From: Andrew Morton <akpm@linux-foundation.org>
To: andi@firstfloor.org, travis@sgi.com, ak@suse.de,
clameter@sgi.com, pageexec@freemail.hu, linux-mm@kvack.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 1/1] mm: Prevent dereferencing non-allocated per_cpu variables
Date: Tue, 27 Nov 2007 15:21:22 -0800 [thread overview]
Message-ID: <20071127152122.1d5fbce3.akpm@linux-foundation.org> (raw)
In-Reply-To: <20071127151241.038c146d.akpm@linux-foundation.org>
On Tue, 27 Nov 2007 15:12:41 -0800
Andrew Morton <akpm@linux-foundation.org> wrote:
> On Tue, 27 Nov 2007 23:16:28 +0100
> Andi Kleen <andi@firstfloor.org> wrote:
>
> > On Tue, Nov 27, 2007 at 01:50:53PM -0800, travis@sgi.com wrote:
> > > Change loops controlled by 'for (i = 0; i < NR_CPUS; i++)' to use
> > > 'for_each_possible_cpu(i)' when there's a _remote possibility_ of
> > > dereferencing a non-allocated per_cpu variable involved.
> > >
> > > All files except mm/vmstat.c are x86 arch.
> > >
> > > Based on 2.6.24-rc3-mm1 .
> > >
> > > Thanks to pageexec@freemail.hu for pointing this out.
> >
> > Looks good to me. 2.6.24 candidate.
>
> hm. Has anyone any evidence that we're actually touching
> not-possible-cpu's memory here?
>
> Also, the sum_vm_events() change looks buggy - it assumes that
> cpu_possible_map has no gaps in it. But that change is unneeded because
> sum_vm_events() is only ever passed cpu_online_map and I'm hoping that we
> don't usually online not-possible CPUs.
>
> --- a/mm/vmstat.c~mm-prevent-dereferencing-non-allocated-per_cpu-variables-fix
> +++ a/mm/vmstat.c
> @@ -27,12 +27,12 @@ static void sum_vm_events(unsigned long
> memset(ret, 0, NR_VM_EVENT_ITEMS * sizeof(unsigned long));
>
> cpu = first_cpu(*cpumask);
> - while (cpu < NR_CPUS && cpu_possible(cpu)) {
> + while (cpu < NR_CPUS) {
> struct vm_event_state *this = &per_cpu(vm_event_states, cpu);
>
> cpu = next_cpu(cpu, *cpumask);
>
> - if (cpu < NR_CPUS && cpu_possible(cpu))
> + if (cpu < NR_CPUS)
> prefetch(&per_cpu(vm_event_states, cpu));
The prefetch however might still need some work - we can indeed do
prefetch() against a not-possible CPU's memory here. And I do recall that
4-5 years ago we did have a CPU (one of mine, iirc) which would oops when
prefetching from a bad address. I forget what the conclusion was on that
matter.
If we do want to fix the prefetch-from-outer-space then we should be using
cpu_isset(cpu, *cpumask) here rather than cpu_possible().
WARNING: multiple messages have this Message-ID (diff)
From: Andrew Morton <akpm@linux-foundation.org>
To: andi@firstfloor.org, travis@sgi.com, ak@suse.de,
clameter@sgi.com, pageexec@freemail.hu, linux-mm@kvack.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 1/1] mm: Prevent dereferencing non-allocated per_cpu variables
Date: Tue, 27 Nov 2007 15:21:22 -0800 [thread overview]
Message-ID: <20071127152122.1d5fbce3.akpm@linux-foundation.org> (raw)
In-Reply-To: <20071127151241.038c146d.akpm@linux-foundation.org>
On Tue, 27 Nov 2007 15:12:41 -0800
Andrew Morton <akpm@linux-foundation.org> wrote:
> On Tue, 27 Nov 2007 23:16:28 +0100
> Andi Kleen <andi@firstfloor.org> wrote:
>
> > On Tue, Nov 27, 2007 at 01:50:53PM -0800, travis@sgi.com wrote:
> > > Change loops controlled by 'for (i = 0; i < NR_CPUS; i++)' to use
> > > 'for_each_possible_cpu(i)' when there's a _remote possibility_ of
> > > dereferencing a non-allocated per_cpu variable involved.
> > >
> > > All files except mm/vmstat.c are x86 arch.
> > >
> > > Based on 2.6.24-rc3-mm1 .
> > >
> > > Thanks to pageexec@freemail.hu for pointing this out.
> >
> > Looks good to me. 2.6.24 candidate.
>
> hm. Has anyone any evidence that we're actually touching
> not-possible-cpu's memory here?
>
> Also, the sum_vm_events() change looks buggy - it assumes that
> cpu_possible_map has no gaps in it. But that change is unneeded because
> sum_vm_events() is only ever passed cpu_online_map and I'm hoping that we
> don't usually online not-possible CPUs.
>
> --- a/mm/vmstat.c~mm-prevent-dereferencing-non-allocated-per_cpu-variables-fix
> +++ a/mm/vmstat.c
> @@ -27,12 +27,12 @@ static void sum_vm_events(unsigned long
> memset(ret, 0, NR_VM_EVENT_ITEMS * sizeof(unsigned long));
>
> cpu = first_cpu(*cpumask);
> - while (cpu < NR_CPUS && cpu_possible(cpu)) {
> + while (cpu < NR_CPUS) {
> struct vm_event_state *this = &per_cpu(vm_event_states, cpu);
>
> cpu = next_cpu(cpu, *cpumask);
>
> - if (cpu < NR_CPUS && cpu_possible(cpu))
> + if (cpu < NR_CPUS)
> prefetch(&per_cpu(vm_event_states, cpu));
The prefetch however might still need some work - we can indeed do
prefetch() against a not-possible CPU's memory here. And I do recall that
4-5 years ago we did have a CPU (one of mine, iirc) which would oops when
prefetching from a bad address. I forget what the conclusion was on that
matter.
If we do want to fix the prefetch-from-outer-space then we should be using
cpu_isset(cpu, *cpumask) here rather than cpu_possible().
--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org. For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
next prev parent reply other threads:[~2007-11-27 23:21 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20071127215052.090968000@sgi.com>
2007-11-27 21:50 ` [PATCH 1/1] mm: Prevent dereferencing non-allocated per_cpu variables travis
2007-11-27 21:50 ` travis
2007-11-27 22:01 ` pageexec
2007-11-27 22:01 ` pageexec
2007-11-27 22:16 ` Andi Kleen
2007-11-27 22:16 ` Andi Kleen
2007-11-27 23:12 ` Andrew Morton
2007-11-27 23:12 ` Andrew Morton
2007-11-27 23:15 ` Christoph Lameter
2007-11-27 23:15 ` Christoph Lameter
2007-11-27 23:21 ` Andrew Morton [this message]
2007-11-27 23:21 ` Andrew Morton
2007-11-27 23:22 ` Christoph Lameter
2007-11-27 23:22 ` Christoph Lameter
2007-11-27 23:42 ` Andrew Morton
2007-11-27 23:42 ` Andrew Morton
2007-11-27 23:48 ` Andi Kleen
2007-11-27 23:48 ` Andi Kleen
2007-11-28 0:15 ` Christoph Lameter
2007-11-28 0:15 ` Christoph Lameter
2007-11-28 0:09 ` Christoph Lameter
2007-11-28 0:09 ` Christoph Lameter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20071127152122.1d5fbce3.akpm@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=ak@suse.de \
--cc=andi@firstfloor.org \
--cc=clameter@sgi.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=pageexec@freemail.hu \
--cc=travis@sgi.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.