[PATCH] proc: pagemap: Hold mmap_sem during page walk

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: San Mehat
Date: Wednesday, March 31, 2010 - 10:23 am

If the mmap_sem is not held while we walk_page_range(), then
it is possible for find_vma() to race with a remove_vma_list()
caused by do_munmap() (or others).

Unable to handle kernel paging request at virtual address 6b6b6b5b
Internal error: Oops: 5 [#1] PREEMPT
CPU: 0    Not tainted  (2.6.32.9-27154-ge3e6e27 #1)
PC is at find_vma+0x40/0x7c
LR is at walk_page_range+0x70/0x230
pc : [<c00aa3ac>]    lr : [<c00b298c>]    psr: 20000013
sp : c6aa9eb8  ip : 6b6b6b53  fp : c6a58f60
r10: c7e1d1b8  r9 : 0001bca0  r8 : 47000000
r7 : c6aa9f80  r6 : c6aa8000  r5 : 46fbd000  r4 : 6b6b6b6b
r3 : c7ca4820  r2 : 6b6b6b6b  r1 : 46fbd000  r0 : c70e3e40
Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment user
Control: 10c5787d  Table: 26574019  DAC: 00000015

[<c00aa3ac>] (find_vma+0x40/0x7c) from [<c00b298c>] (walk_page_range+0x70/0x230)
[<c00b298c>] (walk_page_range+0x70/0x230) from [<c00f5d3c>] (pagemap_read+0x1a4/0x278)
[<c00f5d3c>] (pagemap_read+0x1a4/0x278) from [<c00bac40>] (vfs_read+0xa8/0x150)
[<c00bac40>] (vfs_read+0xa8/0x150) from [<c00bad94>] (sys_read+0x3c/0x68)
[<c00bad94>] (sys_read+0x3c/0x68) from [<c0026f00>] (ret_fast_syscall+0x0/0x2c)
Code: 98bd8010 e5932004 e3a00000 ea000008 (e5124010)

Signed-off-by: San Mehat <san@google.com>
Cc: Brian Swetland <swetland@google.com>
Cc: Matt Mackall <mpm@selenic.com>
Cc: Dave Hansen <haveblue@us.ibm.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
---
 fs/proc/task_mmu.c |    3 +--
 1 files changed, 1 insertions(+), 2 deletions(-)

diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
index 2a1bef9..3f300c1 100644
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -726,8 +726,6 @@ static ssize_t pagemap_read(struct file *file, char __user *buf,
 	down_read(&current->mm->mmap_sem);
 	ret = get_user_pages(current, current->mm, uaddr, pagecount,
 			     1, 0, pages, NULL);
-	up_read(&current->mm->mmap_sem);
-
 	if (ret < 0)
 		goto out_free;
 
@@ -776,6 +774,7 @@ out_pages:
 		page_cache_release(page);
 	}
 out_free:
+	up_read(&current->mm->mmap_sem);
 	kfree(pages);
 out_mm:
 	mmput(mm);
-- 
1.7.0.1

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH] proc: pagemap: Hold mmap_sem during page walk, San Mehat, (Wed Mar 31, 10:23 am)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, Linus Torvalds, (Wed Mar 31, 10:54 am)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, Linus Torvalds, (Wed Mar 31, 6:33 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KOSAKI Motohiro, (Wed Mar 31, 7:10 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, Linus Torvalds, (Wed Mar 31, 9:27 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KOSAKI Motohiro, (Wed Mar 31, 10:54 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KAMEZAWA Hiroyuki, (Wed Mar 31, 10:55 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KOSAKI Motohiro, (Wed Mar 31, 11:05 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KAMEZAWA Hiroyuki, (Wed Mar 31, 11:09 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KAMEZAWA Hiroyuki, (Wed Mar 31, 11:34 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KOSAKI Motohiro, (Thu Apr 1, 12:21 am)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, Linus Torvalds, (Thu Apr 1, 8:10 am)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KAMEZAWA Hiroyuki, (Thu Apr 1, 5:11 pm)
Re: [PATCH] proc: pagemap: Hold mmap_sem during page walk, KAMEZAWA Hiroyuki, (Mon Apr 5, 11:48 pm)