public inbox for kvm@vger.kernel.org
 help / color / mirror / Atom feed
From: Marcelo Tosatti <marcelo@kvack.org>
To: Avi Kivity <avi@qumranet.com>
Cc: Marcelo Tosatti <marcelo@kvack.org>,
	kvm-devel <kvm-devel@lists.sourceforge.net>
Subject: Re: [PATCH] virtio-balloon: do not attempt to release more	than available pages
Date: Wed, 5 Mar 2008 15:12:28 -0300	[thread overview]
Message-ID: <20080305181228.GA12152@dmt> (raw)
In-Reply-To: <47CED15E.4090504@qumranet.com>

On Wed, Mar 05, 2008 at 06:59:10PM +0200, Avi Kivity wrote:
> Marcelo Tosatti wrote:
> >Handle the case where the balloon target is larger than total ram size.
> >
> >BUG: unable to handle kernel paging request at 0000000000100100
> >IP: [<ffffffff881970f9>] :virtio_balloon:leak__balloon+0x2e/0xbe
> >
> >Signed-off-by: Marcelo Tosatti <mtosatti@redhat.com>
> >
> >Index: virtio/virtio_balloon.c
> >===================================================================
> >--- a/drivers/virtio/virtio_balloon.c
> >+++ b/drivers/virtio/virtio_balloon.c
> >@@ -122,10 +122,21 @@ static void release_pages_by_pfn(const u
> > 	}
> > }
> > 
> >+static void update_target_size(struct virtio_balloon *vb)
> >+{
> >+	__le32 num_pages = cpu_to_le32(vb->num_pages);
> >+
> >+	vb->vdev->config->set(vb->vdev,
> >+			      offsetof(struct virtio_balloon_config, 
> >num_pages),
> >+			      &num_pages, sizeof(num_pages));
> >+}
> >  
> 
> The target is host-owned; moreover the problem may be temporary, but 
> you've changed the target permanently.
> 
> Suggest sending the host a message (like the page list) indicating it 
> couldn't allocate any more.
> 
> Also, we may have driven the guest close to oom with this.  We need to 
> notify the host when the guest gets into a low-memory cannot swap condition.

I guess the description was not clear, you understood the opposite.

The problem is when the target for total guest pages (not balloon target
size) is set to be larger than the amount of total pages the guest has
booted with. What happens then is that the driver tries to release pages
from the balloon, without checking if there are any:

static void leak_balloon(struct virtio_balloon *vb, size_t num)
{
        struct page *page;

	/* We can only do one array worth at a time. */
	num = min(num, ARRAY_SIZE(vb->pfns));

        for (vb->num_pfns = 0; vb->num_pfns < num; vb->num_pfns++) {
                page = list_first_entry(&vb->pages, struct page, lru);
                list_del(&page->lru);
                vb->pfns[vb->num_pfns] = page_to_pfn(page);
                vb->num_pages--;
        }

vp->pages is empty here.

So the patch checks for the availability of ballooned pages before
attempting to release any, and sets num_pages to match that. 

The host should not allow that to condition to happen, but its still
fragile code in the guest driver.


-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/

  reply	other threads:[~2008-03-05 18:12 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-03-05 16:28 [PATCH] virtio-balloon: do not attempt to release more than available pages Marcelo Tosatti
2008-03-05 16:59 ` Avi Kivity
2008-03-05 18:12   ` Marcelo Tosatti [this message]
2008-03-05 18:13     ` Avi Kivity
2008-03-05 18:43     ` Anthony Liguori
2008-03-05 19:39       ` Marcelo Tosatti
2008-03-05 19:42         ` Anthony Liguori
2008-03-06  7:06           ` Avi Kivity
2008-03-05 18:42   ` Anthony Liguori
2008-03-05 22:39 ` Rusty Russell
2008-03-08 19:06   ` Marcelo Tosatti
2008-03-11  0:26     ` Rusty Russell
2008-03-11  0:52       ` Anthony Liguori
2008-03-11 11:54         ` Rusty Russell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20080305181228.GA12152@dmt \
    --to=marcelo@kvack.org \
    --cc=avi@qumranet.com \
    --cc=kvm-devel@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox