All of lore.kernel.org
 help / color / mirror / Atom feed
* [LTP] [PATCH v2] hugetlb: add new testcase hugeshmat05.c
@ 2015-12-16  2:59 Li Wang
  2015-12-21  7:20 ` Alexey Kodanev
  0 siblings, 1 reply; 3+ messages in thread
From: Li Wang @ 2015-12-16  2:59 UTC (permalink / raw)
  To: ltp

shmget()/shmat() fails to allocate huge pages shared memory segment
with EINVAL if its size is not in the range [ N*HUGE_PAGE_SIZE - 4095,
N*HUGE_PAGE_SIZE ]. This is a problem in the memory segment size round
up algorithm. The requested size is rounded up to PAGE_SIZE (4096), but
if this roundup does not match HUGE_PAGE_SIZE (2Mb) boundary - the
allocation fails.

This bug is present in all RHEL6 versions, but not in RHEL7. It looks
like this was fixed in mainstream kernel > v3.3 by the following patches:

091d0d5 shm: fix null pointer deref when userspace specifies invalid hugepage size
af73e4d hugetlbfs: fix mmap failure in unaligned size request
42d7395 mm: support more pagesizes for MAP_HUGETLB/SHM_HUGETLB
40716e2 hugetlbfs: fix alignment of huge page requests

Signed-off-by: Li Wang <liwang@redhat.com>
---

Notes:
    v1 --> v2
    a.remove the key value from shmget()
    b.improve the brk messages
    c.just use one loop in the main function

 runtest/hugetlb                                    |   1 +
 testcases/kernel/mem/.gitignore                    |   1 +
 .../kernel/mem/hugetlb/hugeshmat/hugeshmat05.c     | 136 +++++++++++++++++++++
 3 files changed, 138 insertions(+)
 create mode 100644 testcases/kernel/mem/hugetlb/hugeshmat/hugeshmat05.c

diff --git a/runtest/hugetlb b/runtest/hugetlb
index 2e9f215..75e6426 100644
--- a/runtest/hugetlb
+++ b/runtest/hugetlb
@@ -10,6 +10,7 @@ hugeshmat01 hugeshmat01 -i 5
 hugeshmat02 hugeshmat02 -i 5
 hugeshmat03 hugeshmat03 -i 5
 hugeshmat04 hugeshmat04 -i 5
+hugeshmat05 hugeshmat05 -i 5
 
