Skip to content

Commit c0e7cad

Browse files
Mel Gormantorvalds
authored andcommitted
mm: numa: add paranoid check around pte_protnone_numa
pte_protnone_numa is only safe to use after VMA checks for PROT_NONE are complete. Treating a real PROT_NONE PTE as a NUMA hinting fault is going to result in strangeness so add a check for it. BUG_ON looks like overkill but if this is hit then it's a serious bug that could result in corruption so do not even try recovering. It would have been more comprehensive to check VMA flags in pte_protnone_numa but it would have made the API ugly just for a debugging check. Signed-off-by: Mel Gorman <mgorman@suse.de> Cc: Aneesh Kumar K.V <aneesh.kumar@linux.vnet.ibm.com> Cc: Benjamin Herrenschmidt <benh@kernel.crashing.org> Cc: Dave Jones <davej@redhat.com> Cc: Hugh Dickins <hughd@google.com> Cc: Ingo Molnar <mingo@redhat.com> Cc: Kirill Shutemov <kirill.shutemov@linux.intel.com> Cc: Linus Torvalds <torvalds@linux-foundation.org> Cc: Paul Mackerras <paulus@samba.org> Cc: Rik van Riel <riel@redhat.com> Cc: Sasha Levin <sasha.levin@oracle.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
1 parent c819f37 commit c0e7cad

File tree

2 files changed

+6
-0
lines changed

2 files changed

+6
-0
lines changed

mm/huge_memory.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1262,6 +1262,9 @@ int do_huge_pmd_numa_page(struct mm_struct *mm, struct vm_area_struct *vma,
12621262
bool migrated = false;
12631263
int flags = 0;
12641264

1265+
/* A PROT_NONE fault should not end up here */
1266+
BUG_ON(!(vma->vm_flags & (VM_READ | VM_EXEC | VM_WRITE)));
1267+
12651268
ptl = pmd_lock(mm, pmdp);
12661269
if (unlikely(!pmd_same(pmd, *pmdp)))
12671270
goto out_unlock;

mm/memory.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3013,6 +3013,9 @@ static int do_numa_page(struct mm_struct *mm, struct vm_area_struct *vma,
30133013
bool migrated = false;
30143014
int flags = 0;
30153015

3016+
/* A PROT_NONE fault should not end up here */
3017+
BUG_ON(!(vma->vm_flags & (VM_READ | VM_EXEC | VM_WRITE)));
3018+
30163019
/*
30173020
* The "pte" at this point cannot be used safely without
30183021
* validation through pte_unmap_same(). It's of NUMA type but

0 commit comments

Comments
 (0)