From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id B9130C61CE8 for ; Fri, 6 Jun 2025 12:49:44 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 4E1E46B0088; Fri, 6 Jun 2025 08:49:44 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 4B9C16B008C; Fri, 6 Jun 2025 08:49:44 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 3A9026B0092; Fri, 6 Jun 2025 08:49:44 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) by kanga.kvack.org (Postfix) with ESMTP id 181816B0088 for ; Fri, 6 Jun 2025 08:49:44 -0400 (EDT) Received: from smtpin11.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay03.hostedemail.com (Postfix) with ESMTP id AB993BF3C2 for ; Fri, 6 Jun 2025 12:49:43 +0000 (UTC) X-FDA: 83524957446.11.C763FEB Received: from mail-ed1-f49.google.com (mail-ed1-f49.google.com [209.85.208.49]) by imf18.hostedemail.com (Postfix) with ESMTP id B6ABE1C0007 for ; Fri, 6 Jun 2025 12:49:41 +0000 (UTC) Authentication-Results: imf18.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=w8b+MYp4; spf=pass (imf18.hostedemail.com: domain of jannh@google.com designates 209.85.208.49 as permitted sender) smtp.mailfrom=jannh@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1749214181; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=BT+AT6MqsJ3M+MYT3uZEthRD6VpQnEM0vp9KYd7MzOw=; b=jhFAFE9bfzBEqkN15r6NPSJiywQiFaPH6+rdR8XUga3KnnLJLHgZ8tBlDrAEKbmmqOngUm 4x2dmiLkfrydyDYjOcqLW8nLDCH/myo7Z/H5BZgEaZ2ejw7wE6aqW0966SDu3VH+00qPub dNmVb2SjB+KwzJM9jkg0tA+LCS4k8so= ARC-Authentication-Results: i=1; imf18.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=w8b+MYp4; spf=pass (imf18.hostedemail.com: domain of jannh@google.com designates 209.85.208.49 as permitted sender) smtp.mailfrom=jannh@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1749214181; a=rsa-sha256; cv=none; b=VSMiUePr/gCUewckb5ZBamGT5Q58OMwBcSXB9b090nbb9D6kCqoLKotwVUAAjFbW7/vFGc 3n9Yqo6yJF5EVgC8qOlR1YFY/+TSh/VeGaHGjCTIPdqXi8iTeJh9edNRLXey+NBlMV9Vz6 K0vT/TAMGrYcUAouMNsVOeQlNv/8nNs= Received: by mail-ed1-f49.google.com with SMTP id 4fb4d7f45d1cf-5f438523d6fso8540a12.1 for ; Fri, 06 Jun 2025 05:49:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1749214180; x=1749818980; darn=kvack.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=BT+AT6MqsJ3M+MYT3uZEthRD6VpQnEM0vp9KYd7MzOw=; b=w8b+MYp4txVnaXTf/hwWxwwJ3HJ4BT5dlT47+dAI4SgGvKRv3uMO1MCkvMyxMkA4dT itG7nAFpTTa003m4mssb2hAt1zDGYyI14FyDCJ/p0l82sam3XbhrgyaPlvFjLTsUTLDy Y2zxe4c9925EnWt868jGWE1sjrDacsOpUkEhU+vhaNFhxYvAynTQQIIZ6CeZ+xAFQ/tM Nx1aghMVWDJRTaG1mY7Zpjy1pRnaqA/XwSoomGg8MdxJI80yQJeAw3Vm93Krq3yS7XTh tFkLq31CLDS6hN1Uc5SMh0CdstV52Rgh0gcn2S4j2oeIUiZqKWL9gAR0Qq5e8BIs/kJN RnqQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1749214180; x=1749818980; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=BT+AT6MqsJ3M+MYT3uZEthRD6VpQnEM0vp9KYd7MzOw=; b=KDmxCeogAHJ9q374uYtWSuxjK2pwTfDu1VxmZRluAgBwYTXKd72nuj0UJ3J0xr17YY XctorllVPaudNUXfVjE3Rfr/k4nHxz7R3lHBnNGJaxGWWEHl8EaUNTWfBtIiqOJSe+an bC38PJ9PuvV7OIknmg/ehOzeWQ4JK0rkTbVGP3OeAkTXzSomUBxPPTFeAry3WrWf/DQj hKz6MOhqExoeLCAnt/rKSl0j8qOG0A3aIgIQYW2I36dbXMK6TXFBJC+Zf/RCmzVkakb3 mr7kL4xJg2GE5j8/nvQAjrske70Dl9kEHMfW3Sg2OgDJ7CdcSpFtlhwsxDb04TBEXQVP SGEw== X-Forwarded-Encrypted: i=1; AJvYcCXdYsgqZBLz1VJk+6i9lSvzKCLhDLgLRqgy4cpHhTymSWP5qvK2CPwkgUI+4Kya0efqHDcSFKQAng==@kvack.org X-Gm-Message-State: AOJu0YzZBQvR2Qq3WBsaJOKXbUZ6PWx0TqHS3d5cc5xWztOI2wuu7wWj Y7aWyvTgUilWzMpYLmvTy4em2JE1y+mgcmnVJ1aypLo3+2yhJcaTvDRa+U76/Asd1Q129pjjiBM wfspVDGe5BQgDOkQekgpdHKhEsY+yN+y+GtcEsZ4F X-Gm-Gg: ASbGncs0pzKJh5KjH6SGpYIPrVdtPFelresNCgN37ySIsM/y3QJF9vSxnN1jqa8cfRX NpjQRv3D0GHn1tzJHrucsVU/38ECOTbN18F3bTAEyJppGnzO45HSabmKJfclmKOvvpKt3p16fIJ vBDjz1222cCR6GJpbyAZnRcpzupGu0kB3KYN8tzwXFV+MqbNudL4SFaaplazRB9AmmGCmlsESkb 6X1XJE+ X-Google-Smtp-Source: AGHT+IEj+Za0UCwvZRT2mQseG+6UqOCA9QEGxUq6fGXHr3bK5GUTUQ0XMmeQy0xVJPsfoDBqZGJWVfK2y2vy3sqMkxY= X-Received: by 2002:a05:6402:344:b0:606:9166:767 with SMTP id 4fb4d7f45d1cf-60773eca718mr76167a12.2.1749214179846; Fri, 06 Jun 2025 05:49:39 -0700 (PDT) MIME-Version: 1.0 References: <20250603-fork-tearing-v1-0-a7f64b7cfc96@google.com> <20250603-fork-tearing-v1-1-a7f64b7cfc96@google.com> In-Reply-To: <20250603-fork-tearing-v1-1-a7f64b7cfc96@google.com> From: Jann Horn Date: Fri, 6 Jun 2025 14:49:03 +0200 X-Gm-Features: AX0GCFt0UyWLtHOJ7Xl9oT_PxdylGZdccUKq5b21dR__hVZmMxZwE8eGyyenLKQ Message-ID: Subject: Re: [PATCH 1/2] mm/memory: ensure fork child sees coherent memory snapshot To: Andrew Morton , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , linux-mm@kvack.org Cc: Peter Xu , linux-kernel@vger.kernel.org, stable@vger.kernel.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspam-User: X-Rspamd-Queue-Id: B6ABE1C0007 X-Rspamd-Server: rspam09 X-Stat-Signature: u18jn8ou4jq53hrnw3r55zhsrk63php1 X-HE-Tag: 1749214181-989192 X-HE-Meta: U2FsdGVkX1+59b8pHh6k6PxYDPLe9ugadPVq0PRnTBujuL0YaYFffVL46srJQdr69F7vz2xiUr4uECr8WV2ThIC+9rJIIW4JdjWRIOLjtVnjXy3J+FK/HWsdIjb16AZ+tEEqrMhSm6Sz8cxQlvO5sd1ZJiwK1CHNkKDXHVThuBHrSCAhtGRe29tuSyTHDoRmF0yB4dsLILT/b1hOTNKJEHKh/SA7CEaOWX75YV2aVAq9OVjtfZ03PXCLkldwj2aP94Gwu/hAY84VhClYPH60AVZ17L9Gp23eq3Ki8G7+93MPII5Swm3NJXi+48LudAU8435fhAeUJ9f3Uc3nBO0f+v8kMbBnJz7ioexpqqdfLse0ZcqH+gVJ1ZQufm447WNJUaJTE8AokJeeCkU/kTQCI15czGD+mTBlJJzvzZW3qXZsVEwMAgbOtYSVWLDYnYAaI1DXyQlUtbNHFCczw964ZaMDi+jPHDMUGPmM9vaHVL3luuVxNGVVVXh7u2XncRrWdRVfeL7Q9QgV2Iz0rZbxQtWax51miLSXM+utmH/BTlmLcs8/Pq2M9xiIKbVzFOWlltSzOXoDAADLXWJl+rQ4aD1WUx5ftScRMdJ4CHGD04alSEtuKaROzBnjzZSCrgcqPy6tMHO64Y+Y3BZ1KvRwIRnGFwkdVmFGU+P2mJSvY51zSrfrbcSN0nj8d2hJ91n+uENLYnKhUguzuW3zYrYcQh3LMHKNKsIEPEe75R/BYGV24ZlpWlhYmQsGUUMdaSjp3aFbQfK1mey9Po/osVNcZ27el7E7wydJtO8d1ku7uoOx0K7QAjuoxjiVKUU/YqGg1HeNcIwIHavBFr1zmnBlY2ZVutQezgxAt07D167tvVqLKHSQsr/AMl/DvbMdxi1FDySFxOqVfurSvbsx5XX5y+Ox6ydCgawJsgRn0Ubc1ETEqPIZSBecwH/uw+Lg1BgUyD+O8ygeRsllE5x6qgs ITkVNcFI lDtRQ7gFX/oir4lr7+SHiHPZ4lVJ5WQYUDmto0YiHVcJOTZLkCh27hm6AiB9YoNTk4Kun0iyzezH4e2O/jB2uaKPzb2538RRP+/JEs4q8NCYJMeS3a5f9fZuVKcof/+Y7qoWevpFrCPEav8GguFV+Qsqk4oWFzxf0tcx47DKe9MdzX6l9dNu1uGpeY/8Pd2YQGTvVKn1k6ilYKBitTaKnGLCQZvUKlRPlVEdP X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Tue, Jun 3, 2025 at 8:21=E2=80=AFPM Jann Horn wrote: > @@ -917,7 +917,25 @@ copy_present_page(struct vm_area_struct *dst_vma, st= ruct vm_area_struct *src_vma > /* > * We have a prealloc page, all good! Take it > * over and copy the page & arm it. > + * > + * One nasty aspect is that we could be in a multithreaded proces= s or > + * such, where another thread is in the middle of writing to memo= ry > + * while this thread is forking. As long as we're just marking PT= Es as > + * read-only to make copy-on-write happen *later*, that's easy; w= e just > + * need to do a single TLB flush before dropping the mmap/VMA loc= ks, and > + * that's enough to guarantee that the child gets a coherent snap= shot of > + * memory. > + * But here, where we're doing an immediate copy, we must ensure = that > + * threads in the parent process can no longer write into the pag= e being > + * copied until we're done forking. > + * This means that we still need to mark the source PTE as read-o= nly, > + * with an immediate TLB flush. > + * (To make the source PTE writable again after fork() is done, w= e can > + * rely on the page fault handler to do that lazily, thanks to > + * PageAnonExclusive().) > */ > + ptep_set_wrprotect(src_vma->vm_mm, addr, src_pte); > + flush_tlb_page(src_vma, addr); Hmm... this is actually wrong, because we did arch_enter_lazy_mmu_mode() up in copy_pte_range(). So I guess I actually have to do: arch_leave_lazy_mmu_mode(); ptep_set_wrprotect(src_vma->vm_mm, addr, src_pte); flush_tlb_page(src_vma, addr); arch_enter_lazy_mmu_mode(); (arch_flush_lazy_mmu_mode() would look a bit nicer, but powerpc doesn't implement that.)