• Ralph Campbell's avatar
    mm/hmm: fix ZONE_DEVICE anon page mapping reuse · 7ab0ad0e
    Ralph Campbell authored
    When a ZONE_DEVICE private page is freed, the page->mapping field can be
    set.  If this page is reused as an anonymous page, the previous value
    can prevent the page from being inserted into the CPU's anon rmap table.
    For example, when migrating a pte_none() page to device memory:
    
      migrate_vma(ops, vma, start, end, src, dst, private)
        migrate_vma_collect()
          src[] = MIGRATE_PFN_MIGRATE
        migrate_vma_prepare()
          /* no page to lock or isolate so OK */
        migrate_vma_unmap()
          /* no page to unmap so OK */
        ops->alloc_and_copy()
          /* driver allocates ZONE_DEVICE page for dst[] */
        migrate_vma_pages()
          migrate_vma_insert_page()
            page_add_new_anon_rmap()
              __page_set_anon_rmap()
                /* This check sees the page's stale mapping field */
                if (PageAnon(page))
                  return
                /* page->mapping is not updated */
    
    The result is that the migration appears to succeed but a subsequent CPU
    fault will be unable to migrate the page back to system memory or worse.
    
    Clear the page->mapping field when freeing the ZONE_DEVICE page so stale
    pointer data doesn't affect future page use.
    
    Link: http://lkml.kernel.org/r/20190719192955.30462-3-rcampbell@nvidia.com
    Fixes: b7a52310 ("mm: don't clear ->mapping in hmm_devmem_free")
    Signed-off-by: default avatarRalph Campbell <rcampbell@nvidia.com>
    Reviewed-by: default avatarJohn Hubbard <jhubbard@nvidia.com>
    Reviewed-by: default avatarChristoph Hellwig <hch@lst.de>
    Cc: Dan Williams <dan.j.williams@intel.com>
    Cc: Jason Gunthorpe <jgg@mellanox.com>
    Cc: Logan Gunthorpe <logang@deltatee.com>
    Cc: Ira Weiny <ira.weiny@intel.com>
    Cc: Matthew Wilcox <willy@infradead.org>
    Cc: Mel Gorman <mgorman@techsingularity.net>
    Cc: Jan Kara <jack@suse.cz>
    Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
    Cc: Michal Hocko <mhocko@suse.com>
    Cc: Andrea Arcangeli <aarcange@redhat.com>
    Cc: Mike Kravetz <mike.kravetz@oracle.com>
    Cc: "Jérôme Glisse" <jglisse@redhat.com>
    Cc: Andrey Ryabinin <aryabinin@virtuozzo.com>
    Cc: Christoph Lameter <cl@linux.com>
    Cc: Dave Hansen <dave.hansen@linux.intel.com>
    Cc: Lai Jiangshan <jiangshanlai@gmail.com>
    Cc: Martin Schwidefsky <schwidefsky@de.ibm.com>
    Cc: Pekka Enberg <penberg@kernel.org>
    Cc: Randy Dunlap <rdunlap@infradead.org>
    Cc: Vlastimil Babka <vbabka@suse.cz>
    Cc: <stable@vger.kernel.org>
    Signed-off-by: default avatarAndrew Morton <akpm@linux-foundation.org>
    Signed-off-by: default avatarLinus Torvalds <torvalds@linux-foundation.org>
    7ab0ad0e
memremap.c 11.9 KB