diff for duplicates of <20260923140650.177967426@linuxfoundation.org> diff --git a/a/1.txt b/N1/1.txt index 81e65f1..e8a4027 100644 --- a/a/1.txt +++ b/N1/1.txt @@ -1,47 +1,84 @@ -7.2-stable review patch. If anyone has any objections, please let me know. +6.18-stable review patch. If anyone has any objections, please let me know. ------------------ -From: Farhad Alemi <farhad.alemi@berkeley.edu> - -[ Upstream commit 150dba2c69e93302af24a0c868eebe4871e2e107 ] - -ipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the -route to the tunnel's remote endpoint and set ctx->dev to its device, -which is the tunnel itself when that route resolves back to the tunnel. -dev_fill_forward_path() then makes no progress and trips -WARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to -offload a flow through the tunnel. That routing loop is a configuration -any CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and -ip6_tnl_xmit() already treat it as a tx error, so remove the warning and -just fail the walk, as commit 008e7a7c293b ("net: remove WARN_ON_ONCE -when accessing forward path array") did for the path stack overflow. - -Fixes: ab427db17885 ("netfilter: flowtable: Add IPIP rx sw acceleration") -Fixes: d98103575dcd ("netfilter: flowtable: Add IP6IP6 rx sw acceleration") -Closes: https://lore.kernel.org/all/CA+0ovCgaRvbd0Udj70b2xxG8Cx3CaCpNhnf1V4RWQuDveZYZhA@mail.gmail.com/ -Suggested-by: Pablo Neira Ayuso <pablo@netfilter.org> -Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu> -Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn> -Link: https://patch.msgid.link/CA+0ovCgKDOk+Bg6Gh5Lwx94u_jJjQ30-vY1JcY2BYfhnWJJbPA@mail.gmail.com -Signed-off-by: Jakub Kicinski <kuba@kernel.org> -Signed-off-by: Sasha Levin <sashal@kernel.org> +From: Lorenzo Stoakes (ARM) <ljs@kernel.org> + +commit 397432cab17bccb600fd6c16ed593f1149042268 upstream. + +When a VMA is mremap()'d with MREMAP_DONTUNMAP set, that results in the +VMA being copied, but the source VMA not being unmapped. + +If the VMA is mlock()'d this is a legal operation, though the source VMA +has its VMA_LOCKED_BIT cleared. + +However this is done in dontunmap_complete(), after mm->locked_vm was +incremented via vrm_stat_account(), resulting in double-counting. + +Worse, this is not even corrected when source VMA is unmapped, due to the +VMA_LOCKED_BIT flag having been cleared. + +This all works fine in the usual mremap() case (without MREMAP_DONTUNMAP), +as the source VMA is unmapped with VMA_LOCKED_BIT intact, at which time +mm->locked_vm is decremented accordingly. + +Resolve the issue by invoking vrm_stat_account() only after +dontunmap_complete() has run. + +Note that MREMAP_DONTUNMAP requires old_len == new_len, so no need to +account for a delta in size in this case. + +The bug was introduced by commit b714ccb02a76 ("mm/mremap: complete +refactor of move_vma()") which incorrectly reordered the accounting and +the clearing of the VMA_LOCKED_BIT flag. + +Link: https://lore.kernel.org/20260828-mremap-fix-locked-vm-v1-1-c80be7505d1e@kernel.org +Fixes: b714ccb02a76 ("mm/mremap: complete refactor of move_vma()") +Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org> +Reported-by: sashiko-bot <sashiko-bot@kernel.org> +Closes: https://sashiko.dev/#/patchset/20260825-fix-mremap-dontunmap-pgoff-v1-1-39a40b2c98b3@kernel.org +Reported-by: Kunwu Chan <kunwu.chan@gmail.com> +Closes: https://lore.kernel.org/all/20260828094823.594279-1-kunwu.chan@linux.dev/ +Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org> +Tested-by: Kunwu Chan <kunwu.chan@gmail.com> +Reviewed-by: Kunwu Chan <kunwu.chan@gmail.com> +Cc: Jann Horn <jannh@google.com> +Cc: Liam R. Howlett <liam@infradead.org> +Cc: Pedro Falcato <pfalcato@suse.de> +Cc: <stable@vger.kernel.org> +Signed-off-by: Andrew Morton <akpm@linux-foundation.org> +Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- - net/core/dev.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/net/core/dev.c b/net/core/dev.c -index 679e75d3699ae..ff25e4c71588e 100644 ---- a/net/core/dev.c -+++ b/net/core/dev.c -@@ -789,7 +789,7 @@ int dev_fill_forward_path(struct net_device_path_ctx *ctx, - goto err_out; - - stack->num_paths++; -- if (WARN_ON_ONCE(last_dev == ctx->dev)) -+ if (last_dev == ctx->dev) - goto err_out; + mm/mremap.c | 9 ++++----- + 1 file changed, 4 insertions(+), 5 deletions(-) + +--- a/mm/mremap.c ++++ b/mm/mremap.c +@@ -1270,12 +1270,11 @@ static void dontunmap_complete(struct vm + if (vma_is_anonymous(vma) && !vma->vm_file) + vma->vm_pgoff = pgoff_unfaulted; } +- +- /* Because we won't unmap we don't need to touch locked_vm. */ + } + + static unsigned long move_vma(struct vma_remap_struct *vrm) + { ++ const bool is_dontunmap = vrm->flags & MREMAP_DONTUNMAP; + struct mm_struct *mm = current->mm; + struct vm_area_struct *new_vma; + unsigned long hiwater_vm; +@@ -1316,10 +1315,10 @@ static unsigned long move_vma(struct vma + */ + hiwater_vm = mm->hiwater_vm; + +- vrm_stat_account(vrm, vrm->new_len); +- if (unlikely(!err && (vrm->flags & MREMAP_DONTUNMAP))) ++ if (unlikely(is_dontunmap && !err)) + dontunmap_complete(vrm, new_vma); +- else ++ vrm_stat_account(vrm, vrm->new_len); ++ if (!is_dontunmap || err) + unmap_source_vma(vrm); --- -2.53.0 + mm->hiwater_vm = hiwater_vm; diff --git a/a/content_digest b/N1/content_digest index bd80dcf..84cc926 100644 --- a/a/content_digest +++ b/N1/content_digest @@ -1,63 +1,103 @@ - "ref\020260923140644.756254324@linuxfoundation.org\0" + "ref\020260923140643.441954610@linuxfoundation.org\0" "From\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>\0" - "Subject\0[PATCH 7.2 209/438] net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check\0" - "Date\0Wed, 23 Sep 2026 16:03:50 +0200\0" + "Subject\0[PATCH 6.18 261/398] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP\0" + "Date\0Wed, 23 Sep 2026 16:05:35 +0200\0" "To\0stable@vger.kernel.org\0" "Cc\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>" patches@lists.linux.dev - Pablo Neira Ayuso <pablo@netfilter.org> - Farhad Alemi <farhad.alemi@berkeley.edu> - Xuanqiang Luo <luoxuanqiang@kylinos.cn> - Jakub Kicinski <kuba@kernel.org> - " Sasha Levin <sashal@kernel.org>\0" + Lorenzo Stoakes (ARM) <ljs@kernel.org> + sashiko-bot <sashiko-bot@kernel.org> + Kunwu Chan <kunwu.chan@gmail.com> + Vlastimil Babka (SUSE) <vbabka@kernel.org> + Jann Horn <jannh@google.com> + Liam R. Howlett <liam@infradead.org> + Pedro Falcato <pfalcato@suse.de> + " Andrew Morton <akpm@linux-foundation.org>\0" "\00:1\0" "b\0" - "7.2-stable review patch. If anyone has any objections, please let me know.\n" + "6.18-stable review patch. If anyone has any objections, please let me know.\n" "\n" "------------------\n" "\n" - "From: Farhad Alemi <farhad.alemi@berkeley.edu>\n" - "\n" - "[ Upstream commit 150dba2c69e93302af24a0c868eebe4871e2e107 ]\n" - "\n" - "ipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the\n" - "route to the tunnel's remote endpoint and set ctx->dev to its device,\n" - "which is the tunnel itself when that route resolves back to the tunnel.\n" - "dev_fill_forward_path() then makes no progress and trips\n" - "WARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to\n" - "offload a flow through the tunnel. That routing loop is a configuration\n" - "any CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and\n" - "ip6_tnl_xmit() already treat it as a tx error, so remove the warning and\n" - "just fail the walk, as commit 008e7a7c293b (\"net: remove WARN_ON_ONCE\n" - "when accessing forward path array\") did for the path stack overflow.\n" - "\n" - "Fixes: ab427db17885 (\"netfilter: flowtable: Add IPIP rx sw acceleration\")\n" - "Fixes: d98103575dcd (\"netfilter: flowtable: Add IP6IP6 rx sw acceleration\")\n" - "Closes: https://lore.kernel.org/all/CA+0ovCgaRvbd0Udj70b2xxG8Cx3CaCpNhnf1V4RWQuDveZYZhA@mail.gmail.com/\n" - "Suggested-by: Pablo Neira Ayuso <pablo@netfilter.org>\n" - "Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu>\n" - "Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>\n" - "Link: https://patch.msgid.link/CA+0ovCgKDOk+Bg6Gh5Lwx94u_jJjQ30-vY1JcY2BYfhnWJJbPA@mail.gmail.com\n" - "Signed-off-by: Jakub Kicinski <kuba@kernel.org>\n" - "Signed-off-by: Sasha Levin <sashal@kernel.org>\n" + "From: Lorenzo Stoakes (ARM) <ljs@kernel.org>\n" + "\n" + "commit 397432cab17bccb600fd6c16ed593f1149042268 upstream.