From: Carlos Llamas <cmllamas@google.com>
To: Alice Ryhl <aliceryhl@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
Suren Baghdasaryan <surenb@google.com>,
dave.hansen@linux.intel.com, Liam.Howlett@oracle.com,
ljs@kernel.org, david@redhat.com, willy@infradead.org,
shakeel.butt@linux.dev, vbabka@kernel.org, jannh@google.com,
arve@android.com, christian@brauner.io, tkjos@android.com,
dsahern@kernel.org, davem@davemloft.net,
gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org,
linux-mm@kvack.org, netdev@vger.kernel.org
Subject: Re: [PATCH v6 0/5] mm: Unconditional per-VMA locks and cleanups
Date: Mon, 31 Aug 2026 22:26:55 +0000 [thread overview]
Message-ID: <apX_r59k4e-XiI-C@google.com> (raw)
In-Reply-To: <apVhzM2501wSiGGg@google.com>
On Mon, Aug 31, 2026 at 11:13:16AM +0000, Alice Ryhl wrote:
> On Sat, Aug 29, 2026 at 06:56:25PM -0700, Andrew Morton wrote:
> > On Thu, 13 Aug 2026 12:34:28 -0700 Suren Baghdasaryan <surenb@google.com> wrote:
> >
> > > v2 version of this patchset [1] was written by Dave Hansen and per his
> > > request, I'm taking over this series.
> > >
> > > tl;dr: Make per-VMA locks available in all configs. Simplify some
> > > of the per-VMA lock users now that they can rely on them being
> > > always available.
> >
> > It's been 2+ weeks so perhaps a refresh-and-remind would be helpful.
> >
> > But it applies well enough and is adequately reviewed so I put it in
> > there for testing, thanks.
> >
> > AI review might have found a couple of pre-existing binder bugs:
> >
> > https://sashiko.dev/#/patchset/20260813193433.3318288-1-surenb@google.com
> >
> > and a small rusty thing which you might wish to attend to.
>
> The binder bug is not actually a bug. When using VM_MIXEDMAP and
> vm_insert_page(), the vma takes a refcount on the page, so there is no
> use-after-free even if free_page() is invoked without removing it from
> the vma.
Exactly! I agree the refcount on the page would prevent the UAF.
However, we should still reject mremap() because this leaves the page in
limbo since it is not given back to the shrinker and also binder can't
make use of it anymore. I'll send out a patch to fix this.
Thanks,
--
Carlos Llamas
next prev parent reply other threads:[~2026-08-31 22:27 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 19:34 [PATCH v6 0/5] mm: Unconditional per-VMA locks and cleanups Suren Baghdasaryan
2026-08-13 19:34 ` [PATCH v6 1/5] mm: Make per-VMA locks available universally Suren Baghdasaryan
2026-08-14 19:03 ` Lorenzo Stoakes (ARM)
2026-08-14 20:33 ` Suren Baghdasaryan
2026-08-13 19:34 ` [PATCH v6 2/5] binder: Make shrinker rely solely on per-VMA lock Suren Baghdasaryan
2026-08-13 19:37 ` Carlos Llamas
2026-08-13 19:34 ` [PATCH v6 3/5] mm: Add RCU-based VMA lookup helper that waits for writers Suren Baghdasaryan
2026-08-13 19:34 ` [PATCH v6 4/5] binder: Remove mmap_lock fallback Suren Baghdasaryan
2026-08-13 19:34 ` [PATCH v6 5/5] tcp: Remove mmap_lock fallback path Suren Baghdasaryan
2026-08-30 1:56 ` [PATCH v6 0/5] mm: Unconditional per-VMA locks and cleanups Andrew Morton
2026-08-30 16:57 ` Suren Baghdasaryan
2026-08-31 11:13 ` Alice Ryhl
2026-08-31 20:42 ` Suren Baghdasaryan
2026-08-31 22:26 ` Carlos Llamas [this message]
2026-08-31 23:19 ` Suren Baghdasaryan
2026-08-31 23:29 ` Carlos Llamas
2026-09-01 5:13 ` Suren Baghdasaryan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apX_r59k4e-XiI-C@google.com \
--to=cmllamas@google.com \
--cc=Liam.Howlett@oracle.com \
--cc=akpm@linux-foundation.org \
--cc=aliceryhl@google.com \
--cc=arve@android.com \
--cc=christian@brauner.io \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=david@redhat.com \
--cc=dsahern@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=jannh@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=shakeel.butt@linux.dev \
--cc=surenb@google.com \
--cc=tkjos@android.com \
--cc=vbabka@kernel.org \
--cc=willy@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox