Linux-mm Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Matthew Wilcox <willy@infradead.org>
To: Andrew Morton <akpm@linux-foundation.org>,
	Jane Chu <jane.chu@oracle.com>,
	linux-mm@kvack.org
Cc: Muchun Song <muchun.song@linux.dev>,
	Oscar Salvador <osalvador@suse.de>,
	David Hildenbrand <david@kernel.org>,
	Miaohe Lin <linmiaohe@huawei.com>,
	Naoya Horiguchi <nao.horiguchi@gmail.com>,
	Jan Kara <jack@suse.cz>,
	linux-fsdevel@vger.kernel.org,
	Christian Brauner <christian@brauner.io>,
	Jiaqi Yan <jiaqiyan@google.com>
Subject: Re: [PATCH v4 08/14] mm: Remove locking mf_mutex in is_raw_hwpoison_page_in_hugepage()
Date: Fri, 24 Jul 2026 14:41:17 +0100	[thread overview]
Message-ID: <amNrfc_FDfEdPaD6@casper.infradead.org> (raw)
In-Reply-To: <20260723143034.175661-9-willy@infradead.org>

Sashiko review:
> --- Patch [8]: [PATCH v4 08/14] mm: Remove locking mf_mutex in is_raw_hwpoison_page_in_hugepage() ---
> commit c0f68557b399585852271ea0bc6a590caa47b3ad
> Author: Matthew Wilcox (Oracle) <willy@infradead.org>
> 
> mm: Remove locking mf_mutex in is_raw_hwpoison_page_in_hugepage()
> 
> This commit removes the mf_mutex protection from the raw hwpoison list
> iteration in hugetlb_page_hwpoison(), relying on lockless llist traversal
> using READ_ONCE(). It also renames the function and modifies it to take a
> folio.
> 
> > diff --git a/mm/memory-failure.c b/mm/memory-failure.c
> > index 4200deab2c3c4..5076ee5d4788d 100644
> > --- a/mm/memory-failure.c
> > +++ b/mm/memory-failure.c
> [ ... ]
> > @@ -1817,37 +1817,30 @@ struct raw_hwp_page {
> >  	struct page *page;
> >  };
> >  
> > -bool is_raw_hwpoison_page_in_hugepage(struct page *page)
> > +/*
> > + * Check if a given @page in a hugetlb folio is HWPOISON.
> > + */
> > +bool hugetlb_page_hwpoison(const struct folio *folio, const struct page *page)
> >  {
> [ ... ]
> > -	mutex_lock(&mf_mutex);
> > -
> > -	llist_for_each_entry(p, folio->hugetlb_hwpoison.first, node) {
> > -		if (page == p->page) {
> > -			ret = true;
> > -			break;
> > -		}
> > +	llist_for_each_entry(p, READ_ONCE(list->first), node) {
> > +		if (page == p->page)
> > +			return true;
> >  	}
> 
> Is the assumption in the commit message that updates only add to the head of
> the list accurate?
> 
> Looking at __folio_free_raw_hwp() in mm/memory-failure.c, the entire list can
> be concurrently detached and its nodes freed via kfree() without an RCU grace
> period:
> 
>     head = llist_del_all(&folio->hugetlb_hwpoison);
>     llist_for_each_entry_safe(p, next, head, node) {
>         ...
>         kfree(p);
>     }
> 
> This freeing can happen while the folio is still in active use. For example,
> if a subsequent memory failure on the same folio fails a GFP_ATOMIC allocation
> in hugetlb_update_hwpoison():
> 
>     } else {
>         folio_set_hugetlb_raw_hwp_unreliable(folio);
>         __folio_free_raw_hwp(folio, false);
>     }
> 
> Since callers like hugetlbfs_read_iter() explicitly drop the folio lock before
> calling adjust_range_hwpoison() (which triggers this lockless traversal),
> could a concurrent memory failure free these list nodes while this loop is
> still accessing them, leading to a use-after-free?
> 
> > -	mutex_unlock(&mf_mutex);
> > -
> > -	return ret;
> > +	return false;
> >  }

argh.  I give up on this cleverness.  I'm going with the new spinlock
approach (like I did in v3) but retaining the per-folio list of pages
rather than having a global hash table.


  reply	other threads:[~2026-07-24 13:41 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23 14:30 [PATCH v4 00/14] Use generic_file_read_iter() in hugetlbfs Matthew Wilcox (Oracle)
2026-07-23 14:30 ` [PATCH v4 01/14] memory-failure: Fix hardware poison check in unpoison_memory() again Matthew Wilcox (Oracle)
2026-07-24 12:32   ` Matthew Wilcox
2026-07-23 14:30 ` [PATCH v4 02/14] memory-failure: Test the page is hwpoison before taking the mutex Matthew Wilcox (Oracle)
2026-07-24 12:34   ` Matthew Wilcox
2026-07-23 14:30 ` [PATCH v4 03/14] mm: Rename folio_contain_hwpoison_page() to folio_has_hwpoison_page() Matthew Wilcox (Oracle)
2026-07-24 12:36   ` Matthew Wilcox
2026-07-24 12:52   ` Michael S. Tsirkin
2026-07-24 13:24     ` Matthew Wilcox
2026-07-23 14:30 ` [PATCH v4 04/14] hugetlb: Mark some function arguments as const Matthew Wilcox (Oracle)
2026-07-24 12:38   ` Matthew Wilcox
2026-07-23 14:30 ` [PATCH v4 05/14] guest_memfd: Use folio_has_hwpoisoned_page() Matthew Wilcox (Oracle)
2026-07-24 12:44   ` Matthew Wilcox
2026-07-24 15:16     ` Sean Christopherson
2026-07-24 15:16   ` Sean Christopherson
2026-07-23 14:30 ` [PATCH v4 06/14] memory-failure: Remove raw_hwp_list_head() Matthew Wilcox (Oracle)
2026-07-24 12:45   ` Matthew Wilcox
2026-07-23 14:30 ` [PATCH v4 07/14] hugetlb: Use the has_hwpoisoned flag Matthew Wilcox (Oracle)
2026-07-24 13:21   ` Matthew Wilcox
2026-07-23 14:30 ` [PATCH v4 08/14] mm: Remove locking mf_mutex in is_raw_hwpoison_page_in_hugepage() Matthew Wilcox (Oracle)
2026-07-24 13:41   ` Matthew Wilcox [this message]
2026-07-23 14:30 ` [PATCH v4 09/14] mm: Check individual hugetlb pages for poison Matthew Wilcox (Oracle)
2026-07-24 14:00   ` Matthew Wilcox
2026-07-23 14:30 ` [PATCH v4 10/14] filemap: Add hwpoison handling to filemap_read() Matthew Wilcox (Oracle)
2026-07-23 14:30 ` [PATCH v4 11/14] filemap: Remove checks in mapping_set_folio_order_range() Matthew Wilcox (Oracle)
2026-07-23 14:30 ` [PATCH v4 12/14] hugetlb: Set mapping folio order Matthew Wilcox (Oracle)
2026-07-23 14:30 ` [PATCH v4 13/14] filemap: Add support for authoritative mappings Matthew Wilcox (Oracle)
2026-07-23 14:30 ` [PATCH v4 14/14] hugetlb: replace hugetlbfs_read_iter() with generic_file_read_iter() Matthew Wilcox (Oracle)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=amNrfc_FDfEdPaD6@casper.infradead.org \
    --to=willy@infradead.org \
    --cc=akpm@linux-foundation.org \
    --cc=christian@brauner.io \
    --cc=david@kernel.org \
    --cc=jack@suse.cz \
    --cc=jane.chu@oracle.com \
    --cc=jiaqiyan@google.com \
    --cc=linmiaohe@huawei.com \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=muchun.song@linux.dev \
    --cc=nao.horiguchi@gmail.com \
    --cc=osalvador@suse.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox