forked from mirrors/linux
		
	mm: fix hang on anon_vma->root->lock
After several hours, kbuild tests hang with anon_vma_prepare() spinning on a newly allocated anon_vma's lock - on a box with CONFIG_TREE_PREEMPT_RCU=y (which makes this very much more likely, but it could happen without). The ever-subtle page_lock_anon_vma() now needs a further twist: since anon_vma_prepare() and anon_vma_fork() are liable to change the ->root of a reused anon_vma structure at any moment, page_lock_anon_vma() needs to check page_mapped() again before succeeding, otherwise page_unlock_anon_vma() might address a different root->lock. Signed-off-by: Hugh Dickins <hughd@google.com> Reviewed-by: Rik van Riel <riel@redhat.com> Cc: Christoph Lameter <cl@linux.com> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Andrea Arcangeli <aarcange@redhat.com> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
This commit is contained in:
		
							parent
							
								
									d4348c6789
								
							
						
					
					
						commit
						f18194275c
					
				
					 1 changed files with 16 additions and 3 deletions
				
			
		
							
								
								
									
										19
									
								
								mm/rmap.c
									
									
									
									
									
								
							
							
						
						
									
										19
									
								
								mm/rmap.c
									
									
									
									
									
								
							|  | @ -316,7 +316,7 @@ void __init anon_vma_init(void) | ||||||
|  */ |  */ | ||||||
| struct anon_vma *page_lock_anon_vma(struct page *page) | struct anon_vma *page_lock_anon_vma(struct page *page) | ||||||
| { | { | ||||||
| 	struct anon_vma *anon_vma; | 	struct anon_vma *anon_vma, *root_anon_vma; | ||||||
| 	unsigned long anon_mapping; | 	unsigned long anon_mapping; | ||||||
| 
 | 
 | ||||||
| 	rcu_read_lock(); | 	rcu_read_lock(); | ||||||
|  | @ -327,8 +327,21 @@ struct anon_vma *page_lock_anon_vma(struct page *page) | ||||||
| 		goto out; | 		goto out; | ||||||
| 
 | 
 | ||||||
| 	anon_vma = (struct anon_vma *) (anon_mapping - PAGE_MAPPING_ANON); | 	anon_vma = (struct anon_vma *) (anon_mapping - PAGE_MAPPING_ANON); | ||||||
| 	anon_vma_lock(anon_vma); | 	root_anon_vma = ACCESS_ONCE(anon_vma->root); | ||||||
| 	return anon_vma; | 	spin_lock(&root_anon_vma->lock); | ||||||
|  | 
 | ||||||
|  | 	/*
 | ||||||
|  | 	 * If this page is still mapped, then its anon_vma cannot have been | ||||||
|  | 	 * freed.  But if it has been unmapped, we have no security against | ||||||
|  | 	 * the anon_vma structure being freed and reused (for another anon_vma: | ||||||
|  | 	 * SLAB_DESTROY_BY_RCU guarantees that - so the spin_lock above cannot | ||||||
|  | 	 * corrupt): with anon_vma_prepare() or anon_vma_fork() redirecting | ||||||
|  | 	 * anon_vma->root before page_unlock_anon_vma() is called to unlock. | ||||||
|  | 	 */ | ||||||
|  | 	if (page_mapped(page)) | ||||||
|  | 		return anon_vma; | ||||||
|  | 
 | ||||||
|  | 	spin_unlock(&root_anon_vma->lock); | ||||||
| out: | out: | ||||||
| 	rcu_read_unlock(); | 	rcu_read_unlock(); | ||||||
| 	return NULL; | 	return NULL; | ||||||
|  |  | ||||||
		Loading…
	
		Reference in a new issue
	
	 Hugh Dickins
						Hugh Dickins