From patchwork Sat Oct 5 06:41:14 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Lorenzo Stoakes X-Patchwork-Id: 13823126 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 208ACCF8869 for ; Sat, 5 Oct 2024 06:41:38 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 4721B6B0196; Sat, 5 Oct 2024 02:41:38 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 421C56B0198; Sat, 5 Oct 2024 02:41:38 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 24E326B0199; Sat, 5 Oct 2024 02:41:38 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0012.hostedemail.com [216.40.44.12]) by kanga.kvack.org (Postfix) with ESMTP id EE5466B0196 for ; Sat, 5 Oct 2024 02:41:37 -0400 (EDT) Received: from smtpin20.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay07.hostedemail.com (Postfix) with ESMTP id 5B014160122 for ; Sat, 5 Oct 2024 06:41:37 +0000 (UTC) X-FDA: 82638602634.20.A3D710E Received: from mx0b-00069f02.pphosted.com (mx0b-00069f02.pphosted.com [205.220.177.32]) by imf09.hostedemail.com (Postfix) with ESMTP id 16B6714000A for ; Sat, 5 Oct 2024 06:41:33 +0000 (UTC) Authentication-Results: imf09.hostedemail.com; dkim=pass header.d=oracle.com header.s=corp-2023-11-20 header.b=VDOFMdxd; dkim=pass header.d=oracle.onmicrosoft.com header.s=selector2-oracle-onmicrosoft-com header.b=m10FjYbh; dmarc=pass (policy=reject) header.from=oracle.com; arc=pass ("microsoft.com:s=arcselector10001:i=1"); spf=pass (imf09.hostedemail.com: domain of lorenzo.stoakes@oracle.com designates 205.220.177.32 as permitted sender) smtp.mailfrom=lorenzo.stoakes@oracle.com ARC-Seal: i=2; s=arc-20220608; d=hostedemail.com; t=1728110470; a=rsa-sha256; cv=pass; b=zcpfjkeOztgQ+U8udReXMSTlYIVXy5NLL6H9eV+JYgOH0JI8vfBI559ILzbV+EdWWyslCG D6s65NPcLmJFpGWxrDlDbdcdNetM/E0xpiWJSDTADEXuIr5jCg2pYd4npn7/cEexjvL4MX +uoyt3Tz163BYkAWL+SQNEpwBvVr7V8= ARC-Authentication-Results: i=2; imf09.hostedemail.com; dkim=pass header.d=oracle.com header.s=corp-2023-11-20 header.b=VDOFMdxd; dkim=pass header.d=oracle.onmicrosoft.com header.s=selector2-oracle-onmicrosoft-com header.b=m10FjYbh; dmarc=pass (policy=reject) header.from=oracle.com; arc=pass ("microsoft.com:s=arcselector10001:i=1"); spf=pass (imf09.hostedemail.com: domain of lorenzo.stoakes@oracle.com designates 205.220.177.32 as permitted sender) smtp.mailfrom=lorenzo.stoakes@oracle.com ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1728110470; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:in-reply-to: references:dkim-signature; bh=yHIp+Ttfytb7zmionUFzdEy8ZUaJVxCqNEMeg3kp04k=; b=PIQrEHwRuOd8aalru8N+tNlw/4rDvuQQWLT/us0TsKoGO5+W5g3mtH/zq0xkp0/6wCFK3U Q2QwvPZ80fWoPqCOTBxHX1toIQK/DTtx8IgEu1j2iB2htxGk7JpnC1SYzFuhy//LlMrXI5 bdh8BoxrYzexesXivYAK/D4YRz2majU= Received: from pps.filterd (m0333520.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 4956J7dn028698; Sat, 5 Oct 2024 06:41:29 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=cc :content-transfer-encoding:content-type:date:from:message-id :mime-version:subject:to; s=corp-2023-11-20; bh=yHIp+Ttfytb7zmio nUFzdEy8ZUaJVxCqNEMeg3kp04k=; b=VDOFMdxdThSJEG1cemMnxI/ToZPPzL8b dImDcpTDXiIQbr51Jzk/gdPhz10PyBF1tt8rRb4lkmXLCyyCXHVSySLJKxrHsgN8 z8aDlZgkTyvIydTs6h+rCB/5QP9AKBrlfTD7cJQNm/sHKF6LkQhSNtv2P/dKcRFX ymsLhs7oHjA2Bjz9hzSoOAKWv9g0aIh33y2vLdRc5x9rMNfS1gKgYaquLYkP5nZ9 FozVcLGItfZi4BVItXksEAZrROR3QjEj4fl3nqR7g6hv/PsAvi6mtYi7LKOsY5F4 +RtPw5wUFLwrXv1BRfmLr6mEozyi7emsenk60eivXeZTRysLAoe2lA== Received: from iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta03.appoci.oracle.com [130.35.103.27]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 423034g0bg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sat, 05 Oct 2024 06:41:29 +0000 (GMT) Received: from pps.filterd (iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (8.18.1.2/8.18.1.2) with ESMTP id 49566w58004682; Sat, 5 Oct 2024 06:41:28 GMT Received: from nam11-bn8-obe.outbound.protection.outlook.com (mail-bn8nam11lp2171.outbound.protection.outlook.com [104.47.58.171]) by iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 422uw44dd6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sat, 05 Oct 2024 06:41:28 +0000 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=dV0nGBWqsSiSgUKfqEX2G5g5e8h3ySoJja4E/nvhkBt45KZiRY8jCgcjpI8oPClOXQoJqJp6saRPSSWz9SZ4bRKg7WpCiIY8VRK6uLn6gew/w15C8j+h3WWe9fgWhRrRHLzbS4IYG3Kl/0Kt7svP2QN0bl8wjIChpmFmYwpWn8yoJd2nPEn9XYGPCX+gS6ilDLhuGji9cU3cwsPFgpZmMtxBelgZyEG8ld4onAWWkuY/uW362Qv+hUwo9cy0MzyRSjnPHZ0NJVw8B1fGtNS2NSyndkbTk6q+ceVCYKad0KpbseNs5xKMyWqx+MzFbRkRcg03LafxD3Och+XBqOWtMQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=yHIp+Ttfytb7zmionUFzdEy8ZUaJVxCqNEMeg3kp04k=; b=isoz8F1g5NAhXYMHfJDgJpK4Lop2NAB6FdVGoPIUnikAt7Nw0jNKx7f6Lr8QmDBnyDRalZLCecG5r14ACmO02Mgrw94oyHpnA9wpNwT6oi7gHTb92Zm3csDofQvb04qXLpz/yymWil+nv9pZbl/RqS4gAxBAQhQsohHhMwB4pGRgBYhPv7hNe8JGTnbXTGXks5UUtN/dnYK4SmJiarTwzL/NmAxZ18WTXzYJHGnVw5ziM8N8qvf54w9KE7Cn1c4ettanX0mlQoENwuZel1YzkvLffGoF0YVmvCzrTmA8WAMsdjCm1JNXGEZMltvyhrSiWlx2mXeTciM3jP1YUCaqYQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=oracle.com; dmarc=pass action=none header.from=oracle.com; dkim=pass header.d=oracle.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.onmicrosoft.com; s=selector2-oracle-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=yHIp+Ttfytb7zmionUFzdEy8ZUaJVxCqNEMeg3kp04k=; b=m10FjYbhiPSc+7ixupuBmBHdQYGXIH/nFgE75G2ftAy6iJkIko5zSE0RUnaJwtTWM1xFzoccYXVOWF1zRUjgR8h0deIfQp/yfwmg6PfSJ9ZFEwM48LHbvAp4D1KME2VuNR4BJxXEia4p6A09zHTYsh+I5hUA9Lkpv++VnBJBEew= Received: from SJ0PR10MB5613.namprd10.prod.outlook.com (2603:10b6:a03:3d0::5) by MN6PR10MB8192.namprd10.prod.outlook.com (2603:10b6:208:4fd::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8026.19; Sat, 5 Oct 2024 06:41:26 +0000 Received: from SJ0PR10MB5613.namprd10.prod.outlook.com ([fe80::4239:cf6f:9caa:940e]) by SJ0PR10MB5613.namprd10.prod.outlook.com ([fe80::4239:cf6f:9caa:940e%5]) with mapi id 15.20.8026.019; Sat, 5 Oct 2024 06:41:26 +0000 From: Lorenzo Stoakes To: Andrew Morton Cc: "Liam R . Howlett" , Matthew Wilcox , Vlastimil Babka , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Sidhartha Kumar , Bert Karwatzki , Mikhail Gavrilov Subject: [PATCH hotfix 6.12] maple_tree: correct tree corruption on spanning store Date: Sat, 5 Oct 2024 07:41:14 +0100 Message-ID: <20241005064114.42770-1-lorenzo.stoakes@oracle.com> X-Mailer: git-send-email 2.46.2 X-ClientProxiedBy: LO4P123CA0299.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:196::16) To SJ0PR10MB5613.namprd10.prod.outlook.com (2603:10b6:a03:3d0::5) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: SJ0PR10MB5613:EE_|MN6PR10MB8192:EE_ X-MS-Office365-Filtering-Correlation-Id: 77a10436-ce5d-4ce5-e9c5-08dce508bc3e X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|10070799003|366016|376014; X-Microsoft-Antispam-Message-Info: +RNpb0BKc1ER35U1T2lY8cyP+ASH4eMq3919+/gA2m5gGyM5u82cqIHc5G0cvM8TjtZc0m/+pAbh/DvpUrqCaD6QzbeKKAVNY0BdRUbeIAG5HbONvxJjvZ7mH2SEC9FZQiBG4MulTJOQv3tbxO3V1ixQh2JGcKOjLTDZLOblxAKDP5vCkReD41AdoIrusImr9voILixikIe/atqiLwc5TT3WVB2rvOBsTViRqTQZ+k8FGszBJfxNVx4LfVRyVePn2xwWvZp2w3S2K1QAphr81uBIk45gWh7IRztIt/6bqAKKhr6S3TYXKRryAptZdTqR1mRindtfiEULpH9MY1moAXIeSMMzUobXLWvBSvUmGpwJ7N1QGw6DiozOtxEA54g0Wio4zh26zmuGVqAsbfr9Kk240NXCYUrOoFIx6voEMp+zcRdWYzDg6L7GfsFsVTb3ALIU9b/0K+egRW++QZNMDd9RmbKykujO6bfkeBolvbCSNkFeUuFXsJGnqwDzfrXeRgXJti72QAtbw9cgjMvAOSX1/3cToILcd6rQXOJu7QY/JTIqrcraiXIL+R2rNNvj8suSU+KF8xyFeCAaNwO28KghejrQn7MAjtaz8DJLa10b5MaMq4+yb6vM5K4HU0D7552gzjHkPT+0xNctSqe7oS7AleYznXfZ++Yj0XTpWY006s9mrG7lum2MkOv0lF2IBHQgVksInQ2cIwFYn5e75w9eVtj4RKKBnV4rmytY1Zw1IJ2uWmd9qb05c3xYnsZshbAHzUjDcZRGAksTv8B1V7DamXTuut9MjKnxSVf0wcIsHgRn1YaqRw/Vpr0MwWe+r2bFCCBK4j/e+6zkmeXzJtfLwcMwgPXougKIZeInh7oOa7PDIjlneUs+GnhZccyzT5URQ9OEtTZzH+GZnyiUdmNqmyyRthxBNLFPmmOKEv78x8WwybI/yhxHyrzhOVZsM0Zgx+iaN9UPNbeuCqZor+GHlHCRZA7On1rp/n6TEAby1JaRdsJTREchRuLi0WL7RHvGyqOmO7Tz7hW77iwjZhk9zELvMwTttVShfXRpPFKSmg5T/Xdon2VZnH3ElDLB6VEeVlcPnNOqNr+RmGfikBF1Vd9rzT9/PSlUxttN2OwSpz+vCqSUdvckM5u3s3Jd+eRGfO3fAhPZmlM/ujNzRXQcpDmJ9km9ZVmXlXG7PU9ttiQQd9ebcPAtuZhh4PiMjpjMT9EIF/XewG7c/Koc6vm42kOcR7InSGXICdyECwI= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SJ0PR10MB5613.namprd10.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(10070799003)(366016)(376014);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: m329Tnm058/s7PHQpKMc7s3lrqhCmNX/96QFelni69ZsN0OMYsJgPWd4+1ZsMf573fUIV6QpzGxcxZkwmT4Zprqz8vgW5RkQcTQL99EVfbSWvfWTFvaBd7/IL2aaLBWSDIw0kwoYsM+hQr5PYAsVDE4uFFXvE+uhWeEbdPKaPvCT+0h0w6crt0qY19BMDh91N+fIWydaHfD4cDJvzy2+7SRFRa1LiKX8j3mzICpz+4YQ0Z2wbMYwu5SHC9Kn/rBTU1bR6p9RIgz+L3IUeD0iX65rNtY3ogFuNS2lPCKOxK6w4IcRQrP8dTzQin6U/Eq8rtv86N3t8E13/W5pnjj9uYfky6OtxOP3BG2F4Sw8IF6cO++iLdA748gUPurmHXMzkoysHG7RAeM8HjA2QDyNhWmDMtBVgm2f6oO4CyrGapnHgRqCEfo0Fi5223R0S0Lw3DYiZ2TtbKliX3KkNdoBgn88t2cvXZeVmA+6f/hUcH9Xfgsg/2UuhvKN0m057/wG6IReM2fInJ23CZ++Tg49+5YcqEuWRB0nOZ88DgMTSIrTfKFwtvF1wvD3oCY5YoIJ6/vHlnhwaDTgNRSzAi7liYNs30CLQ769XXwcevs5oQDwO2uBgyaubpFZBthJL7YMZKvgQG4oEBLEDVVWF4ke4udFRUUzVEfcBqnGYKs32SacRVG9D7Rq1x4gUGmKqzUbMI+zTxOsF2jEb5DsttV7WV1dIOLcvaDh2jPv4RyjU7Rqc5xAku9mAUtEsoBxljypdM1t1NTbs+gXQn7O5I07qlZoGtbY62vzEtsyISRDrvxefJlzekmcI2zAuvNwlGrtqBSP0tvXRRGobD8G+viRjM9fOyrBPHTD4nnG+yz76FVK3nrsdutqbDPcDNuiM4iFcYBFgklkVtkxk67KZYFtGzcfHhmpcElyEv1S4EoRwPmP+Evm4JlMI1xYK/aPOneuBoV+96gqExIaFw6jqIR/3fQJFQwPQBWW5pYZYgMwVPRD1iyUopZW61I5Z0wx/nPHasBw0MRBc7b3Lttgo+6Ogvo96rm324cwG+8r9bBs08P4tFMMLHFQl1a1j5EFRXGK531+dd7Oo+Cvu71GixLo4FFWURZ5EiXLqqfeHRD39FKgmm3deMchIPaaB/fYYMMHv3ZdwBNqdXkf4ozR2nqcn1cnvGJSRf9pJssTR8XCT9mJV6D3EzygjEPkkkWZMAi4YUYdqgbHtE7UNIgkt0xn3S09jUFtWMNoHOuKeuLLBMXGMz2jpFpwqs+Lr/r+JdjbnDfvVGZPZW34psSlrvM61UFvfQsedjebwQiz16gDDAW0fXcKyoP96Q4T96Xsvmx8bUAwP8WJme9ubk2Fj8LDt/qfY0B6UCHDsm7aYbpO9Hfq/z8euGk9giQCnb3PmYlNLkxONtiv4dRiMVGTrgaRNBffSVgarqQT+GHXXOHHC4wEZl8YarAbZvefyT0Fsg3ng54X4kqfoBWgSO4YxRf0Q1XLhkquQYonzLFe/Lpaq0JZVh+wFC2gXDaomBuys+zgwF0b576fET0P372J+/+TDe15yOi1m9A3kUR1f1Ol9yjUP3wwtP1T05mJLKgBz0QAhZ84V9I8EAW45io4o5VyhDi9vCFa9v2uRysNaIhn08n5WfxrCKt4RPnuGE4IkgJmYCKtgQMsMS4MmxRmFiMOkg== X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: 4cpZnTWH70VgRibR9gAG6YJ1Cj7eWXQABeJI2M06mlB2MTAleZDhLAI3LJao7oiTSZY49QS2pV+elGVhGdLUaol2fO4FJoxAbdZRNBiLinUnDzAKI2tF/9isqbRCNfotU0zCdEX8OGCDZ+hYzytFaGQ8qSVeitoEg3GX3MSsNvWtB7wCgb7h3imf91rNTAE2dnVVgABpMPQrwFTMS39M5sGyQ4IJkAaSX0HYsL3ZIWueCfeh9lhfmTOz71GINhT6Jyif8EEsJLTk2lxGC1/cCWDqC42T3C8sfKIl+9KaCWYiTuCrU/VCq6ul+4RpnRH+eCVtJx83j+RSMv95ipkwo7rF2pg7BP7JQIX16PFRIyVupFBWK8NMh7l2q035tMHvxZCVvS3hS0YJKLROs2uVtCXVjJz0nhITxfrcOu7h+FCdhoMPcEf6Ha/1iiHxeXSB1th9auxwtLbVeq/W4LTahXal4G+uHgOs7xbHJzBluu5NazM1K0RtQr8H+5XJ/AFyjW+1YU9VuemWuxP7o+05M34qWsO9BZswH309lspyIv0iefGf49NNIxPXI+RD/Z1cHPsR3uAiU1698weL3ZYTWFhl34V4eEOL5shmas+Yj84= X-OriginatorOrg: oracle.com X-MS-Exchange-CrossTenant-Network-Message-Id: 77a10436-ce5d-4ce5-e9c5-08dce508bc3e X-MS-Exchange-CrossTenant-AuthSource: SJ0PR10MB5613.namprd10.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Oct 2024 06:41:26.2694 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 4e2c6054-71cb-48f1-bd6c-3a9705aca71b X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: ihubEKXxTgDrvicgqKhUVOeSpKo34WQzytt/Enc74YjBgLLa4v3ZGQcsHfAtiOe2MdEMd7KrHvqTbMV6J/6mpBp4SACK3jIziI0EzXJ8hBA= X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN6PR10MB8192 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1051,Hydra:6.0.680,FMLib:17.12.62.30 definitions=2024-10-05_06,2024-10-04_01,2024-09-30_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 bulkscore=0 malwarescore=0 suspectscore=0 mlxscore=0 phishscore=0 adultscore=0 spamscore=0 mlxlogscore=999 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2409260000 definitions=main-2410050046 X-Proofpoint-GUID: _1-R_h9JdQSS9AILaQIC04o6psiGEaNC X-Proofpoint-ORIG-GUID: _1-R_h9JdQSS9AILaQIC04o6psiGEaNC X-Rspam-User: X-Stat-Signature: niyxe8aswatmijyibrcc9cp1gj6gika8 X-Rspamd-Queue-Id: 16B6714000A X-Rspamd-Server: rspam02 X-HE-Tag: 1728110493-475054 X-HE-Meta: U2FsdGVkX1/Ge24IdhEEnAesx/Rvbq9eczCZ2S0hvh6LnwXEmv6yP1oqai6jDvYtIsqGIg6qmVgGbXCOvaa4U3mIaueqlSERxKn8KXkHm9ZX8eNNpIG0dKMVDljQGyWL8Iegg8fCOLfZnNsXhSs1NpLYEp47w9V5bmoekTPeun+DIcGbwvLeLETIIQuPZ8aio4xLq5VWKoRZRnHc02/38yrXu5oIWvuTrVC5VUWZ9Y6dtZTswGGlqq+i7Zfqb8EuDF8UrHvhyRvUNKfG3yBcYuG3td9nmR9kz70pvkIzvJivPXmjo87HMbi/hJRTRZzobCoPNkJ8UnpcudqCqhUuB4fdZjJXzQBXRWewVlIAbcVoDP9XTIsrm235/zyCtetH9WcJjCvAvGQVJIu5GL1FItlhjcyEwne4zfcjNHng9PuHAegiRDPGU9UH8WMjIMyC66lp+T2e0MKw7xT3Zz375j1Kxqb8yzO03jIpBrCGcejemrLfgs4jM1m7Z/bXGbkCyZZz5tBDQ+OWFLoqUyeQzgJDh/0w6T69NXFltTRDo6Cv7Z8uT7l4Es3x56fQxyFzf7YeG2iMlbCs4nOIWnByrCtLvjc4VRarVKSaTdW8pdSHzgwx1KMT0ocsHeyxmBeX3hXdIbuoMbViO8vRLLeChn3KtAluE4hU66tawICgIcNzInaYOC0n0wr/v5uJRlOmXMpG7SIcisGEDTisUBgtG1D1MoWoUEsx0S5VJnCTV67YiINJf0FmH5jUzoaUzzx14qYq/EIi5+0ZWmi1jrVkiXjVXvHvppB+XPqZdxS6WGKDaU7GeeqjS4lEzC9IK1hJwwsxlNDBEQRu5bAA+yuPENOSET4+vD8fKDFIW3uomgmqJNnt2MT7Ob1kFLpm+PcF+oPM1ALvYiOi7RoxwyKPehMqGjqtgX/R+7T7STJy0DZYjZHBi6KI/TyAmwzQz0Xf7xr8S36OcmeAa2yW9i4 NjEc6SCH H6dwkt86US7nN1Wibi7LMQcrewwejaaO89jGMvfOvaHD6gS87ta9hvxeydt5XGBqReqpA/BlkM3QbQYZJZOLuek3fl3w5Z9AxVmaGJUJAoffUYhCEwzHYPk2leRuV1FVUkzuDY363xzQAiK+eWj5O8aY6NPJvZKFLvna0wWMzRHQGAZBjzAX5XVM0j2rDZT+k0LOfHbSAxBxIcDOi/ziJMLalUPrH4IKwdUEVgoTOnVn+s7vhcn79tsVoH/wFVIvxmW+XgTJPH/n0E39jsDwHUnEkbqIxFKTd6RrcvIeXmOvfdBq6O5797fiKzeU1wSKY6VQixOgkBG3/LvDV+QUXv0QgV3W0LCxCNhRwxR/XW7yLrVEeuTL34akTqb509sghZ5zD2KKy8YkE0WBxN+gQ+zKCKfJ++ob6SjLlvsfO1UegqdprrnH1pIHtEn3vBRuW4TE1bBSG07ZUBdbHa7BCtZKeJzTDptuRgEUq3qrncyE9CCOGRSsDbmU2cL0BUm/659MdjQDKLQko8qvkVVcGabbUIhI5GLQZjq2+AEiX0BbK4CJtmjomEVge6Cq78VO6Ju+gjrCPdZq7ZhzeaKwS7o6BknNlclSMmkiYLRv1OWlxUhWlPfeu4ogKEUw+d1BRazK1piMh4R6NNTbyDZrPdAxAbZ8rlFhQLgAVW8rR2RJgxxP2f8PwXWaUAQ== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: Writing a data range into a maple tree may involve overwriting a number of existing entries that span across more than one node. Doing so invokes a 'spanning' store. Performing a spanning store across two leaf nodes in a maple tree in which entries are overwritten is achieved by first initialising a 'big' node, which will store the coalesced entries between the two nodes comprising entries prior to the newly stored entry, the newly stored entry, and subsequent entries. This 'big node' is then merged back into the tree and the tree is rebalanced, replacing the entries across the spanned nodes with those contained in the big node. The operation is performed in mas_wr_spanning_store() which starts by establishing two maple tree state objects ('mas' objects) on the left of the range and on the right (l_mas and r_mas respectively). l_mas traverses to the beginning of the range to be stored in order to copy the data BEFORE the requested store into the big node. We then insert our new entry immediately afterwards (both the left copy and the storing of the new entry are combined and performed by mas_store_b_node()). r_mas traverses to the populated slot immediately after, in order to copy the data AFTER the requested store into the big node. This copy of the right-hand node is performed by mas_mab_cp() as long as r_mas indicates that there's data to copy, i.e. r_mas.offset <= r_mas.end. We traverse r_mas to this position in mas_wr_node_walk() using a simple loop: while (offset < count && mas->index > wr_mas->pivots[offset]) offset++; Note here that count is determined to be the (inclusive) index of the last node containing data in the node as determined by ma_data_end(). This means that even in searching for mas->index, which will have been set to one plus the end of the target range in order to traverse to the next slot in mas_wr_spanning_store(), we will terminate the iteration at the end of the node range even if this condition is not met due to the offset < count condition. The fact this right hand node contains the end of the range being stored is why we are traversing it, and this loop is why we appear to discover a viable range within the right node to copy to the big one. However, if the node that r_mas traverses contains a pivot EQUAL to the end of the range being stored, and this is the LAST pivot contained within the node, something unexpected happens: 1. The l_mas traversal copy and insertion of the new entry in the big node is performed via mas_store_b_node() correctly. 2. The traversal performed by mas_wr_node_walk() means our r_mas.offset is set to the offset of the entry equal to the end of the range we store. 3. We therefore copy this DUPLICATE of the final pivot into the big node, and insert this DUPLICATE entry, alongside its invalid slot entry immediately after the newly inserted entry. 4. The big node containing this duplicated is inserted into the tree which is rebalanced, and therefore the maple tree becomes corrupted. Note that if the right hand node had one or more entries with pivots of greater value than the end of the stored range, this would not happen. If it contained entries with pivots of lesser value it would not be the right node in this spanning store. This appears to have been at risk of happening throughout the maple tree's history, however it seemed significantly less likely to occur until recently. The balancing of the tree seems to have made it unlikely that you would happen to perform a store that both spans two nodes AND would overwrite precisely the entry with the largest pivot in the right-hand node which contains no further larger pivots. The work performed in commit f8d112a4e657 ("mm/mmap: avoid zeroing vma tree in mmap_region()") seems to have made the probability of this event much more likely. Previous to this change, MAP_FIXED mappings which were overwritten would first be cleared before any subsequent store or importantly - merge of surrounding entries - would be performed. After this change, this is no longer the case, and this means that, in the worst case, a number of entries might be overwritten in combination with a merge (and subsequent overwriting expansion) between both the prior entry AND a subsequent entry. The motivation for this change arose from Bert Karwatzki's report of encountering mm instability after the release of kernel v6.12-rc1 which, after the use of CONFIG_DEBUG_VM_MAPLE_TREE and similar configuration options, was identified as maple tree corruption. After Bert very generously provided his time and ability to reproduce this event consistently, I was able to finally identify that the issue discussed in this commit message was occurring for him. The solution implemented in this patch is: 1. Adjust mas_wr_walk_index() to return a boolean value indicating whether the containing node is actually populated with entries possessing pivots equal to or greater than mas->index. 2. When traversing the right node in mas_wr_spanning_store(), use this value to determine whether to try to copy from the right node - if it is not populated, then do not do so. This passes all maple tree unit tests and resolves the reported bug. Reported-and-tested-by: Bert Karwatzki Closes: https://lore.kernel.org/all/20241001023402.3374-1-spasswolf@web.de/ Reported-by: Mikhail Gavrilov Closes: https://lore.kernel.org/all/CABXGCsOPwuoNOqSMmAvWO2Fz4TEmPnjFj-b7iF+XFRu1h7-+Dg@mail.gmail.com/ Fixes: 54a611b60590 ("Maple Tree: add new data structure") Signed-off-by: Lorenzo Stoakes --- lib/maple_tree.c | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) -- 2.46.2 diff --git a/lib/maple_tree.c b/lib/maple_tree.c index 20990ecba2dd..f72e1a5a4dfa 100644 --- a/lib/maple_tree.c +++ b/lib/maple_tree.c @@ -2196,6 +2196,8 @@ static inline void mas_node_or_none(struct ma_state *mas, /* * mas_wr_node_walk() - Find the correct offset for the index in the @mas. + * If @mas->index cannot be found within the containing + * node, we traverse to the last entry in the node. * @wr_mas: The maple write state * * Uses mas_slot_locked() and does not need to worry about dead nodes. @@ -3532,6 +3534,12 @@ static bool mas_wr_walk(struct ma_wr_state *wr_mas) return true; } +/* + * Traverse the maple tree until the offset of mas->index is reached. + * + * Return: Is this node actually populated with entries possessing pivots equal + * to or greater than mas->index? + */ static bool mas_wr_walk_index(struct ma_wr_state *wr_mas) { struct ma_state *mas = wr_mas->mas; @@ -3540,8 +3548,11 @@ static bool mas_wr_walk_index(struct ma_wr_state *wr_mas) mas_wr_walk_descend(wr_mas); wr_mas->content = mas_slot_locked(mas, wr_mas->slots, mas->offset); - if (ma_is_leaf(wr_mas->type)) - return true; + if (ma_is_leaf(wr_mas->type)) { + unsigned long pivot = wr_mas->pivots[mas->offset]; + + return pivot == 0 || mas->index <= pivot; + } mas_wr_walk_traverse(wr_mas); } @@ -3701,6 +3712,7 @@ static noinline void mas_wr_spanning_store(struct ma_wr_state *wr_mas) struct maple_big_node b_node; struct ma_state *mas; unsigned char height; + bool r_populated; /* Left and Right side of spanning store */ MA_STATE(l_mas, NULL, 0, 0); @@ -3742,7 +3754,7 @@ static noinline void mas_wr_spanning_store(struct ma_wr_state *wr_mas) r_mas.last++; r_mas.index = r_mas.last; - mas_wr_walk_index(&r_wr_mas); + r_populated = mas_wr_walk_index(&r_wr_mas); r_mas.last = r_mas.index = mas->last; /* Set up left side. */ @@ -3766,7 +3778,7 @@ static noinline void mas_wr_spanning_store(struct ma_wr_state *wr_mas) /* Copy l_mas and store the value in b_node. */ mas_store_b_node(&l_wr_mas, &b_node, l_mas.end); /* Copy r_mas into b_node. */ - if (r_mas.offset <= r_mas.end) + if (r_populated && r_mas.offset <= r_mas.end) mas_mab_cp(&r_mas, r_mas.offset, r_mas.end, &b_node, b_node.b_end + 1); else