From: Andrew Morton <akpm@linux-foundation.org>
To: Maurizio Lombardi <mlombard@redhat.com>
Cc: alexander.duyck@gmail.com, kuba@kernel.org, linux-mm@kvack.org,
linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
chen45464546@163.com
Subject: Re: [PATCH V2] mm: prevent page_frag_alloc() from corrupting the memory
Date: Wed, 13 Jul 2022 08:45:36 -0700 [thread overview]
Message-ID: <20220713084536.1af461b016a16c58baad7db2@linux-foundation.org> (raw)
In-Reply-To: <20220713150143.147537-1-mlombard@redhat.com>
On Wed, 13 Jul 2022 17:01:43 +0200 Maurizio Lombardi <mlombard@redhat.com> wrote:
> A number of drivers call page_frag_alloc() with a
> fragment's size > PAGE_SIZE.
> In low memory conditions, __page_frag_cache_refill() may fail the order 3
> cache allocation and fall back to order 0;
> In this case, the cache will be smaller than the fragment, causing
> memory corruptions.
>
> Prevent this from happening by checking if the newly allocated cache
> is large enough for the fragment; if not, the allocation will fail
> and page_frag_alloc() will return NULL.
>
> ...
>
> --- a/mm/page_alloc.c
> +++ b/mm/page_alloc.c
> @@ -5617,6 +5617,8 @@ void *page_frag_alloc_align(struct page_frag_cache *nc,
> /* reset page count bias and offset to start of new frag */
> nc->pagecnt_bias = PAGE_FRAG_CACHE_MAX_SIZE + 1;
> offset = size - fragsz;
> + if (unlikely(offset < 0))
> + return NULL;
> }
>
> nc->pagecnt_bias--;
I think we should have a comment here explaining (at least) why we'd
bale after a successful allocation and explaining why we don't call
free_the_page().
prev parent reply other threads:[~2022-07-13 15:45 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-07-13 15:01 [PATCH V2] mm: prevent page_frag_alloc() from corrupting the memory Maurizio Lombardi
2022-07-13 15:12 ` Alexander Duyck
2022-07-13 15:45 ` Andrew Morton [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20220713084536.1af461b016a16c58baad7db2@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=alexander.duyck@gmail.com \
--cc=chen45464546@163.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mlombard@redhat.com \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.