All of lore.kernel.org
 help / color / mirror / Atom feed
From: Oleg Nesterov <oleg@redhat.com>
To: Andrew Morton <akpm@linux-foundation.org>
Cc: Al Viro <viro@ZenIV.linux.org.uk>,
	Benjamin LaHaise <bcrl@kvack.org>,
	Hugh Dickins <hughd@google.com>, Jeff Moyer <jmoyer@redhat.com>,
	Kirill Shutemov <kirill.shutemov@linux.intel.com>,
	linux-kernel@vger.kernel.org
Subject: [PATCH 1/4] mremap: don't leak new_vma if f_op->mremap() fails
Date: Sat, 20 Jun 2015 01:19:13 +0200	[thread overview]
Message-ID: <20150619231913.GA25877@redhat.com> (raw)
In-Reply-To: <20150619231854.GA25858@redhat.com>

move_vma() can't just return if f_op->mremap() fails, we should
unmap the new vma like we do if move_page_tables() fails. To avoid
the code duplication this patch moves the "move entries back" under
the new "if (err)" branch.

Signed-off-by: Oleg Nesterov <oleg@redhat.com>
---
 mm/mremap.c |   15 +++++++--------
 1 files changed, 7 insertions(+), 8 deletions(-)

diff --git a/mm/mremap.c b/mm/mremap.c
index 034e2d3..a6306bc 100644
--- a/mm/mremap.c
+++ b/mm/mremap.c
@@ -275,6 +275,12 @@ static unsigned long move_vma(struct vm_area_struct *vma,
 	moved_len = move_page_tables(vma, old_addr, new_vma, new_addr, old_len,
 				     need_rmap_locks);
 	if (moved_len < old_len) {
+		err = -ENOMEM;
+	} else if (vma->vm_file && vma->vm_file->f_op->mremap) {
+		err = vma->vm_file->f_op->mremap(vma->vm_file, new_vma);
+	}
+
+	if (unlikely(err)) {
 		/*
 		 * On error, move entries back from new area to old,
 		 * which will succeed since page tables still there,
@@ -285,14 +291,7 @@ static unsigned long move_vma(struct vm_area_struct *vma,
 		vma = new_vma;
 		old_len = new_len;
 		old_addr = new_addr;
-		new_addr = -ENOMEM;
-	} else if (vma->vm_file && vma->vm_file->f_op->mremap) {
-		err = vma->vm_file->f_op->mremap(vma->vm_file, new_vma);
-		if (err < 0) {
-			move_page_tables(new_vma, new_addr, vma, old_addr,
-					 moved_len, true);
-			return err;
-		}
+		new_addr = err;
 	}
 
 	/* Conceal VM_ACCOUNT so old reservation is not undone */
-- 
1.5.5.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
Please read the FAQ at  http://www.tux.org/lkml/

  reply	other threads:[~2015-06-19 23:20 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-06-19 23:18 [PATCH 0/4] mremap fix/cleanups Oleg Nesterov
2015-06-19 23:19 ` Oleg Nesterov [this message]
2015-06-30 22:31   ` [PATCH 1/4] mremap: don't leak new_vma if f_op->mremap() fails David Rientjes
2015-07-01 15:46     ` Oleg Nesterov
2015-07-01 22:55       ` David Rientjes
2015-06-19 23:19 ` [PATCH 2/4] mremap: don't do mm_populate(new_addr) on failure Oleg Nesterov
2015-06-30 22:34   ` David Rientjes
2015-07-01 15:47     ` Oleg Nesterov
2015-07-01 21:45   ` David Rientjes
2015-07-01 22:41     ` Oleg Nesterov
2015-06-19 23:19 ` [PATCH 3/4] mremap: don't do uneccesary checks if new_len == old_len Oleg Nesterov
2015-06-30 22:36   ` David Rientjes
2015-06-19 23:19 ` [PATCH 4/4] mremap: simplify the "overlap" check in mremap_to() Oleg Nesterov
2015-06-30 22:45   ` David Rientjes

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20150619231913.GA25877@redhat.com \
    --to=oleg@redhat.com \
    --cc=akpm@linux-foundation.org \
    --cc=bcrl@kvack.org \
    --cc=hughd@google.com \
    --cc=jmoyer@redhat.com \
    --cc=kirill.shutemov@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=viro@ZenIV.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.