Steven Price
393a1aa421
mm: pagewalk: Fix race between unmap and page walker
...
commit 8782fb61cc848364e1e1599d76d3c9dd58a1cc06 upstream.
The mmap lock protects the page walker from changes to the page tables
during the walk. However a read lock is insufficient to protect those
areas which don't have a VMA as munmap() detaches the VMAs before
downgrading to a read lock and actually tearing down PTEs/page tables.
For users of walk_page_range() the solution is to simply call pte_hole()
immediately without checking the actual page tables when a VMA is not
present. We now never call __walk_page_range() without a valid vma.
For walk_page_range_novma() the locking requirements are tightened to
require the mmap write lock to be taken, and then walking the pgd
directly with 'no_vma' set.
This in turn means that all page walkers either have a valid vma, or
it's that special 'novma' case for page table debugging. As a result,
all the odd '(!walk->vma && !walk->no_vma)' tests can be removed.
Fixes: dd2283f260 ("mm: mmap: zap pages with read mmap_sem in munmap")
Reported-by: Jann Horn <jannh@google.com>
Signed-off-by: Steven Price <steven.price@arm.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Cc: Konstantin Khlebnikov <koct9i@gmail.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[manually backported. backport note: walk_page_range_novma() does not exist in
5.4, so I'm omitting it from the backport]
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-10-15 07:54:36 +02:00
..
kasan
kasan: fix incorrect arguments passing in kasan_add_zero_shadow
2021-01-27 11:47:53 +01:00
backing-dev.c
mm: bdi: initialize bdi_min_ratio when bdi is unregistered
2021-12-14 14:49:00 +01:00
balloon_compaction.c
cleancache.c
cma.c
cma: don't quit at first error when activating reserved areas
2020-09-03 11:26:51 +02:00
cma.h
cma_debug.c
compaction.c
mm, compaction: fast_find_migrateblock() should return pfn in the target zone
2022-06-14 18:11:46 +02:00
debug.c
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
failslab.c
filemap.c
mm/filemap: fix storing to a THP shadow entry
2021-06-10 13:37:15 +02:00
frame_vector.c
frontswap.c
gup.c
mm/gup: fix gup_fast with dynamic page table folding
2020-10-01 13:18:24 +02:00
gup_benchmark.c
highmem.c
hmm.c
huge_memory.c
mm/huge_memory.c: don't discard hugepage if other processes are mapping it
2021-07-14 16:53:47 +02:00
hugetlb.c
hugetlb: fix huge_pmd_unshare address update
2022-06-14 18:11:48 +02:00
hugetlb_cgroup.c
hwpoison-inject.c
init-mm.c
internal.h
mm/thp: fix vma_address() if virtual address below file offset
2021-06-30 08:47:52 -04:00
interval_tree.c
Kconfig
mm/zsmalloc.c: drop ZSMALLOC_PGTABLE_MAPPING
2020-12-16 10:56:59 +01:00
Kconfig.debug
khugepaged.c
khugepaged: fix wrong result value for trace_mm_collapse_huge_page_isolate()
2021-05-19 10:08:27 +02:00
kmemleak-test.c
kmemleak.c
Revert "mm: kmemleak: take a full lowmem check in kmemleak_*_phys()"
2022-09-15 12:04:49 +02:00
ksm.c
ksm: fix potential missing rmap_item for stable_node
2021-05-19 10:08:27 +02:00
list_lru.c
mm: list_lru: set shrinker map bit when child nr_items is not zero
2020-12-11 13:23:31 +01:00
maccess.c
madvise.c
mm: fix madivse_pageout mishandling on non-LRU page
2022-10-05 10:37:43 +02:00
Makefile
memblock.c
memblock: use kfree() to release kmalloced memblock regions
2022-03-02 11:41:18 +01:00
memcontrol.c
mm/memcontrol: return 1 from cgroup.memory __setup() handler
2022-04-15 14:18:29 +02:00
memfd.c
memfd: fix F_SEAL_WRITE after shmem huge page allocated
2022-03-08 19:07:49 +01:00
memory-failure.c
mm/memory-failure: make sure wait for page writeback in memory_failure
2021-06-23 14:41:23 +02:00
memory.c
mm: hugetlb: fix missing cache flush in copy_huge_page_from_user()
2022-05-15 19:54:47 +02:00
memory_hotplug.c
mm/memory_hotplug: use "unsigned long" for PFN in zone_for_pfn_range()
2021-09-22 12:26:43 +02:00
mempolicy.c
mm/mempolicy: fix uninit-value in mpol_rebind_policy()
2022-07-29 17:14:16 +02:00
mempool.c
memremap.c
memtest.c
migrate.c
mm/migrate_device.c: flush TLB while holding PTL
2022-10-05 10:37:43 +02:00
mincore.c
mlock.c
mm_init.c
mmap.c
mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region()
2022-09-20 12:28:00 +02:00
mmu_context.c
mm: fix kthread_use_mm() vs TLB invalidate
2020-09-03 11:26:51 +02:00
mmu_gather.c
mmu_notifier.c
mmzone.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
mprotect.c
mremap.c
mm/mremap: hold the rmap lock in write mode when moving page table entries.
2022-08-25 11:17:20 +02:00
msync.c
nommu.c
x86/mm: split vmalloc_sync_all()
2020-03-25 08:25:58 +01:00
oom_kill.c
oom_kill.c: futex: delay the OOM reaper to allow time for proper futex cleanup
2022-04-27 13:50:48 +02:00
page-writeback.c
page_alloc.c
mm: prevent page_frag_alloc() from corrupting the memory
2022-10-05 10:37:43 +02:00
page_counter.c
mm/page_counter.c: fix protection usage propagation
2020-08-21 13:05:27 +02:00
page_ext.c
page_idle.c
page_io.c
mm: fix unexpected zeroed page mapping with zram swap
2022-05-12 12:23:48 +02:00
page_isolation.c
mm/memory_hotplug: drain per-cpu pages again during memory offline
2020-09-23 12:40:47 +02:00
page_owner.c
mm/page_owner: change split_page_owner to take a count
2020-10-29 09:57:52 +01:00
page_poison.c
page_vma_mapped.c
mm/thp: another PVMW_SYNC fix in page_vma_mapped_walk()
2021-06-30 08:47:55 -04:00
pagewalk.c
mm: pagewalk: Fix race between unmap and page walker
2022-10-15 07:54:36 +02:00
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
percpu: fix first chunk size calculation for populated bitmap
2020-09-23 12:40:45 +02:00
pgtable-generic.c
mm/thp: fix __split_huge_pmd_locked() on shmem migration entry
2021-06-30 08:47:52 -04:00
process_vm_access.c
readahead.c
rmap.c
mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse
2022-09-05 10:27:46 +02:00
rodata_test.c
shmem.c
shmem: fix a race between shmem_unused_huge_shrink and shmem_evict_inode
2022-01-27 09:19:29 +01:00
shuffle.c
mm/shuffle: don't move pages between zones and don't read garbage memmaps
2020-09-03 11:26:51 +02:00
shuffle.h
slab.c
slab.h
mm: kmemleak: slob: respect SLAB_NOLEAKTRACE flag
2021-11-26 10:47:21 +01:00
slab_common.c
mm: slab: fix kmem_cache_create failed when sysfs node not destroyed
2021-07-25 14:35:14 +02:00
slob.c
slub.c
mm/slub: fix to return errno if kmalloc() fails
2022-09-28 11:04:04 +02:00
sparse-vmemmap.c
sparse.c
mm/sparse: add the missing sparse_buffer_fini() in error branch
2021-05-14 09:44:32 +02:00
swap.c
swap_cgroup.c
swap_slots.c
swap_state.c
mm/swap_state: fix a data race in swapin_nr_pages
2020-10-01 13:18:08 +02:00
swapfile.c
swap: fix swapfile read/write offset
2021-03-07 12:20:49 +01:00
truncate.c
mm/thp: unmap_mapping_page() to fix THP truncate_cleanup_page()
2021-06-30 08:47:53 -04:00
usercopy.c
mm/usercopy: return 1 from hardened_usercopy __setup() handler
2022-04-15 14:18:30 +02:00
userfaultfd.c
mm: userfaultfd: fix missing cache flush in mcopy_atomic_pte() and __mcopy_atomic()
2022-05-15 19:54:47 +02:00
util.c
random: move randomize_page() into mm where it belongs
2022-06-22 14:11:17 +02:00
vmacache.c
vmalloc.c
mm/vunmap: add cond_resched() in vunmap_pmd_range
2020-09-03 11:26:52 +02:00
vmpressure.c
vmscan.c
mm,vmscan: fix divide by zero in get_scan_count
2021-09-22 12:26:37 +02:00
vmstat.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
workingset.c
z3fold.c
mm/z3fold: fix potential memory leak in z3fold_destroy_pool()
2021-07-14 16:53:47 +02:00
zbud.c
zpool.c
zsmalloc.c
zsmalloc: fix races between asynchronous zspage free and page migration
2022-06-06 08:33:50 +02:00
zswap.c