Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1298416

[PATCH 1/2] virtio_balloon: fix race by fill and leak

From Minchan Kim <minchan@kernel.org>
Newsgroups linux.kernel
Subject [PATCH 1/2] virtio_balloon: fix race by fill and leak
Date 2015-12-28 03:50 +0100
Message-ID <qKw2J-3Io-13@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


During my compaction-related stuff, I encountered a bug
with ballooning.

With repeated inflating and deflating cycle, guest memory(
ie, cat /proc/meminfo | grep MemTotal) is decreased and
couldn't be recovered.

The reason is balloon_lock doesn't cover release_pages_balloon
so struct virtio_balloon fields could be overwritten by race
of fill_balloon(e,g, vb->*pfns could be critical).

This patch fixes it in my test.

Cc: <stable@vger.kernel.org>
Signed-off-by: Minchan Kim <minchan@kernel.org>
---
 drivers/virtio/virtio_balloon.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/virtio/virtio_balloon.c b/drivers/virtio/virtio_balloon.c
index 7efc32945810..7d3e5d0e9aa4 100644
--- a/drivers/virtio/virtio_balloon.c
+++ b/drivers/virtio/virtio_balloon.c
@@ -209,8 +209,8 @@ static unsigned leak_balloon(struct virtio_balloon *vb, size_t num)
 	 */
 	if (vb->num_pfns != 0)
 		tell_host(vb, vb->deflate_vq);
-	mutex_unlock(&vb->balloon_lock);
 	release_pages_balloon(vb);
+	mutex_unlock(&vb->balloon_lock);
 	return num_freed_pages;
 }
 
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

[PATCH 1/2] virtio_balloon: fix race by fill and leak Minchan Kim <minchan@kernel.org> - 2015-12-28 03:50 +0100
  [PATCH 2/2] virtio_balloon: fix race between migration and ballooning Minchan Kim <minchan@kernel.org> - 2015-12-28 03:50 +0100
    Re: [PATCH 2/2] virtio_balloon: fix race between migration and  ballooning "Michael S. Tsirkin" <mst@redhat.com> - 2016-01-01 10:40 +0100
  Re: [PATCH 1/2] virtio_balloon: fix race by fill and leak "Michael S. Tsirkin" <mst@redhat.com> - 2016-01-01 09:30 +0100

csiph-web