RE: [PATCH V1 5/5] mm/gup: fix memfd_pin_folios alloc race panic

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> Subject: [PATCH V1 5/5] mm/gup: fix memfd_pin_folios alloc race panic
> 
> If memfd_pin_folios tries to create a hugetlb page, but someone else
> already did, then folio gets the value -EEXIST here:
> 
>         folio = memfd_alloc_folio(memfd, start_idx);
>         if (IS_ERR(folio)) {
>                 ret = PTR_ERR(folio);
>                 if (ret != -EEXIST)
>                         goto err;
> 
> then on the next trip through the "while start_idx" loop we panic here:
> 
>         if (folio) {
>                 folio_put(folio);
> 
> To fix, set the folio to NULL on error.
> 
> Fixes: 89c1905d9c14 ("mm/gup: introduce memfd_pin_folios() for pinning
> memfd folios")
> 
> Signed-off-by: Steve Sistare <steven.sistare@xxxxxxxxxx>
> ---
>  mm/gup.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/mm/gup.c b/mm/gup.c
> index 5b92f1d..bccabaa 100644
> --- a/mm/gup.c
> +++ b/mm/gup.c
> @@ -3705,6 +3705,7 @@ long memfd_pin_folios(struct file *memfd, loff_t
> start, loff_t end,
>  					ret = PTR_ERR(folio);
>  					if (ret != -EEXIST)
>  						goto err;
> +					folio = NULL;
Acked-by: Vivek Kasireddy <vivek.kasireddy@xxxxxxxxx>

Thanks,
Vivek
>  				}
>  			}
>  		}
> --
> 1.8.3.1






[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Bugtraq]     [Linux OMAP]     [Linux MIPS]     [eCos]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux