Repository navigation
Downstream oss mem fixes - #18030
Downstream oss mem fixes#18030behlendorf wants to merge 4 commits into
Conversation
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: Brian BehlendorfSigned-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
This PR addresses memory-related bugs in ZFS's handling of high memory pages on Linux systems. The changes ensure proper page boundary handling when mapping and unmapping memory regions, fixing potential memory corruption issues.
Key changes:
- Fixed highmem page handling in ABD iterator map/unmap operations to properly handle multi-page scatter-gather lists
- Corrected page boundary calculations in bio_vec operations to prevent out-of-bounds memory access
- Reordered unmap operations in RAIDZ generation to ensure correct cleanup sequence
- Enhanced commit message checking to exempt signed-off-by/reviewed-by lines from length limits
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| scripts/commitcheck.sh | Added filters to exempt signed-off-by and reviewed-by lines from 72-character length check |
| module/zfs/abd.c | Reordered unmap loop to occur after data ABD cleanup in RAIDZ generation |
| module/os/linux/zfs/zfs_uio.c | Fixed page offset and size calculations for multi-page bio_vec handling |
| module/os/linux/zfs/abd_os.c | Added highmem page handling with nth_page() and proper offset masking in ABD iterators |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: Brian BehlendorfSigned-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: Brian BehlendorfSigned-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Signed-off-by: Brian Behlendorf
81cb3ea to
62f8206
Compare
robn
left a comment
There was a problem hiding this comment.
This makes sense to me. One question about an API detail but I don't think it changes anything for now.
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes #15668 Closes #18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes #15668 Closes #18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes #18030
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes openzfs#18030
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes openzfs#18030
|
@behlendorf can these be backported to stable releases? It looks like they're staged for 2.4.0 but they're been needed on my system to boot the root pool since 2.3.1 i believe. |
|
@sempervictus yes, we'll want to pull these in for the next 2.3.x release. |
|
Thank you! |
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes openzfs#18030
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes openzfs#18030
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes #15668 Closes #18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes #15668 Closes #18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes #15668 Closes #18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes #18030
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes openzfs#18030
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes openzfs#18030
HIGHMEM kmap interfaces operate on only a single page at a time yet ZFS hadn't accounted for this, resulting in crashes and potential memory corruption on HIGHMEM (typically 32-bit) systems. This was caught by PaX's KERNSEAL feature as it makes use of HIGHMEM functionality on x64. On typical 64-bit systems, this issue wouldn't have been observed, as the map interfaces simply fall back to returning an address in lowmem where the contiguous pages can be accessed directly. Joint work with the PaX Team, tested by Mark van Dijk Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
ZFS typically preserves proper LIFO ordering regarding map/unmap operations that wrap the Linux kernel's kmap interfaces that require such ordering, but one instance in abd_raidz_gen_iterate() did not. Similar issues have been fixed in the Linux kernel in the past, see for instance CVE-2025-39899 for userfaultfd. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Fix another instance where ZFS assumes multiple pages can be mapped at once via zfs_kmap_local(), resulting in crashes and potential memory corruption on HIGHMEM-enabled (typically 32-bit) systems. Reviewed-by: RageLtManReviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com> Closes openzfs#15668 Closes openzfs#18030
Allow an author or reviewer's name and email address to exceed the 72 character limit enforced by the commitcheck target. Reviewed-by: RageLtManReviewed-by: Rob Norris Signed-off-by: Brian Behlendorf Closes openzfs#18030
Motivation and Context
Replaces #17973. I've opened to PR to test the final patch set.
The following small changes have been made from the original:
struct page *where it's assigned inabd_iter_mapandabd_iter_unmap.This really should be its own PR, but it's trivial enough I included it here as a separate commit.
Description
See #17973 and #15668 for details.
How Has This Been Tested?
The change is identical to the updated #17973 with the exception of 2. above.
Types of changes