From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.2 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE, SPF_PASS,URIBL_BLOCKED,USER_AGENT_SANE_1 autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 32942C433DB for ; Thu, 28 Jan 2021 01:46:45 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 4F66E64DC4 for ; Thu, 28 Jan 2021 01:46:44 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 4F66E64DC4 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=huawei.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 8478D6B0006; Wed, 27 Jan 2021 20:46:43 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 7F8BD6B006C; Wed, 27 Jan 2021 20:46:43 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 70F756B006E; Wed, 27 Jan 2021 20:46:43 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0251.hostedemail.com [216.40.44.251]) by kanga.kvack.org (Postfix) with ESMTP id 5739B6B0006 for ; Wed, 27 Jan 2021 20:46:43 -0500 (EST) Received: from smtpin14.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay02.hostedemail.com (Postfix) with ESMTP id 259FD362B for ; Thu, 28 Jan 2021 01:46:43 +0000 (UTC) X-FDA: 77753494686.14.bread80_630c3472759b Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin14.hostedemail.com (Postfix) with ESMTP id 076E318229818 for ; Thu, 28 Jan 2021 01:46:43 +0000 (UTC) X-HE-Tag: bread80_630c3472759b X-Filterd-Recvd-Size: 2996 Received: from szxga05-in.huawei.com (szxga05-in.huawei.com [45.249.212.191]) by imf48.hostedemail.com (Postfix) with ESMTP for ; Thu, 28 Jan 2021 01:46:42 +0000 (UTC) Received: from DGGEMS410-HUB.china.huawei.com (unknown [172.30.72.60]) by szxga05-in.huawei.com (SkyGuard) with ESMTP id 4DR3Fd0gHvzjFLj; Thu, 28 Jan 2021 09:45:25 +0800 (CST) Received: from [10.174.179.117] (10.174.179.117) by DGGEMS410-HUB.china.huawei.com (10.3.19.210) with Microsoft SMTP Server id 14.3.498.0; Thu, 28 Jan 2021 09:46:33 +0800 Subject: Re: [PATCH] mm/hugetlb: Fix use after free when subpool max_hpages accounting is not enabled To: Andrew Morton CC: Mike Kravetz , , References: <20210126115510.53374-1-linmiaohe@huawei.com> <20210127161755.68bf43047007a8a2889e302a@linux-foundation.org> From: Miaohe Lin Message-ID: Date: Thu, 28 Jan 2021 09:46:33 +0800 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.6.0 MIME-Version: 1.0 In-Reply-To: <20210127161755.68bf43047007a8a2889e302a@linux-foundation.org> Content-Type: text/plain; charset="utf-8" Content-Language: en-US Content-Transfer-Encoding: 7bit X-Originating-IP: [10.174.179.117] X-CFilter-Loop: Reflected X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: Hi: On 2021/1/28 8:17, Andrew Morton wrote: > On Wed, 27 Jan 2021 10:08:22 +0800 Miaohe Lin wrote: > >> On 2021/1/27 8:06, Mike Kravetz wrote: >>> On 1/26/21 3:55 AM, Miaohe Lin wrote: >>>> When subpool max_hpages accounting is not enabled, used_hpages is always 0 >>>> and might lead to release subpool prematurely because it indicates no pages >>>> are used now while there might be. >>> >>> It might be good to say that you need min_hpages accounting (min_size mount >>> option) enabled for this issue to occur. Or, perhaps say this is possible >>> if a hugetlbfs filesystem is created with the min_size option and without >>> the size option. >>> >>> That might better explain the conditions in which a user could see the issue. >> >> So commit log might looks like this ? >> """ >> If a hugetlbfs filesystem is created with the min_size option and without >> the size option, used_hpages is always 0 and might lead to release subpool >> prematurely because it indicates no pages are used now while there might >> be. >> >> In order to fix this issue, we should check used_hpages == 0 iff max_hpages >> accounting is enabled. As max_hpages accounting should be enabled in most >> common case, this is not worth a Cc stable. >> """ >> >> If so, should I send a V2 or Andrew would kindly do this? >> Many thanks. > > I made that change, thanks.> It's very kind of you. Many thanks.:) > . >