Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1649413 > unrolled thread

[PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

Started byWei Yang <richard.weiyang@gmail.com>
First post2017-05-24 12:10 +0200
Last post2017-06-03 04:30 +0200
Articles 10 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area() Wei Yang <richard.weiyang@gmail.com> - 2017-05-24 12:10 +0200
    Re: [PATCH] mm/vmalloc: a slight change of compare target in  __insert_vmap_area() Michal Hocko <mhocko@kernel.org> - 2017-05-24 14:20 +0200
      Re: [PATCH] mm/vmalloc: a slight change of compare target in  __insert_vmap_area() Wei Yang <richard.weiyang@gmail.com> - 2017-05-24 17:10 +0200
        Re: [PATCH] mm/vmalloc: a slight change of compare target in  __insert_vmap_area() Michal Hocko <mhocko@kernel.org> - 2017-05-25 07:40 +0200
    Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area() zhong jiang <zhongjiang@huawei.com> - 2017-05-25 05:10 +0200
      Re: [PATCH] mm/vmalloc: a slight change of compare target in  __insert_vmap_area() Wei Yang <richard.weiyang@gmail.com> - 2017-05-26 03:40 +0200
        Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area() zhong jiang <zhongjiang@huawei.com> - 2017-05-26 04:10 +0200
          Re: [PATCH] mm/vmalloc: a slight change of compare target in  __insert_vmap_area() Wei Yang <richard.weiyang@gmail.com> - 2017-06-02 03:50 +0200
            Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area() zhong jiang <zhongjiang@huawei.com> - 2017-06-02 04:30 +0200
              Re: [PATCH] mm/vmalloc: a slight change of compare target in  __insert_vmap_area() Wei Yang <richard.weiyang@gmail.com> - 2017-06-03 04:30 +0200

#1649413 — [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

FromWei Yang <richard.weiyang@gmail.com>
Date2017-05-24 12:10 +0200
Subject[PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()
Message-ID<tKBoS-Xp-21@gated-at.bofh.it>
The vmap RB tree store the elements in order and no overlap between any of
them. The comparison in __insert_vmap_area() is to decide which direction
the search should follow and make sure the new vmap_area is not overlap
with any other.

Current implementation fails to do the overlap check.

When first "if" is not true, it means

    va->va_start >= tmp_va->va_end

And with the truth

    xxx->va_end > xxx->va_start

The deduction is

    va->va_end > tmp_va->va_start

which is the condition in second "if".

This patch changes a little of the comparison in __insert_vmap_area() to
make sure it forbids the overlapped vmap_area.

Signed-off-by: Wei Yang <richard.weiyang@gmail.com>
---
 mm/vmalloc.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/mm/vmalloc.c b/mm/vmalloc.c
index 0b057628a7ba..8087451cb332 100644
--- a/mm/vmalloc.c
+++ b/mm/vmalloc.c
@@ -360,9 +360,9 @@ static void __insert_vmap_area(struct vmap_area *va)
 
 		parent = *p;
 		tmp_va = rb_entry(parent, struct vmap_area, rb_node);
-		if (va->va_start < tmp_va->va_end)
+		if (va->va_end <= tmp_va->va_start)
 			p = &(*p)->rb_left;
-		else if (va->va_end > tmp_va->va_start)
+		else if (va->va_start >= tmp_va->va_end)
 			p = &(*p)->rb_right;
 		else
 			BUG();
-- 
2.11.0

[toc] | [next] | [standalone]


#1649563 — Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

FromMichal Hocko <mhocko@kernel.org>
Date2017-05-24 14:20 +0200
SubjectRe: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()
Message-ID<tKDqG-2fU-11@gated-at.bofh.it>
In reply to#1649413
On Wed 24-05-17 18:03:47, Wei Yang wrote:
> The vmap RB tree store the elements in order and no overlap between any of
> them. The comparison in __insert_vmap_area() is to decide which direction
> the search should follow and make sure the new vmap_area is not overlap
> with any other.
> 
> Current implementation fails to do the overlap check.
> 
> When first "if" is not true, it means
> 
>     va->va_start >= tmp_va->va_end
> 
> And with the truth
> 
>     xxx->va_end > xxx->va_start
> 
> The deduction is
> 
>     va->va_end > tmp_va->va_start
> 
> which is the condition in second "if".
> 
> This patch changes a little of the comparison in __insert_vmap_area() to
> make sure it forbids the overlapped vmap_area.

Why do we care about overlapping vmap areas at this level. This is an
internal function and all the sanity checks should have been done by
that time AFAIR. Could you describe the problem which you are trying to
fix/address?

> Signed-off-by: Wei Yang <richard.weiyang@gmail.com>
> ---
>  mm/vmalloc.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/mm/vmalloc.c b/mm/vmalloc.c
> index 0b057628a7ba..8087451cb332 100644
> --- a/mm/vmalloc.c
> +++ b/mm/vmalloc.c
> @@ -360,9 +360,9 @@ static void __insert_vmap_area(struct vmap_area *va)
>  
>  		parent = *p;
>  		tmp_va = rb_entry(parent, struct vmap_area, rb_node);
> -		if (va->va_start < tmp_va->va_end)
> +		if (va->va_end <= tmp_va->va_start)
>  			p = &(*p)->rb_left;
> -		else if (va->va_end > tmp_va->va_start)
> +		else if (va->va_start >= tmp_va->va_end)
>  			p = &(*p)->rb_right;
>  		else
>  			BUG();
> -- 
> 2.11.0
> 
> --
> To unsubscribe, send a message with 'unsubscribe linux-mm' in
> the body to majordomo@kvack.org.  For more info on Linux MM,
> see: http://www.linux-mm.org/ .
> Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>

-- 
Michal Hocko
SUSE Labs

[toc] | [prev] | [next] | [standalone]


#1649695 — Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

FromWei Yang <richard.weiyang@gmail.com>
Date2017-05-24 17:10 +0200
SubjectRe: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()
Message-ID<tKG5b-3Wx-17@gated-at.bofh.it>
In reply to#1649563

[Multipart message — attachments visible in raw view] — view raw

On Wed, May 24, 2017 at 02:11:35PM +0200, Michal Hocko wrote:
>On Wed 24-05-17 18:03:47, Wei Yang wrote:
>> The vmap RB tree store the elements in order and no overlap between any of
>> them. The comparison in __insert_vmap_area() is to decide which direction
>> the search should follow and make sure the new vmap_area is not overlap
>> with any other.
>> 
>> Current implementation fails to do the overlap check.
>> 
>> When first "if" is not true, it means
>> 
>>     va->va_start >= tmp_va->va_end
>> 
>> And with the truth
>> 
>>     xxx->va_end > xxx->va_start
>> 
>> The deduction is
>> 
>>     va->va_end > tmp_va->va_start
>> 
>> which is the condition in second "if".
>> 
>> This patch changes a little of the comparison in __insert_vmap_area() to
>> make sure it forbids the overlapped vmap_area.
>
>Why do we care about overlapping vmap areas at this level. This is an
>internal function and all the sanity checks should have been done by
>that time AFAIR. Could you describe the problem which you are trying to
>fix/address?
>

No problem it tries to fix.

I just follow the original idea, which tries to catch the exception case by
the BUG(). While in the above analysis, the BUG() will never be triggered.

So we have two options:
1. Still tries to catch the exception by change the "if" a little.
2. If we don't care about the overlap case, the "if" clause could be
   simplified.  Only "if ... else ..." is enough.

You prefer the second one?

>> Signed-off-by: Wei Yang <richard.weiyang@gmail.com>
>> ---
>>  mm/vmalloc.c | 4 ++--
>>  1 file changed, 2 insertions(+), 2 deletions(-)
>> 
>> diff --git a/mm/vmalloc.c b/mm/vmalloc.c
>> index 0b057628a7ba..8087451cb332 100644
>> --- a/mm/vmalloc.c
>> +++ b/mm/vmalloc.c
>> @@ -360,9 +360,9 @@ static void __insert_vmap_area(struct vmap_area *va)
>>  
>>  		parent = *p;
>>  		tmp_va = rb_entry(parent, struct vmap_area, rb_node);
>> -		if (va->va_start < tmp_va->va_end)
>> +		if (va->va_end <= tmp_va->va_start)
>>  			p = &(*p)->rb_left;
>> -		else if (va->va_end > tmp_va->va_start)
>> +		else if (va->va_start >= tmp_va->va_end)
>>  			p = &(*p)->rb_right;
>>  		else
>>  			BUG();
>> -- 
>> 2.11.0
>> 
>> --
>> To unsubscribe, send a message with 'unsubscribe linux-mm' in
>> the body to majordomo@kvack.org.  For more info on Linux MM,
>> see: http://www.linux-mm.org/ .
>> Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
>
>-- 
>Michal Hocko
>SUSE Labs

-- 
Wei Yang
Help you, Help me

[toc] | [prev] | [next] | [standalone]


#1650181 — Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

FromMichal Hocko <mhocko@kernel.org>
Date2017-05-25 07:40 +0200
SubjectRe: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()
Message-ID<tKTF7-45C-7@gated-at.bofh.it>
In reply to#1649695
On Wed 24-05-17 23:07:30, Wei Yang wrote:
> On Wed, May 24, 2017 at 02:11:35PM +0200, Michal Hocko wrote:
> >On Wed 24-05-17 18:03:47, Wei Yang wrote:
> >> The vmap RB tree store the elements in order and no overlap between any of
> >> them. The comparison in __insert_vmap_area() is to decide which direction
> >> the search should follow and make sure the new vmap_area is not overlap
> >> with any other.
> >> 
> >> Current implementation fails to do the overlap check.
> >> 
> >> When first "if" is not true, it means
> >> 
> >>     va->va_start >= tmp_va->va_end
> >> 
> >> And with the truth
> >> 
> >>     xxx->va_end > xxx->va_start
> >> 
> >> The deduction is
> >> 
> >>     va->va_end > tmp_va->va_start
> >> 
> >> which is the condition in second "if".
> >> 
> >> This patch changes a little of the comparison in __insert_vmap_area() to
> >> make sure it forbids the overlapped vmap_area.
> >
> >Why do we care about overlapping vmap areas at this level. This is an
> >internal function and all the sanity checks should have been done by
> >that time AFAIR. Could you describe the problem which you are trying to
> >fix/address?
> >
> 
> No problem it tries to fix.

I would prefer the not touch the code if there is no problem to fix.
-- 
Michal Hocko
SUSE Labs

[toc] | [prev] | [next] | [standalone]


#1650137

Fromzhong jiang <zhongjiang@huawei.com>
Date2017-05-25 05:10 +0200
Message-ID<tKRjX-2Fj-1@gated-at.bofh.it>
In reply to#1649413
I hit the overlap issue, but it  is hard to reproduced. if you think it is safe. and the situation
is not happen. AFAIC, it is no need to add the code.

if you insist on the point. Maybe VM_WARN_ON is a choice.

Regards
zhongjiang
On 2017/5/24 18:03, Wei Yang wrote:
> The vmap RB tree store the elements in order and no overlap between any of
> them. The comparison in __insert_vmap_area() is to decide which direction
> the search should follow and make sure the new vmap_area is not overlap
> with any other.
>
> Current implementation fails to do the overlap check.
>
> When first "if" is not true, it means
>
>     va->va_start >= tmp_va->va_end
>
> And with the truth
>
>     xxx->va_end > xxx->va_start
>
> The deduction is
>
>     va->va_end > tmp_va->va_start
>
> which is the condition in second "if".
>
> This patch changes a little of the comparison in __insert_vmap_area() to
> make sure it forbids the overlapped vmap_area.
>
> Signed-off-by: Wei Yang <richard.weiyang@gmail.com>
> ---
>  mm/vmalloc.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/mm/vmalloc.c b/mm/vmalloc.c
> index 0b057628a7ba..8087451cb332 100644
> --- a/mm/vmalloc.c
> +++ b/mm/vmalloc.c
> @@ -360,9 +360,9 @@ static void __insert_vmap_area(struct vmap_area *va)
>  
>  		parent = *p;
>  		tmp_va = rb_entry(parent, struct vmap_area, rb_node);
> -		if (va->va_start < tmp_va->va_end)
> +		if (va->va_end <= tmp_va->va_start)
>  			p = &(*p)->rb_left;
> -		else if (va->va_end > tmp_va->va_start)
> +		else if (va->va_start >= tmp_va->va_end)
>  			p = &(*p)->rb_right;
>  		else
>  			BUG();

[toc] | [prev] | [next] | [standalone]


#1651023 — Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

FromWei Yang <richard.weiyang@gmail.com>
Date2017-05-26 03:40 +0200
SubjectRe: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()
Message-ID<tLcop-7Hu-7@gated-at.bofh.it>
In reply to#1650137

[Multipart message — attachments visible in raw view] — view raw

On Thu, May 25, 2017 at 11:04:44AM +0800, zhong jiang wrote:
>I hit the overlap issue, but it  is hard to reproduced. if you think it is safe. and the situation
>is not happen. AFAIC, it is no need to add the code.
>
>if you insist on the point. Maybe VM_WARN_ON is a choice.
>

Do you have some log to show the overlap happens?

[toc] | [prev] | [next] | [standalone]


#1651037

Fromzhong jiang <zhongjiang@huawei.com>
Date2017-05-26 04:10 +0200
Message-ID<tLcRr-87p-1@gated-at.bofh.it>
In reply to#1651023
On 2017/5/26 9:36, Wei Yang wrote:
> On Thu, May 25, 2017 at 11:04:44AM +0800, zhong jiang wrote:
>> I hit the overlap issue, but it  is hard to reproduced. if you think it is safe. and the situation
>> is not happen. AFAIC, it is no need to add the code.
>>
>> if you insist on the point. Maybe VM_WARN_ON is a choice.
>>
> Do you have some log to show the overlap happens?
 Hi  wei

cat /proc/vmallocinfo
0xf1580000-0xf1600000  524288 raw_dump_mem_write+0x10c/0x188 phys=8b901000 ioremap
0xf1638000-0xf163a000    8192 mcss_pou_queue_init+0xa0/0x13c [mcss] phys=fc614000 ioremap
0xf528e000-0xf5292000   16384 n_tty_open+0x10/0xd0 pages=3 vmalloc
0xf5000000-0xf9001000 67112960 devm_ioremap+0x38/0x70 phys=40000000 ioremap
0xfe001000-0xfe002000    4096 iotable_init+0x0/0xc phys=20001000 ioremap
0xfe200000-0xfe201000    4096 iotable_init+0x0/0xc phys=1a000000 ioremap
0xff100000-0xff101000    4096 iotable_init+0x0/0xc phys=2000a000 ioremap

I hit the above issue, but the log no more useful info. it just is found by accident.
and it is hard to reprodeced. no more info can be supported for further investigation.
therefore, it is no idea for me. 

Thanks
zhongjinag

[toc] | [prev] | [next] | [standalone]


#1655834 — Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

FromWei Yang <richard.weiyang@gmail.com>
Date2017-06-02 03:50 +0200
SubjectRe: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()
Message-ID<tNJSV-2n1-7@gated-at.bofh.it>
In reply to#1651037

[Multipart message — attachments visible in raw view] — view raw

On Fri, May 26, 2017 at 09:55:31AM +0800, zhong jiang wrote:
>On 2017/5/26 9:36, Wei Yang wrote:
>> On Thu, May 25, 2017 at 11:04:44AM +0800, zhong jiang wrote:
>>> I hit the overlap issue, but it  is hard to reproduced. if you think it is safe. and the situation
>>> is not happen. AFAIC, it is no need to add the code.
>>>
>>> if you insist on the point. Maybe VM_WARN_ON is a choice.
>>>
>> Do you have some log to show the overlap happens?
> Hi  wei
>
>cat /proc/vmallocinfo
>0xf1580000-0xf1600000  524288 raw_dump_mem_write+0x10c/0x188 phys=8b901000 ioremap
>0xf1638000-0xf163a000    8192 mcss_pou_queue_init+0xa0/0x13c [mcss] phys=fc614000 ioremap
>0xf528e000-0xf5292000   16384 n_tty_open+0x10/0xd0 pages=3 vmalloc
>0xf5000000-0xf9001000 67112960 devm_ioremap+0x38/0x70 phys=40000000 ioremap

These two ranges overlap.

This is hard to say where is the problem. From the code point of view, I don't
see there is possibility to allocate an overlapped range.

Which version of your kernel?
Hard to reproduce means just see once? 

>0xfe001000-0xfe002000    4096 iotable_init+0x0/0xc phys=20001000 ioremap
>0xfe200000-0xfe201000    4096 iotable_init+0x0/0xc phys=1a000000 ioremap
>0xff100000-0xff101000    4096 iotable_init+0x0/0xc phys=2000a000 ioremap
>
>I hit the above issue, but the log no more useful info. it just is found by accident.
>and it is hard to reprodeced. no more info can be supported for further investigation.
>therefore, it is no idea for me. 
>
>Thanks
>zhongjinag
>

-- 
Wei Yang
Help you, Help me

[toc] | [prev] | [next] | [standalone]


#1655855

Fromzhong jiang <zhongjiang@huawei.com>
Date2017-06-02 04:30 +0200
Message-ID<tNKvD-2VE-3@gated-at.bofh.it>
In reply to#1655834
On 2017/6/2 9:45, Wei Yang wrote:
> On Fri, May 26, 2017 at 09:55:31AM +0800, zhong jiang wrote:
>> On 2017/5/26 9:36, Wei Yang wrote:
>>> On Thu, May 25, 2017 at 11:04:44AM +0800, zhong jiang wrote:
>>>> I hit the overlap issue, but it  is hard to reproduced. if you think it is safe. and the situation
>>>> is not happen. AFAIC, it is no need to add the code.
>>>>
>>>> if you insist on the point. Maybe VM_WARN_ON is a choice.
>>>>
>>> Do you have some log to show the overlap happens?
>> Hi  wei
>>
>> cat /proc/vmallocinfo
>> 0xf1580000-0xf1600000  524288 raw_dump_mem_write+0x10c/0x188 phys=8b901000 ioremap
>> 0xf1638000-0xf163a000    8192 mcss_pou_queue_init+0xa0/0x13c [mcss] phys=fc614000 ioremap
>> 0xf528e000-0xf5292000   16384 n_tty_open+0x10/0xd0 pages=3 vmalloc
>> 0xf5000000-0xf9001000 67112960 devm_ioremap+0x38/0x70 phys=40000000 ioremap
> These two ranges overlap.
>
> This is hard to say where is the problem. From the code point of view, I don't
> see there is possibility to allocate an overlapped range.
>
> Which version of your kernel?
> Hard to reproduce means just see once? 
  yes, just once.  I have also no see any problem from the code.   The kernel version is linux 4.1.
 but That indeed exist. 

 Thanks
zhongjiang
>> 0xfe001000-0xfe002000    4096 iotable_init+0x0/0xc phys=20001000 ioremap
>> 0xfe200000-0xfe201000    4096 iotable_init+0x0/0xc phys=1a000000 ioremap
>> 0xff100000-0xff101000    4096 iotable_init+0x0/0xc phys=2000a000 ioremap
>>
>> I hit the above issue, but the log no more useful info. it just is found by accident.
>> and it is hard to reprodeced. no more info can be supported for further investigation.
>> therefore, it is no idea for me. 
>>
>> Thanks
>> zhongjinag
>>

[toc] | [prev] | [next] | [standalone]


#1656676 — Re: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()

FromWei Yang <richard.weiyang@gmail.com>
Date2017-06-03 04:30 +0200
SubjectRe: [PATCH] mm/vmalloc: a slight change of compare target in __insert_vmap_area()
Message-ID<tO6Zb-13v-3@gated-at.bofh.it>
In reply to#1655855

[Multipart message — attachments visible in raw view] — view raw

On Fri, Jun 02, 2017 at 10:26:06AM +0800, zhong jiang wrote:
>On 2017/6/2 9:45, Wei Yang wrote:
>> On Fri, May 26, 2017 at 09:55:31AM +0800, zhong jiang wrote:
>>> On 2017/5/26 9:36, Wei Yang wrote:
>>>> On Thu, May 25, 2017 at 11:04:44AM +0800, zhong jiang wrote:
>>>>> I hit the overlap issue, but it  is hard to reproduced. if you think it is safe. and the situation
>>>>> is not happen. AFAIC, it is no need to add the code.
>>>>>
>>>>> if you insist on the point. Maybe VM_WARN_ON is a choice.
>>>>>
>>>> Do you have some log to show the overlap happens?
>>> Hi  wei
>>>
>>> cat /proc/vmallocinfo
>>> 0xf1580000-0xf1600000  524288 raw_dump_mem_write+0x10c/0x188 phys=8b901000 ioremap
>>> 0xf1638000-0xf163a000    8192 mcss_pou_queue_init+0xa0/0x13c [mcss] phys=fc614000 ioremap
>>> 0xf528e000-0xf5292000   16384 n_tty_open+0x10/0xd0 pages=3 vmalloc
>>> 0xf5000000-0xf9001000 67112960 devm_ioremap+0x38/0x70 phys=40000000 ioremap
>> These two ranges overlap.
>>
>> This is hard to say where is the problem. From the code point of view, I don't
>> see there is possibility to allocate an overlapped range.
>>
>> Which version of your kernel?
>> Hard to reproduce means just see once? 
>  yes, just once.  I have also no see any problem from the code.   The kernel version is linux 4.1.
> but That indeed exist. 
>

This is really interesting. While without reproducing the behavior, it is
really costly to debug in the code.

I took a look into my own /proc/vmallocinfo, there are around hundred entries.
Currently, I don't have a clue to dive into the issue.

> Thanks
>zhongjiang
>>> 0xfe001000-0xfe002000    4096 iotable_init+0x0/0xc phys=20001000 ioremap
>>> 0xfe200000-0xfe201000    4096 iotable_init+0x0/0xc phys=1a000000 ioremap
>>> 0xff100000-0xff101000    4096 iotable_init+0x0/0xc phys=2000a000 ioremap
>>>
>>> I hit the above issue, but the log no more useful info. it just is found by accident.
>>> and it is hard to reprodeced. no more info can be supported for further investigation.
>>> therefore, it is no idea for me. 
>>>
>>> Thanks
>>> zhongjinag
>>>
>

-- 
Wei Yang
Help you, Help me

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web