* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-27 12:50 ` syzbot
@ 2024-05-28 8:54 ` Oscar Salvador
2024-05-28 9:51 ` Oscar Salvador
` (4 subsequent siblings)
5 siblings, 0 replies; 13+ messages in thread
From: Oscar Salvador @ 2024-05-28 8:54 UTC (permalink / raw)
To: syzbot; +Cc: akpm, linux-kernel, linux-mm, muchun.song, netdev, syzkaller-bugs
[-- Attachment #1: Type: text/plain, Size: 1221 bytes --]
On Mon, May 27, 2024 at 05:50:24AM -0700, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 66ad4829ddd0 Merge tag 'net-6.10-rc1' of git://git.kernel...
> git tree: net-next
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=15c114aa980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=48c05addbb27f3b0
> dashboard link: https://syzkaller.appspot.com/bug?extid=d3fe2dc5ffe9380b714b
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17770d72980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10db1592980000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/05c6f2231ef8/disk-66ad4829.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/5f4fc63b22e3/vmlinux-66ad4829.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/67f5c4c88729/bzImage-66ad4829.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
Let us see if the attached patch fixes it.
--
Oscar Salvador
SUSE Labs
[-- Attachment #2: 0001-mm-hugetlb-Do-not-call-vma_add_reservation-upon-ENOM.patch --]
[-- Type: text/x-patch, Size: 2190 bytes --]
From 917fa54481422c650425c8b0330439f8a3308479 Mon Sep 17 00:00:00 2001
From: Oscar Salvador <osalvador@suse.de>
Date: Tue, 28 May 2024 10:43:14 +0200
Subject: [PATCH] mm/hugetlb: Do not call vma_add_reservation upon ENOMEM
sysbot reported a splat [1] on __unmap_hugepage_range().
This is because vma_needs_reservation() can return -ENOMEM if
allocate_file_region_entries() fails to allocate the file_region struct for
the reservation.
Check for that and do not call vma_add_reservation() if that is the case,
otherwise region_abort() and region_del() will see that we do not have any
file_regions.
If we detect that vma_needs_reservation returned -ENOMEM, we clear the
hugetlb_restore_reserve flag as if this reservation was still consumed,
so free_huge_folio will not increment the resv count.
[1] https://lore.kernel.org/linux-mm/0000000000004096100617c58d54@google.com/T/#ma5983bc1ab18a54910da83416b3f89f3c7ee43aa
Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/linux-mm/0000000000004096100617c58d54@google.com/
Signed-off-by: Oscar Salvador <osalvador@suse.de>
---
mm/hugetlb.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 6be78e7d4f6e..a178e4bcca1b 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -5768,8 +5768,20 @@ void __unmap_hugepage_range(struct mmu_gather *tlb, struct vm_area_struct *vma,
* do_exit() will not see it, and will keep the reservation
* forever.
*/
- if (adjust_reservation && vma_needs_reservation(h, vma, address))
- vma_add_reservation(h, vma, address);
+ if (adjust_reservation) {
+ int rc = vma_needs_reservation(h, vma, address)
+
+ if (rc < 0)
+ /* Pressumably allocate_file_region_entries failed
+ * to allocate a file_region struct. Clear
+ * hugetlb_restore_reserve so that global reserve
+ * count will not be incremented by free_huge_folio.
+ * Act as if we consumed the reservation.
+ */
+ folio_clear_hugetlb_restore_reserve(folio);
+ else if (rc)
+ vma_add_reservation(h, vma, address);
+ }
tlb_remove_page_size(tlb, page, huge_page_size(h));
/*
--
2.45.1
^ permalink raw reply related [flat|nested] 13+ messages in thread* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-27 12:50 ` syzbot
2024-05-28 8:54 ` Oscar Salvador
@ 2024-05-28 9:51 ` Oscar Salvador
2024-05-28 10:31 ` syzbot
2024-05-28 9:52 ` Oscar Salvador
` (3 subsequent siblings)
5 siblings, 1 reply; 13+ messages in thread
From: Oscar Salvador @ 2024-05-28 9:51 UTC (permalink / raw)
To: syzbot; +Cc: akpm, linux-kernel, linux-mm, muchun.song, netdev, syzkaller-bugs
On Mon, May 27, 2024 at 05:50:24AM -0700, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 66ad4829ddd0 Merge tag 'net-6.10-rc1' of git://git.kernel...
> git tree: net-next
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=15c114aa980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=48c05addbb27f3b0
> dashboard link: https://syzkaller.appspot.com/bug?extid=d3fe2dc5ffe9380b714b
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17770d72980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10db1592980000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/05c6f2231ef8/disk-66ad4829.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/5f4fc63b22e3/vmlinux-66ad4829.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/67f5c4c88729/bzImage-66ad4829.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
#syz test: git://github.com/leberus/linux.git hugetlb-vma_resv-enomem
--
Oscar Salvador
SUSE Labs
^ permalink raw reply [flat|nested] 13+ messages in thread* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-27 12:50 ` syzbot
2024-05-28 8:54 ` Oscar Salvador
2024-05-28 9:51 ` Oscar Salvador
@ 2024-05-28 9:52 ` Oscar Salvador
2024-05-28 11:29 ` Oscar Salvador
` (2 subsequent siblings)
5 siblings, 0 replies; 13+ messages in thread
From: Oscar Salvador @ 2024-05-28 9:52 UTC (permalink / raw)
To: syzbot; +Cc: akpm, linux-kernel, linux-mm, muchun.song, netdev, syzkaller-bugs
[-- Attachment #1: Type: text/plain, Size: 1210 bytes --]
On Mon, May 27, 2024 at 05:50:24AM -0700, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 66ad4829ddd0 Merge tag 'net-6.10-rc1' of git://git.kernel...
> git tree: net-next
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=15c114aa980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=48c05addbb27f3b0
> dashboard link: https://syzkaller.appspot.com/bug?extid=d3fe2dc5ffe9380b714b
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17770d72980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10db1592980000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/05c6f2231ef8/disk-66ad4829.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/5f4fc63b22e3/vmlinux-66ad4829.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/67f5c4c88729/bzImage-66ad4829.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
And let us have it here as well
--
Oscar Salvador
SUSE Labs
[-- Attachment #2: 0001-mm-hugetlb-Do-not-call-vma_add_reservation-upon-ENOM.patch --]
[-- Type: text/x-patch, Size: 2190 bytes --]
From 917fa54481422c650425c8b0330439f8a3308479 Mon Sep 17 00:00:00 2001
From: Oscar Salvador <osalvador@suse.de>
Date: Tue, 28 May 2024 10:43:14 +0200
Subject: [PATCH] mm/hugetlb: Do not call vma_add_reservation upon ENOMEM
sysbot reported a splat [1] on __unmap_hugepage_range().
This is because vma_needs_reservation() can return -ENOMEM if
allocate_file_region_entries() fails to allocate the file_region struct for
the reservation.
Check for that and do not call vma_add_reservation() if that is the case,
otherwise region_abort() and region_del() will see that we do not have any
file_regions.
If we detect that vma_needs_reservation returned -ENOMEM, we clear the
hugetlb_restore_reserve flag as if this reservation was still consumed,
so free_huge_folio will not increment the resv count.
[1] https://lore.kernel.org/linux-mm/0000000000004096100617c58d54@google.com/T/#ma5983bc1ab18a54910da83416b3f89f3c7ee43aa
Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/linux-mm/0000000000004096100617c58d54@google.com/
Signed-off-by: Oscar Salvador <osalvador@suse.de>
---
mm/hugetlb.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 6be78e7d4f6e..a178e4bcca1b 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -5768,8 +5768,20 @@ void __unmap_hugepage_range(struct mmu_gather *tlb, struct vm_area_struct *vma,
* do_exit() will not see it, and will keep the reservation
* forever.
*/
- if (adjust_reservation && vma_needs_reservation(h, vma, address))
- vma_add_reservation(h, vma, address);
+ if (adjust_reservation) {
+ int rc = vma_needs_reservation(h, vma, address)
+
+ if (rc < 0)
+ /* Pressumably allocate_file_region_entries failed
+ * to allocate a file_region struct. Clear
+ * hugetlb_restore_reserve so that global reserve
+ * count will not be incremented by free_huge_folio.
+ * Act as if we consumed the reservation.
+ */
+ folio_clear_hugetlb_restore_reserve(folio);
+ else if (rc)
+ vma_add_reservation(h, vma, address);
+ }
tlb_remove_page_size(tlb, page, huge_page_size(h));
/*
--
2.45.1
^ permalink raw reply related [flat|nested] 13+ messages in thread* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-27 12:50 ` syzbot
` (2 preceding siblings ...)
2024-05-28 9:52 ` Oscar Salvador
@ 2024-05-28 11:29 ` Oscar Salvador
2024-05-28 15:43 ` syzbot
2024-05-28 12:08 ` Oscar Salvador
2024-05-28 16:38 ` Oscar Salvador
5 siblings, 1 reply; 13+ messages in thread
From: Oscar Salvador @ 2024-05-28 11:29 UTC (permalink / raw)
To: syzbot; +Cc: akpm, linux-kernel, linux-mm, muchun.song, netdev, syzkaller-bugs
On Mon, May 27, 2024 at 05:50:24AM -0700, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 66ad4829ddd0 Merge tag 'net-6.10-rc1' of git://git.kernel...
> git tree: net-next
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=15c114aa980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=48c05addbb27f3b0
> dashboard link: https://syzkaller.appspot.com/bug?extid=d3fe2dc5ffe9380b714b
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17770d72980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10db1592980000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/05c6f2231ef8/disk-66ad4829.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/5f4fc63b22e3/vmlinux-66ad4829.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/67f5c4c88729/bzImage-66ad4829.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
#syz test
From 917fa54481422c650425c8b0330439f8a3308479 Mon Sep 17 00:00:00 2001
From: Oscar Salvador <osalvador@suse.de>
Date: Tue, 28 May 2024 10:43:14 +0200
Subject: [PATCH] mm/hugetlb: Do not call vma_add_reservation upon ENOMEM
sysbot reported a splat [1] on __unmap_hugepage_range().
This is because vma_needs_reservation() can return -ENOMEM if
allocate_file_region_entries() fails to allocate the file_region struct for
the reservation.
Check for that and do not call vma_add_reservation() if that is the case,
otherwise region_abort() and region_del() will see that we do not have any
file_regions.
If we detect that vma_needs_reservation returned -ENOMEM, we clear the
hugetlb_restore_reserve flag as if this reservation was still consumed,
so free_huge_folio will not increment the resv count.
[1] https://lore.kernel.org/linux-mm/0000000000004096100617c58d54@google.com/T/#ma5983bc1ab18a54910da83416b3f89f3c7ee43aa
Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/linux-mm/0000000000004096100617c58d54@google.com/
Signed-off-by: Oscar Salvador <osalvador@suse.de>
---
mm/hugetlb.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index 6be78e7d4f6e..a178e4bcca1b 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -5768,8 +5768,20 @@ void __unmap_hugepage_range(struct mmu_gather *tlb, struct vm_area_struct *vma,
* do_exit() will not see it, and will keep the reservation
* forever.
*/
- if (adjust_reservation && vma_needs_reservation(h, vma, address))
- vma_add_reservation(h, vma, address);
+ if (adjust_reservation) {
+ int rc = vma_needs_reservation(h, vma, address)
+
+ if (rc < 0)
+ /* Pressumably allocate_file_region_entries failed
+ * to allocate a file_region struct. Clear
+ * hugetlb_restore_reserve so that global reserve
+ * count will not be incremented by free_huge_folio.
+ * Act as if we consumed the reservation.
+ */
+ folio_clear_hugetlb_restore_reserve(folio);
+ else if (rc)
+ vma_add_reservation(h, vma, address);
+ }
tlb_remove_page_size(tlb, page, huge_page_size(h));
/*
--
2.45.1
--
Oscar Salvador
SUSE Labs
^ permalink raw reply related [flat|nested] 13+ messages in thread* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-28 11:29 ` Oscar Salvador
@ 2024-05-28 15:43 ` syzbot
2024-05-28 16:40 ` Oscar Salvador
0 siblings, 1 reply; 13+ messages in thread
From: syzbot @ 2024-05-28 15:43 UTC (permalink / raw)
To: akpm, linux-kernel, linux-mm, muchun.song, netdev, osalvador,
syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
mm/hugetlb.c:5772:51: error: expected ';' at end of declaration
mm/hugetlb.c:5782:4: error: expected expression
Tested on:
commit: 4b3529ed Merge tag 'for-netdev' of https://git.kernel...
git tree: net-next
kernel config: https://syzkaller.appspot.com/x/.config?x=48c05addbb27f3b0
dashboard link: https://syzkaller.appspot.com/bug?extid=d3fe2dc5ffe9380b714b
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=17c8c38a980000
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-28 15:43 ` syzbot
@ 2024-05-28 16:40 ` Oscar Salvador
0 siblings, 0 replies; 13+ messages in thread
From: Oscar Salvador @ 2024-05-28 16:40 UTC (permalink / raw)
To: syzbot
Cc: akpm, linux-kernel, linux-mm, muchun.song, netdev, osalvador,
syzkaller-bugs
On Tue, May 28, 2024 at 08:43:06AM -0700, syzbot wrote:
> Hello,
>
> syzbot tried to test the proposed patch but the build/boot failed:
>
> mm/hugetlb.c:5772:51: error: expected ';' at end of declaration
> mm/hugetlb.c:5782:4: error: expected expression
Heh, silly me, I should have compile-tested, but was confident.
Anyway, now pushed a fixed version.
--
Oscar Salvador
SUSE Labs
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-27 12:50 ` syzbot
` (3 preceding siblings ...)
2024-05-28 11:29 ` Oscar Salvador
@ 2024-05-28 12:08 ` Oscar Salvador
2024-05-28 15:36 ` syzbot
2024-05-28 16:38 ` Oscar Salvador
5 siblings, 1 reply; 13+ messages in thread
From: Oscar Salvador @ 2024-05-28 12:08 UTC (permalink / raw)
To: syzbot; +Cc: akpm, linux-kernel, linux-mm, muchun.song, netdev, syzkaller-bugs
On Mon, May 27, 2024 at 05:50:24AM -0700, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 66ad4829ddd0 Merge tag 'net-6.10-rc1' of git://git.kernel...
> git tree: net-next
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=15c114aa980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=48c05addbb27f3b0
> dashboard link: https://syzkaller.appspot.com/bug?extid=d3fe2dc5ffe9380b714b
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17770d72980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10db1592980000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/05c6f2231ef8/disk-66ad4829.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/5f4fc63b22e3/vmlinux-66ad4829.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/67f5c4c88729/bzImage-66ad4829.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
#syz test https://github.com/leberus/linux.git hugetlb-vma_resv-enomem
--
Oscar Salvador
SUSE Labs
^ permalink raw reply [flat|nested] 13+ messages in thread* Re: [syzbot] [mm?] kernel BUG in __vma_reservation_common
2024-05-27 12:50 ` syzbot
` (4 preceding siblings ...)
2024-05-28 12:08 ` Oscar Salvador
@ 2024-05-28 16:38 ` Oscar Salvador
2024-05-28 17:24 ` syzbot
5 siblings, 1 reply; 13+ messages in thread
From: Oscar Salvador @ 2024-05-28 16:38 UTC (permalink / raw)
To: syzbot; +Cc: akpm, linux-kernel, linux-mm, muchun.song, netdev, syzkaller-bugs
On Mon, May 27, 2024 at 05:50:24AM -0700, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 66ad4829ddd0 Merge tag 'net-6.10-rc1' of git://git.kernel...
> git tree: net-next
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=15c114aa980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=48c05addbb27f3b0
> dashboard link: https://syzkaller.appspot.com/bug?extid=d3fe2dc5ffe9380b714b
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17770d72980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10db1592980000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/05c6f2231ef8/disk-66ad4829.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/5f4fc63b22e3/vmlinux-66ad4829.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/67f5c4c88729/bzImage-66ad4829.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+d3fe2dc5ffe9380b714b@syzkaller.appspotmail.com
#syz test https://github.com/leberus/linux.git hugetlb-vma_resv-enomem
--
Oscar Salvador
SUSE Labs
^ permalink raw reply [flat|nested] 13+ messages in thread