Vlastimil Babka
d827fe702e
mm, compaction: make capture control handling safe wrt interrupts
...
commit b9e20f0da1f5c9c68689450a8cb436c9486434c8 upstream.
Hugh reports:
"While stressing compaction, one run oopsed on NULL capc->cc in
__free_one_page()'s task_capc(zone): compact_zone_order() had been
interrupted, and a page was being freed in the return from interrupt.
Though you would not expect it from the source, both gccs I was using
(4.8.1 and 7.5.0) had chosen to compile compact_zone_order() with the
".cc = &cc" implemented by mov %rbx,-0xb0(%rbp) immediately before
callq compact_zone - long after the "current->capture_control =
&capc". An interrupt in between those finds capc->cc NULL (zeroed by
an earlier rep stos).
This could presumably be fixed by a barrier() before setting
current->capture_control in compact_zone_order(); but would also need
more care on return from compact_zone(), in order not to risk leaking
a page captured by interrupt just before capture_control is reset.
Maybe that is the preferable fix, but I felt safer for task_capc() to
exclude the rather surprising possibility of capture at interrupt
time"
I have checked that gcc10 also behaves the same.
The advantage of fix in compact_zone_order() is that we don't add
another test in the page freeing hot path, and that it might prevent
future problems if we stop exposing pointers to uninitialized structures
in current task.
So this patch implements the suggestion for compact_zone_order() with
barrier() (and WRITE_ONCE() to prevent store tearing) for setting
current->capture_control, and prevents page leaking with
WRITE_ONCE/READ_ONCE in the proper order.
Link: http://lkml.kernel.org/r/20200616082649.27173-1-vbabka@suse.cz
Fixes: 5e1f0f098b ("mm, compaction: capture a page under direct compaction")
Signed-off-by: Vlastimil Babka <vbabka@suse.cz>
Reported-by: Hugh Dickins <hughd@google.com>
Suggested-by: Hugh Dickins <hughd@google.com>
Acked-by: Hugh Dickins <hughd@google.com>
Cc: Alex Shi <alex.shi@linux.alibaba.com>
Cc: Li Wang <liwang@redhat.com>
Cc: Mel Gorman <mgorman@techsingularity.net>
Cc: <stable@vger.kernel.org> [5.1+]
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-09 09:37:57 +02:00
..
kasan
kasan: disable branch tracing for core runtime
2020-05-27 17:46:48 +02:00
backing-dev.c
bdi: add a ->dev_name field to struct backing_dev_info
2020-05-14 07:58:30 +02:00
balloon_compaction.c
cleancache.c
cma.c
cma.h
cma_debug.c
compaction.c
mm, compaction: make capture control handling safe wrt interrupts
2020-07-09 09:37:57 +02:00
debug.c
mm/debug.c: always print flags in dump_page()
2020-03-05 16:43:51 +01:00
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
failslab.c
filemap.c
mm: drop mmap_sem before calling balance_dirty_pages() in write fault
2020-01-09 10:19:55 +01:00
frame_vector.c
mm: untag user pointers in get_vaddr_frames
2019-09-25 17:51:41 -07:00
frontswap.c
gup.c
gup: document and work around "COW can break either way" issue
2020-06-17 16:40:30 +02:00
gup_benchmark.c
mm/gup: fix memory leak in __gup_benchmark_ioctl
2020-01-09 10:20:00 +01:00
highmem.c
hmm.c
huge_memory.c
mm: thp: make the THP mapcount atomic against __split_huge_pmd_locked()
2020-06-22 09:31:14 +02:00
hugetlb.c
mm/hugetlb: fix a addressing exception caused by huge_pte_offset
2020-04-29 16:33:14 +02:00
hugetlb_cgroup.c
mm: hugetlb: switch to css_tryget() in hugetlb_cgroup_charge_cgroup()
2019-11-15 18:34:00 -08:00
hwpoison-inject.c
init-mm.c
mm/init-mm.c: include <linux/mman.h> for vm_committed_as_batch
2019-10-19 06:32:32 -04:00
internal.h
mm: drop mmap_sem before calling balance_dirty_pages() in write fault
2020-01-09 10:19:55 +01:00
interval_tree.c
Kconfig
mm,thp: add read-only THP support for (non-shmem) FS
2019-09-24 15:54:11 -07:00
Kconfig.debug
mm, page_owner, debug_pagealloc: save and dump freeing stack trace
2019-09-24 15:54:08 -07:00
khugepaged.c
mm,thp: stop leaking unreleased file pages
2020-06-03 08:21:26 +02:00
kmemleak-test.c
kmemleak.c
kmemleak: Do not corrupt the object_list during clean-up
2019-10-14 08:56:16 -07:00
ksm.c
mm/ksm: fix NULL pointer dereference when KSM zero page is enabled
2020-04-29 16:33:15 +02:00
list_lru.c
maccess.c
uaccess: Add non-pagefault user-space write function
2020-01-17 19:48:40 +01:00
madvise.c
mm: do not allow MADV_PAGEOUT for CoW pages
2020-03-25 08:25:57 +01:00
Makefile
mm: silence -Woverride-init/initializer-overrides
2019-09-24 15:54:10 -07:00
memblock.c
mm: memblock: do not enforce current limit for memblock_phys* family
2019-10-19 06:32:32 -04:00
memcontrol.c
mm/memcontrol.c: add missed css_put()
2020-06-30 15:37:09 -04:00
memfd.c
mm: page cache: store only head pages in i_pages
2019-09-24 15:54:08 -07:00
memory-failure.c
mm/memory-failure.c: don't access uninitialized memmaps in memory_failure()
2019-10-19 06:32:31 -04:00
memory.c
mm: drop mmap_sem before calling balance_dirty_pages() in write fault
2020-01-09 10:19:55 +01:00
memory_hotplug.c
mm, hotplug: fix page online with DEBUG_PAGEALLOC compiled but not enabled
2020-03-12 13:00:19 +01:00
mempolicy.c
mm: mempolicy: require at least one nodeid for MPOL_PREFERRED
2020-04-08 09:08:47 +02:00
mempool.c
memremap.c
mm/memory_hotplug: shrink zones when offlining memory
2020-01-09 10:19:56 +01:00
memtest.c
migrate.c
mm: move_pages: report the number of non-attempted pages
2020-02-11 04:35:13 -08:00
mincore.c
mm: untag user pointers passed to memory syscalls
2019-09-25 17:51:41 -07:00
mlock.c
mm: untag user pointers passed to memory syscalls
2019-09-25 17:51:41 -07:00
mm_init.c
mmap.c
mm: Avoid creating virtual address aliases in brk()/mmap()/mremap()
2020-02-28 17:22:21 +01:00
mmu_context.c
mmu_gather.c
mm/mmu_gather: invalidate TLB correctly on batch allocation failure and flush
2020-02-11 04:35:42 -08:00
mmu_notifier.c
mm/mmu_notifiers: use the right return code for WARN_ON
2019-11-06 08:47:50 -08:00
mmzone.c
mprotect.c
mm, numa: fix bad pmd by atomically check for pmd_trans_huge when marking page tables prot_numa
2020-03-12 13:00:19 +01:00
mremap.c
mm: Fix mremap not considering huge pmd devmap
2020-06-07 13:18:46 +02:00
msync.c
mm: untag user pointers passed to memory syscalls
2019-09-25 17:51:41 -07:00
nommu.c
x86/mm: split vmalloc_sync_all()
2020-03-25 08:25:58 +01:00
oom_kill.c
mm/oom: fix pgtables units mismatch in Killed process message
2020-01-09 10:19:57 +01:00
page-writeback.c
mm/page-writeback.c: avoid potential division by zero in wb_min_max_ratio()
2020-01-23 08:22:41 +01:00
page_alloc.c
mm: call cond_resched() from deferred_init_memmap()
2020-06-22 09:31:14 +02:00
page_counter.c
page_ext.c
mm, page_owner: fix off-by-one error in __set_page_owner_handle()
2019-10-14 15:04:00 -07:00
page_idle.c
page_io.c
mm/page_io.c: do not free shared swap slots
2019-11-15 18:34:00 -08:00
page_isolation.c
page_owner.c
mm/page_owner: don't access uninitialized memmaps when reading /proc/pagetypeinfo
2019-10-19 06:32:31 -04:00
page_poison.c
page_vma_mapped.c
pagewalk.c
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
pgtable-generic.c
process_vm_access.c
readahead.c
rmap.c
mm: include <linux/huge_mm.h> for is_vma_temporary_stack
2019-10-19 06:32:32 -04:00
rodata_test.c
shmem.c
shmem: fix possible deadlocks on shmlock_user_lock
2020-05-20 08:20:03 +02:00
shuffle.c
mm: fix -Wmissing-prototypes warnings
2019-10-07 15:47:19 -07:00
shuffle.h
slab.c
mm, debug_pagealloc: don't rely on static keys too early
2020-01-23 08:22:40 +01:00
slab.h
mm: slab: make page_cgroup_ino() to recognize non-compound slab pages properly
2019-11-06 08:47:50 -08:00
slab_common.c
mm/slab: use memzero_explicit() in kzfree()
2020-06-30 15:37:09 -04:00
slob.c
mm, sl[aou]b: guarantee natural alignment for kmalloc(power-of-two)
2019-10-07 15:47:20 -07:00
slub.c
mm/slub: fix stack overruns with SLUB_STATS
2020-07-09 09:37:50 +02:00
sparse-vmemmap.c
sparse.c
mm/sparse: fix kernel crash with pfn_section_valid check
2020-04-01 11:02:03 +02:00
swap.c
mm: introduce MADV_COLD
2019-09-25 17:51:41 -07:00
swap_cgroup.c
swap_slots.c
swap_state.c
mm: fix swap cache node allocation mask
2020-07-09 09:37:49 +02:00
swapfile.c
mm/swapfile.c: move inode_lock out of claim_swapfile
2020-04-01 11:02:02 +02:00
truncate.c
mm/thp: allow dropping THP from page cache
2019-10-19 06:32:33 -04:00
usercopy.c
userfaultfd.c
util.c
mm: add kvfree_sensitive() for freeing sensitive data objects
2020-06-17 16:40:23 +02:00
vmacache.c
vmalloc.c
vmalloc: fix remap_vmalloc_range() bounds checks
2020-04-29 16:33:14 +02:00
vmpressure.c
mm/vmpressure.c: fix a signedness bug in vmpressure_register_event()
2019-10-07 15:47:19 -07:00
vmscan.c
mm/vmscan.c: don't round up scan size for online memory cgroup
2020-02-28 17:22:20 +01:00
vmstat.c
mm, vmstat: reduce zone->lock holding time by /proc/pagetypeinfo
2019-11-06 08:47:50 -08:00
workingset.c
z3fold.c
mm/z3fold.c: claim page in the beginning of free
2019-10-07 15:47:19 -07:00
zbud.c
zpool.c
zpool: add malloc_support_movable to zpool_driver
2019-09-24 15:54:12 -07:00
zsmalloc.c
mm/zsmalloc.c: fix the migrated zspage statistics.
2020-01-09 10:19:56 +01:00
zswap.c
zswap: do not map same object twice
2019-09-24 15:54:12 -07:00