| From a85dfc305a21acfc48fa28a0fa0a0cb6ad496120 Mon Sep 17 00:00:00 2001 |
| From: Yang Shi <yang.shi@linux.alibaba.com> |
| Date: Fri, 15 Nov 2019 17:34:33 -0800 |
| Subject: mm: mempolicy: fix the wrong return value and potential pages leak of mbind |
| |
| From: Yang Shi <yang.shi@linux.alibaba.com> |
| |
| commit a85dfc305a21acfc48fa28a0fa0a0cb6ad496120 upstream. |
| |
| Commit d883544515aa ("mm: mempolicy: make the behavior consistent when |
| MPOL_MF_MOVE* and MPOL_MF_STRICT were specified") fixed the return value |
| of mbind() for a couple of corner cases. But, it altered the errno for |
| some other cases, for example, mbind() should return -EFAULT when part |
| or all of the memory range specified by nodemask and maxnode points |
| outside your accessible address space, or there was an unmapped hole in |
| the specified memory range specified by addr and len. |
| |
| Fix this by preserving the errno returned by queue_pages_range(). And, |
| the pagelist may be not empty even though queue_pages_range() returns |
| error, put the pages back to LRU since mbind_range() is not called to |
| really apply the policy so those pages should not be migrated, this is |
| also the old behavior before the problematic commit. |
| |
| Link: http://lkml.kernel.org/r/1572454731-3925-1-git-send-email-yang.shi@linux.alibaba.com |
| Fixes: d883544515aa ("mm: mempolicy: make the behavior consistent when MPOL_MF_MOVE* and MPOL_MF_STRICT were specified") |
| Signed-off-by: Yang Shi <yang.shi@linux.alibaba.com> |
| Reported-by: Li Xinhai <lixinhai.lxh@gmail.com> |
| Reviewed-by: Li Xinhai <lixinhai.lxh@gmail.com> |
| Cc: Vlastimil Babka <vbabka@suse.cz> |
| Cc: Michal Hocko <mhocko@suse.com> |
| Cc: Mel Gorman <mgorman@techsingularity.net> |
| Cc: <stable@vger.kernel.org> [4.19 and 5.2+] |
| Signed-off-by: Andrew Morton <akpm@linux-foundation.org> |
| Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| mm/mempolicy.c | 14 +++++++++----- |
| 1 file changed, 9 insertions(+), 5 deletions(-) |
| |
| --- a/mm/mempolicy.c |
| +++ b/mm/mempolicy.c |
| @@ -666,7 +666,9 @@ static int queue_pages_test_walk(unsigne |
| * 1 - there is unmovable page, but MPOL_MF_MOVE* & MPOL_MF_STRICT were |
| * specified. |
| * 0 - queue pages successfully or no misplaced page. |
| - * -EIO - there is misplaced page and only MPOL_MF_STRICT was specified. |
| + * errno - i.e. misplaced pages with MPOL_MF_STRICT specified (-EIO) or |
| + * memory range specified by nodemask and maxnode points outside |
| + * your accessible address space (-EFAULT) |
| */ |
| static int |
| queue_pages_range(struct mm_struct *mm, unsigned long start, unsigned long end, |
| @@ -1273,7 +1275,7 @@ static long do_mbind(unsigned long start |
| flags | MPOL_MF_INVERT, &pagelist); |
| |
| if (ret < 0) { |
| - err = -EIO; |
| + err = ret; |
| goto up_out; |
| } |
| |
| @@ -1292,10 +1294,12 @@ static long do_mbind(unsigned long start |
| |
| if ((ret > 0) || (nr_failed && (flags & MPOL_MF_STRICT))) |
| err = -EIO; |
| - } else |
| - putback_movable_pages(&pagelist); |
| - |
| + } else { |
| up_out: |
| + if (!list_empty(&pagelist)) |
| + putback_movable_pages(&pagelist); |
| + } |
| + |
| up_write(&mm->mmap_sem); |
| mpol_out: |
| mpol_put(new); |