From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 058C4C00140 for ; Wed, 10 Aug 2022 07:23:35 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 1DBD78E0002; Wed, 10 Aug 2022 03:23:35 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 18BE28E0001; Wed, 10 Aug 2022 03:23:35 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 054808E0002; Wed, 10 Aug 2022 03:23:35 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id E70A58E0001 for ; Wed, 10 Aug 2022 03:23:34 -0400 (EDT) Received: from smtpin13.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay09.hostedemail.com (Postfix) with ESMTP id B936381115 for ; Wed, 10 Aug 2022 07:23:34 +0000 (UTC) X-FDA: 79782842748.13.A5C2FA4 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.220.29]) by imf22.hostedemail.com (Postfix) with ESMTP id 4BD0BC0063 for ; Wed, 10 Aug 2022 07:23:33 +0000 (UTC) Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id A56B85C5F4; Wed, 10 Aug 2022 07:23:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=susede1; t=1660116211; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=XAF+Y7ib/KCBJKhHgL+UmuGO+OSVwbzTJiPOyXkFvyI=; b=YonhsmUCdhCcf0jEe6L1hAkGeyUHL3vBNrF3HeMGpp6gYkotJ7PaKD5lNibpb8hVQcz80t XMiwmgMqaL6WC0iShE0ITVe5v9oFXZ1sLVTxffXk/onJXHBvvce54dfEis8AKdoeUN0C8Y ohUD0xDjO+i7Dp/D9bni+wetxFw0gbs= Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by imap2.suse-dmz.suse.de (Postfix) with ESMTPS id 8607F13AB3; Wed, 10 Aug 2022 07:23:31 +0000 (UTC) Received: from dovecot-director2.suse.de ([192.168.254.65]) by imap2.suse-dmz.suse.de with ESMTPSA id pkw8HvNc82IDYAAAMHmgww (envelope-from ); Wed, 10 Aug 2022 07:23:31 +0000 Date: Wed, 10 Aug 2022 09:23:30 +0200 From: Michal Hocko To: Andrew Morton Cc: Charan Teja Kalla , david@redhat.com, pasha.tatashin@soleen.com, sieberf@amazon.com, shakeelb@google.com, sjpark@amazon.de, dhowells@redhat.com, willy@infradead.org, quic_pkondeti@quicinc.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: Re: [PATCH V3] mm: fix use-after free of page_ext after race with memory-offline Message-ID: References: <1660056403-20894-1-git-send-email-quic_charante@quicinc.com> <20220809185714.5af7057c1270b11079cb196a@linux-foundation.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220809185714.5af7057c1270b11079cb196a@linux-foundation.org> ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1660116213; a=rsa-sha256; cv=none; b=dpC2E8JKSrOEf9ZHRbvcnZiRk03RVeBEEAk8jNiSydl0lSTeQkUN9WIYjFbPg/jbzlNW6T dTVHBSy1pfXKyfGNxZ25xL/te40UGDmsD6hDd17YmKQ848zjtC+wAeR3rvLciQ4FJZ9H+5 ReiIAI/1BRZ2Xs8h8/7RoL52zMM9ewU= ARC-Authentication-Results: i=1; imf22.hostedemail.com; dkim=pass header.d=suse.com header.s=susede1 header.b=YonhsmUC; dmarc=pass (policy=quarantine) header.from=suse.com; spf=pass (imf22.hostedemail.com: domain of mhocko@suse.com designates 195.135.220.29 as permitted sender) smtp.mailfrom=mhocko@suse.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1660116213; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=XAF+Y7ib/KCBJKhHgL+UmuGO+OSVwbzTJiPOyXkFvyI=; b=z4N8AD179hH3/v383XJ2m5znz8hRJzxzekxpzawYf7fZWGeGUT+ZhNjlHPAd+aMwxjEy2W C7X4Ew1C2TQoyn+EIaKX+XWhEGkt2G5La6UaB7hBo8HwS/fsOFkg+8pjbyiZeBs630Yphv 8YyFH+51xe8tUHuqizOyM8Cp3dSzlPI= X-Rspamd-Server: rspam10 X-Stat-Signature: xm7ghky1fo34ttcrswp5jxem8r68g6fb Authentication-Results: imf22.hostedemail.com; dkim=pass header.d=suse.com header.s=susede1 header.b=YonhsmUC; dmarc=pass (policy=quarantine) header.from=suse.com; spf=pass (imf22.hostedemail.com: domain of mhocko@suse.com designates 195.135.220.29 as permitted sender) smtp.mailfrom=mhocko@suse.com X-Rspam-User: X-Rspamd-Queue-Id: 4BD0BC0063 X-HE-Tag: 1660116213-427700 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Tue 09-08-22 18:57:14, Andrew Morton wrote: > On Tue, 9 Aug 2022 20:16:43 +0530 Charan Teja Kalla wrote: > > > The below is one path where race between page_ext and offline of the > > respective memory blocks will cause use-after-free on the access of > > page_ext structure. > > Has this race ever been observed at runtime? > > Given the size of the fix, I'm looking for excuses to not backport it > into -stable kernels! I believe this is quite theoretical for two reasons 1) the memory hotplug (offlining) is quite rare operation 2) with all the retries the race window is quite hard to trigger So this is good to have address long term but nothing really for stable until somebody actually hits that with a real world workload. Btw. I plan to have a look and review this but times are busy. Hopefully soon. Thanks! -- Michal Hocko SUSE Labs