All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: stable@vger.kernel.org, linux-kernel@vger.kernel.org
Cc: Kiran Kumar Modukuri <kiran.modukuri@gmail.com>,
	Shantanu Goel <sgoel01@yahoo.com>, Daniel Axtens <dja@axtens.net>,
	David Howells <dhowells@redhat.com>,
	Sasha Levin <sashal@kernel.org>
Subject: [PATCH AUTOSEL 4.9 29/45] cachefiles: Fix page leak in cachefiles_read_backing_file while vmscan is active
Date: Wed,  5 Dec 2018 04:46:50 -0500	[thread overview]
Message-ID: <20181205094706.7225-29-sashal@kernel.org> (raw)
In-Reply-To: <20181205094706.7225-1-sashal@kernel.org>

From: Kiran Kumar Modukuri <kiran.modukuri@gmail.com>

[ Upstream commit 9a24ce5b66f9c8190d63b15f4473600db4935f1f ]

[Description]

In a heavily loaded system where the system pagecache is nearing memory
limits and fscache is enabled, pages can be leaked by fscache while trying
read pages from cachefiles backend.  This can happen because two
applications can be reading same page from a single mount, two threads can
be trying to read the backing page at same time.  This results in one of
the threads finding that a page for the backing file or netfs file is
already in the radix tree.  During the error handling cachefiles does not
clean up the reference on backing page, leading to page leak.

[Fix]
The fix is straightforward, to decrement the reference when error is
encountered.

  [dhowells: Note that I've removed the clearance and put of newpage as
   they aren't attested in the commit message and don't appear to actually
   achieve anything since a new page is only allocated is newpage!=NULL and
   any residual new page is cleared before returning.]

[Testing]
I have tested the fix using following method for 12+ hrs.

1) mkdir -p /mnt/nfs ; mount -o vers=3,fsc <server_ip>:/export /mnt/nfs
2) create 10000 files of 2.8MB in a NFS mount.
3) start a thread to simulate heavy VM presssure
   (while true ; do echo 3 > /proc/sys/vm/drop_caches ; sleep 1 ; done)&
4) start multiple parallel reader for data set at same time
   find /mnt/nfs -type f | xargs -P 80 cat > /dev/null &
   find /mnt/nfs -type f | xargs -P 80 cat > /dev/null &
   find /mnt/nfs -type f | xargs -P 80 cat > /dev/null &
   ..
   ..
   find /mnt/nfs -type f | xargs -P 80 cat > /dev/null &
   find /mnt/nfs -type f | xargs -P 80 cat > /dev/null &
5) finally check using cat /proc/fs/fscache/stats | grep -i pages ;
   free -h , cat /proc/meminfo and page-types -r -b lru
   to ensure all pages are freed.

Reviewed-by: Daniel Axtens <dja@axtens.net>
Signed-off-by: Shantanu Goel <sgoel01@yahoo.com>
Signed-off-by: Kiran Kumar Modukuri <kiran.modukuri@gmail.com>
[dja: forward ported to current upstream]
Signed-off-by: Daniel Axtens <dja@axtens.net>
Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/cachefiles/rdwr.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/fs/cachefiles/rdwr.c b/fs/cachefiles/rdwr.c
index 5e3bc9de7a16..8d43306c038b 100644
--- a/fs/cachefiles/rdwr.c
+++ b/fs/cachefiles/rdwr.c
@@ -537,7 +537,10 @@ static int cachefiles_read_backing_file(struct cachefiles_object *object,
 					    netpage->index, cachefiles_gfp);
 		if (ret < 0) {
 			if (ret == -EEXIST) {
+				put_page(backpage);
+				backpage = NULL;
 				put_page(netpage);
+				netpage = NULL;
 				fscache_retrieval_complete(op, 1);
 				continue;
 			}
@@ -610,7 +613,10 @@ static int cachefiles_read_backing_file(struct cachefiles_object *object,
 					    netpage->index, cachefiles_gfp);
 		if (ret < 0) {
 			if (ret == -EEXIST) {
+				put_page(backpage);
+				backpage = NULL;
 				put_page(netpage);
+				netpage = NULL;
 				fscache_retrieval_complete(op, 1);
 				continue;
 			}
-- 
2.17.1


  parent reply	other threads:[~2018-12-05  9:50 UTC|newest]

Thread overview: 52+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-12-05  9:46 [PATCH AUTOSEL 4.9 01/45] ARM: OMAP2+: prm44xx: Fix section annotation on omap44xx_prm_enable_io_wakeup Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 02/45] iio:st_magn: Fix enable device after trigger Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 03/45] ARM: dts: logicpd-somlv: Fix interrupt on mmc3_dat1 Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 04/45] ARM: OMAP1: ams-delta: Fix possible use of uninitialized field Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 05/45] sysv: return 'err' instead of 0 in __sysv_write_inode Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 06/45] selftests: add script to stress-test nft packet path vs. control plane Sasha Levin
2018-12-05  9:46   ` Sasha Levin
2018-12-05  9:46   ` sashal
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 07/45] s390/cpum_cf: Reject request for sampling in event initialization Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 08/45] hwmon: (ina2xx) Fix current value calculation Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 09/45] ASoC: omap-abe-twl6040: Fix missing audio card caused by deferred probing Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 10/45] ASoC: dapm: Recalculate audio map forcely when card instantiated Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 11/45] hwmon: (w83795) temp4_type has writable permission Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 12/45] objtool: Fix double-free in .cold detection error path Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 13/45] objtool: Fix segfault in .cold detection with -ffunction-sections Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 14/45] Btrfs: send, fix infinite loop due to directory rename dependencies Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 15/45] RDMA/mlx5: Fix fence type for IB_WR_LOCAL_INV WR Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 16/45] uprobes: Fix handle_swbp() vs. unregister() + register() race once more Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 17/45] ASoC: omap-mcpdm: Add pm_qos handling to avoid under/overruns with CPU_IDLE Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 18/45] ASoC: omap-dmic: Add pm_qos handling to avoid overruns " Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 19/45] exportfs: do not read dentry after free Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 20/45] bpf: fix check of allowed specifiers in bpf_trace_printk Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 21/45] ipvs: call ip_vs_dst_notifier earlier than ipv6_dev_notf Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 22/45] USB: omap_udc: use devm_request_irq() Sasha Levin
2018-12-05  9:46   ` [AUTOSEL,4.9,22/45] " Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 23/45] USB: omap_udc: fix crashes on probe error and module removal Sasha Levin
2018-12-05  9:46   ` [AUTOSEL,4.9,23/45] " Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 24/45] USB: omap_udc: fix omap_udc_start() on 15xx machines Sasha Levin
2018-12-05  9:46   ` [AUTOSEL,4.9,24/45] " Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 25/45] USB: omap_udc: fix USB gadget functionality on Palm Tungsten E Sasha Levin
2018-12-05  9:46   ` [AUTOSEL,4.9,25/45] " Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 26/45] KVM: x86: fix empty-body warnings Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 27/45] x86/kvm/vmx: fix old-style function declaration Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 28/45] net: thunderx: fix NULL pointer dereference in nic_remove Sasha Levin
2018-12-05  9:46 ` Sasha Levin [this message]
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 30/45] igb: fix uninitialized variables Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 31/45] ixgbe: recognize 1000BaseLX SFP modules as 1Gbps Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 32/45] rapidio/rionet: do not free skb before reading its length Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 33/45] net: hisilicon: remove unexpected free_netdev Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 34/45] s390/qeth: fix length check in SNMP processing Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 35/45] drm/ast: fixed reading monitor EDID not stable issue Sasha Levin
2018-12-05  9:46   ` Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 36/45] xen: xlate_mmu: add missing header to fix 'W=1' warning Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 37/45] fscache: fix race between enablement and dropping of object Sasha Levin
2018-12-05  9:46 ` [PATCH AUTOSEL 4.9 38/45] fscache, cachefiles: remove redundant variable 'cache' Sasha Levin
2018-12-05  9:47 ` [PATCH AUTOSEL 4.9 39/45] test_hexdump: use memcpy instead of strncpy Sasha Levin
2018-12-05  9:47 ` [PATCH AUTOSEL 4.9 40/45] unifdef: " Sasha Levin
2018-12-05  9:47 ` [PATCH AUTOSEL 4.9 41/45] ocfs2: fix deadlock caused by ocfs2_defrag_extent() Sasha Levin
2018-12-05  9:47 ` [PATCH AUTOSEL 4.9 42/45] hfs: do not free node before using Sasha Levin
2018-12-05  9:47 ` [PATCH AUTOSEL 4.9 43/45] hfsplus: " Sasha Levin
2018-12-05  9:47 ` [PATCH AUTOSEL 4.9 44/45] debugobjects: avoid recursive calls with kmemleak Sasha Levin
2018-12-05  9:47 ` [PATCH AUTOSEL 4.9 45/45] ocfs2: fix potential use after free Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20181205094706.7225-29-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=dhowells@redhat.com \
    --cc=dja@axtens.net \
    --cc=kiran.modukuri@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sgoel01@yahoo.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.