Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1550059 > unrolled thread

[PATCH] Fix SLAB freelist randomization duplicate entries

Started byThomas Garnier <thgarnie@google.com>
First post2017-01-03 19:20 +0100
Last post2017-01-06 22:50 +0100
Articles 5 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] Fix SLAB freelist randomization duplicate entries Thomas Garnier <thgarnie@google.com> - 2017-01-03 19:20 +0100
    Re: [PATCH] Fix SLAB freelist randomization duplicate entries Andrew Morton <akpm@linux-foundation.org> - 2017-01-06 01:40 +0100
      Re: [PATCH] Fix SLAB freelist randomization duplicate entries Thomas Garnier <thgarnie@google.com> - 2017-01-06 19:00 +0100
        Re: [PATCH] Fix SLAB freelist randomization duplicate entries Andrew Morton <akpm@linux-foundation.org> - 2017-01-06 21:50 +0100
          Re: [PATCH] Fix SLAB freelist randomization duplicate entries Thomas Garnier <thgarnie@google.com> - 2017-01-06 22:50 +0100

#1550059 — [PATCH] Fix SLAB freelist randomization duplicate entries

FromThomas Garnier <thgarnie@google.com>
Date2017-01-03 19:20 +0100
Subject[PATCH] Fix SLAB freelist randomization duplicate entries
Message-ID<sVBQL-1Kc-67@gated-at.bofh.it>
This patch fixes a bug in the freelist randomization code. When a high
random number is used, the freelist will contain duplicate entries. It
will result in different allocations sharing the same chunk.

Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
Signed-off-by: John Sperbeck <jsperbeck@google.com>
Reviewed-by: Thomas Garnier <thgarnie@google.com>
---
 mm/slab.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/mm/slab.c b/mm/slab.c
index 29bc6c0dedd0..4f2ec6bb46eb 100644
--- a/mm/slab.c
+++ b/mm/slab.c
@@ -2457,7 +2457,6 @@ union freelist_init_state {
 		unsigned int pos;
 		unsigned int *list;
 		unsigned int count;
-		unsigned int rand;
 	};
 	struct rnd_state rnd_state;
 };
@@ -2483,8 +2482,7 @@ static bool freelist_state_initialize(union freelist_init_state *state,
 	} else {
 		state->list = cachep->random_seq;
 		state->count = count;
-		state->pos = 0;
-		state->rand = rand;
+		state->pos = rand % count;
 		ret = true;
 	}
 	return ret;
@@ -2493,7 +2491,9 @@ static bool freelist_state_initialize(union freelist_init_state *state,
 /* Get the next entry on the list and randomize it using a random shift */
 static freelist_idx_t next_random_slot(union freelist_init_state *state)
 {
-	return (state->list[state->pos++] + state->rand) % state->count;
+	if (state->pos >= state->count)
+		state->pos = 0;
+	return state->list[state->pos++];
 }
 
 /* Swap two freelist entries */
-- 
2.11.0.390.gc69c2f50cf-goog

[toc] | [next] | [standalone]


#1552429

FromAndrew Morton <akpm@linux-foundation.org>
Date2017-01-06 01:40 +0100
Message-ID<sWqJz-2cg-3@gated-at.bofh.it>
In reply to#1550059
On Tue,  3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:

> This patch fixes a bug in the freelist randomization code. When a high
> random number is used, the freelist will contain duplicate entries. It
> will result in different allocations sharing the same chunk.

Important: what are the user-visible runtime effects of the bug?

> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
> Signed-off-by: John Sperbeck <jsperbeck@google.com>
> Reviewed-by: Thomas Garnier <thgarnie@google.com>

This should have been signed off by yourself.

I'm guessing that the author was in fact John?  If so, you should
indicate this by putting his From: line at the start of the changelog. 
Otherwise, authorship will default to the sender (ie, yourself).

[toc] | [prev] | [next] | [standalone]


#1552997

FromThomas Garnier <thgarnie@google.com>
Date2017-01-06 19:00 +0100
Message-ID<sWGY1-5hC-9@gated-at.bofh.it>
In reply to#1552429
On Thu, Jan 5, 2017 at 4:35 PM, Andrew Morton <akpm@linux-foundation.org> wrote:
> On Tue,  3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:
>
>> This patch fixes a bug in the freelist randomization code. When a high
>> random number is used, the freelist will contain duplicate entries. It
>> will result in different allocations sharing the same chunk.
>
> Important: what are the user-visible runtime effects of the bug?

It will result in odd behaviours and crashes. It should be uncommon
but it depends on the machines. We saw it happening more often on some
machines (every few hours of running tests).

>
>> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
>> Signed-off-by: John Sperbeck <jsperbeck@google.com>
>> Reviewed-by: Thomas Garnier <thgarnie@google.com>
>
> This should have been signed off by yourself.
>
> I'm guessing that the author was in fact John?  If so, you should
> indicate this by putting his From: line at the start of the changelog.
> Otherwise, authorship will default to the sender (ie, yourself).
>

Sorry, I though the sign-off was enough. Do you want me to send a v2?

-- 
Thomas

[toc] | [prev] | [next] | [standalone]


#1553099

FromAndrew Morton <akpm@linux-foundation.org>
Date2017-01-06 21:50 +0100
Message-ID<sWJCx-7a6-7@gated-at.bofh.it>
In reply to#1552997
On Fri, 6 Jan 2017 09:58:48 -0800 Thomas Garnier <thgarnie@google.com> wrote:

> On Thu, Jan 5, 2017 at 4:35 PM, Andrew Morton <akpm@linux-foundation.org> wrote:
> > On Tue,  3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:
> >
> >> This patch fixes a bug in the freelist randomization code. When a high
> >> random number is used, the freelist will contain duplicate entries. It
> >> will result in different allocations sharing the same chunk.
> >
> > Important: what are the user-visible runtime effects of the bug?
> 
> It will result in odd behaviours and crashes. It should be uncommon
> but it depends on the machines. We saw it happening more often on some
> machines (every few hours of running tests).

So should the fix be backported into -stable kernels?

> >
> >> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
> >> Signed-off-by: John Sperbeck <jsperbeck@google.com>
> >> Reviewed-by: Thomas Garnier <thgarnie@google.com>
> >
> > This should have been signed off by yourself.
> >
> > I'm guessing that the author was in fact John?  If so, you should
> > indicate this by putting his From: line at the start of the changelog.
> > Otherwise, authorship will default to the sender (ie, yourself).
> >
> 
> Sorry, I though the sign-off was enough. Do you want me to send a v2?

I have the patch as

From: John Sperbeck <jsperbeck@google.com>
Signed-off-by: John Sperbeck <jsperbeck@google.com>
Signed-off-by: Thomas Garnier <thgarnie@google.com>

Is that correct?  Is John the primary author?

[toc] | [prev] | [next] | [standalone]


#1553157

FromThomas Garnier <thgarnie@google.com>
Date2017-01-06 22:50 +0100
Message-ID<sWKyC-7RC-7@gated-at.bofh.it>
In reply to#1553099
On Fri, Jan 6, 2017 at 12:42 PM, Andrew Morton
<akpm@linux-foundation.org> wrote:
> On Fri, 6 Jan 2017 09:58:48 -0800 Thomas Garnier <thgarnie@google.com> wrote:
>
>> On Thu, Jan 5, 2017 at 4:35 PM, Andrew Morton <akpm@linux-foundation.org> wrote:
>> > On Tue,  3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:
>> >
>> >> This patch fixes a bug in the freelist randomization code. When a high
>> >> random number is used, the freelist will contain duplicate entries. It
>> >> will result in different allocations sharing the same chunk.
>> >
>> > Important: what are the user-visible runtime effects of the bug?
>>
>> It will result in odd behaviours and crashes. It should be uncommon
>> but it depends on the machines. We saw it happening more often on some
>> machines (every few hours of running tests).
>
> So should the fix be backported into -stable kernels?
>

I think it should, yes.

>> >
>> >> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
>> >> Signed-off-by: John Sperbeck <jsperbeck@google.com>
>> >> Reviewed-by: Thomas Garnier <thgarnie@google.com>
>> >
>> > This should have been signed off by yourself.
>> >
>> > I'm guessing that the author was in fact John?  If so, you should
>> > indicate this by putting his From: line at the start of the changelog.
>> > Otherwise, authorship will default to the sender (ie, yourself).
>> >
>>
>> Sorry, I though the sign-off was enough. Do you want me to send a v2?
>
> I have the patch as
>
> From: John Sperbeck <jsperbeck@google.com>
> Signed-off-by: John Sperbeck <jsperbeck@google.com>
> Signed-off-by: Thomas Garnier <thgarnie@google.com>
>
> Is that correct?  Is John the primary author?

That's correct.

-- 
Thomas

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web