linux-mm.kvack.org archive mirror
 help / color / mirror / Atom feed
From: "Liam R. Howlett" <Liam.Howlett@oracle.com>
To: Kalesh Singh <kaleshsingh@google.com>
Cc: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>,
	akpm@linux-foundation.org, minchan@kernel.org,
	kernel-team@android.com, android-mm@google.com,
	David Hildenbrand <david@redhat.com>,
	Vlastimil Babka <vbabka@suse.cz>, Mike Rapoport <rppt@kernel.org>,
	Suren Baghdasaryan <surenb@google.com>,
	Michal Hocko <mhocko@suse.com>, Jann Horn <jannh@google.com>,
	Pedro Falcato <pfalcato@suse.de>,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] mm: centralize and fix max map count limit checking
Date: Thu, 4 Sep 2025 14:41:09 -0400	[thread overview]
Message-ID: <5n37yzto6ylq2a5lnxwcr7osygwkvlbv35fkilkhfc5eqhdqca@iji543qzcy2t> (raw)
In-Reply-To: <CAC_TJvcCW003ef3=RCXTbC7daSS2+tiS24-7JdTLn3QVJX3Bgg@mail.gmail.com>

* Kalesh Singh <kaleshsingh@google.com> [250904 13:44]:
> On Thu, Sep 4, 2025 at 10:33 AM Lorenzo Stoakes
> <lorenzo.stoakes@oracle.com> wrote:
> >
> > On Thu, Sep 04, 2025 at 01:22:51PM -0400, Liam R. Howlett wrote:
> > > > > diff --git a/mm/mremap.c b/mm/mremap.c
> > > > > index e618a706aff5..793fad58302c 100644
> > > > > --- a/mm/mremap.c
> > > > > +++ b/mm/mremap.c
> > > > > @@ -1040,7 +1040,7 @@ static unsigned long prep_move_vma(struct vma_remap_struct *vrm)
> > > > >    * We'd prefer to avoid failure later on in do_munmap:
> > > > >    * which may split one vma into three before unmapping.
> > > > >    */
> > > > > - if (current->mm->map_count >= sysctl_max_map_count - 3)
> > > > > + if (exceeds_max_map_count(current->mm, 4))
> > > > >           return -ENOMEM;
> > > >
> > > > In my version this would be:
> > > >
> > > >     if (map_count_capacity(current->mm) < 4)
> > > >             return -ENOMEM;
> > > >
> > >
> > > Someone could write map_count_capacity(current->mm) <= 4 and reintroduce
> > > what this is trying to solve.  And with the way it is written in this
> > > patch, someone could pass in the wrong number.
> 
> Hi Liam,
> 
> I still think there is value to this as it's lot less likely to get
> the common case incorrectly:
> 
> if (!map_count_capacity(mm))
>         return -ENOMEM;
> 
> It also facilitate us adding the asserts as Pedro suggested (excluding
> the munmap() case.

And munmap() callers case, I guess.

There is still the possibility of us failing to unmap after a split and
having shot ourselves, so just don't assert that in the case of the
failure and recovery path (ie exit_mmap()).

> 
> >
> > Right, but I think 'capacity' is pretty clear here, if the caller does something
> > silly then that's on them...

Turns out it's on us, not them :)

> >
> > >
> > > I'm not sure this is worth doing.  There are places we allow the count
> > > to go higher.
> >
> > ...But yeah, it's kinda borderline as to how useful this is.
> >
> > I _do_ however like the 'put map count in one place statically' rather than
> > having a global, so a minimal version of this could be to just have a helper
> > function that gets the sysctl_max_map_count, e.g.:
> >
> > if (current->mm->mmap_count >= max_map_count() - 3)
> >
> > etc. etc.
> >
> > >
> > > Certainly fix the brk < to be <= and any other calculations, but the
> > > rest seem okay as-is to me.  The only real way to be sure we don't cause
> > > a bug in the future is to have better testing.
> >
> > Speaking of testing - Kalesh - do make sure to test the VMA tests to make sure
> > this doesn't break those - they live in tools/testing/vma and you just have to
> > do make && ./vma

Bonus points if you can add some tests for it!

Thanks,
Liam


      reply	other threads:[~2025-09-04 18:41 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-09-03 23:24 Kalesh Singh
2025-09-03 23:46 ` Pedro Falcato
2025-09-04  3:01   ` Kalesh Singh
2025-09-04 15:24     ` Pedro Falcato
2025-09-04 16:32       ` Kalesh Singh
2025-09-05 19:43   ` Minchan Kim
2025-09-07  4:24     ` Kalesh Singh
2025-09-04  7:29 ` Mike Rapoport
2025-09-04 16:20   ` Kalesh Singh
2025-09-04 10:14 ` David Hildenbrand
2025-09-04 16:24   ` Kalesh Singh
2025-09-04 16:02 ` Lorenzo Stoakes
2025-09-04 16:34   ` Kalesh Singh
2025-09-04 17:22   ` Liam R. Howlett
2025-09-04 17:33     ` Lorenzo Stoakes
2025-09-04 17:41       ` David Hildenbrand
2025-09-04 17:51         ` Kalesh Singh
2025-09-04 18:49           ` Liam R. Howlett
2025-09-04 19:02             ` David Hildenbrand
2025-09-04 19:11               ` Liam R. Howlett
2025-09-05  7:40                 ` Mike Rapoport
2025-09-04 17:43       ` Kalesh Singh
2025-09-04 18:41         ` Liam R. Howlett [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5n37yzto6ylq2a5lnxwcr7osygwkvlbv35fkilkhfc5eqhdqca@iji543qzcy2t \
    --to=liam.howlett@oracle.com \
    --cc=akpm@linux-foundation.org \
    --cc=android-mm@google.com \
    --cc=david@redhat.com \
    --cc=jannh@google.com \
    --cc=kaleshsingh@google.com \
    --cc=kernel-team@android.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=lorenzo.stoakes@oracle.com \
    --cc=mhocko@suse.com \
    --cc=minchan@kernel.org \
    --cc=pfalcato@suse.de \
    --cc=rppt@kernel.org \
    --cc=surenb@google.com \
    --cc=vbabka@suse.cz \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox