MREMAP_DONTUNMAP keeps the source VMA in place, but clears its mlock flags while setting them on the destination VMA. The "mm/mremap: fix two issues with MREMAP_DONTUNMAP" series fixed two cases where this leaked mm->locked_vm:
- an unfaulted mlock-on-fault VMA moved behind itself self-merges, so the single resulting VMA loses the flags without the accounting being dropped; - a partial mremap() moves only part of the range, leaving the pages which are not moved accounted as locked in a VMA whose flags were cleared. Add a test which mlock2()s a source mapping, moves all or part of it with MREMAP_DONTUNMAP, unmaps everything and checks that VmLck is back to its value from before, and run it for the self-merge case and for a partial move with and without MLOCK_ONFAULT. Verified on x86_64: the three cases fail on mm-unstable with the two fixes reverted and pass with them applied. Signed-off-by: Jose A. Perez de Azpillaga <[email protected]> --- v2: - Reduce the churn (David): fold the three cases into one parameterised test and drop the child process per case, comparing VmLck against its value before each case instead. - Use the file's BUG_ON() for setup failures and vm_util's check_for_pattern() to read VmLck, call mlock2() directly. - Verify against mm-unstable with the two fixes reverted rather than an older -rc, now that the series is applied. tools/testing/selftests/mm/mremap_dontunmap.c | 63 ++++++++++++++++++- 1 file changed, 62 insertions(+), 1 deletion(-) diff --git a/tools/testing/selftests/mm/mremap_dontunmap.c b/tools/testing/selftests/mm/mremap_dontunmap.c index 96ba537facf7..5ca33d9d42af 100644 --- a/tools/testing/selftests/mm/mremap_dontunmap.c +++ b/tools/testing/selftests/mm/mremap_dontunmap.c @@ -7,6 +7,7 @@ */ #define _GNU_SOURCE #include <sys/mman.h> +#include <sys/syscall.h> #include <linux/mman.h> #include <errno.h> #include <stdio.h> @@ -15,6 +16,7 @@ #include <unistd.h> #include "kselftest.h" +#include "vm_util.h" unsigned long page_size; char *page_buffer; @@ -335,6 +337,62 @@ static void mremap_dontunmap_partial_mapping_overwrite(void) ksft_test_result_pass("%s\n", __func__); } +/* VmLck from /proc/self/status, which is mm->locked_vm in kB. */ +static unsigned long locked_vm_kb(void) +{ + unsigned long kb; + char buf[256]; + FILE *fp; + + fp = fopen("/proc/self/status", "r"); + BUG_ON(!fp, "unable to open /proc/self/status"); + BUG_ON(!check_for_pattern(fp, "VmLck:", buf, sizeof(buf)) || + sscanf(buf, "VmLck: %lu kB", &kb) != 1, "unable to read VmLck"); + fclose(fp); + + return kb; +} + +/* + * MREMAP_DONTUNMAP clears the mlock flags of the source VMA and sets them on + * the destination, and mm->locked_vm has to follow. mlock2() a source of + * num_pages and move its first move_pages to gap pages past its end: + * + * |------ source ------|... gap ...|-- dest --| + * + * then unmap everything and check that VmLck is back where it started. With + * no gap the destination is adjacent to the source and could merge with it, + * otherwise the gap is left PROT_NONE so that it cannot. + */ +static void mremap_dontunmap_mlock(const char *desc, unsigned long num_pages, + unsigned long move_pages, unsigned long gap, + int mlock_flags) +{ + unsigned long size = (num_pages + gap + move_pages) * page_size; + unsigned long locked = locked_vm_kb(); + void *source, *dest; + + source = mmap(NULL, size, PROT_NONE, MAP_PRIVATE | MAP_ANONYMOUS, -1, 0); + BUG_ON(source == MAP_FAILED, "mmap"); + BUG_ON(mprotect(source, num_pages * page_size, + PROT_READ | PROT_WRITE) == -1, "mprotect"); + dest = source + (num_pages + gap) * page_size; + + if (syscall(__NR_mlock2, source, num_pages * page_size, mlock_flags)) { + ksft_test_result_skip("%s: %s: mlock2: %s\n", __func__, desc, + strerror(errno)); + BUG_ON(munmap(source, size) == -1, "unable to unmap mappings"); + return; + } + + BUG_ON(mremap(source, move_pages * page_size, move_pages * page_size, + MREMAP_DONTUNMAP | MREMAP_MAYMOVE | MREMAP_FIXED, + dest) != dest, "mremap"); + + BUG_ON(munmap(source, size) == -1, "unable to unmap mappings"); + ksft_test_result(locked_vm_kb() == locked, "%s: %s\n", __func__, desc); +} + int main(void) { ksft_print_header(); @@ -348,7 +406,7 @@ int main(void) ksft_finished(); } - ksft_set_plan(5); + ksft_set_plan(8); // Keep a page sized buffer around for when we need it. page_buffer = @@ -361,6 +419,9 @@ int main(void) mremap_dontunmap_simple_fixed(); mremap_dontunmap_partial_mapping(); mremap_dontunmap_partial_mapping_overwrite(); + mremap_dontunmap_mlock("onfault self-merge", 1, 1, 0, MLOCK_ONFAULT); + mremap_dontunmap_mlock("partial", 3, 2, 1, 0); + mremap_dontunmap_mlock("onfault partial", 3, 2, 1, MLOCK_ONFAULT); BUG_ON(munmap(page_buffer, page_size) == -1, "unable to unmap page buffer"); -- 2.55.0

