From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 64536C6FD18 for ; Tue, 25 Apr 2023 16:45:44 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 4BAF56B007E; Tue, 25 Apr 2023 12:45:43 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 469D36B0080; Tue, 25 Apr 2023 12:45:43 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 30A0F6B0081; Tue, 25 Apr 2023 12:45:43 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id 2213D6B007E for ; Tue, 25 Apr 2023 12:45:43 -0400 (EDT) Received: from smtpin14.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay10.hostedemail.com (Postfix) with ESMTP id 4DDFFC02F4 for ; Tue, 25 Apr 2023 16:45:42 +0000 (UTC) X-FDA: 80720489724.14.ECEA7E1 Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by imf28.hostedemail.com (Postfix) with ESMTP id 63641C0003 for ; Tue, 25 Apr 2023 16:45:40 +0000 (UTC) Authentication-Results: imf28.hostedemail.com; dkim=pass header.d=gmail.com header.s=20221208 header.b=sIcEl1Tq; spf=pass (imf28.hostedemail.com: domain of lstoakes@gmail.com designates 209.85.128.54 as permitted sender) smtp.mailfrom=lstoakes@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1682441140; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=DQgl8loxAa0veEtZSLtrUvcvIyw2BmuwVPdtNPCihQg=; b=fjZHQ4BqmzEgsAOCd/xtPEOTSMTehkhXxNHikd3Kb86vuSlff8ror4NEP041NjzfpBFVRv gWxXfgekrY5/cizaiVRy4OxzeYwIJsS95Zs8z92HuNu5MamacRYonFp2yqqMbEBb8B2B4p Bw3dG9gm7/eokO8v2WBcRj3Cxlfz7K4= ARC-Authentication-Results: i=1; imf28.hostedemail.com; dkim=pass header.d=gmail.com header.s=20221208 header.b=sIcEl1Tq; spf=pass (imf28.hostedemail.com: domain of lstoakes@gmail.com designates 209.85.128.54 as permitted sender) smtp.mailfrom=lstoakes@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1682441140; a=rsa-sha256; cv=none; b=Opa1h2JSPcInwW8RNxq+ydP5+4vSZhIFo58LYklU8frw/OoaMotVWhU9o2ElIH6x5ytpLm 4CTtChoAATsBXLTlfgQxAsTr57Tt0KJLyE4AxLaIM1pcwWP6/E2Yx9lFJHCcRdc3GlSkj1 o9qn78AU1WdKMYuVPz+zV7MlwEZGzoU= Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-3f1cfed93e2so32512165e9.3 for ; Tue, 25 Apr 2023 09:45:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1682441139; x=1685033139; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=DQgl8loxAa0veEtZSLtrUvcvIyw2BmuwVPdtNPCihQg=; b=sIcEl1Tq3fwrs5UA5d0jX7GXW2Kr1kzevC2acB6kGpDEHKhEr1s9Nv64aQTPCMYV3b 8ogebBHtokSZSmEB38ASPWmJFv8VhO9CXDIGJ7A3a0jSniormcYUo170KQJgaZ/9ZNhH cOfQjXRcRLByvhH8UPAVLiw4tMzfQCtNEO1KMn6VCHOdb3sKSnbH/IcHPKhOeMrChhNv JMb0WcLeiws5HqMPX8V0OIa1fx6cu4d4gQ0O1QMNmcSGGMhIWpJ6dE602GjSAh8KDHHy /ei4tBSGhgulm1GTAscNu1bTIhOBVZ+E3mup8DtyVPaVcm5IQ6WVGGr4ObkkwKUvTf5L XsHw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1682441139; x=1685033139; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=DQgl8loxAa0veEtZSLtrUvcvIyw2BmuwVPdtNPCihQg=; b=AAtlripptJSLCyCt7SCtYbRM+1SyZ2V5xGQnOWtEEHxLB1IrPpxnJSvmf9sCu2b5mn /q2GyijY6iEIcKx9NisnClt8slwzBxSUfQvop9FHnWrc6S3OdnHHVTK6m31qEM2XOKjH RU75LZ7BVLorWX1dAbL/6rcYo3wEyD/bhcZgK5sllLDBMtZXmDkipOhz0i0KMJ64DWUv UGdrWrZAHT0W52gE/s3YsX5t1si/ZaBu2mWEX6eBsdu6EOCcoSXCO92bb/6P+a4XxAX3 GACxDctu0xDuXSnTWA51bZW16cadC9jfBTax2TzhDV23xoTGfuUX2SlcQzUDflqkV5ow IjNQ== X-Gm-Message-State: AAQBX9dP7KW7FCXY9/mX1T4K8Gd7iIUX5TJVVOJxTlKsxEAzLqRikp54 XiTBH7dPvjudAJBNvDlHfdg= X-Google-Smtp-Source: AKy350bhH1kCJAVU7jh/SMJsu6YcMsWKt9KQNik/pi2ziZhXf7/st499uGWpq4b1M825P+kzcwiSwA== X-Received: by 2002:a05:600c:3783:b0:3f1:6fb4:44cf with SMTP id o3-20020a05600c378300b003f16fb444cfmr10814511wmr.28.1682441138560; Tue, 25 Apr 2023 09:45:38 -0700 (PDT) Received: from localhost ([208.34.186.1]) by smtp.gmail.com with ESMTPSA id p10-20020a1c544a000000b003f03d483966sm18820138wmi.44.2023.04.25.09.45.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Apr 2023 09:45:37 -0700 (PDT) Date: Tue, 25 Apr 2023 17:45:36 +0100 From: Lorenzo Stoakes To: "Kirill A . Shutemov" Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrew Morton , Jason Gunthorpe , Jens Axboe , Matthew Wilcox , Dennis Dalessandro , Leon Romanovsky , Christian Benvenuti , Nelson Escobar , Bernard Metzler , Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Mark Rutland , Alexander Shishkin , Jiri Olsa , Namhyung Kim , Ian Rogers , Adrian Hunter , Bjorn Topel , Magnus Karlsson , Maciej Fijalkowski , Jonathan Lemon , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Christian Brauner , Richard Cochran , Alexei Starovoitov , Daniel Borkmann , Jesper Dangaard Brouer , John Fastabend , linux-fsdevel@vger.kernel.org, linux-perf-users@vger.kernel.org, netdev@vger.kernel.org, bpf@vger.kernel.org, Oleg Nesterov , Jason Gunthorpe , John Hubbard , Jan Kara , Pavel Begunkov Subject: Re: [PATCH v3] mm/gup: disallow GUP writing to file-backed mappings by default Message-ID: References: <23c19e27ef0745f6d3125976e047ee0da62569d4.1682406295.git.lstoakes@gmail.com> <20230425101153.xxi4arpwkz7ijnvm@box.shutemov.name> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230425101153.xxi4arpwkz7ijnvm@box.shutemov.name> X-Rspam-User: X-Rspamd-Server: rspam03 X-Stat-Signature: mtkkm67k9uafkt8ufz54tc53e9g9f659 X-Rspamd-Queue-Id: 63641C0003 X-HE-Tag: 1682441140-751923 X-HE-Meta: U2FsdGVkX1/hBJE5FtQhVffUidJpaKA2YGuuG1m5MyjzuZQth8oSQbI1tGo5pKwDXE9imPN6p6CGWVJl5rVF25TDPdaQi4MDzEnmNOxy5X64x6S+N89xwxQTlbs7GkofsGMvih1iJgi1FY81oBvyK3a1rap56ZE/4gYmnXzT5mY9FKfcG+Knfs+c0QHXBzoExZp0igJmbDzjJE4ckAL3u/PK+d7ywA/i0f81dk0jIQbwKnqhwK1Z3xVNj7PRpJhhd33KWlO5GduHFTApq9wL/Bmm/CyPBmhWii46QWw7UizeTdK8A09v7tX2xvrUXw0IdMWTVrKcdqFtGvqgX9ofJlcUyj1fyRySyQFbDOER/zdCqfO6098DasPgjs+jyy0VwatKtgf4UKb+JpuxLlXzljy6e3o8pQt65GNJkMk9wWut6raDlwltfmVq3fE/bodf6h5dzYttMIPNHRgFCSbw8b0iMaKgvPHyM8T1qx1+sxpaC3gkOWwkAHAdNGn3hKHaRvTH4b1UhHgmTXHjX/kV5k47aLyAQj1Xy4aPWlfksvOZQESvJz4yJOA6e9aUXGJ8djbEjX8/RLZcTUW9W4Uon0zo8XaeZwYw65SS7ZfMULU53kun3D4JIfNuH3kMRevspX6i2l3OlxsGo7YA1Qz4CN4DjkCojvo1qt1bjIKrkm728UeQusfbVtL/BAk/fSeaIwb1EK6zAaj/X13ye7eV2jdAdpYFeIppIQ3lNQv8U0Ci/ldLp/22Cps0TwOg7lYaZ0qWfOr8cm9RZxHMPTGzfyilwYY+/wSIiDc9RBRQvKquijRWBZuIxS3ox+8ebvxfLMkjx8d+dQM7iqFjSljI9lVRCZniDICMMM3IIGQjhaZKwPKa0OXVQ5av9r8w65D0cCfZqISjkc31Obn2cgK+3jXZlq/sq0cUMz6PqpIl9A09eDDAZQg1zpBGcp6v+7i1yaQHB49QeDRkb6ZYVEL IiggbCOY e8oNqfNfAjRAT8CWWh8TL/kF8RCT6pZvmMLvOqSskk14YX3SaoRZULRN/nJ2WJPiCU357Zmer4bQyv+GDmxnNMsBsE2EfS/5/co1dhkWipsWzRrTkOx6FGidh5IuRNUdPCWptjpJBmD1n/eJHmsYpftCQIlMau4gwUAJCyOOX75KXs6PDyKbLDg1ppYYgvj48xWVrhiBKlRdf9+lnzLH4Po9AS3RK4k/opWlP7siIHrgFBKkg46/vkK/B53J+bKrlmTHW1uFr24Jibb0e84JrdpiDn7nYSqVZqSY7X1/Jjbw5V3T1CTya1g+lSQtDmxQ924iDrUwl0cEr9y7mZPS9rikgCAoZdiG30w6DgswSGIZwSjoU5IO8vKlGsyZnBcgHVcFroNN6N2hiRqLgSq59jDFSIjlJ5wZMYiffE6lMjp+94sE8juRjSdp3gKdmaopXq8kYPC5ZSLl+wv0mTPa0G88bRn4duX8QEBMBoUMKC2s4Ue1z7C6+k0/l69O9/N1cYGjCyZ+WA0dwDWVEf8UogbG9OPltmxaxxMJPCv79Wt/OObA= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Tue, Apr 25, 2023 at 01:11:53PM +0300, Kirill A . Shutemov wrote: > On Tue, Apr 25, 2023 at 08:14:14AM +0100, Lorenzo Stoakes wrote: > > GUP does not correctly implement write-notify semantics, nor does it > > guarantee that the underlying pages are correctly dirtied, which could lead > > to a kernel oops or data corruption when writing to file-backed mappings. > > > > This is only relevant when the mappings are file-backed and the underlying > > file system requires folio dirty tracking. File systems which do not, such > > as shmem or hugetlb, are not at risk and therefore can be written to > > without issue. > > > > Unfortunately this limitation of GUP has been present for some time and > > requires future rework of the GUP API in order to provide correct write > > access to such mappings. > > > > In the meantime, we add a check for the most broken GUP case - > > FOLL_LONGTERM - which really under no circumstances can safely access > > dirty-tracked file mappings. > > > > Suggested-by: Jason Gunthorpe > > Signed-off-by: Lorenzo Stoakes > > --- > > v3: > > - Rebased on latest mm-unstable as of 24th April 2023. > > - Explicitly check whether file system requires folio dirtying. Note that > > vma_wants_writenotify() could not be used directly as it is very much focused > > on determining if the PTE r/w should be set (e.g. assuming private mapping > > does not require it as already set, soft dirty considerations). > > Hm. Okay. Have you considered having a common base for your case and > vma_wants_writenotify()? Code duplication doesn't look good. > I did and I actually started implementing something for the same reason, however I wondered whether it was worth it for essentially 3 clauses that are shared between the two. On second thoughts, it is painful to have this duplicated, so let me take another look. > > -- > Kiryl Shutsemau / Kirill A. Shutemov