From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-15.3 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER,INCLUDES_PATCH, MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED, USER_AGENT_SANE_1 autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 360D1C433DB for ; Wed, 27 Jan 2021 02:08:35 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 850762068D for ; Wed, 27 Jan 2021 02:08:34 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 850762068D Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=huawei.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id B7CAC6B0005; Tue, 26 Jan 2021 21:08:33 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id B064A6B0006; Tue, 26 Jan 2021 21:08:33 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 9CDC26B0007; Tue, 26 Jan 2021 21:08:33 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0210.hostedemail.com [216.40.44.210]) by kanga.kvack.org (Postfix) with ESMTP id 844C26B0005 for ; Tue, 26 Jan 2021 21:08:33 -0500 (EST) Received: from smtpin25.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay01.hostedemail.com (Postfix) with ESMTP id 3478B180AD82F for ; Wed, 27 Jan 2021 02:08:33 +0000 (UTC) X-FDA: 77749920906.25.fowl82_2117cd727593 Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin25.hostedemail.com (Postfix) with ESMTP id 136721804E3A1 for ; Wed, 27 Jan 2021 02:08:33 +0000 (UTC) X-HE-Tag: fowl82_2117cd727593 X-Filterd-Recvd-Size: 3180 Received: from szxga04-in.huawei.com (szxga04-in.huawei.com [45.249.212.190]) by imf43.hostedemail.com (Postfix) with ESMTP for ; Wed, 27 Jan 2021 02:08:32 +0000 (UTC) Received: from DGGEMS401-HUB.china.huawei.com (unknown [172.30.72.60]) by szxga04-in.huawei.com (SkyGuard) with ESMTP id 4DQRnG6QC1z1607m; Wed, 27 Jan 2021 10:07:14 +0800 (CST) Received: from [10.174.179.117] (10.174.179.117) by DGGEMS401-HUB.china.huawei.com (10.3.19.201) with Microsoft SMTP Server id 14.3.498.0; Wed, 27 Jan 2021 10:08:22 +0800 Subject: Re: [PATCH] mm/hugetlb: Fix use after free when subpool max_hpages accounting is not enabled To: Mike Kravetz , CC: , References: <20210126115510.53374-1-linmiaohe@huawei.com> From: Miaohe Lin Message-ID: Date: Wed, 27 Jan 2021 10:08:22 +0800 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.6.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset="utf-8" Content-Language: en-US Content-Transfer-Encoding: 7bit X-Originating-IP: [10.174.179.117] X-CFilter-Loop: Reflected X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On 2021/1/27 8:06, Mike Kravetz wrote: > On 1/26/21 3:55 AM, Miaohe Lin wrote: >> When subpool max_hpages accounting is not enabled, used_hpages is always 0 >> and might lead to release subpool prematurely because it indicates no pages >> are used now while there might be. > > It might be good to say that you need min_hpages accounting (min_size mount > option) enabled for this issue to occur. Or, perhaps say this is possible > if a hugetlbfs filesystem is created with the min_size option and without > the size option. > > That might better explain the conditions in which a user could see the issue. So commit log might looks like this ? """ If a hugetlbfs filesystem is created with the min_size option and without the size option, used_hpages is always 0 and might lead to release subpool prematurely because it indicates no pages are used now while there might be. In order to fix this issue, we should check used_hpages == 0 iff max_hpages accounting is enabled. As max_hpages accounting should be enabled in most common case, this is not worth a Cc stable. """ If so, should I send a V2 or Andrew would kindly do this? Many thanks. > >> In order to fix this issue, we should check used_hpages == 0 iff max_hpages >> accounting is enabled. As max_hpages accounting should be enabled in most >> common case, this is not worth a Cc stable. > > I agree that such a combination of mount options is very uncommon. > >> >> Signed-off-by: Hongxiang Lou >> Signed-off-by: Miaohe Lin >> --- >> mm/hugetlb.c | 16 +++++++++++++--- >> 1 file changed, 13 insertions(+), 3 deletions(-) > > Thanks, > > Reviewed-by: Mike Kravetz > Many thanks for review.