Skip to content

Commit 2a797fd

Browse files
davejianggregkh
authored andcommitted
mm: disallow mappings that conflict for devm_memremap_pages()
commit 15d36fe upstream. When pmem namespaces created are smaller than section size, this can cause an issue during removal and gpf was observed: general protection fault: 0000 1 SMP PTI CPU: 36 PID: 3941 Comm: ndctl Tainted: G W 4.14.28-1.el7uek.x86_64 #2 task: ffff88acda150000 task.stack: ffffc900233a4000 RIP: 0010:__put_page+0x56/0x79 Call Trace: devm_memremap_pages_release+0x155/0x23a release_nodes+0x21e/0x260 devres_release_all+0x3c/0x48 device_release_driver_internal+0x15c/0x207 device_release_driver+0x12/0x14 unbind_store+0xba/0xd8 drv_attr_store+0x27/0x31 sysfs_kf_write+0x3f/0x46 kernfs_fop_write+0x10f/0x18b __vfs_write+0x3a/0x16d vfs_write+0xb2/0x1a1 SyS_write+0x55/0xb9 do_syscall_64+0x79/0x1ae entry_SYSCALL_64_after_hwframe+0x3d/0x0 Add code to check whether we have a mapping already in the same section and prevent additional mappings from being created if that is the case. Link: http://lkml.kernel.org/r/152909478401.50143.312364396244072931.stgit@djiang5-desk3.ch.intel.com Signed-off-by: Dave Jiang <dave.jiang@intel.com> Cc: Dan Williams <dan.j.williams@intel.com> Cc: Robert Elliott <elliott@hpe.com> Cc: Jeff Moyer <jmoyer@redhat.com> Cc: Matthew Wilcox <willy@infradead.org> Cc: <stable@vger.kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> Signed-off-by: Sudip Mukherjee <sudipm.mukherjee@gmail.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 8e6173c commit 2a797fd

1 file changed

Lines changed: 17 additions & 1 deletion

File tree

kernel/memremap.c

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -355,10 +355,27 @@ void *devm_memremap_pages(struct device *dev, struct resource *res,
355355
struct dev_pagemap *pgmap;
356356
struct page_map *page_map;
357357
int error, nid, is_ram, i = 0;
358+
struct dev_pagemap *conflict_pgmap;
358359

359360
align_start = res->start & ~(SECTION_SIZE - 1);
360361
align_size = ALIGN(res->start + resource_size(res), SECTION_SIZE)
361362
- align_start;
363+
align_end = align_start + align_size - 1;
364+
365+
conflict_pgmap = get_dev_pagemap(PHYS_PFN(align_start), NULL);
366+
if (conflict_pgmap) {
367+
dev_WARN(dev, "Conflicting mapping in same section\n");
368+
put_dev_pagemap(conflict_pgmap);
369+
return ERR_PTR(-ENOMEM);
370+
}
371+
372+
conflict_pgmap = get_dev_pagemap(PHYS_PFN(align_end), NULL);
373+
if (conflict_pgmap) {
374+
dev_WARN(dev, "Conflicting mapping in same section\n");
375+
put_dev_pagemap(conflict_pgmap);
376+
return ERR_PTR(-ENOMEM);
377+
}
378+
362379
is_ram = region_intersects(align_start, align_size,
363380
IORESOURCE_SYSTEM_RAM, IORES_DESC_NONE);
364381

@@ -396,7 +413,6 @@ void *devm_memremap_pages(struct device *dev, struct resource *res,
396413

397414
mutex_lock(&pgmap_lock);
398415
error = 0;
399-
align_end = align_start + align_size - 1;
400416

401417
foreach_order_pgoff(res, order, pgoff) {
402418
struct dev_pagemap *dup;

0 commit comments

Comments
 (0)