 hugeshmctl01 hugeshmctl01 -i 5
 hugeshmctl02 hugeshmctl02 -i 5
diff --git a/testcases/kernel/mem/.gitignore b/testcases/kernel/mem/.gitignore
index 4702377..46c2432 100644
--- a/testcases/kernel/mem/.gitignore
+++ b/testcases/kernel/mem/.gitignore
@@ -7,6 +7,7 @@
 /hugetlb/hugeshmat/hugeshmat02
 /hugetlb/hugeshmat/hugeshmat03
 /hugetlb/hugeshmat/hugeshmat04
+/hugetlb/hugeshmat/hugeshmat05
 /hugetlb/hugeshmctl/hugeshmctl01
 /hugetlb/hugeshmctl/hugeshmctl02
 /hugetlb/hugeshmctl/hugeshmctl03
diff --git a/testcases/kernel/mem/hugetlb/hugeshmat/hugeshmat05.c b/testcases/kernel/mem/hugetlb/hugeshmat/hugeshmat05.c
new file mode 100644
index 0000000..10cadea
--- /dev/null
+++ b/testcases/kernel/mem/hugetlb/hugeshmat/hugeshmat05.c
@@ -0,0 +1,136 @@
+/*
+ * Copyright (c) 2015 Red Hat, Inc.
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License
+ * along with this program.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+/*
+ * DESCRIPTION
+ *	shmget()/shmat() fails to allocate huge pages shared memory segment
+ *	with EINVAL if its size is not in the range [ N*HUGE_PAGE_SIZE - 4095,
+ *	N*HUGE_PAGE_SIZE ]. This is a problem in the memory segment size round
+ *	up algorithm. The requested size is rounded up to PAGE_SIZE (4096), but
+ *	if this roundup does not match HUGE_PAGE_SIZE (2Mb) boundary - the
+ *	allocation fails.
+ *
+ *	This bug is present in all RHEL6 versions, but not in RHEL7. It looks
+ *	like this was fixed in mainstream kernel > v3.3 by the following patches:
+ *
+ *	091d0d5 (shm: fix null pointer deref when userspace specifies invalid hugepage size)
+ *	af73e4d (hugetlbfs: fix mmap failure in unaligned size request)
+ *	42d7395 (mm: support more pagesizes for MAP_HUGETLB/SHM_HUGETLB)
+ *	40716e2 (hugetlbfs: fix alignment of huge page requests)
+ *
+ * AUTHORS
+ *	Vladislav Dronov <vdronov@redhat.com>
+ *	Li Wang <liwang@redhat.com>
+ *
+ */
+
+#include <stdlib.h>
+#include <stdio.h>
+#include <sys/types.h>
+#include <sys/ipc.h>
+#include <sys/shm.h>
+#include <sys/mman.h>
+#include <fcntl.h>
+
+#include "test.h"
+#include "mem.h"
+#include "hugetlb.h"
+
+char *TCID = "hugeshmat05";
+int TST_TOTAL = 1;
+
+static long page_size;
+static long hpage_size;
+static long hugepages;
+
+#define N 4
+
+void setup(void)
+{
+	tst_require_root();
+	check_hugepage();
+
+	orig_hugepages = get_sys_tune("nr_hugepages");
+	page_size = getpagesize();
+	hpage_size = read_meminfo("Hugepagesize:") * 1024;
+
+	hugepages = N + 1;
+	set_sys_tune("nr_hugepages", hugepages, 1);
+
+	TEST_PAUSE;
+}
+
+void cleanup(void)
+{
+	set_sys_tune("nr_hugepages", orig_hugepages, 0);
+}
+
+void shm_test(int size)
+{
+	int shmid;
+	char *shmaddr;
+
+	shmid = shmget(IPC_PRIVATE, size, 0600 | IPC_CREAT | SHM_HUGETLB);
+	if (shmid < 0)
+		tst_brkm(TBROK | TERRNO, cleanup, "shmget failed");
+
+	shmaddr = shmat(shmid, 0, 0);
+	if (shmaddr == (char *)-1) {
+		shmctl(shmid, IPC_RMID, NULL);
+		tst_brkm(TFAIL | TERRNO, cleanup, "Bug: shared memory attach failure.");
+	}
+
+	shmaddr[0] = 1;
+	tst_resm(TINFO, "allocated %d huge bytes", size);
+
+	if (shmdt((const void *)shmaddr) != 0) {
+		shmctl(shmid, IPC_RMID, NULL);
+		tst_brkm(TFAIL | TERRNO, cleanup, "Detach failure.");
+	}
+
+	shmctl(shmid, IPC_RMID, NULL);
+}
+
+int main(int ac, char **av)
+{
+	int lc;
+
+	tst_parse_opts(ac, av, NULL, NULL);
+
+	setup();
+
+	for (lc = 0; TEST_LOOPING(lc); lc++) {
+		tst_count = 0;
+
+		/* N*hpage_size - page_size FAIL */
+		shm_test(N * hpage_size - page_size);
+
+		/* N*hpage_size - page_size - 1 SUCCESS*/
+		shm_test(N * hpage_size - page_size - 1);
+
+		/* N*hpage_size  SUCCESS */
+		shm_test(N * hpage_size);
+
+		/* N*hpage_size + 1 FAIL */
+		shm_test(N * hpage_size + 1);
+
+		tst_resm(TPASS, "No regression found.");
+	}
+
+	cleanup();
+	tst_exit();
+}
-- 
1.8.3.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [LTP] [PATCH v2] hugetlb: add new testcase hugeshmat05.c
  2015-12-16  2:59 [LTP] [PATCH v2] hugetlb: add new testcase hugeshmat05.c Li Wang
@ 2015-12-21  7:20 ` Alexey Kodanev
  2015-12-21  9:35   ` Li Wang
  0 siblings, 1 reply; 3+ messages in thread
From: Alexey Kodanev @ 2015-12-21  7:20 UTC (permalink / raw)
  To: ltp

Hi,
On 12/16/2015 05:59 AM, Li Wang wrote:
> shmget()/shmat() fails to allocate huge pages shared memory segment
> with EINVAL if its size is not in the range [ N*HUGE_PAGE_SIZE - 4095,
> N*HUGE_PAGE_SIZE ]. This is a problem in the memory segment size round
> up algorithm. The requested size is rounded up to PAGE_SIZE (4096), but
> if this roundup does not match HUGE_PAGE_SIZE (2Mb) boundary - the
> allocation fails.
>
> This bug is present in all RHEL6 versions, but not in RHEL7. It looks
> like this was fixed in mainstream kernel > v3.3 by the following patches:
>
> 091d0d5 shm: fix null pointer deref when userspace specifies invalid hugepage size
> af73e4d hugetlbfs: fix mmap failure in unaligned size request
> 42d7395 mm: support more pagesizes for MAP_HUGETLB/SHM_HUGETLB
> 40716e2 hugetlbfs: fix alignment of huge page requests
>
> Signed-off-by: Li Wang <liwang@redhat.com>
> ---
>
> Notes:
>      v1 --> v2
>      a.remove the key value from shmget()
>      b.improve the brk messages
>      c.just use one loop in the main function
>
>   runtest/hugetlb                                    |   1 +
>   testcases/kernel/mem/.gitignore                    |   1 +
>   .../kernel/mem/hugetlb/hugeshmat/hugeshmat05.c     | 136 +++++++++++++++++++++
>   3 files changed, 138 insertions(+)
>   create mode 100644 testcases/kernel/mem/hugetlb/hugeshmat/hugeshmat05.c
>
> diff --git a/runtest/hugetlb b/runtest/hugetlb
> index 2e9f215..75e6426 100644
> --- a/runtest/hugetlb
> +++ b/runtest/hugetlb
> @@ -10,6 +10,7 @@ hugeshmat01 hugeshmat01 -i 5
>   hugeshmat02 hugeshmat02 -i 5
>   hugeshmat03 hugeshmat03 -i 5
>   hugeshmat04 hugeshmat04 -i 5
> +hugeshmat05 hugeshmat05 -i 5

Did you forget to increase iterations here or it is not needed anymore?
In the first patch, if I am not mistaken, was 15 (because of two loops).

>   
>   hugeshmctl01 hugeshmctl01 -i 5
>   hugeshmctl02 hugeshmctl02 -i 5
...
> +
> +int main(int ac, char **av)
> +{
> +	int lc;
> +
> +	tst_parse_opts(ac, av, NULL, NULL);
> +
> +	setup();
> +
> +	for (lc = 0; TEST_LOOPING(lc); lc++) {
> +		tst_count = 0;
> +
> +		/* N*hpage_size - page_size FAIL */
> +		shm_test(N * hpage_size - page_size);
> +
> +		/* N*hpage_size - page_size - 1 SUCCESS*/
> +		shm_test(N * hpage_size - page_size - 1);
> +
> +		/* N*hpage_size  SUCCESS */
> +		shm_test(N * hpage_size);
> +
> +		/* N*hpage_size + 1 FAIL */

Could you please add more informative comments (may be explaining why it 
is "FAIL"/"SUCCESS")
or remove them completely, they just repeat what is passed to the function.

We could also set sizes in array, defining it before the "for":

const int tst_sizes[] = { N * hpage_size - page_size,
                                             N * hpage_size, ... };

for (lc ...) {
     tst_count = 0;
     for(i = 0; i < ARRAY_SIZE(tst_sizes); ++i)
         shm_test(tst_sizes[i]);
}


Best regards,
Alexey
> +		shm_test(N * hpage_size + 1);
> +
> +		tst_resm(TPASS, "No regression found.");
> +	}
> +
> +	cleanup();
> +	tst_exit();
> +}


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [LTP] [PATCH v2] hugetlb: add new testcase hugeshmat05.c
  2015-12-21  7:20 ` Alexey Kodanev
@ 2015-12-21  9:35   ` Li Wang
  0 siblings, 0 replies; 3+ messages in thread
From: Li Wang @ 2015-12-21  9:35 UTC (permalink / raw)
  To: ltp

Hi,

On Mon, Dec 21, 2015 at 3:20 PM, Alexey Kodanev <alexey.kodanev@oracle.com>
wrote:

> Hi,
>
> On 12/16/2015 05:59 AM, Li Wang wrote:
>
>> shmget()/shmat() fails to allocate huge pages shared memory segment
>> with EINVAL if its size is not in the range [ N*HUGE_PAGE_SIZE - 4095,
>> N*HUGE_PAGE_SIZE ]. This is a problem in the memory segment size round
>> up algorithm. The requested size is rounded up to PAGE_SIZE (4096), but
>> if this roundup does not match HUGE_PAGE_SIZE (2Mb) boundary - the
>> allocation fails.
>>
>> This bug is present in all RHEL6 versions, but not in RHEL7. It looks
>> like this was fixed in mainstream kernel > v3.3 by the following patches:
>>
>> 091d0d5 shm: fix null pointer deref when userspace specifies invalid
>> hugepage size
>> af73e4d hugetlbfs: fix mmap failure in unaligned size request
>> 42d7395 mm: support more pagesizes for MAP_HUGETLB/SHM_HUGETLB
>> 40716e2 hugetlbfs: fix alignment of huge page requests
>>
>> Signed-off-by: Li Wang <liwang@redhat.com>
>> ---
>>
>> Notes:
>>      v1 --> v2
>>      a.remove the key value from shmget()
>>      b.improve the brk messages
>>      c.just use one loop in the main function
>>
>>   runtest/hugetlb                                    |   1 +
>>   testcases/kernel/mem/.gitignore                    |   1 +
>>   .../kernel/mem/hugetlb/hugeshmat/hugeshmat05.c     | 136
>> +++++++++++++++++++++
>>   3 files changed, 138 insertions(+)
>>   create mode 100644 testcases/kernel/mem/hugetlb/hugeshmat/hugeshmat05.c
>>
>> diff --git a/runtest/hugetlb b/runtest/hugetlb
>> index 2e9f215..75e6426 100644
>> --- a/runtest/hugetlb
>> +++ b/runtest/hugetlb
>> @@ -10,6 +10,7 @@ hugeshmat01 hugeshmat01 -i 5
>>   hugeshmat02 hugeshmat02 -i 5
>>   hugeshmat03 hugeshmat03 -i 5
>>   hugeshmat04 hugeshmat04 -i 5
>> +hugeshmat05 hugeshmat05 -i 5
>>
>
> Did you forget to increase iterations here or it is not needed anymore?
> In the first patch, if I am not mistaken, was 15 (because of two loops).
>

it is no needed, 5 loops is enough i think. :)


>
>     hugeshmctl01 hugeshmctl01 -i 5
>>   hugeshmctl02 hugeshmctl02 -i 5
>>
> ...
>
>> +
>> +int main(int ac, char **av)
>> +{
>> +       int lc;
>> +
>> +       tst_parse_opts(ac, av, NULL, NULL);
>> +
>> +       setup();
>> +
>> +       for (lc = 0; TEST_LOOPING(lc); lc++) {
>> +               tst_count = 0;
>> +
>> +               /* N*hpage_size - page_size FAIL */
>> +               shm_test(N * hpage_size - page_size);
>> +
>> +               /* N*hpage_size - page_size - 1 SUCCESS*/
>> +               shm_test(N * hpage_size - page_size - 1);
>> +
>> +               /* N*hpage_size  SUCCESS */
>> +               shm_test(N * hpage_size);
>> +
>> +               /* N*hpage_size + 1 FAIL */
>>
>
> Could you please add more informative comments (may be explaining why it
> is "FAIL"/"SUCCESS")
> or remove them completely, they just repeat what is passed to the function.
>
> We could also set sizes in array, defining it before the "for":
>

ok, I tend to accept the second suggestion. because it looks like more
neatly than before.


>
> const int tst_sizes[] = { N * hpage_size - page_size,
>                                             N * hpage_size, ... };
>
> for (lc ...) {
>     tst_count = 0;
>     for(i = 0; i < ARRAY_SIZE(tst_sizes); ++i)
>         shm_test(tst_sizes[i]);
> }
>
>
> Best regards,
> Alexey
>
>
thanks a lot! If there is no other comments, I'd like to sent patch v3 this
evening.


-- 
Regards,
Li Wang
Email: liwang@redhat.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linux.it/pipermail/ltp/attachments/20151221/90d14354/attachment-0001.html>

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-12-21  9:35 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-12-16  2:59 [LTP] [PATCH v2] hugetlb: add new testcase hugeshmat05.c Li Wang
2015-12-21  7:20 ` Alexey Kodanev
2015-12-21  9:35   ` Li Wang

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.