From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7C1ABCF11F8 for ; Thu, 10 Oct 2024 14:28:09 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id EC4E86B0083; Thu, 10 Oct 2024 10:28:08 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id E9B3B6B0085; Thu, 10 Oct 2024 10:28:08 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id D3B4B6B0089; Thu, 10 Oct 2024 10:28:08 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id B5BF96B0083 for ; Thu, 10 Oct 2024 10:28:08 -0400 (EDT) Received: from smtpin15.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay05.hostedemail.com (Postfix) with ESMTP id DFEE340656 for ; Thu, 10 Oct 2024 14:28:05 +0000 (UTC) X-FDA: 82657922256.15.172908E Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by imf19.hostedemail.com (Postfix) with ESMTP id 032561A0029 for ; Thu, 10 Oct 2024 14:28:04 +0000 (UTC) Authentication-Results: imf19.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=34Go9uLg; dmarc=pass (policy=reject) header.from=google.com; spf=pass (imf19.hostedemail.com: domain of tabba@google.com designates 209.85.128.46 as permitted sender) smtp.mailfrom=tabba@google.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1728570458; a=rsa-sha256; cv=none; b=BPCVau4x+1FnEgV+5Mq60XMpyayihVwvZkffBuCd4/UqCBaJT3idXqhoMTIGQHmqjZY+dL 2M61Dw3mpyALXCuIU2MZbyr2foGlfHBfSIpWTU6zcoL3pQZ3aKHVlPD2w1fi0jNiAvrHbQ x2E6nnIen5kWxg3a4YWs/QoROQqYO08= ARC-Authentication-Results: i=1; imf19.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=34Go9uLg; dmarc=pass (policy=reject) header.from=google.com; spf=pass (imf19.hostedemail.com: domain of tabba@google.com designates 209.85.128.46 as permitted sender) smtp.mailfrom=tabba@google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1728570458; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=wBCsx6f+siqvoCuj4B+Pvu9ADkJZ7wKgsSIJdEcIngE=; b=grSakOND+egVLnES4WrKOCoxlyubNgjpZRamzvYsBYmcK8nxJjlIGDJcSt5oPBnlcyKM+A EipDQTp4fcmD1QaWuiTe+hNvN8TpthlJGqiYWyGVVkXzcNxVKftx5YasiQrLe1nyRWR5Ti HbKBDpjrbZ6AdYKaIt7BMApCjId1X7g= Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-431157f7e80so221355e9.1 for ; Thu, 10 Oct 2024 07:28:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1728570485; x=1729175285; darn=kvack.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=wBCsx6f+siqvoCuj4B+Pvu9ADkJZ7wKgsSIJdEcIngE=; b=34Go9uLgm7Jb1vaKFgc6DQin74NUObqc++t6CeU0DxPZ1EC33Wq2bPz7oyQba0A9iv OJFn970UDFu1FOHFaOR31d0/fLkixHVEvrhTtQQLzwrbiBe5P2HEk5b7SkYhctB+vKv3 rLtuRI/1QLX43oDj69QBkfSloUXyNSFqpMT3qJR7S6yRxSfEySeARJ++FsJ2N5UhFiMV 2z5KY/v/HiOLfn2bWv3UsDFrB2+nWiOS9ld3Zk3pDIojKRfsxNya0WsZzLQrEcKlGVzC XX1tbLrGJFZQeN8A48W2nOJBg3VwMDm+8LX/E1K5JKf5MYJoRFhNKZBopIhDd5loYFnj 9q1A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1728570485; x=1729175285; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=wBCsx6f+siqvoCuj4B+Pvu9ADkJZ7wKgsSIJdEcIngE=; b=VS2RwzhP4wtvENtVY9TPk4WWR/AhtttTlb8VZ76rUplGcZMe7QneQOeaIZNi7V+zZy /neaYmKoAX9gZJldML4S/z6k5smSFULC2LXJfgaTJx784RbIkoPwTebcrxhZe0uiHAVV AwKO7a+VMITFoIzcEOwuKhRpE7PvDToOzDIQumRfqI+9iQRKdYzq5ye9HSXmpXjYXKzy