All of lore.kernel.org
 help / color / mirror / Atom feed
From: Robin Holt <holt@sgi.com>
To: Christoph Lameter <clameter@sgi.com>
Cc: Andrea Arcangeli <andrea@qumranet.com>, Robin Holt <holt@sgi.com>,
	Avi Kivity <avi@qumranet.com>, Izik Eidus <izike@qumranet.com>,
	Nick Piggin <npiggin@suse.de>,
	kvm-devel@lists.sourceforge.net,
	Benjamin Herrenschmidt <benh@kernel.crashing.org>,
	Peter Zijlstra <a.p.zijlstra@chello.nl>,
	steiner@sgi.com, linux-kernel@vger.kernel.org,
	linux-mm@kvack.org, daniel.blueman@quadrics.com,
	Hugh Dickins <hugh@veritas.com>
Subject: Re: [patch 1/6] mmu_notifier: Core code
Date: Mon, 28 Jan 2008 18:05:35 -0600	[thread overview]
Message-ID: <20080129000534.GT3058@sgi.com> (raw)
In-Reply-To: <20080128202923.609249585@sgi.com>

> +void mmu_notifier_release(struct mm_struct *mm)
...
> +		hlist_for_each_entry_safe_rcu(mn, n, t,
> +					  &mm->mmu_notifier.head, hlist) {
> +			if (mn->ops->release)
> +				mn->ops->release(mn, mm);
> +			hlist_del(&mn->hlist);

USE_AFTER_FREE!!!  I made this same comment as well as other relavent
comments last week.


Robin

WARNING: multiple messages have this Message-ID (diff)
From: Robin Holt <holt-sJ/iWh9BUns@public.gmane.org>
To: Christoph Lameter <clameter-sJ/iWh9BUns@public.gmane.org>
Cc: Nick Piggin <npiggin-l3A5Bk7waGM@public.gmane.org>,
	Andrea Arcangeli <andrea-atKUWr5tajBWk0Htik3J/w@public.gmane.org>,
	Peter Zijlstra
	<a.p.zijlstra-/NLkJaSkS4VmR6Xm/wNWPw@public.gmane.org>,
	linux-mm-Bw31MaZKKs3YtjvyW6yDsg@public.gmane.org,
	Benjamin Herrenschmidt
	<benh-XVmvHMARGAS8U2dJNN8I7kB+6BGkLq7r@public.gmane.org>,
	steiner-sJ/iWh9BUns@public.gmane.org,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	Avi Kivity <avi-atKUWr5tajBWk0Htik3J/w@public.gmane.org>,
	kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org,
	daniel.blueman-xqY44rlHlBpWk0Htik3J/w@public.gmane.org,
	Robin Holt <holt-sJ/iWh9BUns@public.gmane.org>,
	Hugh Dickins <hugh-DTz5qymZ9yRBDgjK7y7TUQ@public.gmane.org>
Subject: Re: [patch 1/6] mmu_notifier: Core code
Date: Mon, 28 Jan 2008 18:05:35 -0600	[thread overview]
Message-ID: <20080129000534.GT3058@sgi.com> (raw)
In-Reply-To: <20080128202923.609249585-sJ/iWh9BUns@public.gmane.org>

> +void mmu_notifier_release(struct mm_struct *mm)
...
> +		hlist_for_each_entry_safe_rcu(mn, n, t,
> +					  &mm->mmu_notifier.head, hlist) {
> +			if (mn->ops->release)
> +				mn->ops->release(mn, mm);
> +			hlist_del(&mn->hlist);

USE_AFTER_FREE!!!  I made this same comment as well as other relavent
comments last week.


Robin

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/

WARNING: multiple messages have this Message-ID (diff)
From: Robin Holt <holt@sgi.com>
To: Christoph Lameter <clameter@sgi.com>
Cc: Andrea Arcangeli <andrea@qumranet.com>, Robin Holt <holt@sgi.com>,
	Avi Kivity <avi@qumranet.com>, Izik Eidus <izike@qumranet.com>,
	Nick Piggin <npiggin@suse.de>,
	kvm-devel@lists.sourceforge.net,
	Benjamin Herrenschmidt <benh@kernel.crashing.org>,
	Peter Zijlstra <a.p.zijlstra@chello.nl>,
	steiner@sgi.com, linux-kernel@vger.kernel.org,
	linux-mm@kvack.org, daniel.blueman@quadrics.com,
	Hugh Dickins <hugh@veritas.com>
Subject: Re: [patch 1/6] mmu_notifier: Core code
Date: Mon, 28 Jan 2008 18:05:35 -0600	[thread overview]
Message-ID: <20080129000534.GT3058@sgi.com> (raw)
In-Reply-To: <20080128202923.609249585@sgi.com>

> +void mmu_notifier_release(struct mm_struct *mm)
...
> +		hlist_for_each_entry_safe_rcu(mn, n, t,
> +					  &mm->mmu_notifier.head, hlist) {
> +			if (mn->ops->release)
> +				mn->ops->release(mn, mm);
> +			hlist_del(&mn->hlist);

USE_AFTER_FREE!!!  I made this same comment as well as other relavent
comments last week.


Robin

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>

  parent reply	other threads:[~2008-01-29  0:05 UTC|newest]

Thread overview: 267+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-01-28 20:28 [patch 0/6] [RFC] MMU Notifiers V2 Christoph Lameter
2008-01-28 20:28 ` Christoph Lameter
2008-01-28 20:28 ` [patch 1/6] mmu_notifier: Core code Christoph Lameter
2008-01-28 20:28   ` Christoph Lameter
2008-01-28 22:06   ` Christoph Lameter
2008-01-28 22:06     ` Christoph Lameter
2008-01-28 22:06     ` Christoph Lameter
2008-01-29  0:05   ` Robin Holt [this message]
2008-01-29  0:05     ` Robin Holt
2008-01-29  0:05     ` Robin Holt
2008-01-29  1:19     ` Christoph Lameter
2008-01-29  1:19       ` Christoph Lameter
2008-01-29  1:19       ` Christoph Lameter
2008-01-29 13:59   ` Andrea Arcangeli
2008-01-29 13:59     ` Andrea Arcangeli
2008-01-29 13:59     ` Andrea Arcangeli
2008-01-29 14:34     ` Andrea Arcangeli
2008-01-29 14:34       ` Andrea Arcangeli
2008-01-29 14:34       ` Andrea Arcangeli
2008-01-29 19:49     ` Christoph Lameter
2008-01-29 19:49       ` Christoph Lameter
2008-01-29 19:49       ` Christoph Lameter
2008-01-29 20:41       ` Avi Kivity
2008-01-29 20:41         ` Avi Kivity
2008-01-29 20:41         ` Avi Kivity
2008-01-29 16:07   ` Robin Holt
2008-01-29 16:07     ` Robin Holt
2008-01-29 16:07     ` Robin Holt
2008-02-05 18:05   ` Andy Whitcroft
2008-02-05 18:05     ` Andy Whitcroft
2008-02-05 18:05     ` Andy Whitcroft
2008-02-05 18:17     ` Peter Zijlstra
2008-02-05 18:17       ` Peter Zijlstra
2008-02-05 18:19     ` Christoph Lameter
2008-02-05 18:19       ` Christoph Lameter
2008-02-05 18:19       ` Christoph Lameter
2008-01-28 20:28 ` [patch 2/6] mmu_notifier: Callbacks to invalidate address ranges Christoph Lameter
2008-01-28 20:28   ` Christoph Lameter
2008-01-29 16:20   ` Andrea Arcangeli
2008-01-29 16:20     ` Andrea Arcangeli
2008-01-29 16:20     ` Andrea Arcangeli
2008-01-29 18:28     ` Andrea Arcangeli
2008-01-29 18:28       ` Andrea Arcangeli
2008-01-29 18:28       ` Andrea Arcangeli
2008-01-29 20:30       ` Christoph Lameter
2008-01-29 20:30         ` Christoph Lameter
2008-01-29 20:30         ` Christoph Lameter
2008-01-29 21:36         ` Andrea Arcangeli
2008-01-29 21:36           ` Andrea Arcangeli
2008-01-29 21:36           ` Andrea Arcangeli
2008-01-29 21:53           ` Christoph Lameter
2008-01-29 21:53             ` Christoph Lameter
2008-01-29 21:53             ` Christoph Lameter
2008-01-29 22:35             ` Andrea Arcangeli
2008-01-29 22:35               ` Andrea Arcangeli
2008-01-29 22:35               ` Andrea Arcangeli
2008-01-29 22:55               ` Christoph Lameter
2008-01-29 22:55                 ` Christoph Lameter
2008-01-29 22:55                 ` Christoph Lameter
2008-01-29 23:43                 ` Andrea Arcangeli
2008-01-29 23:43                   ` Andrea Arcangeli
2008-01-29 23:43                   ` Andrea Arcangeli
2008-01-30  0:34                   ` Christoph Lameter
2008-01-30  0:34                     ` Christoph Lameter
2008-01-30  0:34                     ` Christoph Lameter
2008-01-29 19:55     ` Christoph Lameter
2008-01-29 19:55       ` Christoph Lameter
2008-01-29 19:55       ` Christoph Lameter
2008-01-29 21:17       ` Andrea Arcangeli
2008-01-29 21:17         ` Andrea Arcangeli
2008-01-29 21:35         ` Christoph Lameter
2008-01-29 21:35           ` Christoph Lameter
2008-01-29 21:35           ` Christoph Lameter
2008-01-29 22:02           ` Andrea Arcangeli
2008-01-29 22:02             ` Andrea Arcangeli
2008-01-29 22:02             ` Andrea Arcangeli
2008-01-29 22:39             ` Christoph Lameter
2008-01-29 22:39               ` Christoph Lameter
2008-01-29 22:39               ` Christoph Lameter
2008-01-30  0:00               ` Andrea Arcangeli
2008-01-30  0:00                 ` Andrea Arcangeli
2008-01-30  0:00                 ` Andrea Arcangeli
2008-01-30  0:05                 ` Andrea Arcangeli
2008-01-30  0:05                   ` Andrea Arcangeli
2008-01-30  0:05                   ` Andrea Arcangeli
2008-01-30  0:22                   ` Christoph Lameter
2008-01-30  0:22                     ` Christoph Lameter
2008-01-30  0:22                     ` Christoph Lameter
2008-01-30  0:59                     ` Andrea Arcangeli
2008-01-30  0:59                       ` Andrea Arcangeli
2008-01-30  0:59                       ` Andrea Arcangeli
2008-01-30  8:26                       ` Peter Zijlstra
2008-01-30  8:26                         ` Peter Zijlstra
2008-01-30  0:20                 ` Christoph Lameter
2008-01-30  0:20                   ` Christoph Lameter
2008-01-30  0:20                   ` Christoph Lameter
2008-01-30  0:28                   ` Jack Steiner
2008-01-30  0:28                     ` Jack Steiner
2008-01-30  0:28                     ` Jack Steiner
2008-01-30  0:35                     ` Christoph Lameter
2008-01-30  0:35                       ` Christoph Lameter
2008-01-30  0:35                       ` Christoph Lameter
2008-01-30 13:37                     ` Andrea Arcangeli
2008-01-30 13:37                       ` Andrea Arcangeli
2008-01-30 13:37                       ` Andrea Arcangeli
2008-01-30 14:43                       ` Jack Steiner
2008-01-30 14:43                         ` Jack Steiner
2008-01-30 14:43                         ` Jack Steiner
2008-01-30 19:41                         ` Christoph Lameter
2008-01-30 19:41                           ` Christoph Lameter
2008-01-30 19:41                           ` Christoph Lameter
2008-01-30 20:29                           ` Jack Steiner
2008-01-30 20:29                             ` Jack Steiner
2008-01-30 20:29                             ` Jack Steiner
2008-01-30 20:55                             ` Christoph Lameter
2008-01-30 20:55                               ` Christoph Lameter
2008-01-30 20:55                               ` Christoph Lameter
2008-01-30 16:11                 ` Robin Holt
2008-01-30 16:11                   ` Robin Holt
2008-01-30 16:11                   ` Robin Holt
2008-01-30 17:04                   ` Andrea Arcangeli
2008-01-30 17:04                     ` Andrea Arcangeli
2008-01-30 17:04                     ` Andrea Arcangeli
2008-01-30 17:30                     ` Robin Holt
2008-01-30 17:30                       ` Robin Holt
2008-01-30 17:30                       ` Robin Holt
2008-01-30 18:25                       ` Andrea Arcangeli
2008-01-30 18:25                         ` Andrea Arcangeli
2008-01-30 18:25                         ` Andrea Arcangeli
2008-01-30 19:50                         ` Christoph Lameter
2008-01-30 19:50                           ` Christoph Lameter
2008-01-30 19:50                           ` Christoph Lameter
2008-01-30 22:18                           ` Robin Holt
2008-01-30 22:18                             ` Robin Holt
2008-01-30 22:18                             ` Robin Holt
2008-01-30 23:52                           ` Andrea Arcangeli
2008-01-30 23:52                             ` Andrea Arcangeli
2008-01-31  0:01                             ` Christoph Lameter
2008-01-31  0:01                               ` Christoph Lameter
2008-01-31  0:01                               ` Christoph Lameter
2008-01-31  0:34                               ` [kvm-devel] " Andrea Arcangeli
2008-01-31  0:34                                 ` Andrea Arcangeli
2008-01-31  0:34                                 ` Andrea Arcangeli
2008-01-31  1:46                                 ` [kvm-devel] " Christoph Lameter
2008-01-31  1:46                                   ` Christoph Lameter
2008-01-31  1:46                                   ` Christoph Lameter
2008-01-31  2:34                                   ` [kvm-devel] " Robin Holt
2008-01-31  2:34                                     ` Robin Holt
2008-01-31  2:34                                     ` Robin Holt
2008-01-31  2:37                                     ` [kvm-devel] " Christoph Lameter
2008-01-31  2:37                                       ` Christoph Lameter
2008-01-31  2:37                                       ` Christoph Lameter
2008-01-31  2:56                                     ` [kvm-devel] mmu_notifier: invalidate_range_start with lock=1 Christoph Lameter
2008-01-31  2:56                                       ` Christoph Lameter
2008-01-31  2:56                                       ` Christoph Lameter
2008-01-31 10:52                                   ` [kvm-devel] [patch 2/6] mmu_notifier: Callbacks to invalidate address ranges Andrea Arcangeli
2008-01-31 10:52                                     ` Andrea Arcangeli
2008-01-31 10:52                                     ` Andrea Arcangeli
2008-01-31  2:08                                 ` [kvm-devel] " Christoph Lameter
2008-01-31  2:08                                   ` Christoph Lameter
2008-01-31  2:08                                   ` Christoph Lameter
2008-01-31  2:42                                   ` [kvm-devel] " Andrea Arcangeli
2008-01-31  2:42                                     ` Andrea Arcangeli
2008-01-31  2:42                                     ` Andrea Arcangeli
2008-01-31  2:51                                     ` [kvm-devel] " Christoph Lameter
2008-01-31  2:51                                       ` Christoph Lameter
2008-01-31  2:51                                       ` Christoph Lameter
2008-01-31 13:39                                       ` [kvm-devel] " Andrea Arcangeli
2008-01-31 13:39                                         ` Andrea Arcangeli
2008-01-31 13:39                                         ` Andrea Arcangeli
2008-01-30 19:35                   ` Christoph Lameter
2008-01-30 19:35                     ` Christoph Lameter
2008-01-30 19:35                     ` Christoph Lameter
2008-01-28 20:28 ` [patch 3/6] mmu_notifier: invalidate_page callbacks for subsystems with rmap Christoph Lameter
2008-01-28 20:28   ` Christoph Lameter
2008-01-29 16:28   ` Robin Holt
2008-01-29 16:28     ` Robin Holt
2008-01-28 20:28 ` [patch 4/6] MMU notifier: invalidate_page callbacks using Linux rmaps Christoph Lameter
2008-01-28 20:28   ` Christoph Lameter
2008-01-29 14:03   ` Andrea Arcangeli
2008-01-29 14:03     ` Andrea Arcangeli
2008-01-29 14:03     ` Andrea Arcangeli
2008-01-29 14:24     ` Andrea Arcangeli
2008-01-29 14:24       ` Andrea Arcangeli
2008-01-29 14:24       ` Andrea Arcangeli
2008-01-29 19:51       ` Christoph Lameter
2008-01-29 19:51         ` Christoph Lameter
2008-01-29 19:51         ` Christoph Lameter
2008-01-28 20:28 ` [patch 5/6] mmu_notifier: Callbacks for xip_filemap.c Christoph Lameter
2008-01-28 20:28   ` Christoph Lameter
2008-01-28 20:28 ` [patch 6/6] mmu_notifier: Add invalidate_all() Christoph Lameter
2008-01-28 20:28   ` Christoph Lameter
2008-01-29 16:31   ` Robin Holt
2008-01-29 16:31     ` Robin Holt
2008-01-29 20:02     ` Christoph Lameter
2008-01-29 20:02       ` Christoph Lameter
2008-01-29 20:02       ` Christoph Lameter
  -- strict thread matches above, loose matches on Subject: below --
2008-01-30  2:29 [patch 0/6] [RFC] MMU Notifiers V3 Christoph Lameter
2008-01-30  2:29 ` [patch 1/6] mmu_notifier: Core code Christoph Lameter
2008-01-30  2:29   ` Christoph Lameter
2008-01-30 15:37   ` Andrea Arcangeli
2008-01-30 15:37     ` Andrea Arcangeli
2008-01-30 15:37     ` Andrea Arcangeli
2008-01-30 15:53     ` Jack Steiner
2008-01-30 15:53       ` Jack Steiner
2008-01-30 15:53       ` Jack Steiner
2008-01-30 16:38       ` Andrea Arcangeli
2008-01-30 16:38         ` Andrea Arcangeli
2008-01-30 16:38         ` Andrea Arcangeli
2008-01-30 19:19       ` Christoph Lameter
2008-01-30 19:19         ` Christoph Lameter
2008-01-30 19:19         ` Christoph Lameter
2008-01-30 22:20         ` Robin Holt
2008-01-30 22:20           ` Robin Holt
2008-01-30 22:20           ` Robin Holt
2008-01-30 23:38           ` Andrea Arcangeli
2008-01-30 23:38             ` Andrea Arcangeli
2008-01-30 23:38             ` Andrea Arcangeli
2008-01-30 23:55             ` Christoph Lameter
2008-01-30 23:55               ` Christoph Lameter
     [not found]               ` <Pine.LNX.4.64.0801301552210.1722-RYO/mD75kfhx2SFC9UQUAuF7EQX82lMiAL8bYrjMMd8@public.gmane.org>
2008-01-31  0:12                 ` Andrea Arcangeli
     [not found]                   ` <20080131001258.GD7185-lysg2Xt5kKMAvxtiuMwx3w@public.gmane.org>
2008-01-31  1:27                     ` Christoph Lameter
2008-01-30 17:10     ` Peter Zijlstra
2008-01-30 17:10       ` Peter Zijlstra
2008-01-30 19:28       ` Christoph Lameter
2008-01-30 19:28         ` Christoph Lameter
2008-01-30 19:28         ` Christoph Lameter
2008-01-30 18:02   ` Robin Holt
2008-01-30 18:02     ` Robin Holt
2008-01-30 18:02     ` Robin Holt
2008-01-30 19:08     ` Christoph Lameter
2008-01-30 19:08       ` Christoph Lameter
2008-01-30 19:08       ` Christoph Lameter
2008-01-30 19:14     ` Christoph Lameter
2008-01-30 19:14       ` Christoph Lameter
2008-01-30 19:14       ` Christoph Lameter
2008-02-08 22:06 [patch 0/6] MMU Notifiers V6 Christoph Lameter
2008-02-08 22:06 ` [patch 1/6] mmu_notifier: Core code Christoph Lameter
2008-02-08 22:06   ` Christoph Lameter
2008-02-15  6:48 [patch 0/6] MMU Notifiers V7 Christoph Lameter
2008-02-15  6:49 ` [patch 1/6] mmu_notifier: Core code Christoph Lameter
2008-02-15  6:49   ` Christoph Lameter
2008-02-16  3:37   ` Andrew Morton
2008-02-16  3:37     ` Andrew Morton
2008-02-16  8:45     ` Avi Kivity
2008-02-16  8:45       ` Avi Kivity
2008-02-16  8:45       ` Avi Kivity
2008-02-16  8:56       ` Andrew Morton
2008-02-16  8:56         ` Andrew Morton
2008-02-16  9:21         ` Avi Kivity
2008-02-16  9:21           ` Avi Kivity
2008-02-16  9:21           ` Avi Kivity
2008-02-16 10:41     ` Brice Goglin
2008-02-16 10:41       ` Brice Goglin
2008-02-16 10:58       ` Andrew Morton
2008-02-16 10:58         ` Andrew Morton
2008-02-16 19:31         ` Christoph Lameter
2008-02-16 19:31           ` Christoph Lameter
2008-02-16 19:21     ` Christoph Lameter
2008-02-16 19:21       ` Christoph Lameter
2008-02-17  3:01       ` Andrea Arcangeli
2008-02-17  3:01         ` Andrea Arcangeli
2008-02-17 12:24         ` Robin Holt
2008-02-17 12:24           ` Robin Holt
2008-02-17 12:24           ` Robin Holt
2008-02-17  5:04     ` Doug Maxey
2008-02-17  5:04       ` Doug Maxey
2008-02-17  5:04       ` Doug Maxey
2008-02-18 22:33   ` Roland Dreier
2008-02-18 22:33     ` Roland Dreier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20080129000534.GT3058@sgi.com \
    --to=holt@sgi.com \
    --cc=a.p.zijlstra@chello.nl \
    --cc=andrea@qumranet.com \
    --cc=avi@qumranet.com \
    --cc=benh@kernel.crashing.org \
    --cc=clameter@sgi.com \
    --cc=daniel.blueman@quadrics.com \
    --cc=hugh@veritas.com \
    --cc=izike@qumranet.com \
    --cc=kvm-devel@lists.sourceforge.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=npiggin@suse.de \
    --cc=steiner@sgi.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.