From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 38275C433EF for ; Thu, 26 May 2022 13:38:24 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 61E608D0003; Thu, 26 May 2022 09:38:23 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 5CDB88D0001; Thu, 26 May 2022 09:38:23 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 4BDE18D0003; Thu, 26 May 2022 09:38:23 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0015.hostedemail.com [216.40.44.15]) by kanga.kvack.org (Postfix) with ESMTP id 3B2A68D0001 for ; Thu, 26 May 2022 09:38:23 -0400 (EDT) Received: from smtpin18.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay07.hostedemail.com (Postfix) with ESMTP id 0523320607 for ; Thu, 26 May 2022 13:38:23 +0000 (UTC) X-FDA: 79507998486.18.9E580DE Received: from mail-ej1-f45.google.com (mail-ej1-f45.google.com [209.85.218.45]) by imf08.hostedemail.com (Postfix) with ESMTP id 46438160034 for ; Thu, 26 May 2022 13:37:59 +0000 (UTC) Received: by mail-ej1-f45.google.com with SMTP id gi33so3117933ejc.3 for ; Thu, 26 May 2022 06:38:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=soleen.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=zZ9DAhCNK6+O0V4masvprPNhs/nf8Fvi/U/e6pxEsj0=; b=T4I1s68XXJRufZfuiZ1VZqCrjcDXks8TmQ8oOs2CAd82x1Ea5MYgXQ/hfb66CkrVKh 5xOeCj8uHt2B+CgY6Q9qIMpIvsttNrIw4aGRB/7PctSnXHNgMY251O68aaf6GrtMnSxw Doy1oSWuSM7cQ7+q6k1B60IEafItMK0tUJHf/44SIx2D66qkNgFXDF6L2grXHIvKPwCO vHXqTLPG6SIeYKbhzT09p+jRk/c2LO6ko+9+u/LDyxvtUREQCd98SebqpPmUHdMuXze2 qXgOaZV4I7bUXjTMWtzpwUa3WnqrYGrGciOuF8smnswGCoeRXOcELI9l1MOExdSN7yj7 tMzw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=zZ9DAhCNK6+O0V4masvprPNhs/nf8Fvi/U/e6pxEsj0=; b=SuGXUVkUvPKy5OlwCuXceDNN3RhZPSM5LcTc1FBUeI5ZecLnEBAgujllPUGv5wv1+U kadfAwk+huGOGtMgZ63NDFxHluk3zcD6ToczdfKQmO7OQqQ5U/wpSwxHaoxOGSa1TH8x or42WJflhuSAVNi2tbp0sk/lYWUG2GIWpj9MuwVoG952NlZE48mLvie5ZBKfM0w+/BsQ 2EOpiXxGJ+q3aK5NTjC2L6L+QxSxEvkcVGZ7yKY45UO8HpgdybZPMVzCTj898AUj1zF+ iTD5KlWBGWMbjWH/LOrrOg9A0VOHef5YcT5XZX/icfPbUiTfqP0poZRncVEw/iefvSz9 wX4A== X-Gm-Message-State: AOAM53077AqaGbuqsRYw+dwkidDNCzUKHEAEs7UL4QE+Bv0pcYywHs1v B3yUQJJ8i2Etuwb+oHryVE7xt7daPUZgna47Sn1TKg== X-Google-Smtp-Source: ABdhPJxwsu+q88tcq7anl1xlkA6jRqbX/Y2WxaXnApABL4iLZzEE9mWLZ5XTPYNtc14+W7qgANcEq8W+9zqihQphORo= X-Received: by 2002:a17:906:9b86:b0:6fe:d37f:b29d with SMTP id dd6-20020a1709069b8600b006fed37fb29dmr19980411ejc.327.1653572300197; Thu, 26 May 2022 06:38:20 -0700 (PDT) MIME-Version: 1.0 References: <20220526113350.30806-1-linmiaohe@huawei.com> In-Reply-To: From: Pasha Tatashin Date: Thu, 26 May 2022 09:37:43 -0400 Message-ID: Subject: Re: [PATCH] mm/page_table_check: fix accessing unmapped ptep To: Matthew Wilcox Cc: Miaohe Lin , Andrew Morton , David Rientjes , linux-mm , LKML Content-Type: text/plain; charset="UTF-8" X-Rspamd-Server: rspam08 X-Rspamd-Queue-Id: 46438160034 X-Stat-Signature: f1diw7176sdeigjdpkm7gsuewcb4fws8 Authentication-Results: imf08.hostedemail.com; dkim=pass header.d=soleen.com header.s=google header.b=T4I1s68X; dmarc=none; spf=pass (imf08.hostedemail.com: domain of pasha.tatashin@soleen.com designates 209.85.218.45 as permitted sender) smtp.mailfrom=pasha.tatashin@soleen.com X-Rspam-User: X-HE-Tag: 1653572279-613740 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Thu, May 26, 2022 at 9:34 AM Matthew Wilcox wrote: > > On Thu, May 26, 2022 at 07:33:50PM +0800, Miaohe Lin wrote: > > ptep is unmapped too early, so ptep will be accessed while it's unmapped. > > Fix it by deferring pte_unmap() until page table checking is done. > > > > Fixes: 80110bbfbba6 ("mm/page_table_check: check entries at pmd levels") > > Signed-off-by: Miaohe Lin > > --- > > mm/page_table_check.c | 2 +- > > 1 file changed, 1 insertion(+), 1 deletion(-) > > > > diff --git a/mm/page_table_check.c b/mm/page_table_check.c > > index 3692bea2ea2c..971c3129b0e3 100644 > > --- a/mm/page_table_check.c > > +++ b/mm/page_table_check.c > > @@ -234,11 +234,11 @@ void __page_table_check_pte_clear_range(struct mm_struct *mm, > > pte_t *ptep = pte_offset_map(&pmd, addr); > > unsigned long i; > > > > - pte_unmap(ptep); > > for (i = 0; i < PTRS_PER_PTE; i++) { > > __page_table_check_pte_clear(mm, addr, *ptep); > > addr += PAGE_SIZE; > > ptep++; > > } > > + pte_unmap(ptep); > > But ptep was mutated in the loop. So surely this needs to be: > > pte_unmap(ptep - PTRS_PER_PTE); > > or you'll be unmapping the wrong page. Right, thank you Matthew. Miaohe, please store the ptep, or maybe drop this patch entirely. Thanks, Pasha