\n" + "\n" + "When a VMA is mremap()'d with MREMAP_DONTUNMAP set, that results in the\n" + "VMA being copied, but the source VMA not being unmapped.\n" + "\n" + "If the VMA is mlock()'d this is a legal operation, though the source VMA\n" + "has its VMA_LOCKED_BIT cleared.\n" + "\n" + "However this is done in dontunmap_complete(), after mm->locked_vm was\n" + "incremented via vrm_stat_account(), resulting in double-counting.\n" + "\n" + "Worse, this is not even corrected when source VMA is unmapped, due to the\n" + "VMA_LOCKED_BIT flag having been cleared.\n" + "\n" + "This all works fine in the usual mremap() case (without MREMAP_DONTUNMAP),\n" + "as the source VMA is unmapped with VMA_LOCKED_BIT intact, at which time\n" + "mm->locked_vm is decremented accordingly.\n" + "\n" + "Resolve the issue by invoking vrm_stat_account() only after\n" + "dontunmap_complete() has run.\n" + "\n" + "Note that MREMAP_DONTUNMAP requires old_len == new_len, so no need to\n" + "account for a delta in size in this case.\n" + "\n" + "The bug was introduced by commit b714ccb02a76 (\"mm/mremap: complete\n" + "refactor of move_vma()\") which incorrectly reordered the accounting and\n" + "the clearing of the VMA_LOCKED_BIT flag.\n" + "\n" + "Link: https://lore.kernel.org/20260828-mremap-fix-locked-vm-v1-1-c80be7505d1e@kernel.org\n" + "Fixes: b714ccb02a76 (\"mm/mremap: complete refactor of move_vma()\")\n" + "Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>\n" + "Reported-by: sashiko-bot <sashiko-bot@kernel.org>\n" + "Closes: https://sashiko.dev/#/patchset/20260825-fix-mremap-dontunmap-pgoff-v1-1-39a40b2c98b3@kernel.org\n" + "Reported-by: Kunwu Chan <kunwu.chan@gmail.com>\n" + "Closes: https://lore.kernel.org/all/20260828094823.594279-1-kunwu.chan@linux.dev/\n" + "Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>\n" + "Tested-by: Kunwu Chan <kunwu.chan@gmail.com>\n" + "Reviewed-by: Kunwu Chan <kunwu.chan@gmail.com>\n" + "Cc: Jann Horn <jannh@google.com>\n" + "Cc: Liam R. Howlett <liam@infradead.org>\n" + "Cc: Pedro Falcato <pfalcato@suse.de>\n" + "Cc: <stable@vger.kernel.org>\n" + "Signed-off-by: Andrew Morton <akpm@linux-foundation.org>\n" + "Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>\n" "---\n" - " net/core/dev.c | 2 +-\n" - " 1 file changed, 1 insertion(+), 1 deletion(-)\n" - "\n" - "diff --git a/net/core/dev.c b/net/core/dev.c\n" - "index 679e75d3699ae..ff25e4c71588e 100644\n" - "--- a/net/core/dev.c\n" - "+++ b/net/core/dev.c\n" - "@@ -789,7 +789,7 @@ int dev_fill_forward_path(struct net_device_path_ctx *ctx,\n" - " \t\t\tgoto err_out;\n" - " \n" - " \t\tstack->num_paths++;\n" - "-\t\tif (WARN_ON_ONCE(last_dev == ctx->dev))\n" - "+\t\tif (last_dev == ctx->dev)\n" - " \t\t\tgoto err_out;\n" + " mm/mremap.c | 9 ++++-----\n" + " 1 file changed, 4 insertions(+), 5 deletions(-)\n" + "\n" + "--- a/mm/mremap.c\n" + "+++ b/mm/mremap.c\n" + "@@ -1270,12 +1270,11 @@ static void dontunmap_complete(struct vm\n" + " \t\tif (vma_is_anonymous(vma) && !vma->vm_file)\n" + " \t\t\tvma->vm_pgoff = pgoff_unfaulted;\n" " \t}\n" + "-\n" + "-\t/* Because we won't unmap we don't need to touch locked_vm. */\n" + " }\n" + " \n" + " static unsigned long move_vma(struct vma_remap_struct *vrm)\n" + " {\n" + "+\tconst bool is_dontunmap = vrm->flags & MREMAP_DONTUNMAP;\n" + " \tstruct mm_struct *mm = current->mm;\n" + " \tstruct vm_area_struct *new_vma;\n" + " \tunsigned long hiwater_vm;\n" + "@@ -1316,10 +1315,10 @@ static unsigned long move_vma(struct vma\n" + " \t */\n" + " \thiwater_vm = mm->hiwater_vm;\n" + " \n" + "-\tvrm_stat_account(vrm, vrm->new_len);\n" + "-\tif (unlikely(!err && (vrm->flags & MREMAP_DONTUNMAP)))\n" + "+\tif (unlikely(is_dontunmap && !err))\n" + " \t\tdontunmap_complete(vrm, new_vma);\n" + "-\telse\n" + "+\tvrm_stat_account(vrm, vrm->new_len);\n" + "+\tif (!is_dontunmap || err)\n" + " \t\tunmap_source_vma(vrm);\n" " \n" - "-- \n" - 2.53.0 + " \tmm->hiwater_vm = hiwater_vm;" -c598686c9a9edcbc3a3db33210618fc44b0e30acef7e3507f1229a009e43afe1 +f8238e57ea5abe78770b3ed48e35ceb831720696a67a2e3c47087b464928a06a
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox