# HG changeset patch
# User kaf24@xxxxxxxxxxxxxxxxxxxx
# Node ID 49a0f2160a6c806333fb3174e431f52117fff54a
# Parent 62f7675aeb5152a498d9277081a9fdee1bb7e3e8
kunmap_atomic() must zap the PTE to avoid dangling references
when attempting to free memory back to Xen. We can implement
something more efficient in future.
Also add debug print message if guest tries to free 'in use'
memory. We'll make it a real guest-visible error in future.
Signed-off-by: Keir Fraser <keir@xxxxxxxxxxxxx>
xen-unstable changeset: 10529:4260eb8c08740de0000081c61a6237ffcb95b2d5
xen-unstable date: Wed Jun 28 18:17:41 2006 +0100
---
linux-2.6-xen-sparse/arch/i386/mm/highmem-xen.c | 10 ++++++++++
xen/common/memory.c | 9 +++++++++
2 files changed, 19 insertions(+)
diff -r 62f7675aeb51 -r 49a0f2160a6c
linux-2.6-xen-sparse/arch/i386/mm/highmem-xen.c
--- a/linux-2.6-xen-sparse/arch/i386/mm/highmem-xen.c Wed Jun 28 18:38:03
2006 +0100
+++ b/linux-2.6-xen-sparse/arch/i386/mm/highmem-xen.c Wed Jun 28 18:40:23
2006 +0100
@@ -79,6 +79,16 @@ void kunmap_atomic(void *kvaddr, enum km
*/
pte_clear(&init_mm, vaddr, kmap_pte-idx);
__flush_tlb_one(vaddr);
+#elif defined(CONFIG_XEN)
+ /*
+ * We must ensure there are no dangling pagetable references when
+ * returning memory to Xen (decrease_reservation).
+ * XXX TODO: We could make this faster by only zapping when
+ * kmap_flush_unused is called but that is trickier and more invasive.
+ */
+ unsigned long vaddr = (unsigned long) kvaddr & PAGE_MASK;
+ enum fixed_addresses idx = type + KM_TYPE_NR*smp_processor_id();
+ pte_clear(&init_mm, vaddr, kmap_pte-idx);
#endif
dec_preempt_count();
diff -r 62f7675aeb51 -r 49a0f2160a6c xen/common/memory.c
--- a/xen/common/memory.c Wed Jun 28 18:38:03 2006 +0100
+++ b/xen/common/memory.c Wed Jun 28 18:40:23 2006 +0100
@@ -166,6 +166,15 @@ guest_remove_page(
if ( test_and_clear_bit(_PGC_allocated, &page->count_info) )
put_page(page);
+
+ if ( unlikely((page->count_info & PGC_count_mask) != 1) )
+ {
+ /* We'll make this a guest-visible error in future, so take heed! */
+ DPRINTK("Dom%d freeing in-use page %lx (pseudophys %lx):"
+ " count=%x type=%lx\n",
+ d->domain_id, mfn, get_gpfn_from_mfn(mfn),
+ page->count_info, page->u.inuse.type_info);
+ }
guest_physmap_remove_page(d, gmfn, mfn);
_______________________________________________
Xen-changelog mailing list
Xen-changelog@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-changelog
|