public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org,
	Benjamin Herrenschmidt <benh@kernel.crashing.org>
Cc: Justin Forbes <jmforbes@linuxtx.org>,
	Zwane Mwaikambo <zwane@arm.linux.org.uk>,
	"Theodore Ts'o" <tytso@mit.edu>,
	Randy Dunlap <rdunlap@xenotime.net>,
	Dave Jones <davej@redhat.com>,
	Chuck Wolber <chuckw@quantumlinux.com>,
	Chris Wedgwood <reviews@ml.cw.f00f.org>,
	Michael Krufky <mkrufky@linuxtv.org>,
	Chuck Ebbert <cebbert@redhat.com>,
	Domenico Andreoli <cavokz@gmail.com>, Willy Tarreau <w@1wt.eu>,
	Rodrigo Rubira Branco <rbranco@la.checkpoint.com>,
	Jake Edge <jake@lwn.net>, Eugene Teo <eteo@redhat.com>,
	torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk, Greg KH <greg@kroah.com>,
	Andy Whitcroft <apw@shadowen.org>,
	David Gibson <david@gibson.dropbear.id.au>
Subject: [patch 27/29] Correct hash flushing from huge_ptep_set_wrprotect()
Date: Wed, 30 Jul 2008 16:27:43 -0700	[thread overview]
Message-ID: <20080730232743.GB30670@suse.de> (raw)
In-Reply-To: <20080730232451.GA30670@suse.de>

[-- Attachment #1: correct-hash-flushing-from-huge_ptep_set_wrprotect.patch --]
[-- Type: text/plain, Size: 2833 bytes --]

2.6.25-stable review patch.  If anyone has any objections, please let us 
know.

------------------
From: David Gibson <david@gibson.dropbear.id.au>

Correct hash flushing from huge_ptep_set_wrprotect() [stable tree version]

A fix for incorrect flushing of the hash page table at fork() for
hugepages was recently committed as
86df86424939d316b1f6cfac1b6204f0c7dee317.  Without this fix, a process
can make a MAP_PRIVATE hugepage mapping, then fork() and have writes
to the mapping after the fork() pollute the child's version.

Unfortunately this bug also exists in the stable branch.  In fact in
that case copy_hugetlb_page_range() from mm/hugetlb.c calls
ptep_set_wrprotect() directly, the hugepage variant hook
huge_ptep_set_wrprotect() doesn't even exist.

The patch below is a port of the fix to the stable25/master branch.
It introduces a huge_ptep_set_wrprotect() call, but this is #defined
to be equal to ptep_set_wrprotect() unless the arch defines its own
version and sets __HAVE_ARCH_HUGE_PTEP_SET_WRPROTECT.

This arch preprocessor flag is kind of nasty, but it seems the sanest
way to introduce this fix with minimum risk of breaking other archs
for whom prep_set_wprotect() is suitable for hugepages.

Signed-off-by: Andy Whitcroft <apw@shadowen.org>
Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 include/asm-powerpc/pgtable-ppc64.h |   11 +++++++++++
 mm/hugetlb.c                        |    6 +++++-
 2 files changed, 16 insertions(+), 1 deletion(-)

--- a/include/asm-powerpc/pgtable-ppc64.h
+++ b/include/asm-powerpc/pgtable-ppc64.h
@@ -311,6 +311,17 @@ static inline void ptep_set_wrprotect(st
 	old = pte_update(mm, addr, ptep, _PAGE_RW, 0);
 }
 
+#define __HAVE_ARCH_HUGE_PTEP_SET_WRPROTECT
+static inline void huge_ptep_set_wrprotect(struct mm_struct *mm,
+					   unsigned long addr, pte_t *ptep)
+{
+	unsigned long old;
+
+       	if ((pte_val(*ptep) & _PAGE_RW) == 0)
+       		return;
+	old = pte_update(mm, addr, ptep, _PAGE_RW, 1);
+}
+
 /*
  * We currently remove entries from the hashtable regardless of whether
  * the entry was young or dirty. The generic routines only flush if the
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -738,6 +738,10 @@ static void set_huge_ptep_writable(struc
 }
 
 
+#ifndef __HAVE_ARCH_HUGE_PTEP_SET_WRPROTECT
+#define huge_ptep_set_wrprotect		ptep_set_wrprotect
+#endif
+
 int copy_hugetlb_page_range(struct mm_struct *dst, struct mm_struct *src,
 			    struct vm_area_struct *vma)
 {
@@ -764,7 +768,7 @@ int copy_hugetlb_page_range(struct mm_st
 		spin_lock(&src->page_table_lock);
 		if (!pte_none(*src_pte)) {
 			if (cow)
-				ptep_set_wrprotect(src, addr, src_pte);
+				huge_ptep_set_wrprotect(src, addr, src_pte);
 			entry = *src_pte;
 			ptepage = pte_page(entry);
 			get_page(ptepage);

-- 

  parent reply	other threads:[~2008-07-30 23:43 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20080730231003.655833364@mini.kroah.org>
2008-07-30 23:24 ` [patch 00/29] 2.6.25-stable review Greg KH
2008-07-30 23:26   ` [patch 01/29] quota: fix possible infinite loop in quota code Greg KH
2008-07-30 23:26   ` [patch 02/29] isofs: fix minor filesystem corruption Greg KH
2008-07-30 23:26   ` [patch 03/29] x86: fix crash due to missing debugctlmsr on AMD K6-3 Greg KH
2008-07-30 23:26   ` [patch 04/29] vmlinux.lds: move __attribute__((__cold__)) functions back into final .text section Greg KH
2008-07-30 23:26   ` [patch 05/29] tcp: Clear probes_out more aggressively in tcp_ack() Greg KH
2008-07-30 23:26   ` [patch 06/29] sparc64: Fix lockdep issues in LDC protocol layer Greg KH
2008-07-30 23:26   ` [patch 07/29] sparc64: Fix cpufreq notifier registry Greg KH
2008-07-30 23:26   ` [patch 08/29] sparc64: Do not define BIO_VMERGE_BOUNDARY Greg KH
2008-07-30 23:27   ` [patch 09/29] pata_atiixp: Dont disable Greg KH
2008-07-30 23:27   ` [patch 10/29] markers: fix duplicate modpost entry Greg KH
2008-07-30 23:27   ` [patch 11/29] ide-cd: fix oops when using growisofs Greg KH
2008-07-30 23:27   ` [patch 12/29] Fix build on COMPAT platforms when CONFIG_EPOLL is disabled Greg KH
2008-07-30 23:27   ` [patch 13/29] ARM: fix fls() for 64-bit arguments Greg KH
2008-07-30 23:27   ` [patch 14/29] ALSA: hda - Fix "alc262_sony_unsol" hda_verb array Greg KH
2008-07-30 23:27   ` [patch 15/29] ALSA: trident - pause s/pdif output Greg KH
2008-07-30 23:27   ` [patch 16/29] ahci: retry enabling AHCI a few times before spitting out WARN_ON() Greg KH
2008-07-30 23:27   ` [patch 17/29] x86: fix kernel_physical_mapping_init() for large x86 systems Greg KH
2008-07-30 23:27   ` [patch 18/29] VFS: increase pseudo-filesystem block size to PAGE_SIZE Greg KH
2008-07-30 23:27   ` [patch 19/29] tmpfs: fix kernel BUG in shmem_delete_inode Greg KH
2008-07-30 23:27   ` [patch 20/29] mpc52xx_psc_spi: fix block transfer Greg KH
2008-07-30 23:27   ` [patch 21/29] markers: fix markers read barrier for multiple probes Greg KH
2008-07-30 23:27   ` [patch 22/29] ixgbe: remove device ID for unsupported device Greg KH
2008-07-30 23:27   ` [patch 23/29] eCryptfs: use page_alloc not kmalloc to get a page of memory Greg KH
2008-07-30 23:27   ` [patch 24/29] cpufreq acpi: only call _PPC after cpufreq ACPI init funcs got called already Greg KH
2008-07-30 23:27   ` [patch 25/29] b43legacy: Release mutex in error handling code Greg KH
2008-07-30 23:27   ` [patch 26/29] ath5k: dont enable MSI, we cannot handle it yet Greg KH
2008-07-30 23:27   ` Greg KH [this message]
2008-07-30 23:27   ` [patch 28/29] netfilter -stable: nf_conntrack_tcp: fix endless loop Greg KH
2008-07-30 23:27   ` [patch 29/29] Fix off-by-one error in iov_iter_advance() Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20080730232743.GB30670@suse.de \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=apw@shadowen.org \
    --cc=benh@kernel.crashing.org \
    --cc=cavokz@gmail.com \
    --cc=cebbert@redhat.com \
    --cc=chuckw@quantumlinux.com \
    --cc=davej@redhat.com \
    --cc=david@gibson.dropbear.id.au \
    --cc=eteo@redhat.com \
    --cc=greg@kroah.com \
    --cc=jake@lwn.net \
    --cc=jmforbes@linuxtx.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mkrufky@linuxtv.org \
    --cc=rbranco@la.checkpoint.com \
    --cc=rdunlap@xenotime.net \
    --cc=reviews@ml.cw.f00f.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=tytso@mit.edu \
    --cc=w@1wt.eu \
    --cc=zwane@arm.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox