From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01253CE7B08 for ; Thu, 28 Sep 2023 18:34:28 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 912BA8D00D1; Thu, 28 Sep 2023 14:34:28 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 89AB28D0053; Thu, 28 Sep 2023 14:34:28 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 715BD8D00D1; Thu, 28 Sep 2023 14:34:28 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) by kanga.kvack.org (Postfix) with ESMTP id 5BAD38D0053 for ; Thu, 28 Sep 2023 14:34:28 -0400 (EDT) Received: from smtpin09.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay02.hostedemail.com (Postfix) with ESMTP id 38F1E120146 for ; Thu, 28 Sep 2023 18:34:28 +0000 (UTC) X-FDA: 81286856616.09.4098237 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by imf25.hostedemail.com (Postfix) with ESMTP id 27130A0010 for ; Thu, 28 Sep 2023 18:34:25 +0000 (UTC) Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b=c+frV9aY; spf=pass (imf25.hostedemail.com: domain of peterx@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=peterx@redhat.com; dmarc=pass (policy=none) header.from=redhat.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1695926066; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=tHgQXBAFMtt2xjDagTnzi+QIWg4ufIaPSkBrUwwCR20=; b=rvEREMJmw4YCO0RMsulgD1IrLABLHEMjJwjC8SDrbSL2jByoDFobuI1U5OAZsPrHyFFBMs 8OIFCJnd4W3Lp94dRSFUFhWDP16i73Q9ATBpHppnWSpS4f4q35YjotHDTE1mJfle3HOn5/ G7gBWTBsUwDHRV8Yl4DaoTYafJUVMF4= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1695926066; a=rsa-sha256; cv=none; b=muahJ4cr9khon3O01AgwlvTdQpNS1mx1b+0Pd9XstPmtNE3jCrvVBaGFGbACu0v8v1avbz 6f7igdqLpTqS3mG05TgpQxMfwZZ+O1VPdvZCRwFr8eyw3l/HQbVMQVcjVr7TcrhUyTsaFq 1UUMD84BJ9Aw9zaAQ8nu1GICgYlxMIQ= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b=c+frV9aY; spf=pass (imf25.hostedemail.com: domain of peterx@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=peterx@redhat.com; dmarc=pass (policy=none) header.from=redhat.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1695926065; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=tHgQXBAFMtt2xjDagTnzi+QIWg4ufIaPSkBrUwwCR20=; b=c+frV9aYUCZxINBBhgkusJi0oYAOXq/QDlqCjplcMjAbZarMLm6rahrVWGqcXqo5sdNLyU UUtzw+NIkzajm2kpG1Jue4m8f1uk+zCO6mZLTpPuY/wbE67Z0DJdMTOCeQnmRjUJ1/g1mn lmzTQ5xSBMn/el+6a6K4epwJR8kMp0U= Received: from mail-qk1-f197.google.com (mail-qk1-f197.google.com [209.85.222.197]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-580-sbcbnh1bPJWHDS3Ems-OpA-1; Thu, 28 Sep 2023 14:34:24 -0400 X-MC-Unique: sbcbnh1bPJWHDS3Ems-OpA-1 Received: by mail-qk1-f197.google.com with SMTP id af79cd13be357-77585a78884so10140085a.1 for ; Thu, 28 Sep 2023 11:34:23 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1695926063; x=1696530863; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=tHgQXBAFMtt2xjDagTnzi+QIWg4ufIaPSkBrUwwCR20=; b=qbp1dtK25D6D61mO/0mPUqy7OZdD67Fy1Lp9Xv8We0cI6JgBmzrYmsvufezwHw9Jdl NNSLbkWiJA/DeS3ULonUIRZYFzGpFEwH51rGfyN2ynac2tysiVebLdImZNFb9iCTDQkr szRK7zSYKMGOHSvQItFLY0035XvkhY1PJQbT2aeFJ58S9exHkukFBozKwfRrVoz29++X XAeXtSUtrBpXrih7aoyihnUxrrXtUnVxIIOIAvxB1GH2MkpZFNOp22iIBddL4X4dyhZh lLck4nm4ZodAvuE5qGD3lCj1NLjEjb5RvFc9WDTucyzbwNuta862MteK4a4MDltGMlrb TZow== X-Gm-Message-State: AOJu0Ywt6DmmTEyF6MnSwV0x4FcD7HLF6FWCVD2mL3ANdaCGlsWn+TlH q5Zfl94dwppxb+cY9WneG3BYCUQ2Sj57HQNQrhzj6YgpykHTfBk/46qW9GrLbso8x9rSWIzDeSx 4OffpG90Ojks= X-Received: by 2002:a05:620a:46a4:b0:773:ad1f:3d5b with SMTP id bq36-20020a05620a46a400b00773ad1f3d5bmr2297126qkb.0.1695926063520; Thu, 28 Sep 2023 11:34:23 -0700 (PDT) X-Google-Smtp-Source: AGHT+IEV57Cs3i99fylAO+fmIhSC7kjkZzQuC8SMTvaoqr4J38m/9B5Rlx8C4OeUA5D72OFiWkiufg== X-Received: by 2002:a05:620a:46a4:b0:773:ad1f:3d5b with SMTP id bq36-20020a05620a46a400b00773ad1f3d5bmr2297110qkb.0.1695926063230; Thu, 28 Sep 2023 11:34:23 -0700 (PDT) Received: from x1n (cpe5c7695f3aee0-cm5c7695f3aede.cpe.net.cable.rogers.com. [99.254.144.39]) by smtp.gmail.com with ESMTPSA id e15-20020a05620a12cf00b007756d233fbdsm1857612qkl.37.2023.09.28.11.34.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 28 Sep 2023 11:34:22 -0700 (PDT) Date: Thu, 28 Sep 2023 14:34:19 -0400 From: Peter Xu To: David Hildenbrand Cc: Jann Horn , Suren Baghdasaryan , akpm@linux-foundation.org, viro@zeniv.linux.org.uk, brauner@kernel.org, shuah@kernel.org, aarcange@redhat.com, lokeshgidra@google.com, hughd@google.com, mhocko@suse.com, axelrasmussen@google.com, rppt@kernel.org, willy@infradead.org, Liam.Howlett@oracle.com, zhangpeng362@huawei.com, bgeffon@google.com, kaleshsingh@google.com, ngeoffray@google.com, jdduke@google.com, linux-mm@kvack.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, kernel-team@android.com Subject: Re: [PATCH v2 2/3] userfaultfd: UFFDIO_REMAP uABI Message-ID: References: <20230923013148.1390521-1-surenb@google.com> <20230923013148.1390521-3-surenb@google.com> <03f95e90-82bd-6ee2-7c0d-d4dc5d3e15ee@redhat.com> <98b21e78-a90d-8b54-3659-e9b890be094f@redhat.com> <85e5390c-660c-ef9e-b415-00ee71bc5cbf@redhat.com> MIME-Version: 1.0 In-Reply-To: <85e5390c-660c-ef9e-b415-00ee71bc5cbf@redhat.com> X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=utf-8 Content-Disposition: inline X-Stat-Signature: iszfwju5r7dedh74y1swtu1e1wa6p9h8 X-Rspamd-Server: rspam10 X-Rspamd-Queue-Id: 27130A0010 X-Rspam-User: X-HE-Tag: 1695926065-823434 X-HE-Meta: U2FsdGVkX19OziGWvfrDTcYuNW0VvTwy7rOBdZNaSg28DsQxxnDm15+KezdQFVZrXi1f9D1yk3IPtzQZebjmA1+wrFRp7Xw9O/EmZ4KDCoCnNMFA/AyDfIJuPjc17mUYKKq2qzDKWPrH+dT9HpO/bbq4YXHRlNcfMk6s3KPnWh4a88R+j02N8woi1cOaqjgEbsf6pAres8KuY3A3qQ0Jg0T1zDFygX2Cv2FMhHttLrG4DlGcIu/YP7TJbLXXLf/fAt2e+Nygdp4Pb8AAkMNGz9iL4RjFKwtQBZkjIc1WuLXmw97XWHWBD7pyVXV4iclTZCRpwxs53SmPeVfdbrx/hjWfrhZUO3kFBIzTYqoQ3zK8Ig/VIxibRhbxy0wMzZgC0tH7wiCfyl02MjDgwEBCJyhhw4q15EjWRvU9ChmqG2yum5km7v3JBN8S4KQ7y+hoAgk3Qds2NxqZcyqQWhoSezTWMLzuEWxZ1g7Zi2NTcNebzbt3jqyMO6Kj9FuWQfOYIh7cdUt/bc4xzfkNL6GseZFlXlCWQp8SVSQgtlNmyzixcoS+pCkxWW/1oOnj/OZGqSrdjGIPDJ2ck+lJ+DQhyrQZyxHvnhRQxghw+fZ+dJ9aApKmkW/Yn7/zlRBn3KIyUh30boiJYZknPfgGc9lvdA//lY6TPRlC5/ZWqxologRni9/fSW+a0LDiQDLEg5rVQhYiMdZtd7b04UlpEni7yFEMWW4IpeIizB/+vDPRywr3eAupnzH9ksoNVXU27OyJ6Sbd+UzFmq6tlYXa+kfbKAAnLS1pYTFEcCF2kJNoQ3eSrglbyVTTNDMe0VWvmUxPn7SKsk576VZuHLGWjVcKqgbxTY/WTOyaUPMaGIOv3b9jMRomdLAI05jbrpax7mAX5WYgDi6VjWkA0txl3PMrrX+nmKiefS7i47LkzLIFEoZyiSBrLi3cD7YPdfIR+5D2nsiR4mOJRh2V9LbnvKP JF7+nTu/ 2xOuGPD1PDyO9LU/ykhTd2r4jEIpjN0FphFQ99dxmQUGG2jJZfdy8TOJy/fYaLWIYolcLzkPJzRHSE8FNaMS0rNnaci8WrcfwpDcRJxgEZmOPzgE0850fDZ92xCWPRbfN/8VhIA6Bzlmij6itWHE5VrEy1yVli4+sgJNMEG/oYPpua44tbAJiRkxNouUgfGwH3SnBIAJto3yEAjhNGI9MIsg1XPlYmAVejslIfbCgC1w15z9qhka+aUmNkbyhe10s7xMRSgVWQ7ReYUzDIzzbyIYcbcNGDbfz7M5AUTsicwODR/ttpNUQejJhUWhkMeETpYJWm8YC+WXz9kvSKwKjDZXtDSucSR3A5oxt2qGpUtjteT6sstnP6YvB/cl5JGVMhHYuu6jeYsrBgllUyE7BMi0cNCbc0TJ54hWD X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Thu, Sep 28, 2023 at 07:51:18PM +0200, David Hildenbrand wrote: > On 28.09.23 19:21, Peter Xu wrote: > > On Thu, Sep 28, 2023 at 07:05:40PM +0200, David Hildenbrand wrote: > > > As described as reply to v1, without fork() and KSM, the PAE bit should > > > stick around. If that's not the case, we should investigate why. > > > > > > If we ever support the post-fork case (which the comment above remap_pages() > > > excludes) we'll need good motivation why we'd want to make this > > > overly-complicated feature even more complicated. > > > > The problem is DONTFORK is only a suggestion, but not yet restricted. If > > someone reaches on top of some !PAE page on src it'll never gonna proceed > > and keep failing, iiuc. > > Yes. It won't work if you fork() and not use DONTFORK on the src VMA. We > should document that as a limitation. > > For example, you could return an error to the user that can just call > UFFDIO_COPY. (or to the UFFDIO_COPY from inside uffd code, but that's > probably ugly as well). We could indeed provide some special errno perhaps upon the PAE check, then document it explicitly in the man page and suggest resolutions (like DONTFORK) when user hit it. > > > > > do_wp_page() doesn't have that issue of accuracy only because one round of > > CoW will just allocate a new page with PAE set guaranteed, which is pretty > > much self-heal and unnoticed. > > Yes. But it might have to copy, at which point the whole optimization of > remap is gone :) Right, but that's fine IMHO because it should still be very corner case, definitely not expected to be the majority to start impact the performance results. > > > > > So it'll be great if we can have similar self-heal way for PAE. If not, I > > think it's still fine we just always fail on !PAE src pages, but then maybe > > we should let the user know what's wrong, e.g., the user can just forgot to > > apply DONTFORK then forked. And then the user hits error and don't know > > what happened. Probably at least we should document it well in man pages. > > > Yes, exactly. > > > Another option can be we keep using folio_mapcount() for pte, and another > > helper (perhaps: _nr_pages_mapped==COMPOUND_MAPPED && _entire_mapcount==1) > > for thp. But I know that's not ideal either. > > As long as we only set the pte writable if PAE is set, we're good from a CVE > perspective. The other part is just simplicity of avoiding all these > mapcount+swapcount games where possible. > > (one day folio_mapcount() might be faster -- I'm still working on that patch > in the bigger picture of handling PTE-mapped THP better) Sure. For now as long as we're crystal clear on the possibility of inaccuracy of PAE, it never hits besides fork() && !DONTFORK, and properly document it, then sounds good here. Thanks, -- Peter Xu