NBpniKUKZAwoOZHeCtzhXYKLjcevV+N74IP/+gGsrEJPKFJTq4+yXbkKseXqHi7y3cDo uz9kUbepKimqbw+xGHF9NrdgcPlhP3xassZenzhskZiImErh1NmC0UFcCB49a0bFWMUz 9Eug== X-Forwarded-Encrypted: i=1; AJvYcCXGvgWBI0sA33arGD9ZLWMsxy9OG/1NPxlbhoGNHs0/RgXXLXQvQqzWCBxp+MjCGu1skndUJFSzGQ==@kvack.org X-Gm-Message-State: AOJu0Yy9pvhIIieEYeZKGhoG4qq9wV0PWLBiccuLVaH7NtHyDGKBdtaa ekJkwFnZOQmDsOZxaeC7lzgAjxBLIsv+k7onYZH+886SX2f1GS2onup6A8/rwYSZkAFq6N+257V QfeSHYEEM8J9OYjkUlwp4GiBxsqDKh4jVnLR1 X-Google-Smtp-Source: AGHT+IHMywAqitIx8zT+z6idTauONY/Ezsn94DX4sJ68/dq+KHet2i3FDOkO8nINBGJtBEPSJkUH5cPl2DbLSWlCL7g= X-Received: by 2002:a05:600c:3482:b0:426:66a0:6df6 with SMTP id 5b1f17b1804b1-431160a6792mr4845475e9.0.1728570484599; Thu, 10 Oct 2024 07:28:04 -0700 (PDT) MIME-Version: 1.0 References: <20241010085930.1546800-1-tabba@google.com> <20241010085930.1546800-5-tabba@google.com> <20241010120356.GB3394334@nvidia.com> In-Reply-To: <20241010120356.GB3394334@nvidia.com> From: Fuad Tabba Date: Thu, 10 Oct 2024 15:27:27 +0100 Message-ID: Subject: Re: [PATCH v3 04/11] KVM: guest_memfd: Allow host to mmap guest_memfd() pages when shared To: Jason Gunthorpe Cc: "Kirill A. Shutemov" , kvm@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-mm@kvack.org, pbonzini@redhat.com, chenhuacai@kernel.org, mpe@ellerman.id.au, anup@brainfault.org, paul.walmsley@sifive.com, palmer@dabbelt.com, aou@eecs.berkeley.edu, seanjc@google.com, viro@zeniv.linux.org.uk, brauner@kernel.org, willy@infradead.org, akpm@linux-foundation.org, xiaoyao.li@intel.com, yilun.xu@intel.com, chao.p.peng@linux.intel.com, jarkko@kernel.org, amoorthy@google.com, dmatlack@google.com, yu.c.zhang@linux.intel.com, isaku.yamahata@intel.com, mic@digikod.net, vbabka@suse.cz, vannapurve@google.com, ackerleytng@google.com, mail@maciej.szmigiero.name, david@redhat.com, michael.roth@amd.com, wei.w.wang@intel.com, liam.merwick@oracle.com, isaku.yamahata@gmail.com, kirill.shutemov@linux.intel.com, suzuki.poulose@arm.com, steven.price@arm.com, quic_eberman@quicinc.com, quic_mnalajal@quicinc.com, quic_tsoni@quicinc.com, quic_svaddagi@quicinc.com, quic_cvanscha@quicinc.com, quic_pderrin@quicinc.com, quic_pheragu@quicinc.com, catalin.marinas@arm.com, james.morse@arm.com, yuzenghui@huawei.com, oliver.upton@linux.dev, maz@kernel.org, will@kernel.org, qperret@google.com, keirf@google.com, roypat@amazon.co.uk, shuah@kernel.org, hch@infradead.org, rientjes@google.com, jhubbard@nvidia.com, fvdl@google.com, hughd@google.com, jthoughton@google.com Content-Type: text/plain; charset="UTF-8" X-Rspam-User: X-Stat-Signature: xhp9eqr13esrnk4epmdna4tmjmc7mfya X-Rspamd-Queue-Id: 032561A0029 X-Rspamd-Server: rspam02 X-HE-Tag: 1728570484-978 X-HE-Meta: U2FsdGVkX1+IdAHzqS6wzvFVZW4nRY2rFP3DpPKqdTi9PIlweBWQi2/EOgcJ+KZXHnFQFBlvlNZM+ApC93HwDj1lUv3LhF+xp7qwJ47ZkfTcgA4gdbZAcdnfrPi/HLINT6B14j+NlZ2Q8I87b/qolbvu2OrGIBVyXylNnLnHO9Sz1FVQ/ePX5mX5LKMclbklGZf8ITuE21IdXjyC2vmXstP9R6jXTjNVjV7vG3t/tEE2nTPqXPaRPd1fwru4IWdPMhDyj+MsFMGEuWVF4D26eWCIAy3imigKPgvGQGMs06jXkr65FHPxfQTbu2Pot1AaZwVXGWjXnOiMq1/Q3IPOy7qJt/nfUh+TFGfnZc6b6nIbYPrNqii5vVNCwYSSVoeEkI/ZRXQ9lcrVPpMtBzcqWqPxp+KS9MFIJaRG67r7Yq8L7TvJGt7hK0hI0DhMC+9qA9E+bc9RSQnIJVpDa3BgtAR0ICx4sGCGsTV4xcuLt5I260aWXSiJ3//Spghkhw7EyVbPs+ezleaB3oEtZkjTEwCUG9Y04SA3W+dmzuxp3Brp3W/zTTvql4dazSRxCPJRpTMa9Jv5oNviskkLh1vMkv7zcP+DeGXPukl2u95Br2qcW5GBqEprhuh7DiJev+fkb98ZEPsQ5f45pXdGN4Z6Imut0NsJQRadhGho69YMXBOjT5KjGaEdZeHpxv1jPrjQG7KtJsaCjuGLp3+xsMxg8Jox/MxqmMRHe8AQyby2B8PvPdQlut7JNvRwykg65ijf2BRBag0fyNQliBr7sr9s4uy4UKGvpA7hQdfU7qUxdaebr+YuoqrMR6/CxibvemR7AlKbiGn35OR2NIO3Ma6lIQTXgb1zsX7fHWGZEdklR017/VZwTo7K49WdNhCMw/IUwrvcE52VUBX8x+3HZHhXe5WEKRVI8520ybYmv7fuD3wo+y2Trok/B3SOg7BSqWxakbGcNjIkau6h9TVMATS N9WhKdW3 H4mi+JHaQbsvaIkn29dPEak+7r2Bs8L4OTTHNhMEfvgyBeTTcGmaImCcmqMWAc8Z1EOdcvd3qr5isaSbCACZrZQCwzOxnNt+SrYep1gZ7JVLhnl/GScY/OXDShyPA20tC03KRdKEUo9yKXqpv4BC9Evapo2Nk5e38u2+SkoYIpMlt6wzB+/DnizxVH0vdL6uvM1iJ0YcByRVPbqZSBLKsA3CR+IRglnhVZxTNj7GrY+iBGSQ6QZNkiBFOBRnDp5tv+Nxhm7dmEKJK2+I8rG8Pjstrsw92cQgYBr+VOG+d44C7zAEGh0esy6ebjnuC5K2Us5GeGvm1151vHNN6sPTXrUkrxA== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000071, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: Hi Jason, On Thu, 10 Oct 2024 at 13:04, Jason Gunthorpe wrote: > > On Thu, Oct 10, 2024 at 11:23:55AM +0100, Fuad Tabba wrote: > > Hi Kirill, > > > > On Thu, 10 Oct 2024 at 11:14, Kirill A. Shutemov wrote: > > > > > > On Thu, Oct 10, 2024 at 09:59:23AM +0100, Fuad Tabba wrote: > > > > +out: > > > > + if (ret != VM_FAULT_LOCKED) { > > > > + folio_put(folio); > > > > + folio_unlock(folio); > > > > > > Hm. Here and in few other places you return reference before unlocking. > > > > > > I think it is safe because nobody can (or can they?) remove the page from > > > pagecache while the page is locked so we have at least one refcount on the > > > folie, but it *looks* like a use-after-free bug. > > > > > > Please follow the usual pattern: _unlock() then _put(). > > > > That is deliberate, since these patches rely on the refcount to check > > whether the host has any mappings, and the folio lock in order not to > > race. It's not that it's not safe to decrement the refcount after > > unlocking, but by doing that i cannot rely on the folio lock to ensure > > that there aren't any races between the code added to check whether a > > folio is mappable, and the code that checks whether the refcount is > > safe. It's a tiny window, but it's there. > > That seems very suspicious as the folio lock does not protect the > refcount, and we have things like speculative refcount increments in > GUP. > > When we talked at LPC the notion was you could just check if the > refcount was 1 without sleeping or waiting, and somehow deal with !1 > cases. Which also means you shouldn't need a lock around the refcount. The idea of the lock isn't to protect the refcount, which I know isn't protected by the lock. It is to protect against races with the path that (added in this patch series), would check whether the host is allowed to map a certain page/folio. But as Kirill pointed out, there seems to be other issues there, which I'll cover more in my reply to him. Thank you, /fuad > Jason