All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mel Gorman <mel@csn.ul.ie>
To: Hugh Dickins <hugh.dickins@tiscali.co.uk>
Cc: Andrew Morton <akpm@linux-foundation.org>,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] hugetlb: Acquire the i_mmap_lock before walking the prio_tree to unmap a page
Date: Wed, 2 Dec 2009 22:16:02 +0000	[thread overview]
Message-ID: <20091202221602.GA26702@csn.ul.ie> (raw)
In-Reply-To: <Pine.LNX.4.64.0912022003100.8113@sister.anvils>

On Wed, Dec 02, 2009 at 08:13:39PM +0000, Hugh Dickins wrote:
> On Wed, 2 Dec 2009, Mel Gorman wrote:
> 
> > When the owner of a mapping fails COW because a child process is holding a
> > reference and no pages are available, the children VMAs are walked and the
> > page is unmapped. The i_mmap_lock is taken for the unmapping of the page but
> > not the walking of the prio_tree. In theory, that tree could be changing
> > while the lock is released although in practice it is protected by the
> > hugetlb_instantiation_mutex. This patch takes the i_mmap_lock properly for
> > the duration of the prio_tree walk in case the hugetlb_instantiation_mutex
> > ever goes away.
> > 
> > [hugh.dickins@tiscali.co.uk: Spotted the problem in the first place]
> > Signed-off-by: Mel Gorman <mel@csn.ul.ie>
> 
> The patch looks good - thanks for taking care of that, Mel.
> 
> But the comment seems wrong to me: hugetlb_instantiation_mutex
> guards against concurrent hugetlb_fault()s; but the structure of
> the prio_tree shifts as vmas based on that inode are inserted into
> (mmap'ed) and removed from (munmap'ed) that tree (always while
> holding i_mmap_lock).  I don't see hugetlb_instantiation_mutex
> giving us any protection against this at present.
> 

You're right of course. I'll report without that nonsense included.

Thanks

> 
> > ---
> >  mm/hugetlb.c |    9 ++++++++-
> >  1 files changed, 8 insertions(+), 1 deletions(-)
> > 
> > diff --git a/mm/hugetlb.c b/mm/hugetlb.c
> > index a952cb8..5adc284 100644
> > --- a/mm/hugetlb.c
> > +++ b/mm/hugetlb.c
> > @@ -1906,6 +1906,12 @@ static int unmap_ref_private(struct mm_struct *mm, struct vm_area_struct *vma,
> >  		+ (vma->vm_pgoff >> PAGE_SHIFT);
> >  	mapping = (struct address_space *)page_private(page);
> >  
> > +	/*
> > +	 * Take the mapping lock for the duration of the table walk. As
> > +	 * this mapping should be shared between all the VMAs,
> > +	 * __unmap_hugepage_range() is called as the lock is already held
> > +	 */
> > +	spin_lock(&mapping->i_mmap_lock);
> >  	vma_prio_tree_foreach(iter_vma, &iter, &mapping->i_mmap, pgoff, pgoff) {
> >  		/* Do not unmap the current VMA */
> >  		if (iter_vma == vma)
> > @@ -1919,10 +1925,11 @@ static int unmap_ref_private(struct mm_struct *mm, struct vm_area_struct *vma,
> >  		 * from the time of fork. This would look like data corruption
> >  		 */
> >  		if (!is_vma_resv_set(iter_vma, HPAGE_RESV_OWNER))
> > -			unmap_hugepage_range(iter_vma,
> > +			__unmap_hugepage_range(iter_vma,
> >  				address, address + huge_page_size(h),
> >  				page);
> >  	}
> > +	spin_unlock(&mapping->i_mmap_lock);
> >  
> >  	return 1;
> >  }
> 

-- 
Mel Gorman
Part-time Phd Student                          Linux Technology Center
University of Limerick                         IBM Dublin Software Lab

WARNING: multiple messages have this Message-ID (diff)
From: Mel Gorman <mel@csn.ul.ie>
To: Hugh Dickins <hugh.dickins@tiscali.co.uk>
Cc: Andrew Morton <akpm@linux-foundation.org>,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] hugetlb: Acquire the i_mmap_lock before walking the prio_tree to unmap a page
Date: Wed, 2 Dec 2009 22:16:02 +0000	[thread overview]
Message-ID: <20091202221602.GA26702@csn.ul.ie> (raw)
In-Reply-To: <Pine.LNX.4.64.0912022003100.8113@sister.anvils>

On Wed, Dec 02, 2009 at 08:13:39PM +0000, Hugh Dickins wrote:
> On Wed, 2 Dec 2009, Mel Gorman wrote:
> 
> > When the owner of a mapping fails COW because a child process is holding a
> > reference and no pages are available, the children VMAs are walked and the
> > page is unmapped. The i_mmap_lock is taken for the unmapping of the page but
> > not the walking of the prio_tree. In theory, that tree could be changing
> > while the lock is released although in practice it is protected by the
> > hugetlb_instantiation_mutex. This patch takes the i_mmap_lock properly for
> > the duration of the prio_tree walk in case the hugetlb_instantiation_mutex
> > ever goes away.
> > 
> > [hugh.dickins@tiscali.co.uk: Spotted the problem in the first place]
> > Signed-off-by: Mel Gorman <mel@csn.ul.ie>
> 
> The patch looks good - thanks for taking care of that, Mel.
> 
> But the comment seems wrong to me: hugetlb_instantiation_mutex
> guards against concurrent hugetlb_fault()s; but the structure of
> the prio_tree shifts as vmas based on that inode are inserted into
> (mmap'ed) and removed from (munmap'ed) that tree (always while
> holding i_mmap_lock).  I don't see hugetlb_instantiation_mutex
> giving us any protection against this at present.
> 

You're right of course. I'll report without that nonsense included.

Thanks

> 
> > ---
> >  mm/hugetlb.c |    9 ++++++++-
> >  1 files changed, 8 insertions(+), 1 deletions(-)
> > 
> > diff --git a/mm/hugetlb.c b/mm/hugetlb.c
> > index a952cb8..5adc284 100644
> > --- a/mm/hugetlb.c
> > +++ b/mm/hugetlb.c
> > @@ -1906,6 +1906,12 @@ static int unmap_ref_private(struct mm_struct *mm, struct vm_area_struct *vma,
> >  		+ (vma->vm_pgoff >> PAGE_SHIFT);
> >  	mapping = (struct address_space *)page_private(page);
> >  
> > +	/*
> > +	 * Take the mapping lock for the duration of the table walk. As
> > +	 * this mapping should be shared between all the VMAs,
> > +	 * __unmap_hugepage_range() is called as the lock is already held
> > +	 */
> > +	spin_lock(&mapping->i_mmap_lock);
> >  	vma_prio_tree_foreach(iter_vma, &iter, &mapping->i_mmap, pgoff, pgoff) {
> >  		/* Do not unmap the current VMA */
> >  		if (iter_vma == vma)
> > @@ -1919,10 +1925,11 @@ static int unmap_ref_private(struct mm_struct *mm, struct vm_area_struct *vma,
> >  		 * from the time of fork. This would look like data corruption
> >  		 */
> >  		if (!is_vma_resv_set(iter_vma, HPAGE_RESV_OWNER))
> > -			unmap_hugepage_range(iter_vma,
> > +			__unmap_hugepage_range(iter_vma,
> >  				address, address + huge_page_size(h),
> >  				page);
> >  	}
> > +	spin_unlock(&mapping->i_mmap_lock);
> >  
> >  	return 1;
> >  }
> 

-- 
Mel Gorman
Part-time Phd Student                          Linux Technology Center
University of Limerick                         IBM Dublin Software Lab

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>

  reply	other threads:[~2009-12-02 22:16 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-12-02 14:19 [PATCH] hugetlb: Acquire the i_mmap_lock before walking the prio_tree to unmap a page Mel Gorman
2009-12-02 14:19 ` Mel Gorman
2009-12-02 20:13 ` Hugh Dickins
2009-12-02 20:13   ` Hugh Dickins
2009-12-02 22:16   ` Mel Gorman [this message]
2009-12-02 22:16     ` Mel Gorman
2009-12-02 22:19     ` Mel Gorman
2009-12-02 22:19       ` Mel Gorman
2009-12-05 12:37       ` Hugh Dickins
2009-12-05 12:37         ` Hugh Dickins

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20091202221602.GA26702@csn.ul.ie \
    --to=mel@csn.ul.ie \
    --cc=akpm@linux-foundation.org \
    --cc=hugh.dickins@tiscali.co.uk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.