On Mon, Oct 28, 2013 at 04:20:05PM +0000, Ming Lei wrote: > Commit b1adaf65ba03([SCSI] block: add sg buffer copy helper functions) > introduces two sg buffer copy helpers, and calls flush_kernel_dcache_page() > on pages in SG list after these pages are written to. > > Unfortunately, the commit may introduce a potential bug: > > - Before sending some SCSI commands, kmalloc() buffer may be > passed to block layper, so flush_kernel_dcache_page() can > see a slab page finally > > - According to cachetlb.txt, flush_kernel_dcache_page() is > only called on "a user page", which surely can't be a slab page. > > - ARCH's implementation of flush_kernel_dcache_page() may > use page mapping information to do optimization so page_mapping() > will see the slab page, then VM_BUG_ON() is triggered. > > Aaro Koskinen reported the bug on ARM/kirkwood when DEBUG_VM is enabled, > and this patch fixes the bug by adding test of '!PageSlab(miter->page)' > before calling flush_kernel_dcache_page(). > > Reported-by: Aaro Koskinen <aaro.koski...@iki.fi> > Cc: Russell King - ARM Linux <li...@arm.linux.org.uk> > Cc: linux-arm-ker...@lists.infradead.org > Cc: Simon Baatz <gmbno...@gmail.com> > Cc: Will Deacon <will.dea...@arm.com> > Cc: Aaro Koskinen <aaro.koski...@iki.fi> > Cc: Catalin Marinas <catalin.mari...@arm.com> > Cc: Andrew Morton <a...@linux-foundation.org> > Cc: FUJITA Tomonori <fujita.tomon...@lab.ntt.co.jp> > Cc: Tejun Heo <t...@kernel.org> > Cc: "James E.J. Bottomley" <jbottom...@parallels.com> > Cc: Jens Axboe <ax...@kernel.dk> > Signed-off-by: Ming Lei <ming....@canonical.com>
Acked-by: Catalin Marinas <catalin.mari...@arm.com> -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/