linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [BUG] mm_struct leak on cpu hotplug (s390/ppc64)
@ 2005-01-04 13:11 Heiko Carstens
  2005-01-05  2:41 ` Nathan Lynch
  0 siblings, 1 reply; 8+ messages in thread
From: Heiko Carstens @ 2005-01-04 13:11 UTC (permalink / raw)
  To: rusty, paulus, nathanl; +Cc: linux-kernel

Hi,

there is an mm_struct memory leak when using cpu hotplug. Appearently
start_secondary in smp.c initializes active_mm of the cpu's idle task
and increases init_mm's mm_count. But on cpu_die the idle task's
active_mm doesn't get dropped and therefore on the next cpu_up event
(->start_secondary) it gets overwritten and the result is a forgotten
reference count to whatever mm_struct was active when the cpu
was taken down previously.

The patch below should fix this for s390 (at least it works fine for
me), but I'm not sure if it's ok to call mmdrop from __cpu_die.

Also this very same leak exists for ppc64 as well.

Any opinions?

Thanks,
Heiko

diff -urN linux-2.6.10/arch/s390/kernel/smp.c linux-2.6.10-patched/arch/s390/kernel/smp.c
--- linux-2.6.10/arch/s390/kernel/smp.c	2004-12-24 22:35:50.000000000 +0100
+++ linux-2.6.10-patched/arch/s390/kernel/smp.c	2005-01-04 13:42:14.000000000 +0100
@@ -728,9 +728,14 @@
 void
 __cpu_die(unsigned int cpu)
 {
+	struct task_struct *p;
+
 	/* Wait until target cpu is down */
 	while (!cpu_stopped(cpu));
 	printk("Processor %d spun down\n", cpu);
+	p = current_set[cpu];
+	mmdrop(p->active_mm);
+	p->active_mm = NULL;
 }
 
 void

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2005-01-07 21:49 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2005-01-04 13:11 [BUG] mm_struct leak on cpu hotplug (s390/ppc64) Heiko Carstens
2005-01-05  2:41 ` Nathan Lynch
2005-01-05 11:08   ` Ingo Molnar
2005-01-05 14:22     ` Heiko Carstens
2005-01-05 15:44     ` Nathan Lynch
2005-01-07 11:43       ` Ingo Molnar
2005-01-07 21:43         ` [PATCH] introduce idle_task_exit Nathan Lynch
2005-01-07 21:44           ` [PATCH] ppc64: call idle_task_exit from cpu_die Nathan Lynch

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).