Jan Kara
4d3817b64e
mm: avoid overflows in dirty throttling logic
...
[ Upstream commit 385d838df280eba6c8680f9777bfa0d0bfe7e8b2 ]
The dirty throttling logic is interspersed with assumptions that dirty
limits in PAGE_SIZE units fit into 32-bit (so that various multiplications
fit into 64-bits). If limits end up being larger, we will hit overflows,
possible divisions by 0 etc. Fix these problems by never allowing so
large dirty limits as they have dubious practical value anyway. For
dirty_bytes / dirty_background_bytes interfaces we can just refuse to set
so large limits. For dirty_ratio / dirty_background_ratio it isn't so
simple as the dirty limit is computed from the amount of available memory
which can change due to memory hotplug etc. So when converting dirty
limits from ratios to numbers of pages, we just don't allow the result to
exceed UINT_MAX.
This is root-only triggerable problem which occurs when the operator
sets dirty limits to >16 TB.
Link: https://lkml.kernel.org/r/20240621144246.11148-2-jack@suse.cz
Signed-off-by: Jan Kara <jack@suse.cz>
Reported-by: Zach O'Keefe <zokeefe@google.com>
Reviewed-By: Zach O'Keefe <zokeefe@google.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-08-19 05:33:42 +02:00
..
kasan
panic: Consolidate open-coded panic_on_warn checks
2023-02-06 07:52:50 +01:00
backing-dev.c
balloon_compaction.c
cleancache.c
cma.c
mm/cma: use nth_page() in place of direct struct page manipulation
2023-11-28 16:50:19 +00:00
cma.h
cma_debug.c
compaction.c
mm, vmscan: prevent infinite loop for costly GFP_NOIO | __GFP_RETRY_MAYFAIL allocations
2024-04-13 12:51:34 +02:00
debug.c
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
failslab.c
filemap.c
mm: allow a controlled amount of unfairness in the page lock
2023-08-30 16:27:26 +02:00
frame_vector.c
v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
2022-12-08 11:23:06 +01:00
frontswap.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
gup.c
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
2022-12-19 12:24:15 +01:00
gup_benchmark.c
highmem.c
hmm.c
huge_memory.c
mm/thp: check and bail out if page in deferred queue already
2023-03-11 16:44:05 +01:00
hugetlb.c
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
2022-12-19 12:24:15 +01:00
hugetlb_cgroup.c
hwpoison-inject.c
init-mm.c
internal.h
interval_tree.c
Kconfig
Kconfig.debug
khugepaged.c
mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma
2023-01-24 07:18:01 +01:00
kmemleak-test.c
kmemleak.c
Revert "mm: kmemleak: take a full lowmem check in kmemleak_*_phys()"
2022-09-15 12:04:49 +02:00
ksm.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
list_lru.c
maccess.c
madvise.c
mm: fix madivse_pageout mishandling on non-LRU page
2022-10-05 10:37:43 +02:00
Makefile
memblock.c
Revert "mm: Always release pages to the buddy allocator in memblock_free_late()."
2023-02-22 12:50:39 +01:00
memcontrol.c
memcg: add refcnt for pcpu stock to avoid UAF problem in drain_all_stock()
2024-03-01 13:13:32 +01:00
memfd.c
memfd: fix F_SEAL_WRITE after shmem huge page allocated
2022-03-08 19:07:49 +01:00
memory-failure.c
mm/memory-failure: fix an incorrect use of tail pages
2024-04-13 12:51:31 +02:00
memory.c
x86/mm/pat: fix VM_PAT handling in COW mappings
2024-04-13 12:51:40 +02:00
memory_hotplug.c
mempolicy.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
mempool.c
memremap.c
memtest.c
memtest: use {READ,WRITE}_ONCE in memory scanning
2024-04-13 12:51:27 +02:00
migrate.c
mm/migrate: set swap entry values of THP tail pages properly.
2024-04-13 12:51:31 +02:00
mincore.c
mlock.c
mm_init.c
mmap.c
mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region()
2022-09-20 12:28:00 +02:00
mmu_context.c
mmu_gather.c
mm/khugepaged: fix GUP-fast interaction by sending IPI
2022-12-14 11:30:42 +01:00
mmu_notifier.c
mmzone.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
mprotect.c
mremap.c
mm/mremap: hold the rmap lock in write mode when moving page table entries.
2022-08-25 11:17:20 +02:00
msync.c
nommu.c
oom_kill.c
oom_kill.c: futex: delay the OOM reaper to allow time for proper futex cleanup
2022-04-27 13:50:48 +02:00
page-writeback.c
mm: avoid overflows in dirty throttling logic
2024-08-19 05:33:42 +02:00
page_alloc.c
mm, vmscan: prevent infinite loop for costly GFP_NOIO | __GFP_RETRY_MAYFAIL allocations
2024-04-13 12:51:34 +02:00
page_counter.c
page_ext.c
page_idle.c
page_io.c
mm: fix unexpected zeroed page mapping with zram swap
2022-05-12 12:23:48 +02:00
page_isolation.c
page_owner.c
page_poison.c
page_vma_mapped.c
pagewalk.c
mm: pagewalk: Fix race between unmap and page walker
2022-10-15 07:54:36 +02:00
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
pgtable-generic.c
process_vm_access.c
readahead.c
vfs: fix readahead(2) on block devices
2023-11-20 10:30:08 +01:00
rmap.c
mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse
2022-09-05 10:27:46 +02:00
rodata_test.c
shmem.c
tmpfs: verify {g,u}id mount options correctly
2023-09-23 10:59:40 +02:00
shuffle.c
shuffle.h
slab.c
slab.h
slab_common.c
slob.c
slub.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
sparse-vmemmap.c
sparse.c
swap.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
swap_cgroup.c
swap_slots.c
swap_state.c
swapfile.c
mm/swap: fix swap_info_struct race between swapoff and get_swap_pages()
2023-04-20 12:07:35 +02:00
truncate.c
usercopy.c
mm/usercopy: return 1 from hardened_usercopy __setup() handler
2022-04-15 14:18:30 +02:00
userfaultfd.c
userfaultfd: fix mmap_changing checking in mfill_atomic_hugetlb
2024-03-01 13:13:33 +01:00
util.c
random: move randomize_page() into mm where it belongs
2022-06-22 14:11:17 +02:00
vmacache.c
vmalloc.c
vmpressure.c
vmscan.c
mm, vmscan: prevent infinite loop for costly GFP_NOIO | __GFP_RETRY_MAYFAIL allocations
2024-04-13 12:51:34 +02:00
vmstat.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
workingset.c
z3fold.c
zbud.c
zpool.c
zsmalloc.c
zsmalloc: fix races between asynchronous zspage free and page migration
2022-06-06 08:33:50 +02:00
zswap.c