From: "Liam R. Howlett" <Liam.Howlett@oracle.com>
To: Andrew Morton <akpm@linux-foundation.org>
Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org,
Suren Baghdasaryan <surenb@google.com>,
Lorenzo Stoakes <lorenzo.stoakes@oracle.com>,
Matthew Wilcox <willy@infradead.org>,
Vlastimil Babka <vbabka@suse.cz>,
sidhartha.kumar@oracle.com, Bert Karwatzki <spasswolf@web.de>,
Jiri Olsa <olsajiri@gmail.com>, Kees Cook <kees@kernel.org>,
"Paul E . McKenney" <paulmck@kernel.org>,
"Liam R. Howlett" <Liam.Howlett@Oracle.com>
Subject: [PATCH v7 19/21] mm: Move may_expand_vm() check in mmap_region()
Date: Thu, 22 Aug 2024 15:25:41 -0400 [thread overview]
Message-ID: <20240822192543.3359552-20-Liam.Howlett@oracle.com> (raw)
In-Reply-To: <20240822192543.3359552-1-Liam.Howlett@oracle.com>
From: "Liam R. Howlett" <Liam.Howlett@Oracle.com>
The may_expand_vm() check requires the count of the pages within the
munmap range. Since this is needed for accounting and obtained later,
the reodering of ma_expand_vm() to later in the call stack, after the
vma munmap struct (vms) is initialised and the gather stage is
potentially run, will allow for a single loop over the vmas. The gather
sage does not commit any work and so everything can be undone in the
case of a failure.
The MAP_FIXED page count is available after the vms_gather_munmap_vmas()
call, so use it instead of looping over the vmas twice.
Signed-off-by: Liam R. Howlett <Liam.Howlett@Oracle.com>
Reviewed-by: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
---
mm/mmap.c | 15 ++++-----------
mm/vma.c | 21 ---------------------
mm/vma.h | 3 ---
3 files changed, 4 insertions(+), 35 deletions(-)
diff --git a/mm/mmap.c b/mm/mmap.c
index 51ab0bdb856c..5937607f6949 100644
--- a/mm/mmap.c
+++ b/mm/mmap.c
@@ -1376,17 +1376,6 @@ unsigned long mmap_region(struct file *file, unsigned long addr,
pgoff_t vm_pgoff;
int error = -ENOMEM;
VMA_ITERATOR(vmi, mm, addr);
- unsigned long nr_pages, nr_accounted;
-
- nr_pages = count_vma_pages_range(mm, addr, end, &nr_accounted);
-
- /*
- * Check against address space limit.
- * MAP_FIXED may remove pages of mappings that intersects with requested
- * mapping. Account for the pages it would unmap.
- */
- if (!may_expand_vm(mm, vm_flags, pglen - nr_pages))
- return -ENOMEM;
/* Find the first overlapping VMA */
vma = vma_find(&vmi, end);
@@ -1409,6 +1398,10 @@ unsigned long mmap_region(struct file *file, unsigned long addr,
vma_iter_next_range(&vmi);
}
+ /* Check against address space limit. */
+ if (!may_expand_vm(mm, vm_flags, pglen - vms.nr_pages))
+ goto abort_munmap;
+
/*
* Private writable mapping: check memory availability
*/
diff --git a/mm/vma.c b/mm/vma.c
index 91b027eb9a38..61d51677eaaf 100644
--- a/mm/vma.c
+++ b/mm/vma.c
@@ -1645,27 +1645,6 @@ bool vma_wants_writenotify(struct vm_area_struct *vma, pgprot_t vm_page_prot)
return vma_fs_can_writeback(vma);
}
-unsigned long count_vma_pages_range(struct mm_struct *mm,
- unsigned long addr, unsigned long end,
- unsigned long *nr_accounted)
-{
- VMA_ITERATOR(vmi, mm, addr);
- struct vm_area_struct *vma;
- unsigned long nr_pages = 0;
-
- *nr_accounted = 0;
- for_each_vma_range(vmi, vma, end) {
- unsigned long vm_start = max(addr, vma->vm_start);
- unsigned long vm_end = min(end, vma->vm_end);
-
- nr_pages += PHYS_PFN(vm_end - vm_start);
- if (vma->vm_flags & VM_ACCOUNT)
- *nr_accounted += PHYS_PFN(vm_end - vm_start);
- }
-
- return nr_pages;
-}
-
static DEFINE_MUTEX(mm_all_locks_mutex);
static void vm_lock_anon_vma(struct mm_struct *mm, struct anon_vma *anon_vma)
diff --git a/mm/vma.h b/mm/vma.h
index 8ca32d7cb846..7047fedce459 100644
--- a/mm/vma.h
+++ b/mm/vma.h
@@ -315,9 +315,6 @@ bool vma_wants_writenotify(struct vm_area_struct *vma, pgprot_t vm_page_prot);
int mm_take_all_locks(struct mm_struct *mm);
void mm_drop_all_locks(struct mm_struct *mm);
-unsigned long count_vma_pages_range(struct mm_struct *mm,
- unsigned long addr, unsigned long end,
- unsigned long *nr_accounted);
static inline bool vma_wants_manual_pte_write_upgrade(struct vm_area_struct *vma)
{
--
2.43.0
next prev parent reply other threads:[~2024-08-22 19:27 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-08-22 19:25 [PATCH v7 00/21] Avoid MAP_FIXED gap exposure Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 01/21] mm/vma: Correctly position vma_iterator in __split_vma() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 02/21] mm/vma: Introduce abort_munmap_vmas() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 03/21] mm/vma: Introduce vmi_complete_munmap_vmas() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 04/21] mm/vma: Extract the gathering of vmas from do_vmi_align_munmap() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 05/21] mm/vma: Introduce vma_munmap_struct for use in munmap operations Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 06/21] mm/vma: Change munmap to use vma_munmap_struct() for accounting and surrounding vmas Liam R. Howlett
2024-08-23 8:43 ` Bert Karwatzki
2024-08-23 9:55 ` Lorenzo Stoakes
2024-08-23 10:42 ` Bert Karwatzki
2024-08-23 11:39 ` Lorenzo Stoakes
2024-08-23 11:37 ` Lorenzo Stoakes
2024-08-23 13:30 ` [PATCH] mm/vma: fix bookkeeping checks Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 07/21] mm/vma: Extract validate_mm() from vma_complete() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 08/21] mm/vma: Inline munmap operation in mmap_region() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 09/21] mm/vma: Expand mmap_region() munmap call Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 10/21] mm/vma: Support vma == NULL in init_vma_munmap() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 11/21] mm/mmap: Reposition vma iterator in mmap_region() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 12/21] mm/vma: Track start and end for munmap in vma_munmap_struct Liam R. Howlett
2024-08-26 14:01 ` Geert Uytterhoeven
2024-08-26 14:12 ` Lorenzo Stoakes
2024-08-22 19:25 ` [PATCH v7 13/21] mm: Clean up unmap_region() argument list Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 14/21] mm/mmap: Avoid zeroing vma tree in mmap_region() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 15/21] mm: Change failure of MAP_FIXED to restoring the gap on failure Liam R. Howlett
2024-08-27 17:15 ` [PATCH] mm/vma: Fix null pointer dereference in vms_abort_munmap_vmas() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 16/21] mm/mmap: Use PHYS_PFN in mmap_region() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 17/21] mm/mmap: Use vms accounted pages " Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 18/21] ipc/shm, mm: Drop do_vma_munmap() Liam R. Howlett
2024-08-22 19:25 ` Liam R. Howlett [this message]
2024-08-22 19:25 ` [PATCH v7 20/21] mm/vma: Drop incorrect comment from vms_gather_munmap_vmas() Liam R. Howlett
2024-08-22 19:25 ` [PATCH v7 21/21] mm/vma.h: Optimise vma_munmap_struct Liam R. Howlett
2024-08-22 19:41 ` Lorenzo Stoakes
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240822192543.3359552-20-Liam.Howlett@oracle.com \
--to=liam.howlett@oracle.com \
--cc=akpm@linux-foundation.org \
--cc=kees@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=lorenzo.stoakes@oracle.com \
--cc=olsajiri@gmail.com \
--cc=paulmck@kernel.org \
--cc=sidhartha.kumar@oracle.com \
--cc=spasswolf@web.de \
--cc=surenb@google.com \
--cc=vbabka@suse.cz \
--cc=willy@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.