: >=20 > On Thu, 18 Jul 2024 16:36:07 +0800 Muchun Song = wrote: >=20 >> The mem_cgroup_from_slab_obj() is supposed to be called under rcu >> lock or cgroup_mutex or others which could prevent returned memcg >> from being freed. Fix it by adding missing rcu read lock. >>=20 >=20 > Well I grabbed this, but the review led me to expect a v2. Will do. >=20 > Should it have cc:stable? Yes.