From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mathieu Desnoyers Subject: Re: [RFC PATCH for 4.21 03/16] mm: Replace BUG_ON() by WARN_ON() in vm_unmap_ram() Date: Thu, 1 Nov 2018 18:17:19 -0400 (EDT) Message-ID: <1770995215.4046.1541110639818.JavaMail.zimbra@efficios.com> References: <20181101095844.24462-1-mathieu.desnoyers@efficios.com> <20181101095844.24462-4-mathieu.desnoyers@efficios.com> <20181101144623.61d43102@gandalf.local.home> <278477314.3995.1541102273591.JavaMail.zimbra@efficios.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: Sender: linux-kernel-owner@vger.kernel.org To: Linus Torvalds Cc: rostedt , Thomas Gleixner , Peter Zijlstra , "Paul E. McKenney" , Boqun Feng , linux-kernel , linux-api , Andy Lutomirski , Dave Watson , Paul Turner , Andrew Morton , Russell King , Ingo Molnar , "H. Peter Anvin" , Andi Kleen , Chris Lameter , Ben Maurer , Josh Triplett , Catalin Marinas , Will Deacon , Michael Kerrisk List-Id: linux-api@vger.kernel.org ----- On Nov 1, 2018, at 11:00 PM, Linus Torvalds torvalds@linux-foundation.org wrote: > On Thu, Nov 1, 2018 at 12:57 PM Mathieu Desnoyers > wrote: >> >> > I think the graceful recovery is to simply return: >> > >> > if (WARN_ON(cond)) >> > return; >> > >> > is better than just >> > >> > BUG_ON(cond); >> > >> > As that's what Linus made pretty clear at the Maintainer's Summit. >> >> That's it. For an unmap function, this basically boils down to >> print a warning and leak the memory on internal unmap error. >> >> I will update the commit message describing this behavior. > > It might be even better to use WARN_ON_ONCE(). > > If it's a "this shouldn't happen" situation, the advantage of > WARN_ON_ONCE() is that it will still show the backtrace of the "how > the heck did it happen after all" situation, but if it turns ouit to > be user-triggerable (or simply triggerable by some odd hw situation), > it won't spam your logs forever. > > Obviously, things like rate limiting etc can also be good ideas, but > that's just overkill for "this really should never happen" cases. > > (Side note: WARN_ON_ONCE() will _warn_ just once, but will always > return the condition that it warns for, so the return value is _not_ > "I have warned", but "I have seen the condition that I should warn > about". Just in case people are worried about it). Allright, I'll update this patch (and the following one implementing vm_{map,unmap}_user_ram) to use WARN_ON_ONCE(). Thanks! Mathieu -- Mathieu Desnoyers EfficiOS Inc. http://www.efficios.com