BPF List
 help / color / mirror / Atom feed
From: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
To: "Emil Tsalapatis" <emil@etsalapatis.com>, <bpf@vger.kernel.org>
Cc: <andrii@kernel.org>, <eddyz87@gmail.com>, <memxor@gmail.com>,
	<daniel@iogearbox.net>
Subject: Re: [PATCH bpf-next v3 5/6] bpf: Atomically update PTE and range tree in arena VM fault handler
Date: Wed, 23 Sep 2026 22:42:53 +0000	[thread overview]
Message-ID: <DLN24SAAXQ6F.2PI38BMR6WTRO@gmail.com> (raw)
In-Reply-To: <20260923191125.5311-6-emil@etsalapatis.com>

On Wed, Sep 23, 2026 at 07:11 PM Emil Tsalapatis <emil@etsalapatis.com> wrote:
> There is no way to protect the PTE installation and the range tree
> modification simultaneously, because we cannot nest the synchronization
> primitives for their respective critical sections. PTE allocation
> may require allocations due to PTE reclamation, and its spinlock
> becomes sleepable under PREEMPT_RT. Thus we cannot do this operation
> while holding the range tree spinlock. There is no public API for
> manually taking this spinlock, so we nest the range tree operation
> inside it.

__do_fault() locks the page returned by ->fault() before finish_fault()
installs the pte. That's how filemap_fault() is synchronized with
truncate.
can arena_vm_fault() lock the page, recheck vmalloc_to_page() and
return VM_FAULT_LOCKED, and the free path do
lock_page(); unlock_page(); before zap_pages() ?

[...]
>  out:
> -	page_ref_add(page, 1);
> +	/* Reserve the page while installing its user PTE without the arena lock. */
> +	bpf_map_memcg_enter(&arena->map, &old_memcg, &new_memcg);
> +	unavail_node = range_tree_set_unavail(&arena->rt, vmf->pgoff, 1);
> +	bpf_map_memcg_exit(old_memcg, new_memcg);
>  	raw_res_spin_unlock_irqrestore(&arena->spinlock, flags);
> -	if (new_page)
> +
> +	if (new_page) {
>  		free_pages_nolock(new_page, 0);
> -	vmf->page = page;
> -	return 0;
> +		new_page = NULL;
> +	}
> +
> +	/* If we couldn't mark the page unavailable, retry. */
> +	if (IS_ERR(unavail_node)) {
> +		ret = PTR_ERR(unavail_node);
> +		if (ret == -EAGAIN)
> +			goto retry;
> +		return VM_FAULT_SIGBUS;
> +	}

The race needs user space to access the page while bpf prog is
freeing it.
With this patch every user fault, including the one on a page that
bpf prog already allocated, does kmalloc_nolock() of a range node.
It cannot reclaim, so at memory.max the process gets SIGBUS on
a valid page. That's what commit c7cd8be3d72f fixed.
Two threads touching the same page for the first time: the 2nd one
gets -EAGAIN and spins in VM_FAULT_RETRY until the 1st is done.

  parent reply	other threads:[~2026-09-23 22:42 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 19:11 [PATCH bpf-next v3 0/6] bpf: Fix arena memory incoherence Emil Tsalapatis
2026-09-23 19:11 ` [PATCH bpf-next v3 1/6] bpf: Update is_range_tree_set to work for consecutive ranges Emil Tsalapatis
2026-09-23 19:11 ` [PATCH bpf-next v3 2/6] bpf: Track availability information for ranges in range tree Emil Tsalapatis
2026-09-23 19:11 ` [PATCH bpf-next v3 3/6] bpf: Fix arena race between page free and alloc leading to incoherency Emil Tsalapatis
2026-09-23 22:42   ` Alexei Starovoitov
2026-09-24 19:08     ` Emil Tsalapatis
2026-09-23 19:11 ` [PATCH bpf-next v3 4/6] bpf: Add explicit state machine for arena free spans Emil Tsalapatis
2026-09-23 19:11 ` [PATCH bpf-next v3 5/6] bpf: Atomically update PTE and range tree in arena VM fault handler Emil Tsalapatis
2026-09-23 19:28   ` sashiko-bot
2026-09-23 20:11   ` bot+bpf-ci
2026-09-23 22:42   ` Alexei Starovoitov [this message]
2026-09-23 19:11 ` [PATCH bpf-next v3 6/6] selftests/bpf: Add arena allocation race tests Emil Tsalapatis
2026-09-23 20:12   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DLN24SAAXQ6F.2PI38BMR6WTRO@gmail.com \
    --to=alexei.starovoitov@gmail.com \
    --cc=andrii@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=emil@etsalapatis.com \
    --cc=memxor@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox