mirror of
https://github.com/FEX-Emu/linux.git
synced 2025-01-16 22:51:32 +00:00
a7b100953a
Loading the pmd without holding the pmd_lock exposes us to races with concurrent updaters of the page tables but, worse still, it also allows the compiler to cache the pmd value in a register and reuse it later on, even if we've performed a READ_ONCE in between and seen a more recent value. In the case of page_vma_mapped_walk, this leads to the following crash when the pmd loaded for the initial pmd_trans_huge check is all zeroes and a subsequent valid table entry is loaded by check_pmd. We then proceed into map_pte, but the compiler re-uses the zero entry inside pte_offset_map, resulting in a junk pointer being installed in pvmw->pte: PC is at check_pte+0x20/0x170 LR is at page_vma_mapped_walk+0x2e0/0x540 [...] Process doio (pid: 2463, stack limit = 0xffff00000f2e8000) Call trace: check_pte+0x20/0x170 page_vma_mapped_walk+0x2e0/0x540 page_mkclean_one+0xac/0x278 rmap_walk_file+0xf0/0x238 rmap_walk+0x64/0xa0 page_mkclean+0x90/0xa8 clear_page_dirty_for_io+0x84/0x2a8 mpage_submit_page+0x34/0x98 mpage_process_page_bufs+0x164/0x170 mpage_prepare_extent_to_map+0x134/0x2b8 ext4_writepages+0x484/0xe30 do_writepages+0x44/0xe8 __filemap_fdatawrite_range+0xbc/0x110 file_write_and_wait_range+0x48/0xd8 ext4_sync_file+0x80/0x4b8 vfs_fsync_range+0x64/0xc0 SyS_msync+0x194/0x1e8 This patch fixes the problem by ensuring that READ_ONCE is used before the initial checks on the pmd, and this value is subsequently used when checking whether or not the pmd is present. pmd_check is removed and the pmd_present check is inlined directly. Link: http://lkml.kernel.org/r/1507222630-5839-1-git-send-email-will.deacon@arm.com Fixes: f27176cfc363 ("mm: convert page_mkclean_one() to use page_vma_mapped_walk()") Signed-off-by: Will Deacon <will.deacon@arm.com> Tested-by: Yury Norov <ynorov@caviumnetworks.com> Tested-by: Richard Ruigrok <rruigrok@codeaurora.org> Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com> Cc: "Paul E. McKenney" <paulmck@linux.vnet.ibm.com> Cc: Peter Zijlstra <peterz@infradead.org> Cc: <stable@vger.kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
241 lines
6.3 KiB
C
241 lines
6.3 KiB
C
#include <linux/mm.h>
|
|
#include <linux/rmap.h>
|
|
#include <linux/hugetlb.h>
|
|
#include <linux/swap.h>
|
|
#include <linux/swapops.h>
|
|
|
|
#include "internal.h"
|
|
|
|
static inline bool not_found(struct page_vma_mapped_walk *pvmw)
|
|
{
|
|
page_vma_mapped_walk_done(pvmw);
|
|
return false;
|
|
}
|
|
|
|
static bool map_pte(struct page_vma_mapped_walk *pvmw)
|
|
{
|
|
pvmw->pte = pte_offset_map(pvmw->pmd, pvmw->address);
|
|
if (!(pvmw->flags & PVMW_SYNC)) {
|
|
if (pvmw->flags & PVMW_MIGRATION) {
|
|
if (!is_swap_pte(*pvmw->pte))
|
|
return false;
|
|
} else {
|
|
if (!pte_present(*pvmw->pte))
|
|
return false;
|
|
}
|
|
}
|
|
pvmw->ptl = pte_lockptr(pvmw->vma->vm_mm, pvmw->pmd);
|
|
spin_lock(pvmw->ptl);
|
|
return true;
|
|
}
|
|
|
|
static bool check_pte(struct page_vma_mapped_walk *pvmw)
|
|
{
|
|
if (pvmw->flags & PVMW_MIGRATION) {
|
|
#ifdef CONFIG_MIGRATION
|
|
swp_entry_t entry;
|
|
if (!is_swap_pte(*pvmw->pte))
|
|
return false;
|
|
entry = pte_to_swp_entry(*pvmw->pte);
|
|
|
|
if (!is_migration_entry(entry))
