linux-mm.kvack.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] userfaultfd: non-cooperative: notify about unmap of destination during mremap
@ 2017-07-17  6:18 Mike Rapoport
  2017-07-17  6:46 ` Mike Rapoport
  0 siblings, 1 reply; 2+ messages in thread
From: Mike Rapoport @ 2017-07-17  6:18 UTC (permalink / raw)
  To: Andrew Morton
  Cc: Andrea Arcangeli, Pavel Emelyanov, linux-mm, Mike Rapoport, stable

When mremap is called with MREMAP_FIXED it unmaps memory at the destination
address without notifying userfaultfd monitor. If the destination were
registered with userfaultfd, the monitor has no way to distinguish between
the old and new ranges and to properly relate the page faults that would
occur in the destination region.

Cc: stable@vger.kernel.org
Fixes: 897ab3e0c49e ("userfaultfd: non-cooperative: add event for memory
unmaps")

Signed-off-by: Mike Rapoport <rppt@linux.vnet.ibm.com>
---
 mm/mremap.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/mm/mremap.c b/mm/mremap.c
index cd8a1b199ef9..eb36ef9410e4 100644
--- a/mm/mremap.c
+++ b/mm/mremap.c
@@ -446,9 +446,14 @@ static unsigned long mremap_to(unsigned long addr, unsigned long old_len,
 	if (addr + old_len > new_addr && new_addr + new_len > addr)
 		goto out;
 
-	ret = do_munmap(mm, new_addr, new_len, NULL);
+	/*
+	 * We presume the uf_unmap list is empty by this point and it
+	 * will be cleared again in userfaultfd_unmap_complete.
+	 */
+	ret = do_munmap(mm, new_addr, new_len, uf_unmap);
 	if (ret)
 		goto out;
+	userfaultfd_unmap_complete(mm, uf_unmap);
 
 	if (old_len >= new_len) {
 		ret = do_munmap(mm, addr+new_len, old_len - new_len, uf_unmap);
-- 
2.7.4

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] userfaultfd: non-cooperative: notify about unmap of destination during mremap
  2017-07-17  6:18 [PATCH] userfaultfd: non-cooperative: notify about unmap of destination during mremap Mike Rapoport
@ 2017-07-17  6:46 ` Mike Rapoport
  0 siblings, 0 replies; 2+ messages in thread
From: Mike Rapoport @ 2017-07-17  6:46 UTC (permalink / raw)
  To: Andrew Morton; +Cc: Andrea Arcangeli, Pavel Emelyanov, linux-mm, stable

On Mon, Jul 17, 2017 at 09:18:13AM +0300, Mike Rapoport wrote:
> When mremap is called with MREMAP_FIXED it unmaps memory at the destination
> address without notifying userfaultfd monitor. If the destination were
> registered with userfaultfd, the monitor has no way to distinguish between
> the old and new ranges and to properly relate the page faults that would
> occur in the destination region.
> 
> Cc: stable@vger.kernel.org
> Fixes: 897ab3e0c49e ("userfaultfd: non-cooperative: add event for memory
> unmaps")
> 
> Signed-off-by: Mike Rapoport <rppt@linux.vnet.ibm.com>
> ---

Please discard this patch. I completely missed that
userfaultfd_unmap_complete releases mmap_sem :(

>  mm/mremap.c | 7 ++++++-
>  1 file changed, 6 insertions(+), 1 deletion(-)
> 
> diff --git a/mm/mremap.c b/mm/mremap.c
> index cd8a1b199ef9..eb36ef9410e4 100644
> --- a/mm/mremap.c
> +++ b/mm/mremap.c
> @@ -446,9 +446,14 @@ static unsigned long mremap_to(unsigned long addr, unsigned long old_len,
>  	if (addr + old_len > new_addr && new_addr + new_len > addr)
>  		goto out;
> 
> -	ret = do_munmap(mm, new_addr, new_len, NULL);
> +	/*
> +	 * We presume the uf_unmap list is empty by this point and it
> +	 * will be cleared again in userfaultfd_unmap_complete.
> +	 */
> +	ret = do_munmap(mm, new_addr, new_len, uf_unmap);
>  	if (ret)
>  		goto out;
> +	userfaultfd_unmap_complete(mm, uf_unmap);
> 
>  	if (old_len >= new_len) {
>  		ret = do_munmap(mm, addr+new_len, old_len - new_len, uf_unmap);
> -- 
> 2.7.4
> 

-- 
Sincerely yours,
Mike.

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-07-17  6:46 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-07-17  6:18 [PATCH] userfaultfd: non-cooperative: notify about unmap of destination during mremap Mike Rapoport
2017-07-17  6:46 ` Mike Rapoport

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).