Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1550059 > unrolled thread
| Started by | Thomas Garnier <thgarnie@google.com> |
|---|---|
| First post | 2017-01-03 19:20 +0100 |
| Last post | 2017-01-06 22:50 +0100 |
| Articles | 5 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH] Fix SLAB freelist randomization duplicate entries Thomas Garnier <thgarnie@google.com> - 2017-01-03 19:20 +0100
Re: [PATCH] Fix SLAB freelist randomization duplicate entries Andrew Morton <akpm@linux-foundation.org> - 2017-01-06 01:40 +0100
Re: [PATCH] Fix SLAB freelist randomization duplicate entries Thomas Garnier <thgarnie@google.com> - 2017-01-06 19:00 +0100
Re: [PATCH] Fix SLAB freelist randomization duplicate entries Andrew Morton <akpm@linux-foundation.org> - 2017-01-06 21:50 +0100
Re: [PATCH] Fix SLAB freelist randomization duplicate entries Thomas Garnier <thgarnie@google.com> - 2017-01-06 22:50 +0100
| From | Thomas Garnier <thgarnie@google.com> |
|---|---|
| Date | 2017-01-03 19:20 +0100 |
| Subject | [PATCH] Fix SLAB freelist randomization duplicate entries |
| Message-ID | <sVBQL-1Kc-67@gated-at.bofh.it> |
This patch fixes a bug in the freelist randomization code. When a high
random number is used, the freelist will contain duplicate entries. It
will result in different allocations sharing the same chunk.
Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
Signed-off-by: John Sperbeck <jsperbeck@google.com>
Reviewed-by: Thomas Garnier <thgarnie@google.com>
---
mm/slab.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/mm/slab.c b/mm/slab.c
index 29bc6c0dedd0..4f2ec6bb46eb 100644
--- a/mm/slab.c
+++ b/mm/slab.c
@@ -2457,7 +2457,6 @@ union freelist_init_state {
unsigned int pos;
unsigned int *list;
unsigned int count;
- unsigned int rand;
};
struct rnd_state rnd_state;
};
@@ -2483,8 +2482,7 @@ static bool freelist_state_initialize(union freelist_init_state *state,
} else {
state->list = cachep->random_seq;
state->count = count;
- state->pos = 0;
- state->rand = rand;
+ state->pos = rand % count;
ret = true;
}
return ret;
@@ -2493,7 +2491,9 @@ static bool freelist_state_initialize(union freelist_init_state *state,
/* Get the next entry on the list and randomize it using a random shift */
static freelist_idx_t next_random_slot(union freelist_init_state *state)
{
- return (state->list[state->pos++] + state->rand) % state->count;
+ if (state->pos >= state->count)
+ state->pos = 0;
+ return state->list[state->pos++];
}
/* Swap two freelist entries */
--
2.11.0.390.gc69c2f50cf-goog
[toc] | [next] | [standalone]
| From | Andrew Morton <akpm@linux-foundation.org> |
|---|---|
| Date | 2017-01-06 01:40 +0100 |
| Message-ID | <sWqJz-2cg-3@gated-at.bofh.it> |
| In reply to | #1550059 |
On Tue, 3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:
> This patch fixes a bug in the freelist randomization code. When a high
> random number is used, the freelist will contain duplicate entries. It
> will result in different allocations sharing the same chunk.
Important: what are the user-visible runtime effects of the bug?
> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
> Signed-off-by: John Sperbeck <jsperbeck@google.com>
> Reviewed-by: Thomas Garnier <thgarnie@google.com>
This should have been signed off by yourself.
I'm guessing that the author was in fact John? If so, you should
indicate this by putting his From: line at the start of the changelog.
Otherwise, authorship will default to the sender (ie, yourself).
[toc] | [prev] | [next] | [standalone]
| From | Thomas Garnier <thgarnie@google.com> |
|---|---|
| Date | 2017-01-06 19:00 +0100 |
| Message-ID | <sWGY1-5hC-9@gated-at.bofh.it> |
| In reply to | #1552429 |
On Thu, Jan 5, 2017 at 4:35 PM, Andrew Morton <akpm@linux-foundation.org> wrote:
> On Tue, 3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:
>
>> This patch fixes a bug in the freelist randomization code. When a high
>> random number is used, the freelist will contain duplicate entries. It
>> will result in different allocations sharing the same chunk.
>
> Important: what are the user-visible runtime effects of the bug?
It will result in odd behaviours and crashes. It should be uncommon
but it depends on the machines. We saw it happening more often on some
machines (every few hours of running tests).
>
>> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
>> Signed-off-by: John Sperbeck <jsperbeck@google.com>
>> Reviewed-by: Thomas Garnier <thgarnie@google.com>
>
> This should have been signed off by yourself.
>
> I'm guessing that the author was in fact John? If so, you should
> indicate this by putting his From: line at the start of the changelog.
> Otherwise, authorship will default to the sender (ie, yourself).
>
Sorry, I though the sign-off was enough. Do you want me to send a v2?
--
Thomas
[toc] | [prev] | [next] | [standalone]
| From | Andrew Morton <akpm@linux-foundation.org> |
|---|---|
| Date | 2017-01-06 21:50 +0100 |
| Message-ID | <sWJCx-7a6-7@gated-at.bofh.it> |
| In reply to | #1552997 |
On Fri, 6 Jan 2017 09:58:48 -0800 Thomas Garnier <thgarnie@google.com> wrote:
> On Thu, Jan 5, 2017 at 4:35 PM, Andrew Morton <akpm@linux-foundation.org> wrote:
> > On Tue, 3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:
> >
> >> This patch fixes a bug in the freelist randomization code. When a high
> >> random number is used, the freelist will contain duplicate entries. It
> >> will result in different allocations sharing the same chunk.
> >
> > Important: what are the user-visible runtime effects of the bug?
>
> It will result in odd behaviours and crashes. It should be uncommon
> but it depends on the machines. We saw it happening more often on some
> machines (every few hours of running tests).
So should the fix be backported into -stable kernels?
> >
> >> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
> >> Signed-off-by: John Sperbeck <jsperbeck@google.com>
> >> Reviewed-by: Thomas Garnier <thgarnie@google.com>
> >
> > This should have been signed off by yourself.
> >
> > I'm guessing that the author was in fact John? If so, you should
> > indicate this by putting his From: line at the start of the changelog.
> > Otherwise, authorship will default to the sender (ie, yourself).
> >
>
> Sorry, I though the sign-off was enough. Do you want me to send a v2?
I have the patch as
From: John Sperbeck <jsperbeck@google.com>
Signed-off-by: John Sperbeck <jsperbeck@google.com>
Signed-off-by: Thomas Garnier <thgarnie@google.com>
Is that correct? Is John the primary author?
[toc] | [prev] | [next] | [standalone]
| From | Thomas Garnier <thgarnie@google.com> |
|---|---|
| Date | 2017-01-06 22:50 +0100 |
| Message-ID | <sWKyC-7RC-7@gated-at.bofh.it> |
| In reply to | #1553099 |
On Fri, Jan 6, 2017 at 12:42 PM, Andrew Morton
<akpm@linux-foundation.org> wrote:
> On Fri, 6 Jan 2017 09:58:48 -0800 Thomas Garnier <thgarnie@google.com> wrote:
>
>> On Thu, Jan 5, 2017 at 4:35 PM, Andrew Morton <akpm@linux-foundation.org> wrote:
>> > On Tue, 3 Jan 2017 10:19:08 -0800 Thomas Garnier <thgarnie@google.com> wrote:
>> >
>> >> This patch fixes a bug in the freelist randomization code. When a high
>> >> random number is used, the freelist will contain duplicate entries. It
>> >> will result in different allocations sharing the same chunk.
>> >
>> > Important: what are the user-visible runtime effects of the bug?
>>
>> It will result in odd behaviours and crashes. It should be uncommon
>> but it depends on the machines. We saw it happening more often on some
>> machines (every few hours of running tests).
>
> So should the fix be backported into -stable kernels?
>
I think it should, yes.
>> >
>> >> Fixes: c7ce4f60ac19 ("mm: SLAB freelist randomization")
>> >> Signed-off-by: John Sperbeck <jsperbeck@google.com>
>> >> Reviewed-by: Thomas Garnier <thgarnie@google.com>
>> >
>> > This should have been signed off by yourself.
>> >
>> > I'm guessing that the author was in fact John? If so, you should
>> > indicate this by putting his From: line at the start of the changelog.
>> > Otherwise, authorship will default to the sender (ie, yourself).
>> >
>>
>> Sorry, I though the sign-off was enough. Do you want me to send a v2?
>
> I have the patch as
>
> From: John Sperbeck <jsperbeck@google.com>
> Signed-off-by: John Sperbeck <jsperbeck@google.com>
> Signed-off-by: Thomas Garnier <thgarnie@google.com>
>
> Is that correct? Is John the primary author?
That's correct.
--
Thomas
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web