|
|
return false;
|
|
if (migration_entry_to_page(entry) - pvmw->page >=
|
|
hpage_nr_pages(pvmw->page)) {
|
|
return false;
|
|
}
|
|
if (migration_entry_to_page(entry) < pvmw->page)
|
|
return false;
|
|
#else
|
|
WARN_ON_ONCE(1);
|
|
#endif
|
|
} else {
|
|
if (is_swap_pte(*pvmw->pte)) {
|
|
swp_entry_t entry;
|
|
|
|
entry = pte_to_swp_entry(*pvmw->pte);
|
|
if (is_device_private_entry(entry) &&
|
|
device_private_entry_to_page(entry) == pvmw->page)
|
|
return true;
|
|
}
|
|
|
|
if (!pte_present(*pvmw->pte))
|
|
return false;
|
|
|
|
/* THP can be referenced by any subpage */
|
|
if (pte_page(*pvmw->pte) - pvmw->page >=
|
|
hpage_nr_pages(pvmw->page)) {
|
|
return false;
|
|
}
|
|
if (pte_page(*pvmw->pte) < pvmw->page)
|
|
return false;
|
|
}
|
|
|
|
return true;
|
|
}
|
|
|
|
/**
|
|
* page_vma_mapped_walk - check if @pvmw->page is mapped in @pvmw->vma at
|
|
* @pvmw->address
|
|
* @pvmw: pointer to struct page_vma_mapped_walk. page, vma, address and flags
|
|
* must be set. pmd, pte and ptl must be NULL.
|
|
*
|
|
* Returns true if the page is mapped in the vma. @pvmw->pmd and @pvmw->pte point
|
|
* to relevant page table entries. @pvmw->ptl is locked. @pvmw->address is
|
|
* adjusted if needed (for PTE-mapped THPs).
|
|
*
|
|
* If @pvmw->pmd is set but @pvmw->pte is not, you have found PMD-mapped page
|
|
* (usually THP). For PTE-mapped THP, you should run page_vma_mapped_walk() in
|
|
* a loop to find all PTEs that map the THP.
|
|
*
|
|
* For HugeTLB pages, @pvmw->pte is set to the relevant page table entry
|
|
* regardless of which page table level the page is mapped at. @pvmw->pmd is
|
|
* NULL.
|
|
*
|
|
* Retruns false if there are no more page table entries for the page in
|
|
* the vma. @pvmw->ptl is unlocked and @pvmw->pte is unmapped.
|
|
*
|
|
* If you need to stop the walk before page_vma_mapped_walk() returned false,
|
|
* use page_vma_mapped_walk_done(). It will do the housekeeping.
|
|
*/
|
|
bool page_vma_mapped_walk(struct page_vma_mapped_walk *pvmw)
|
|
{
|
|
struct mm_struct *mm = pvmw->vma->vm_mm;
|
|
struct page *page = pvmw->page;
|
|
pgd_t *pgd;
|
|
p4d_t *p4d;
|
|
pud_t *pud;
|
|
pmd_t pmde;
|
|
|
|
/* The only possible pmd mapping has been handled on last iteration */
|
|
if (pvmw->pmd && !pvmw->pte)
|
|
return not_found(pvmw);
|
|
|
|
if (pvmw->pte)
|
|
goto next_pte;
|
|
|
|
if (unlikely(PageHuge(pvmw->page))) {
|
|
/* when pud is not present, pte will be NULL */
|
|
pvmw->pte = huge_pte_offset(mm, pvmw->address,
|
|
PAGE_SIZE << compound_order(page));
|
|
if (!pvmw->pte)
|
|
return false;
|
|
|
|
pvmw->ptl = huge_pte_lockptr(page_hstate(page), mm, pvmw->pte);
|
|
spin_lock(pvmw->ptl);
|
|
if (!check_pte(pvmw))
|
|
return not_found(pvmw);
|
|
return true;
|
|
}
|
|
restart:
|
|
pgd = pgd_offset(mm, pvmw->address);
|
|
if (!pgd_present(*pgd))
|
|
return false;
|
|
p4d = p4d_offset(pgd, pvmw->address);
|
|
if (!p4d_present(*p4d))
|
|
return false;
|
|
pud = pud_offset(p4d, pvmw->address);
|
|
if (!pud_present(*pud))
|
|
return false;
|
|
pvmw->pmd = pmd_offset(pud, pvmw->address);
|
|
/*
|
|
* Make sure the pmd value isn't cached in a register by the
|
|
* compiler and used as a stale value after we've observed a
|
|
* subsequent update.
|
|
*/
|
|
pmde = READ_ONCE(*pvmw->pmd);
|
|
if (pmd_trans_huge(pmde) || is_pmd_migration_entry(pmde)) {
|
|
pvmw->ptl = pmd_lock(mm, pvmw->pmd);
|
|
if (likely(pmd_trans_huge(*pvmw->pmd))) {
|
|
if (pvmw->flags & PVMW_MIGRATION)
|
|
return not_found(pvmw);
|
|
if (pmd_page(*pvmw->pmd) != page)
|
|
return not_found(pvmw);
|
|
return true;
|
|
} else if (!pmd_present(*pvmw->pmd)) {
|
|
if (thp_migration_supported()) {
|
|
if (!(pvmw->flags & PVMW_MIGRATION))
|
|
return not_found(pvmw);
|
|
if (is_migration_entry(pmd_to_swp_entry(*pvmw->pmd))) {
|
|
swp_entry_t entry = pmd_to_swp_entry(*pvmw->pmd);
|
|
|
|
if (migration_entry_to_page(entry) != page)
|
|
return not_found(pvmw);
|
|
return true;
|
|
}
|
|
}
|
|
return not_found(pvmw);
|
|
} else {
|
|
/* THP pmd was split under us: handle on pte level */
|
|
spin_unlock(pvmw->ptl);
|
|
pvmw->ptl = NULL;
|
|
}
|
|
} else if (!pmd_present(pmde)) {
|
|
return false;
|
|
}
|
|
if (!map_pte(pvmw))
|
|
goto next_pte;
|
|
while (1) {
|
|
if (check_pte(pvmw))
|
|
return true;
|
|
next_pte:
|
|
/* Seek to next pte only makes sense for THP */
|
|
if (!PageTransHuge(pvmw->page) || PageHuge(pvmw->page))
|
|
return not_found(pvmw);
|
|
do {
|
|
pvmw->address += PAGE_SIZE;
|
|
if (pvmw->address >= pvmw->vma->vm_end ||
|
|
pvmw->address >=
|
|
__vma_address(pvmw->page, pvmw->vma) +
|
|
hpage_nr_pages(pvmw->page) * PAGE_SIZE)
|
|
return not_found(pvmw);
|
|
/* Did we cross page table boundary? */
|
|
if (pvmw->address % PMD_SIZE == 0) {
|
|
pte_unmap(pvmw->pte);
|
|
if (pvmw->ptl) {
|
|
spin_unlock(pvmw->ptl);
|
|
pvmw->ptl = NULL;
|
|
}
|
|
goto restart;
|
|
} else {
|
|
pvmw->pte++;
|
|
}
|
|
} while (pte_none(*pvmw->pte));
|
|
|
|
if (!pvmw->ptl) {
|
|
pvmw->ptl = pte_lockptr(mm, pvmw->pmd);
|
|
spin_lock(pvmw->ptl);
|
|
}
|
|
}
|
|
}
|
|
|
|
/**
|
|
* page_mapped_in_vma - check whether a page is really mapped in a VMA
|
|
* @page: the page to test
|
|
* @vma: the VMA to test
|
|
*
|
|
* Returns 1 if the page is mapped into the page tables of the VMA, 0
|
|
* if the page is not mapped into the page tables of this VMA. Only
|
|
* valid for normal file or anonymous VMAs.
|
|
*/
|
|
int page_mapped_in_vma(struct page *page, struct vm_area_struct *vma)
|
|
{
|
|
struct page_vma_mapped_walk pvmw = {
|
|
.page = page,
|
|
.vma = vma,
|
|
.flags = PVMW_SYNC,
|
|
};
|
|
unsigned long start, end;
|
|
|
|
start = __vma_address(page, vma);
|
|
end = start + PAGE_SIZE * (hpage_nr_pages(page) - 1);
|
|
|
|
if (unlikely(end < vma->vm_start || start >= vma->vm_end))
|
|
return 0;
|
|
pvmw.address = max(start, vma->vm_start);
|
|
if (!page_vma_mapped_walk(&pvmw))
|
|
return 0;
|
|
page_vma_mapped_walk_done(&pvmw);
|
|
return 1;
|
|
}
|