Michal Hocko
891cb2a72d
mm, memory_hotplug: fix off-by-one in is_pageblock_removable
...
Rong Chen has reported the following boot crash:
PGD 0 P4D 0
Oops: 0000 [#1 ] PREEMPT SMP PTI
CPU: 1 PID: 239 Comm: udevd Not tainted 5.0.0-rc4-00149-gefad4e4 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1 04/01/2014
RIP: 0010:page_mapping+0x12/0x80
Code: 5d c3 48 89 df e8 0e ad 02 00 85 c0 75 da 89 e8 5b 5d c3 0f 1f 44 00 00 53 48 89 fb 48 8b 43 08 48 8d 50 ff a8 01 48 0f 45 da <48> 8b 53 08 48 8d 42 ff 83 e2 01 48 0f 44 c3 48 83 38 ff 74 2f 48
RSP: 0018:ffff88801fa87cd8 EFLAGS: 00010202
RAX: ffffffffffffffff RBX: fffffffffffffffe RCX: 000000000000000a
RDX: fffffffffffffffe RSI: ffffffff820b9a20 RDI: ffff88801e5c0000
RBP: 6db6db6db6db6db7 R08: ffff88801e8bb000 R09: 0000000001b64d13
R10: ffff88801fa87cf8 R11: 0000000000000001 R12: ffff88801e640000
R13: ffffffff820b9a20 R14: ffff88801f145258 R15: 0000000000000001
FS: 00007fb2079817c0(0000) GS:ffff88801dd00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000006 CR3: 000000001fa82000 CR4: 00000000000006a0
Call Trace:
__dump_page+0x14/0x2c0
is_mem_section_removable+0x24c/0x2c0
removable_show+0x87/0xa0
dev_attr_show+0x25/0x60
sysfs_kf_seq_show+0xba/0x110
seq_read+0x196/0x3f0
__vfs_read+0x34/0x180
vfs_read+0xa0/0x150
ksys_read+0x44/0xb0
do_syscall_64+0x5e/0x4a0
entry_SYSCALL_64_after_hwframe+0x49/0xbe
and bisected it down to commit efad4e475c ("mm, memory_hotplug:
is_mem_section_removable do not pass the end of a zone").
The reason for the crash is that the mapping is garbage for poisoned
(uninitialized) page. This shouldn't happen as all pages in the zone's
boundary should be initialized.
Later debugging revealed that the actual problem is an off-by-one when
evaluating the end_page. 'start_pfn + nr_pages' resp 'zone_end_pfn'
refers to a pfn after the range and as such it might belong to a
differen memory section.
This along with CONFIG_SPARSEMEM then makes the loop condition
completely bogus because a pointer arithmetic doesn't work for pages
from two different sections in that memory model.
Fix the issue by reworking is_pageblock_removable to be pfn based and
only use struct page where necessary. This makes the code slightly
easier to follow and we will remove the problematic pointer arithmetic
completely.
Link: http://lkml.kernel.org/r/20190218181544.14616-1-mhocko@kernel.org
Fixes: efad4e475c ("mm, memory_hotplug: is_mem_section_removable do not pass the end of a zone")
Signed-off-by: Michal Hocko <mhocko@suse.com>
Reported-by: <rong.a.chen@intel.com>
Tested-by: <rong.a.chen@intel.com>
Acked-by: Mike Rapoport <rppt@linux.ibm.com>
Reviewed-by: Oscar Salvador <osalvador@suse.de>
Cc: Matthew Wilcox <willy@infradead.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2019-02-21 09:01:01 -08:00
..
kasan
kasan: prevent tracing of tags.c
2019-02-21 09:01:00 -08:00
backing-dev.c
writeback: synchronize sync(2) against cgroup writeback membership switches
2019-01-22 14:39:38 -07:00
balloon_compaction.c
cleancache.c
mm: use octal not symbolic permissions
2018-06-15 07:55:25 +09:00
cma.c
kasan, mm, arm64: tag non slab memory allocated via pagealloc
2018-12-28 12:11:44 -08:00
cma.h
cma_debug.c
mm/cma: remove unsupported gfp_mask parameter from cma_alloc()
2018-08-17 16:20:32 -07:00
compaction.c
mm: move zone watermark accesses behind an accessor
2018-12-28 12:11:48 -08:00
debug.c
mm/debug.c: fix __dump_page() for poisoned pages
2019-02-21 09:01:00 -08:00
debug_page_ref.c
dmapool.c
mm: use octal not symbolic permissions
2018-06-15 07:55:25 +09:00
early_ioremap.c
fadvise.c
vfs: implement readahead(2) using POSIX_FADV_WILLNEED
2018-08-30 20:01:32 +02:00
failslab.c
mm: use octal not symbolic permissions
2018-06-15 07:55:25 +09:00
filemap.c
mm/: remove caller signal_pending branch predictions
2019-01-04 13:13:48 -08:00
frame_vector.c
frontswap.c
mm: use octal not symbolic permissions
2018-06-15 07:55:25 +09:00
gup.c
mm/gup: fix gup_pmd_range() for dax
2019-02-12 16:33:18 -08:00
gup_benchmark.c
mm/gup_benchmark.c: prevent integer overflow in ioctl
2018-10-31 08:54:12 -07:00
highmem.c
mm: convert totalram_pages and totalhigh_pages variables to atomic
2018-12-28 12:11:47 -08:00
hmm.c
mm/hmm: fix memremap.h, move dev_page_fault_t callback to hmm
2018-12-28 12:11:52 -08:00
huge_memory.c
mm: treewide: remove unused address argument from pte_alloc functions
2019-01-04 13:13:47 -08:00
hugetlb.c
mm/hugetlb.c: teach follow_hugetlb_page() to handle FOLL_NOWAIT
2019-02-01 15:46:23 -08:00
hugetlb_cgroup.c
hwpoison-inject.c
init-mm.c
mm: Allocate the mm_cpumask (mm->cpu_bitmap[]) dynamically based on nr_cpu_ids
2018-07-17 09:35:30 +02:00
internal.h
mm: use alloc_flags to record if kswapd can wake
2018-12-28 12:11:48 -08:00
interval_tree.c
Kconfig
ksm: replace jhash2 with xxhash
2018-12-28 12:11:46 -08:00
Kconfig.debug
mm: clarify CONFIG_PAGE_POISONING and usage
2018-08-22 10:52:44 -07:00
khugepaged.c
mm/mmu_notifier: use structure for invalidate_range_start/end calls v2
2018-12-28 12:11:50 -08:00
kmemleak-test.c
kmemleak.c
kmemleak: account for tagged pointers when calculating pointer range
2019-02-21 09:01:00 -08:00
ksm.c
ksm: react on changing "sleep_millisecs" parameter faster
2018-12-28 12:11:51 -08:00
list_lru.c
mm/list_lru: introduce list_lru_shrink_walk_irq()
2018-08-17 16:20:32 -07:00
maccess.c
x86/fault: BUG() when uaccess helpers fault on kernel addresses
2018-09-03 15:12:09 +02:00
madvise.c
mm/mmu_notifier: use structure for invalidate_range_start/end calls v2
2018-12-28 12:11:50 -08:00
Makefile
mm: remove nobootmem
2018-10-31 08:54:16 -07:00
memblock.c
arm64, mm, efi: Account for GICv3 LPI tables in static memblock reserve table
2019-02-16 15:02:03 +01:00
memcontrol.c
memcg, oom: notify on oom killer invocation from the charge path
2018-12-28 12:11:52 -08:00
memfd.c
memfd: Convert memfd_tag_pins to XArray
2018-10-21 10:46:41 -04:00
memory-failure.c
mm: hwpoison: use do_send_sig_info() instead of force_sig()
2019-02-01 15:46:23 -08:00
memory.c
mm/memory.c: initialise mmu_notifier_range correctly
2019-01-08 17:15:11 -08:00
memory_hotplug.c
mm, memory_hotplug: fix off-by-one in is_pageblock_removable
2019-02-21 09:01:01 -08:00
mempolicy.c
numa: change get_mempolicy() to use nr_node_ids instead of MAX_NUMNODES
2019-02-21 09:00:59 -08:00
mempool.c
mm/mempool.c: add missing parameter description
2018-08-22 10:52:44 -07:00
memtest.c
migrate.c
mm: migrate: don't rely on __PageMovable() of newpage after unlocking it
2019-02-01 15:46:24 -08:00
mincore.c
Revert "Change mincore() to count "mapped" pages rather than "cached" pages"
2019-01-24 09:04:37 +13:00
mlock.c
dax: remove VM_MIXEDMAP for fsdax and device dax
2018-08-17 16:20:27 -07:00
mm_init.c
mm: convert totalram_pages and totalhigh_pages variables to atomic
2018-12-28 12:11:47 -08:00
mmap.c
mm/mmap.c: remove verify_mm_writelocked()
2018-12-28 12:11:47 -08:00
mmu_context.c
mmu_gather.c
mm: Replace call_rcu_sched() with call_rcu()
2018-11-27 09:21:46 -08:00
mmu_notifier.c
mm/mmu_notifier: use structure for invalidate_range_start/end calls v2
2018-12-28 12:11:50 -08:00
mmzone.c
mprotect.c
mm/mmu_notifier: use structure for invalidate_range_start/end calls v2
2018-12-28 12:11:50 -08:00
mremap.c
mm: speed up mremap by 20x on large regions
2019-01-04 13:13:48 -08:00
msync.c
nommu.c
mm/gup: cache dev_pagemap while pinning pages
2018-10-26 16:38:15 -07:00
oom_kill.c
mm, oom: fix use-after-free in oom_kill_process
2019-02-01 15:46:23 -08:00
page-writeback.c
mm/page-writeback.c: don't break integrity writeback on ->writepage() error
2018-12-28 12:11:49 -08:00
page_alloc.c
mm, page_alloc: fix a division by zero error when boosting watermarks v2
2019-02-21 09:01:00 -08:00
page_counter.c
page_ext.c
Revert "mm: use early_pfn_to_nid in page_ext_init"
2019-02-12 16:33:18 -08:00
page_idle.c
mm: remove include/linux/bootmem.h
2018-10-31 08:54:16 -07:00
page_io.c
mm/page_io.c: fix polled swap page in
2019-01-04 13:13:48 -08:00
page_isolation.c
mm: only report isolation failures when offlining memory
2018-12-28 12:11:46 -08:00
page_owner.c
mm/page_owner: clamp read count to PAGE_SIZE
2018-12-28 12:11:46 -08:00
page_poison.c
virtio, vhost: fixes, tweaks
2018-11-01 14:42:49 -07:00
page_vma_mapped.c
mm/rmap: map_pte() was not handling private ZONE_DEVICE page properly
2018-10-31 08:54:11 -07:00
pagewalk.c
percpu-internal.h
percpu-km.c
percpu: convert spin_lock_irq to spin_lock_irqsave.
2018-12-18 09:04:08 -08:00
percpu-stats.c
treewide: Use array_size() in vmalloc()
2018-06-12 16:19:22 -07:00
percpu-vm.c
percpu.c
Merge branch 'for-4.20' of git://git.kernel.org/pub/scm/linux/kernel/git/dennis/percpu
2018-11-01 09:27:57 -07:00
pgtable-generic.c
x86/mm: Page size aware flush_tlb_mm_range()
2018-10-09 16:51:11 +02:00
process_vm_access.c
quicklist.c
readahead.c
mm/readahead.c: simplify get_next_ra_size()
2018-12-28 12:11:46 -08:00
rmap.c
mm/mmu_notifier: mm/rmap.c: Fix a mmu_notifier range bug in try_to_unmap_one
2019-01-10 02:58:21 -08:00
rodata_test.c
shmem.c
tmpfs: fix link accounting when a tmpfile is linked in
2019-02-21 09:01:00 -08:00
slab.c
kasan, slab: remove redundant kasan_slab_alloc hooks
2019-02-21 09:01:00 -08:00
slab.h
kmemleak: account for tagged pointers when calculating pointer range
2019-02-21 09:01:00 -08:00
slab_common.c
kmemleak: account for tagged pointers when calculating pointer range
2019-02-21 09:01:00 -08:00
slob.c
slub.c
slub: fix a crash with SLUB_DEBUG + KASAN_SW_TAGS
2019-02-21 09:01:00 -08:00
sparse-vmemmap.c
mm: remove include/linux/bootmem.h
2018-10-31 08:54:16 -07:00
sparse.c
mm, sparse: pass nid instead of pgdat to sparse_add_one_section()
2018-12-28 12:11:49 -08:00
swap.c
mm: handle lru_add_drain_all for UP properly
2019-02-21 09:01:00 -08:00
swap_cgroup.c
swap_slots.c
mm, swap, get_swap_pages: use entry_size instead of cluster in parameter
2018-08-22 10:52:44 -07:00
swap_state.c
Merge branch 'xarray' of git://git.infradead.org/users/willy/linux-dax
2018-10-28 11:35:40 -07:00
swapfile.c
mm, swap: fix swapoff with KSM pages
2018-12-28 12:11:52 -08:00
truncate.c
mm: cleancache: fix corruption on missed inode invalidation
2018-11-30 14:56:14 -08:00
usercopy.c
mm/usercopy.c: no check page span for stack objects
2019-01-08 17:15:11 -08:00
userfaultfd.c
hugetlbfs: revert "use i_mmap_rwsem for more pmd sharing synchronization"
2019-01-08 17:15:11 -08:00
util.c
mm: don't let userspace spam allocations warnings
2019-02-21 09:01:01 -08:00
vmacache.c
mm: get rid of vmacache_flush_all() entirely
2018-09-13 15:18:04 -10:00
vmalloc.c
mm: convert totalram_pages and totalhigh_pages variables to atomic
2018-12-28 12:11:47 -08:00
vmpressure.c
vmscan.c
Revert "mm: slowly shrink slabs with a relatively small number of objects"
2019-02-12 16:33:18 -08:00
vmstat.c
mm: convert zone->managed_pages to atomic variable
2018-12-28 12:11:47 -08:00
workingset.c
mm: convert totalram_pages and totalhigh_pages variables to atomic
2018-12-28 12:11:47 -08:00
z3fold.c
z3fold: fix possible reclaim races
2018-11-18 10:15:09 -08:00
zbud.c
zpool.c
zsmalloc.c
mm/zsmalloc.c: fix fall-through annotation
2018-10-26 16:26:35 -07:00
zswap.c
mm: convert totalram_pages and totalhigh_pages variables to atomic
2018-12-28 12:11:47 -08:00