From patchwork Tue Oct 4 19:33:58 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Xu X-Patchwork-Id: 12998646 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id DD842C4332F for ; Tue, 4 Oct 2022 19:34:10 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id E399F6B0073; Tue, 4 Oct 2022 15:34:09 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id DC4216B0075; Tue, 4 Oct 2022 15:34:09 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id B51166B007B; Tue, 4 Oct 2022 15:34:09 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0015.hostedemail.com [216.40.44.15]) by kanga.kvack.org (Postfix) with ESMTP id 8E0076B0073 for ; Tue, 4 Oct 2022 15:34:09 -0400 (EDT) Received: from smtpin04.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay08.hostedemail.com (Postfix) with ESMTP id 5D059140EF8 for ; Tue, 4 Oct 2022 19:34:09 +0000 (UTC) X-FDA: 79984267818.04.323B737 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by imf01.hostedemail.com (Postfix) with ESMTP id 0CFFD4001E for ; Tue, 4 Oct 2022 19:34:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1664912048; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=NQaRIORouh5PGNwxNNc/P0MIv99YHmLbB7VcHRYE5ek=; b=WO3qtuQattYKX5xKW+yzgwhdGqBjz8CeTZ94XdTA0OgDL7vRit5hZiFkgw7Sesmgzmppgy KluTf5gpqJhNZCVYOTSUkHduJpnBCe3o8Z4jiRu59/awfrLtMa38pmkfIo1d0q/TGnVR1c G6eZaQeY1yAJone/QSg4XLbDVWjYxKc= Received: from mail-qk1-f198.google.com (mail-qk1-f198.google.com [209.85.222.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_128_GCM_SHA256) id us-mta-546-9huCqXk5OHOtCsSj6GWn6w-1; Tue, 04 Oct 2022 15:34:04 -0400 X-MC-Unique: 9huCqXk5OHOtCsSj6GWn6w-1 Received: by mail-qk1-f198.google.com with SMTP id bm21-20020a05620a199500b006cf6a722b16so12419877qkb.0 for ; Tue, 04 Oct 2022 12:34:04 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date; bh=NQaRIORouh5PGNwxNNc/P0MIv99YHmLbB7VcHRYE5ek=; b=QtaT7dGaBGj4yf2pYdgJKylaq2YJDXak58OcROjJChAO5c2nE4IzMHVv7QrWRlCHBo 3MD9E2MRMcM/JU6LjloQI1edtalTsuiNtNOd6wJuMjImj1nK3EcRWbHvpnBdsmlMCZjE Dr2estBLz/YK5itahX5QZo4/JOVwv0D90ldxJCdL2aK7WyBJ2WUkwvVJeQKJZ0EKpHSG Mf3F/2yElIvGFHrlyy5ipv4IxYCepaS2c7dXfNGl7jgsOEcymFkkcT4jB/F0Q2eGepx6 sLNAyoXTEf5Cfi0N0tyLzRL0Qct4zH6Y4dWNM8iyeyxRorV08lm+UufvQ7ToqPDG+Who qZUA== X-Gm-Message-State: ACrzQf3+YEdFdR6xgeVfuwQ2m+9BiYCV+enjG4QBENMZSpsTLSQfg2Ti O8JMjpLsCAgIOyVUxGOK9usQk9n7JE7TvxJ0Q6t1vj3UOpDx8VltxhHPX7i56yyAVN2/tsJe+G0 DH1oYrmb/+c7KoggAxXRgQJv/2B53O1bQI0R8d8yRW8Jk4nBniAkrpvuC82IT X-Received: by 2002:ad4:5be1:0:b0:496:a686:2bec with SMTP id k1-20020ad45be1000000b00496a6862becmr21051724qvc.85.1664912044005; Tue, 04 Oct 2022 12:34:04 -0700 (PDT) X-Google-Smtp-Source: AMsMyM5tzG6ZNsh+aR3v41H1W2JmcaMFErSNKPMzqwMZhRmPNkNIpkN7hRNRj2Y0ZR1OtrRNmgqlGQ== X-Received: by 2002:ad4:5be1:0:b0:496:a686:2bec with SMTP id k1-20020ad45be1000000b00496a6862becmr21051683qvc.85.1664912043713; Tue, 04 Oct 2022 12:34:03 -0700 (PDT) Received: from x1n.redhat.com (bras-base-aurron9127w-grc-46-70-31-27-79.dsl.bell.ca. [70.31.27.79]) by smtp.gmail.com with ESMTPSA id z5-20020a05622a028500b00342fb07944fsm13299811qtw.82.2022.10.04.12.34.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 04 Oct 2022 12:34:03 -0700 (PDT) From: Peter Xu To: linux-mm@kvack.org, linux-kernel@vger.kernel.org Cc: Mike Rapoport , peterx@redhat.com, David Hildenbrand , Andrew Morton , Andrea Arcangeli , Nadav Amit , Axel Rasmussen , Mike Kravetz Subject: [PATCH v3 1/3] mm/hugetlb: Fix race condition of uffd missing/minor handling Date: Tue, 4 Oct 2022 15:33:58 -0400 Message-Id: <20221004193400.110155-2-peterx@redhat.com> X-Mailer: git-send-email 2.37.3 In-Reply-To: <20221004193400.110155-1-peterx@redhat.com> References: <20221004193400.110155-1-peterx@redhat.com> MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-type: text/plain ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1664912049; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=NQaRIORouh5PGNwxNNc/P0MIv99YHmLbB7VcHRYE5ek=; b=3DSeKMQ9PVOs7JIz+p+MdrmbNgeOJ4upjqIzwhdd1YnJaF4PbVmYDLSWWZlDnu/g2lUCoe C8hZcC9QZm6pGJr9sHWOKWt/c+UnboAjn7gEVt0YBFrENZu3ueojRhtYBr7Fv30eWlksQM 8+u3ugMHEmOpaUQNTj582rL+2CL6HfQ= ARC-Authentication-Results: i=1; imf01.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b=WO3qtuQa; spf=pass (imf01.hostedemail.com: domain of peterx@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=peterx@redhat.com; dmarc=pass (policy=none) header.from=redhat.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1664912049; a=rsa-sha256; cv=none; b=vojbuMXzlpHJpzJAznhQbnGPI6ELcSI2E1ujr7cpgR1tZuEIcb1kbQjm9RKrhcoo2TIYpi LH5/rPWjMKfBHZXMs1HbniejkgsaGhD+AlsFtdjVDiXUrCX5HtwY8qZ3gZu6G20cSrRyew 0T80CGvFjAVVa4aesKkbckTRtTBx8cE= X-Stat-Signature: yqfi73oewfozy8i9puorwtmmya13cgtx X-Rspamd-Queue-Id: 0CFFD4001E Authentication-Results: imf01.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b=WO3qtuQa; spf=pass (imf01.hostedemail.com: domain of peterx@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=peterx@redhat.com; dmarc=pass (policy=none) header.from=redhat.com X-Rspamd-Server: rspam07 X-Rspam-User: X-HE-Tag: 1664912048-851723 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: After the recent rework patchset of hugetlb locking on pmd sharing, kselftest for userfaultfd sometimes fails on hugetlb private tests with unexpected write fault checks. It turns out there's nothing wrong within the locking series regarding this matter, but it could have changed the timing of threads so it can trigger an old bug. The real bug is when we call hugetlb_no_page() we're not with the pgtable lock. It means we're reading the pte values lockless. It's perfectly fine in most cases because before we do normal page allocations we'll take the lock and check pte_same() again. However before that, there are actually two paths on userfaultfd missing/minor handling that may directly move on with the fault process without checking the pte values. It means for these two paths we may be generating an uffd message based on an unstable pte, while an unstable pte can legally be anything as long as the modifier holds the pgtable lock. One example, which is also what happened in the failing kselftest and caused the test failure, is that for private mappings wr-protection changes can happen on one page. While hugetlb_change_protection() generally requires pte being cleared before being changed, then there can be a race condition like: thread 1 thread 2 -------- -------- UFFDIO_WRITEPROTECT hugetlb_fault hugetlb_change_protection pgtable_lock() huge_ptep_modify_prot_start pte==NULL hugetlb_no_page generate uffd missing event even if page existed!! huge_ptep_modify_prot_commit pgtable_unlock() Fix this by recheck the pte after pgtable lock for both userfaultfd missing & minor fault paths. This bug should have been around starting from uffd hugetlb introduced, so attaching a Fixes to the commit. Also attach another Fixes to the minor support commit for easier tracking. Note that userfaultfd is actually fine with false positives (e.g. caused by pte changed), but not wrong logical events (e.g. caused by reading a pte during changing). The latter can confuse the userspace, so the strictness is very much preferred. E.g., MISSING event should never happen on the page after UFFDIO_COPY has correctly installed the page and returned. Cc: Andrea Arcangeli Cc: Mike Kravetz Cc: Axel Rasmussen Cc: Nadav Amit Fixes: 1a1aad8a9b7b ("userfaultfd: hugetlbfs: add userfaultfd hugetlb hook") Fixes: 7677f7fd8be7 ("userfaultfd: add minor fault registration mode") Co-developed-by: Mike Kravetz Reviewed-by: Mike Kravetz Signed-off-by: Peter Xu --- mm/hugetlb.c | 59 +++++++++++++++++++++++++++++++++++++++++++++------- 1 file changed, 52 insertions(+), 7 deletions(-) diff --git a/mm/hugetlb.c b/mm/hugetlb.c index 6022dea6a634..1f059acc38f3 100644 --- a/mm/hugetlb.c +++ b/mm/hugetlb.c @@ -5524,6 +5524,23 @@ static inline vm_fault_t hugetlb_handle_userfault(struct vm_area_struct *vma, return handle_userfault(&vmf, reason); } +/* + * Recheck pte with pgtable lock. Returns true if pte didn't change, or + * false if pte changed or is changing. + */ +static bool hugetlb_pte_stable(struct hstate *h, struct mm_struct *mm, + pte_t *ptep, pte_t old_pte) +{ + spinlock_t *ptl; + bool same; + + ptl = huge_pte_lock(h, mm, ptep); + same = pte_same(huge_ptep_get(ptep), old_pte); + spin_unlock(ptl); + + return same; +} + static vm_fault_t hugetlb_no_page(struct mm_struct *mm, struct vm_area_struct *vma, struct address_space *mapping, pgoff_t idx, @@ -5564,10 +5581,33 @@ static vm_fault_t hugetlb_no_page(struct mm_struct *mm, if (idx >= size) goto out; /* Check for page in userfault range */ - if (userfaultfd_missing(vma)) - return hugetlb_handle_userfault(vma, mapping, idx, - flags, haddr, address, - VM_UFFD_MISSING); + if (userfaultfd_missing(vma)) { + /* + * Since hugetlb_no_page() was examining pte + * without pgtable lock, we need to re-test under + * lock because the pte may not be stable and could + * have changed from under us. Try to detect + * either changed or during-changing ptes and retry + * properly when needed. + * + * Note that userfaultfd is actually fine with + * false positives (e.g. caused by pte changed), + * but not wrong logical events (e.g. caused by + * reading a pte during changing). The latter can + * confuse the userspace, so the strictness is very + * much preferred. E.g., MISSING event should + * never happen on the page after UFFDIO_COPY has + * correctly installed the page and returned. + */ + if (!hugetlb_pte_stable(h, mm, ptep, old_pte)) { + ret = 0; + goto out; + } + + return hugetlb_handle_userfault(vma, mapping, idx, flags, + haddr, address, + VM_UFFD_MISSING); + } page = alloc_huge_page(vma, haddr, 0); if (IS_ERR(page)) { @@ -5633,9 +5673,14 @@ static vm_fault_t hugetlb_no_page(struct mm_struct *mm, if (userfaultfd_minor(vma)) { unlock_page(page); put_page(page); - return hugetlb_handle_userfault(vma, mapping, idx, - flags, haddr, address, - VM_UFFD_MINOR); + /* See comment in userfaultfd_missing() block above */ + if (!hugetlb_pte_stable(h, mm, ptep, old_pte)) { + ret = 0; + goto out; + } + return hugetlb_handle_userfault(vma, mapping, idx, flags, + haddr, address, + VM_UFFD_MINOR); } }