public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] fix VmSize and VmData after mremap
@ 2005-08-04 18:05 Hugh Dickins
  2005-08-05  9:05 ` Frank van Maarseveen
  0 siblings, 1 reply; 2+ messages in thread
From: Hugh Dickins @ 2005-08-04 18:05 UTC (permalink / raw)
  To: Linus Torvalds; +Cc: Andrew Morton, Frank van Maarseveen, linux-kernel

mremap's move_vma is applying __vm_stat_account to the old vma which may
have already been freed: move it to just before the do_munmap.

mremapping to and fro with CONFIG_DEBUG_SLAB=y showed /proc/<pid>/status
VmSize and VmData wrapping just like in kernel bugzilla #4842, and fixed
by this patch - worth including in 2.6.13, though not yet confirmed that
it fixes that specific report from Frank van Maarseveen.

Signed-off-by: Hugh Dickins <hugh@veritas.com>

--- 2.6.13-rc5-git2/mm/mremap.c	2005-06-17 20:48:29.000000000 +0100
+++ linux/mm/mremap.c	2005-08-03 16:22:33.000000000 +0100
@@ -229,6 +229,7 @@ static unsigned long move_vma(struct vm_
 	 * since do_munmap() will decrement it by old_len == new_len
 	 */
 	mm->total_vm += new_len >> PAGE_SHIFT;
+	__vm_stat_account(mm, vma->vm_flags, vma->vm_file, new_len>>PAGE_SHIFT);
 
 	if (do_munmap(mm, old_addr, old_len) < 0) {
 		/* OOM: unable to split vma, just get accounts right */
@@ -243,7 +244,6 @@ static unsigned long move_vma(struct vm_
 			vma->vm_next->vm_flags |= VM_ACCOUNT;
 	}
 
-	__vm_stat_account(mm, vma->vm_flags, vma->vm_file, new_len>>PAGE_SHIFT);
 	if (vm_flags & VM_LOCKED) {
 		mm->locked_vm += new_len >> PAGE_SHIFT;
 		if (new_len > old_len)

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] fix VmSize and VmData after mremap
  2005-08-04 18:05 [PATCH] fix VmSize and VmData after mremap Hugh Dickins
@ 2005-08-05  9:05 ` Frank van Maarseveen
  0 siblings, 0 replies; 2+ messages in thread
From: Frank van Maarseveen @ 2005-08-05  9:05 UTC (permalink / raw)
  To: Hugh Dickins; +Cc: Linus Torvalds, Andrew Morton, linux-kernel

On Thu, Aug 04, 2005 at 07:05:30PM +0100, Hugh Dickins wrote:
> mremap's move_vma is applying __vm_stat_account to the old vma which may
> have already been freed: move it to just before the do_munmap.
> 
> mremapping to and fro with CONFIG_DEBUG_SLAB=y showed /proc/<pid>/status
> VmSize and VmData wrapping just like in kernel bugzilla #4842, and fixed
> by this patch - worth including in 2.6.13, though not yet confirmed that
> it fixes that specific report from Frank van Maarseveen.

The patch works, thanks.

> 
> Signed-off-by: Hugh Dickins <hugh@veritas.com>
> 
> --- 2.6.13-rc5-git2/mm/mremap.c	2005-06-17 20:48:29.000000000 +0100
> +++ linux/mm/mremap.c	2005-08-03 16:22:33.000000000 +0100
> @@ -229,6 +229,7 @@ static unsigned long move_vma(struct vm_
>  	 * since do_munmap() will decrement it by old_len == new_len
>  	 */
>  	mm->total_vm += new_len >> PAGE_SHIFT;
> +	__vm_stat_account(mm, vma->vm_flags, vma->vm_file, new_len>>PAGE_SHIFT);
>  
>  	if (do_munmap(mm, old_addr, old_len) < 0) {
>  		/* OOM: unable to split vma, just get accounts right */
> @@ -243,7 +244,6 @@ static unsigned long move_vma(struct vm_
>  			vma->vm_next->vm_flags |= VM_ACCOUNT;
>  	}
>  
> -	__vm_stat_account(mm, vma->vm_flags, vma->vm_file, new_len>>PAGE_SHIFT);
>  	if (vm_flags & VM_LOCKED) {
>  		mm->locked_vm += new_len >> PAGE_SHIFT;
>  		if (new_len > old_len)

-- 
Frank

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2005-08-05  9:05 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-08-04 18:05 [PATCH] fix VmSize and VmData after mremap Hugh Dickins
2005-08-05  9:05 ` Frank van Maarseveen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox