From patchwork Mon Jun 4 23:12:32 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Dan Williams X-Patchwork-Id: 10447485 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 159E2603D7 for ; Mon, 4 Jun 2018 23:22:34 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 08E0A29222 for ; Mon, 4 Jun 2018 23:22:34 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id F207329227; Mon, 4 Jun 2018 23:22:33 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.9 required=2.0 tests=BAYES_00, MAILING_LIST_MULTI, RCVD_IN_DNSWL_NONE autolearn=unavailable version=3.3.1 Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 6B38A29222 for ; Mon, 4 Jun 2018 23:22:33 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id D33E26B0271; Mon, 4 Jun 2018 19:22:31 -0400 (EDT) Delivered-To: linux-mm-outgoing@kvack.org Received: by kanga.kvack.org (Postfix, from userid 40) id D0A0F6B0272; Mon, 4 Jun 2018 19:22:31 -0400 (EDT) X-Original-To: int-list-linux-mm@kvack.org X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id C21466B0273; Mon, 4 Jun 2018 19:22:31 -0400 (EDT) X-Original-To: linux-mm@kvack.org X-Delivered-To: linux-mm@kvack.org Received: from mail-pl0-f69.google.com (mail-pl0-f69.google.com [209.85.160.69]) by kanga.kvack.org (Postfix) with ESMTP id 82A1B6B0271 for ; Mon, 4 Jun 2018 19:22:31 -0400 (EDT) Received: by mail-pl0-f69.google.com with SMTP id x32-v6so229889pld.16 for ; Mon, 04 Jun 2018 16:22:31 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-original-authentication-results:x-gm-message-state:subject:from :to:cc:date:message-id:in-reply-to:references:user-agent :mime-version:content-transfer-encoding; bh=MVTollL2YjBedqHAsXofXFzTOnYvjEmh0s71CNxk7Qk=; b=ccT+a1kui02wlUYkbqe8P5gYz6Ryn+GlOEuyVxPuFyzizPQ67cmwaZSsTL39pmuysd u5VOM5Pa/+OCumkShF0MZKThAhKav48A1AdGqNXrT2K00vDNUjnga8g+SpPt7vsN7pyD TolXZgbOkB9TScgQQb3fZCfnmINwXDosV2bZWZfeyV+jc3MMZR9GPHfRfaStA6mb4CZl 0zXqJSMRxhRrw4r/ND3F8l8L+vMyU2yNJWTO0FGaMiSquR9tfm5wqF5daRvypXVR2PQv m/rvjPDWbWTp2WuW62bBFPZICk2dVCwah6Iw7kZC5gk2Ax+UFaQdF2Y3bx9/8lFL4Ngx uhQw== X-Original-Authentication-Results: mx.google.com; spf=pass (google.com: domain of dan.j.williams@intel.com designates 192.55.52.43 as permitted sender) smtp.mailfrom=dan.j.williams@intel.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com X-Gm-Message-State: ALKqPwdZF+tCGy2LVKrQ6oKAoamM75DxzSOkwRRZ8PPS/UicDsQdlTiT pBmcZRDMshYYpa12rII8ew8psLItGD1bDoEWjPyrB1on5lbTaCDoMSMEhzbGQTulFo6i4/+Usqn P0u7wwLwJfghQX/cj1OJz07GrUf50TZDzOdXevMKwX+qOwtNLBp5b0j9/7BeCL7nQ/g== X-Received: by 2002:a62:4653:: with SMTP id t80-v6mr18010498pfa.58.1528154551195; Mon, 04 Jun 2018 16:22:31 -0700 (PDT) X-Google-Smtp-Source: ADUXVKIu4mun5r7/66vlr679ilqnSWRVGRkDEnBMEdrP79rHHp0Yd1mP5oPJ5tsNjvOwPyyC1wrs X-Received: by 2002:a62:4653:: with SMTP id t80-v6mr18010440pfa.58.1528154550002; Mon, 04 Jun 2018 16:22:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1528154549; cv=none; d=google.com; s=arc-20160816; b=yuZQH6MLc6RRibwL7+zz3uJmcEqrjFWA7VO/HcJKh2VXt4xGJtMCMkxBoZu5RpLf2M U9qEBuP+XRq0ikTQYA/adevBUXDt0HPqL+ptVAyvGlt0YXNeCoZ+QGfrjba2WSZAm3dm VITQNwAgp1orsmImv51emdU8mf2/72/OmhEh1Unui5c9odi7wKL3Zm129qEmiVIrbtlx cU0jFnL0wTp/pWAtD7K4thYGvT+ZrfaqWZPrMri+Zqw3WbPrmYGaOQs+s1FXZElTFf26 k3FW2c8ZlHVcPgRyfhmE3IPozdsmhZMepw5ntoYyalvxi8cRTxmhBqG9ny49bYCIVmLU zTug== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:user-agent:references :in-reply-to:message-id:date:cc:to:from:subject :arc-authentication-results; bh=MVTollL2YjBedqHAsXofXFzTOnYvjEmh0s71CNxk7Qk=; b=Kw931h9Bb00vliw2wWQ8Ec6tEZxJJrlac2MU17yh20I9+ukmESz2c+KE3NHzw1Xk+V l9miZaU7MwTfXuBXIyIxqX11alepJ62y3IX2Hw/7OTKJpA4nxwSQShnMNemVjuhZ7Uxo Al4a1jsSc5U2jRf4VPmdWfnDZ5GqVnknvqlBLkUQHRVzzifNJ3jDNIc58fZ8UZ4f3JNy WufsZcYEOkeJbUsPAupfr3LHAxjpLUpzNky6u4bGD8k/bekX1KfLPtM9lRs0CDdpQtt5 b9TAULqKxp8rIXcQCmh8YlTQTZnRl3tRtZwQK4LjIBnsWJpHuSYfQzuiFsjrGbcn4No8 uG3w== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of dan.j.williams@intel.com designates 192.55.52.43 as permitted sender) smtp.mailfrom=dan.j.williams@intel.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from mga05.intel.com (mga05.intel.com. [192.55.52.43]) by mx.google.com with ESMTPS id j10-v6si47386908plg.396.2018.06.04.16.22.29 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 04 Jun 2018 16:22:29 -0700 (PDT) Received-SPF: pass (google.com: domain of dan.j.williams@intel.com designates 192.55.52.43 as permitted sender) client-ip=192.55.52.43; Authentication-Results: mx.google.com; spf=pass (google.com: domain of dan.j.williams@intel.com designates 192.55.52.43 as permitted sender) smtp.mailfrom=dan.j.williams@intel.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from fmsmga006.fm.intel.com ([10.253.24.20]) by fmsmga105.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 04 Jun 2018 16:22:29 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.49,477,1520924400"; d="scan'208";a="234629815" Received: from dwillia2-desk3.jf.intel.com (HELO dwillia2-desk3.amr.corp.intel.com) ([10.54.39.16]) by fmsmga006.fm.intel.com with ESMTP; 04 Jun 2018 16:22:29 -0700 Subject: [PATCH v3 10/12] mm, memory_failure: Fix page->mapping assumptions relative to the page lock From: Dan Williams To: linux-nvdimm@lists.01.org Cc: hch@lst.de, linux-mm@kvack.org, linux-fsdevel@vger.kernel.org, jack@suse.cz Date: Mon, 04 Jun 2018 16:12:32 -0700 Message-ID: <152815395246.39010.12602980036860395531.stgit@dwillia2-desk3.amr.corp.intel.com> In-Reply-To: <152815389835.39010.13253559944508110923.stgit@dwillia2-desk3.amr.corp.intel.com> References: <152815389835.39010.13253559944508110923.stgit@dwillia2-desk3.amr.corp.intel.com> User-Agent: StGit/0.18-2-gc94f MIME-Version: 1.0 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: X-Virus-Scanned: ClamAV using ClamSMTP The current memory_failure() implementation assumes that lock_page() is sufficient for stabilizing page->mapping and that ->mapping->host will not be freed. The dax implementation, on the other hand, relies on xa_lock_irq() for stabilizing the page->mapping relationship and it is not possible to hold the lock over current routines in the memory_failure() path that run under lock_page(). Teach the various memory_failure() helpers to pin the address_space and revalidate page->mapping under xa_lock_irq(mapping->i_pages). Signed-off-by: Dan Williams --- mm/memory-failure.c | 56 +++++++++++++++++++++++++++++++++++---------------- 1 file changed, 38 insertions(+), 18 deletions(-) diff --git a/mm/memory-failure.c b/mm/memory-failure.c index 42a193ee14d3..b6efb78ba49b 100644 --- a/mm/memory-failure.c +++ b/mm/memory-failure.c @@ -179,12 +179,20 @@ EXPORT_SYMBOL_GPL(hwpoison_filter); * ``action required'' if error happened in current execution context */ static int kill_proc(struct task_struct *t, unsigned long addr, - unsigned long pfn, unsigned size_shift, int flags) + struct address_space *mapping, struct page *page, + unsigned size_shift, int flags) { - int ret; + int ret = 0; + + /* revalidate the page before killing the process */ + xa_lock_irq(&mapping->i_pages); + if (page->mapping != mapping) { + xa_unlock_irq(&mapping->i_pages); + return 0; + } pr_err("Memory failure: %#lx: Killing %s:%d due to hardware memory corruption\n", - pfn, t->comm, t->pid); + page_to_pfn(page), t->comm, t->pid); if ((flags & MF_ACTION_REQUIRED) && t->mm == current->mm) { ret = force_sig_mceerr(BUS_MCEERR_AR, (void __user *)addr, @@ -199,6 +207,7 @@ static int kill_proc(struct task_struct *t, unsigned long addr, ret = send_sig_mceerr(BUS_MCEERR_AO, (void __user *)addr, size_shift, t); /* synchronous? */ } + xa_unlock_irq(&mapping->i_pages); if (ret < 0) pr_info("Memory failure: Error sending signal to %s:%d: %d\n", t->comm, t->pid, ret); @@ -316,8 +325,8 @@ static void add_to_kill(struct task_struct *tsk, struct page *p, * wrong earlier. */ static void kill_procs(struct list_head *to_kill, int forcekill, - bool fail, unsigned size_shift, unsigned long pfn, - int flags) + bool fail, unsigned size_shift, struct address_space *mapping, + struct page *page, int flags) { struct to_kill *tk, *next; @@ -330,7 +339,8 @@ static void kill_procs(struct list_head *to_kill, int forcekill, */ if (fail || tk->addr_valid == 0) { pr_err("Memory failure: %#lx: forcibly killing %s:%d because of failure to unmap corrupted page\n", - pfn, tk->tsk->comm, tk->tsk->pid); + page_to_pfn(page), tk->tsk->comm, + tk->tsk->pid); force_sig(SIGKILL, tk->tsk); } @@ -341,9 +351,10 @@ static void kill_procs(struct list_head *to_kill, int forcekill, * process anyways. */ else if (kill_proc(tk->tsk, tk->addr, - pfn, size_shift, flags) < 0) + mapping, page, size_shift, flags) < 0) pr_err("Memory failure: %#lx: Cannot send advisory machine check signal to %s:%d\n", - pfn, tk->tsk->comm, tk->tsk->pid); + page_to_pfn(page), tk->tsk->comm, + tk->tsk->pid); } put_task_struct(tk->tsk); kfree(tk); @@ -429,21 +440,27 @@ static void collect_procs_anon(struct page *page, struct list_head *to_kill, /* * Collect processes when the error hit a file mapped page. */ -static void collect_procs_file(struct page *page, struct list_head *to_kill, - struct to_kill **tkc, int force_early) +static void collect_procs_file(struct address_space *mapping, struct page *page, + struct list_head *to_kill, struct to_kill **tkc, + int force_early) { struct vm_area_struct *vma; struct task_struct *tsk; - struct address_space *mapping = page->mapping; i_mmap_lock_read(mapping); read_lock(&tasklist_lock); for_each_process(tsk) { - pgoff_t pgoff = page_to_pgoff(page); + pgoff_t pgoff; struct task_struct *t = task_early_kill(tsk, force_early); if (!t) continue; + xa_lock_irq(&mapping->i_pages); + if (page->mapping != mapping) { + xa_unlock_irq(&mapping->i_pages); + break; + } + pgoff = page_to_pgoff(page); vma_interval_tree_foreach(vma, &mapping->i_mmap, pgoff, pgoff) { /* @@ -456,6 +473,7 @@ static void collect_procs_file(struct page *page, struct list_head *to_kill, if (vma->vm_mm == t->mm) add_to_kill(t, page, vma, to_kill, tkc); } + xa_unlock_irq(&mapping->i_pages); } read_unlock(&tasklist_lock); i_mmap_unlock_read(mapping); @@ -467,12 +485,12 @@ static void collect_procs_file(struct page *page, struct list_head *to_kill, * First preallocate one tokill structure outside the spin locks, * so that we can kill at least one process reasonably reliable. */ -static void collect_procs(struct page *page, struct list_head *tokill, - int force_early) +static void collect_procs(struct address_space *mapping, struct page *page, + struct list_head *tokill, int force_early) { struct to_kill *tk; - if (!page->mapping) + if (!mapping) return; tk = kmalloc(sizeof(struct to_kill), GFP_NOIO); @@ -481,7 +499,7 @@ static void collect_procs(struct page *page, struct list_head *tokill, if (PageAnon(page)) collect_procs_anon(page, tokill, &tk, force_early); else - collect_procs_file(page, tokill, &tk, force_early); + collect_procs_file(mapping, page, tokill, &tk, force_early); kfree(tk); } @@ -986,7 +1004,8 @@ static bool hwpoison_user_mappings(struct page *p, unsigned long pfn, * there's nothing that can be done. */ if (kill) - collect_procs(hpage, &tokill, flags & MF_ACTION_REQUIRED); + collect_procs(mapping, hpage, &tokill, + flags & MF_ACTION_REQUIRED); unmap_success = try_to_unmap(hpage, ttu); if (!unmap_success) @@ -1012,7 +1031,8 @@ static bool hwpoison_user_mappings(struct page *p, unsigned long pfn, */ forcekill = PageDirty(hpage) || (flags & MF_MUST_KILL); size_shift = compound_order(compound_head(p)) + PAGE_SHIFT; - kill_procs(&tokill, forcekill, !unmap_success, size_shift, pfn, flags); + kill_procs(&tokill, forcekill, !unmap_success, size_shift, mapping, + hpage, flags); return unmap_success; }