Archive-only list for patches
 help / color / mirror / Atom feed
diff for duplicates of <20260923140650.177967426@linuxfoundation.org>

diff --git a/a/1.txt b/N1/1.txt
index 81e65f1..e8a4027 100644
--- a/a/1.txt
+++ b/N1/1.txt
@@ -1,47 +1,84 @@
-7.2-stable review patch.  If anyone has any objections, please let me know.
+6.18-stable review patch.  If anyone has any objections, please let me know.
 
 ------------------
 
-From: Farhad Alemi <farhad.alemi@berkeley.edu>
-
-[ Upstream commit 150dba2c69e93302af24a0c868eebe4871e2e107 ]
-
-ipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the
-route to the tunnel's remote endpoint and set ctx->dev to its device,
-which is the tunnel itself when that route resolves back to the tunnel.
-dev_fill_forward_path() then makes no progress and trips
-WARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to
-offload a flow through the tunnel. That routing loop is a configuration
-any CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and
-ip6_tnl_xmit() already treat it as a tx error, so remove the warning and
-just fail the walk, as commit 008e7a7c293b ("net: remove WARN_ON_ONCE
-when accessing forward path array") did for the path stack overflow.
-
-Fixes: ab427db17885 ("netfilter: flowtable: Add IPIP rx sw acceleration")
-Fixes: d98103575dcd ("netfilter: flowtable: Add IP6IP6 rx sw acceleration")
-Closes: https://lore.kernel.org/all/CA+0ovCgaRvbd0Udj70b2xxG8Cx3CaCpNhnf1V4RWQuDveZYZhA@mail.gmail.com/
-Suggested-by: Pablo Neira Ayuso <pablo@netfilter.org>
-Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu>
-Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
-Link: https://patch.msgid.link/CA+0ovCgKDOk+Bg6Gh5Lwx94u_jJjQ30-vY1JcY2BYfhnWJJbPA@mail.gmail.com
-Signed-off-by: Jakub Kicinski <kuba@kernel.org>
-Signed-off-by: Sasha Levin <sashal@kernel.org>
+From: Lorenzo Stoakes (ARM) <ljs@kernel.org>
+
+commit 397432cab17bccb600fd6c16ed593f1149042268 upstream.
+
+When a VMA is mremap()'d with MREMAP_DONTUNMAP set, that results in the
+VMA being copied, but the source VMA not being unmapped.
+
+If the VMA is mlock()'d this is a legal operation, though the source VMA
+has its VMA_LOCKED_BIT cleared.
+
+However this is done in dontunmap_complete(), after mm->locked_vm was
+incremented via vrm_stat_account(), resulting in double-counting.
+
+Worse, this is not even corrected when source VMA is unmapped, due to the
+VMA_LOCKED_BIT flag having been cleared.
+
+This all works fine in the usual mremap() case (without MREMAP_DONTUNMAP),
+as the source VMA is unmapped with VMA_LOCKED_BIT intact, at which time
+mm->locked_vm is decremented accordingly.
+
+Resolve the issue by invoking vrm_stat_account() only after
+dontunmap_complete() has run.
+
+Note that MREMAP_DONTUNMAP requires old_len == new_len, so no need to
+account for a delta in size in this case.
+
+The bug was introduced by commit b714ccb02a76 ("mm/mremap: complete
+refactor of move_vma()") which incorrectly reordered the accounting and
+the clearing of the VMA_LOCKED_BIT flag.
+
+Link: https://lore.kernel.org/20260828-mremap-fix-locked-vm-v1-1-c80be7505d1e@kernel.org
+Fixes: b714ccb02a76 ("mm/mremap: complete refactor of move_vma()")
+Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
+Reported-by: sashiko-bot <sashiko-bot@kernel.org>
+Closes: https://sashiko.dev/#/patchset/20260825-fix-mremap-dontunmap-pgoff-v1-1-39a40b2c98b3@kernel.org
+Reported-by: Kunwu Chan <kunwu.chan@gmail.com>
+Closes: https://lore.kernel.org/all/20260828094823.594279-1-kunwu.chan@linux.dev/
+Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
+Tested-by: Kunwu Chan <kunwu.chan@gmail.com>
+Reviewed-by: Kunwu Chan <kunwu.chan@gmail.com>
+Cc: Jann Horn <jannh@google.com>
+Cc: Liam R. Howlett <liam@infradead.org>
+Cc: Pedro Falcato <pfalcato@suse.de>
+Cc: <stable@vger.kernel.org>
+Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
 ---
- net/core/dev.c | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/net/core/dev.c b/net/core/dev.c
-index 679e75d3699ae..ff25e4c71588e 100644
---- a/net/core/dev.c
-+++ b/net/core/dev.c
-@@ -789,7 +789,7 @@ int dev_fill_forward_path(struct net_device_path_ctx *ctx,
- 			goto err_out;
- 
- 		stack->num_paths++;
--		if (WARN_ON_ONCE(last_dev == ctx->dev))
-+		if (last_dev == ctx->dev)
- 			goto err_out;
+ mm/mremap.c |    9 ++++-----
+ 1 file changed, 4 insertions(+), 5 deletions(-)
+
+--- a/mm/mremap.c
++++ b/mm/mremap.c
+@@ -1270,12 +1270,11 @@ static void dontunmap_complete(struct vm
+ 		if (vma_is_anonymous(vma) && !vma->vm_file)
+ 			vma->vm_pgoff = pgoff_unfaulted;
  	}
+-
+-	/* Because we won't unmap we don't need to touch locked_vm. */
+ }
+ 
+ static unsigned long move_vma(struct vma_remap_struct *vrm)
+ {
++	const bool is_dontunmap = vrm->flags & MREMAP_DONTUNMAP;
+ 	struct mm_struct *mm = current->mm;
+ 	struct vm_area_struct *new_vma;
+ 	unsigned long hiwater_vm;
+@@ -1316,10 +1315,10 @@ static unsigned long move_vma(struct vma
+ 	 */
+ 	hiwater_vm = mm->hiwater_vm;
+ 
+-	vrm_stat_account(vrm, vrm->new_len);
+-	if (unlikely(!err && (vrm->flags & MREMAP_DONTUNMAP)))
++	if (unlikely(is_dontunmap && !err))
+ 		dontunmap_complete(vrm, new_vma);
+-	else
++	vrm_stat_account(vrm, vrm->new_len);
++	if (!is_dontunmap || err)
+ 		unmap_source_vma(vrm);
  
--- 
-2.53.0
+ 	mm->hiwater_vm = hiwater_vm;
diff --git a/a/content_digest b/N1/content_digest
index bd80dcf..84cc926 100644
--- a/a/content_digest
+++ b/N1/content_digest
@@ -1,63 +1,103 @@
- "ref\020260923140644.756254324@linuxfoundation.org\0"
+ "ref\020260923140643.441954610@linuxfoundation.org\0"
  "From\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>\0"
- "Subject\0[PATCH 7.2 209/438] net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check\0"
- "Date\0Wed, 23 Sep 2026 16:03:50 +0200\0"
+ "Subject\0[PATCH 6.18 261/398] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP\0"
+ "Date\0Wed, 23 Sep 2026 16:05:35 +0200\0"
  "To\0stable@vger.kernel.org\0"
  "Cc\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>"
   patches@lists.linux.dev
-  Pablo Neira Ayuso <pablo@netfilter.org>
-  Farhad Alemi <farhad.alemi@berkeley.edu>
-  Xuanqiang Luo <luoxuanqiang@kylinos.cn>
-  Jakub Kicinski <kuba@kernel.org>
- " Sasha Levin <sashal@kernel.org>\0"
+  Lorenzo Stoakes (ARM) <ljs@kernel.org>
+  sashiko-bot <sashiko-bot@kernel.org>
+  Kunwu Chan <kunwu.chan@gmail.com>
+  Vlastimil Babka (SUSE) <vbabka@kernel.org>
+  Jann Horn <jannh@google.com>
+  Liam R. Howlett <liam@infradead.org>
+  Pedro Falcato <pfalcato@suse.de>
+ " Andrew Morton <akpm@linux-foundation.org>\0"
  "\00:1\0"
  "b\0"
- "7.2-stable review patch.  If anyone has any objections, please let me know.\n"
+ "6.18-stable review patch.  If anyone has any objections, please let me know.\n"
  "\n"
  "------------------\n"
  "\n"
- "From: Farhad Alemi <farhad.alemi@berkeley.edu>\n"
- "\n"
- "[ Upstream commit 150dba2c69e93302af24a0c868eebe4871e2e107 ]\n"
- "\n"
- "ipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the\n"
- "route to the tunnel's remote endpoint and set ctx->dev to its device,\n"
- "which is the tunnel itself when that route resolves back to the tunnel.\n"
- "dev_fill_forward_path() then makes no progress and trips\n"
- "WARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to\n"
- "offload a flow through the tunnel. That routing loop is a configuration\n"
- "any CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and\n"
- "ip6_tnl_xmit() already treat it as a tx error, so remove the warning and\n"
- "just fail the walk, as commit 008e7a7c293b (\"net: remove WARN_ON_ONCE\n"
- "when accessing forward path array\") did for the path stack overflow.\n"
- "\n"
- "Fixes: ab427db17885 (\"netfilter: flowtable: Add IPIP rx sw acceleration\")\n"
- "Fixes: d98103575dcd (\"netfilter: flowtable: Add IP6IP6 rx sw acceleration\")\n"
- "Closes: https://lore.kernel.org/all/CA+0ovCgaRvbd0Udj70b2xxG8Cx3CaCpNhnf1V4RWQuDveZYZhA@mail.gmail.com/\n"
- "Suggested-by: Pablo Neira Ayuso <pablo@netfilter.org>\n"
- "Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu>\n"
- "Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>\n"
- "Link: https://patch.msgid.link/CA+0ovCgKDOk+Bg6Gh5Lwx94u_jJjQ30-vY1JcY2BYfhnWJJbPA@mail.gmail.com\n"
- "Signed-off-by: Jakub Kicinski <kuba@kernel.org>\n"
- "Signed-off-by: Sasha Levin <sashal@kernel.org>\n"
+ "From: Lorenzo Stoakes (ARM) <ljs@kernel.org>\n"
+ "\n"
+ "commit 397432cab17bccb600fd6c16ed593f1149042268 upstream.\n"
+ "\n"
+ "When a VMA is mremap()'d with MREMAP_DONTUNMAP set, that results in the\n"
+ "VMA being copied, but the source VMA not being unmapped.\n"
+ "\n"
+ "If the VMA is mlock()'d this is a legal operation, though the source VMA\n"
+ "has its VMA_LOCKED_BIT cleared.\n"
+ "\n"
+ "However this is done in dontunmap_complete(), after mm->locked_vm was\n"
+ "incremented via vrm_stat_account(), resulting in double-counting.\n"
+ "\n"
+ "Worse, this is not even corrected when source VMA is unmapped, due to the\n"
+ "VMA_LOCKED_BIT flag having been cleared.\n"
+ "\n"
+ "This all works fine in the usual mremap() case (without MREMAP_DONTUNMAP),\n"
+ "as the source VMA is unmapped with VMA_LOCKED_BIT intact, at which time\n"
+ "mm->locked_vm is decremented accordingly.\n"
+ "\n"
+ "Resolve the issue by invoking vrm_stat_account() only after\n"
+ "dontunmap_complete() has run.\n"
+ "\n"
+ "Note that MREMAP_DONTUNMAP requires old_len == new_len, so no need to\n"
+ "account for a delta in size in this case.\n"
+ "\n"
+ "The bug was introduced by commit b714ccb02a76 (\"mm/mremap: complete\n"
+ "refactor of move_vma()\") which incorrectly reordered the accounting and\n"
+ "the clearing of the VMA_LOCKED_BIT flag.\n"
+ "\n"
+ "Link: https://lore.kernel.org/20260828-mremap-fix-locked-vm-v1-1-c80be7505d1e@kernel.org\n"
+ "Fixes: b714ccb02a76 (\"mm/mremap: complete refactor of move_vma()\")\n"
+ "Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>\n"
+ "Reported-by: sashiko-bot <sashiko-bot@kernel.org>\n"
+ "Closes: https://sashiko.dev/#/patchset/20260825-fix-mremap-dontunmap-pgoff-v1-1-39a40b2c98b3@kernel.org\n"
+ "Reported-by: Kunwu Chan <kunwu.chan@gmail.com>\n"
+ "Closes: https://lore.kernel.org/all/20260828094823.594279-1-kunwu.chan@linux.dev/\n"
+ "Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>\n"
+ "Tested-by: Kunwu Chan <kunwu.chan@gmail.com>\n"
+ "Reviewed-by: Kunwu Chan <kunwu.chan@gmail.com>\n"
+ "Cc: Jann Horn <jannh@google.com>\n"
+ "Cc: Liam R. Howlett <liam@infradead.org>\n"
+ "Cc: Pedro Falcato <pfalcato@suse.de>\n"
+ "Cc: <stable@vger.kernel.org>\n"
+ "Signed-off-by: Andrew Morton <akpm@linux-foundation.org>\n"
+ "Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>\n"
  "---\n"
- " net/core/dev.c | 2 +-\n"
- " 1 file changed, 1 insertion(+), 1 deletion(-)\n"
- "\n"
- "diff --git a/net/core/dev.c b/net/core/dev.c\n"
- "index 679e75d3699ae..ff25e4c71588e 100644\n"
- "--- a/net/core/dev.c\n"
- "+++ b/net/core/dev.c\n"
- "@@ -789,7 +789,7 @@ int dev_fill_forward_path(struct net_device_path_ctx *ctx,\n"
- " \t\t\tgoto err_out;\n"
- " \n"
- " \t\tstack->num_paths++;\n"
- "-\t\tif (WARN_ON_ONCE(last_dev == ctx->dev))\n"
- "+\t\tif (last_dev == ctx->dev)\n"
- " \t\t\tgoto err_out;\n"
+ " mm/mremap.c |    9 ++++-----\n"
+ " 1 file changed, 4 insertions(+), 5 deletions(-)\n"
+ "\n"
+ "--- a/mm/mremap.c\n"
+ "+++ b/mm/mremap.c\n"
+ "@@ -1270,12 +1270,11 @@ static void dontunmap_complete(struct vm\n"
+ " \t\tif (vma_is_anonymous(vma) && !vma->vm_file)\n"
+ " \t\t\tvma->vm_pgoff = pgoff_unfaulted;\n"
  " \t}\n"
+ "-\n"
+ "-\t/* Because we won't unmap we don't need to touch locked_vm. */\n"
+ " }\n"
+ " \n"
+ " static unsigned long move_vma(struct vma_remap_struct *vrm)\n"
+ " {\n"
+ "+\tconst bool is_dontunmap = vrm->flags & MREMAP_DONTUNMAP;\n"
+ " \tstruct mm_struct *mm = current->mm;\n"
+ " \tstruct vm_area_struct *new_vma;\n"
+ " \tunsigned long hiwater_vm;\n"
+ "@@ -1316,10 +1315,10 @@ static unsigned long move_vma(struct vma\n"
+ " \t */\n"
+ " \thiwater_vm = mm->hiwater_vm;\n"
+ " \n"
+ "-\tvrm_stat_account(vrm, vrm->new_len);\n"
+ "-\tif (unlikely(!err && (vrm->flags & MREMAP_DONTUNMAP)))\n"
+ "+\tif (unlikely(is_dontunmap && !err))\n"
+ " \t\tdontunmap_complete(vrm, new_vma);\n"
+ "-\telse\n"
+ "+\tvrm_stat_account(vrm, vrm->new_len);\n"
+ "+\tif (!is_dontunmap || err)\n"
+ " \t\tunmap_source_vma(vrm);\n"
  " \n"
- "-- \n"
- 2.53.0
+ " \tmm->hiwater_vm = hiwater_vm;"
 
-c598686c9a9edcbc3a3db33210618fc44b0e30acef7e3507f1229a009e43afe1
+f8238e57ea5abe78770b3ed48e35ceb831720696a67a2e3c47087b464928a06a

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox