From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alexey Brodkin Subject: arc: mm->mmap_sem gets locked in do_page_fault() in case of OOM killer invocation Date: Fri, 16 Feb 2018 12:40:30 +0000 Message-ID: <1518784830.3544.33.camel@synopsys.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Return-path: Received: from smtprelay.synopsys.com ([198.182.47.9]:60938 "EHLO smtprelay.synopsys.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S967151AbeBPMkf (ORCPT ); Fri, 16 Feb 2018 07:40:35 -0500 Content-Language: en-US Content-ID: <2A9131B80B16FB4EAC4FB40E2B39EC19@internal.synopsys.com> Sender: linux-arch-owner@vger.kernel.org List-ID: To: Vineet Gupta Cc: "linux-kernel@vger.kernel.org" , "linux-arch@vger.kernel.org" , "linux-snps-arc@lists.infradead.org" SGkgVmluZWV0LA0KDQpXaGlsZSBwbGF5aW5nIHdpdGggT09NIGtpbGxlciBJIGJ1bXBlZCBpbiBh IHB1cmUgc29mdHdhcmUgZGVhZGxvY2sgb24gQVJDDQp3aGljaCBpcyBldmVuIG9ic2VydmVkIGlu IHNpbXVsYXRpb24gKGkuZS4gaXQgaGFzIG5vdGhpbmcgdG8gZG8gd2l0aCBIVyBwZWN1bGlhcml0 aWVzKS4NCg0KV2hhdCdzIG5pY2Uga2VybmVsIGV2ZW4gc2VlcyB0aGF0IGxvY2stdXAgaWYgIkxv Y2sgRGVidWdnaW5nIiBpcyBlbmFibGVkLg0KVGhhdCdzIHdoYXQgSSBzZWU6DQotLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLT44LS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLQ0KIyAvaG9tZS9vb20tdGVzdCA0NTAgJiAvaG9tZS9vb20t dGVzdCA0NTANCm9vbS10ZXN0IGludm9rZWQgb29tLWtpbGxlcjogZ2ZwX21hc2s9MHgxNDIwMGNh KEdGUF9ISUdIVVNFUl9NT1ZBQkxFKSwgbm9kZW1hc2s9KG51bGwpLCAgb3JkZXI9MCwgb29tX3Nj b3JlX2Fkaj0wDQpDUFU6IDAgUElEOiA2NyBDb21tOiBvb20tdGVzdCBOb3QgdGFpbnRlZCA0LjE0 LjE5ICMyDQoNClN0YWNrIFRyYWNlOg0KICBhcmNfdW53aW5kX2NvcmUuY29uc3Rwcm9wLjErMHhk NC8weGY4DQogIGR1bXBfaGVhZGVyLmlzcmEuNisweDg0LzB4MmY4DQogIG9vbV9raWxsX3Byb2Nl c3MrMHgyNTgvMHg3YzgNCiAgb3V0X29mX21lbW9yeSsweGI4LzB4NWUwDQogIF9fYWxsb2NfcGFn ZXNfbm9kZW1hc2srMHg5MjIvMHhkMjgNCiAgaGFuZGxlX21tX2ZhdWx0KzB4Mjg0LzB4ZDkwDQog IGRvX3BhZ2VfZmF1bHQrMHhmNi8weDJhMA0KICByZXRfZnJvbV9leGNlcHRpb24rMHgwLzB4OA0K TWVtLUluZm86DQphY3RpdmVfYW5vbjo2MjI3NiBpbmFjdGl2ZV9hbm9uOjM0MSBpc29sYXRlZF9h bm9uOjANCiBhY3RpdmVfZmlsZTowIGluYWN0aXZlX2ZpbGU6MCBpc29sYXRlZF9maWxlOjANCiB1 bmV2aWN0YWJsZTowIGRpcnR5OjAgd3JpdGViYWNrOjAgdW5zdGFibGU6MA0KIHNsYWJfcmVjbGFp bWFibGU6MjYgc2xhYl91bnJlY2xhaW1hYmxlOjE5Ng0KIG1hcHBlZDoxMDUgc2htZW06NTc4IHBh Z2V0YWJsZXM6MjYzIGJvdW5jZTowDQogZnJlZTozNDQgZnJlZV9wY3A6MzkgZnJlZV9jbWE6MA0K Tm9kZSAwIGFjdGl2ZV9hbm9uOjQ5ODIwOGtCIGluYWN0aXZlX2Fub246MjcyOGtCIGFjdGl2ZV9m aWxlOjBrQiBpbmFjdGl2ZV9maWxlOjBrQiB1bmV2aWN0YWJsZTowa0IgaXNvbGF0ZWQoYW5vbik6 MGtCIGlzb2xhdGVkKGZpbGUpOjBrQiBtYXBwZWQ6ODQwa0INCmRpcnR5Og0KMGtCIHdyaXRlYmFj azowa0Igc2htZW06NDYyNGtCIHdyaXRlYmFja190bXA6MGtCIHVuc3RhYmxlOjBrQiBhbGxfdW5y ZWNsYWltYWJsZT8gbm8NCk5vcm1hbCBmcmVlOjI3NTJrQiBtaW46Mjg0MGtCIGxvdzozNTQ0a0Ig aGlnaDo0MjQ4a0IgYWN0aXZlX2Fub246NDk4MjA4a0IgaW5hY3RpdmVfYW5vbjoyNzI4a0IgYWN0 aXZlX2ZpbGU6MGtCIGluYWN0aXZlX2ZpbGU6MGtCIHVuZXZpY3RhYmxlOjBrQg0Kd3JpdGVwZW5k aW4NCmc6MGtCIHByZXNlbnQ6NTI0Mjg4a0IgbWFuYWdlZDo1MDg1ODRrQiBtbG9ja2VkOjBrQiBr ZXJuZWxfc3RhY2s6MjQwa0IgcGFnZXRhYmxlczoyMTA0a0IgYm91bmNlOjBrQiBmcmVlX3BjcDoz MTJrQiBsb2NhbF9wY3A6MzEya0IgZnJlZV9jbWE6MGtCDQpsb3dtZW1fcmVzZXJ2ZVtdOiAwIDAN Ck5vcm1hbDogMCo4a0IgMCoxNmtCIDAqMzJrQiAxKjY0a0IgKE0pIDEqMTI4a0IgKE0pIDAqMjU2 a0IgMSo1MTJrQiAoTSkgMCoxMDI0a0IgMSoyMDQ4a0IgKE0pIDAqNDA5NmtCIDAqODE5MmtCID0g Mjc1MmtCDQo1NzggdG90YWwgcGFnZWNhY2hlIHBhZ2VzDQo2NTUzNiBwYWdlcyBSQU0NCjAgcGFn ZXMgSGlnaE1lbS9Nb3ZhYmxlT25seQ0KMTk2MyBwYWdlcyByZXNlcnZlZA0KWyBwaWQgXSAgIHVp ZCAgdGdpZCB0b3RhbF92bSAgICAgIHJzcyBucl9wdGVzIG5yX3BtZHMgc3dhcGVudHMgb29tX3Nj b3JlX2FkaiBuYW1lDQpbICAgNDFdICAgICAwICAgIDQxICAgICAgMTU3ICAgICAgMTAzICAgICAg IDMgICAgICAgMCAgICAgICAgMCAgICAgICAgICAgICAwIHN5c2xvZ2QNClsgICA0M10gICAgIDAg ICAgNDMgICAgICAxNTYgICAgICAxMDYgICAgICAgMyAgICAgICAwICAgICAgICAwICAgICAgICAg ICAgIDAga2xvZ2QNClsgICA2M10gICAgIDAgICAgNjMgICAgICAxNTcgICAgICAgOTkgICAgICAg MyAgICAgICAwICAgICAgICAwICAgICAgICAgICAgIDAgZ2V0dHkNClsgICA2NF0gICAgIDAgICAg NjQgICAgICAxNTkgICAgICAxMTggICAgICAgMyAgICAgICAwICAgICAgICAwICAgICAgICAgICAg IDAgc2gNClsgICA2Nl0gICAgIDAgICAgNjYgICAxMTUyOTEgICAgMzEwOTQgICAgIDEyNCAgICAg ICAwICAgICAgICAwICAgICAgICAgICAgIDAgb29tLXRlc3QNClsgICA2N10gICAgIDAgICAgNjcg ICAxMTUyOTEgICAgMzEwMDQgICAgIDEyNCAgICAgICAwICAgICAgICAwICAgICAgICAgICAgIDAg b29tLXRlc3QNCk91dCBvZiBtZW1vcnk6IEtpbGwgcHJvY2VzcyA2NiAob29tLXRlc3QpIHNjb3Jl IDQ3NiBvciBzYWNyaWZpY2UgY2hpbGQNCktpbGxlZCBwcm9jZXNzIDY2IChvb20tdGVzdCkgdG90 YWwtdm06OTIyMzI4a0IsIGFub24tcnNzOjI0ODMyOGtCLCBmaWxlLXJzczowa0IsIHNobWVtLXJz czo0MjRrQg0KDQo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQ0K V0FSTklORzogcG9zc2libGUgcmVjdXJzaXZlIGxvY2tpbmcgZGV0ZWN0ZWQNCjQuMTQuMTkgIzIg Tm90IHRhaW50ZWQNCi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t DQpvb20tdGVzdC82NiBpcyB0cnlpbmcgdG8gYWNxdWlyZSBsb2NrOg0KICgmbW0tPm1tYXBfc2Vt KXsrKysrfSwgYXQ6IFs8ODAyMTdkNTA+XSBkb19leGl0KzB4NDQ0LzB4N2Y4DQoNCmJ1dCB0YXNr IGlzIGFscmVhZHkgaG9sZGluZyBsb2NrOg0KICgmbW0tPm1tYXBfc2VtKXsrKysrfSwgYXQ6IFs8 ODAyMTAyOGE+XSBkb19wYWdlX2ZhdWx0KzB4OWUvMHgyYTANCg0Kb3RoZXIgaW5mbyB0aGF0IG1p Z2h0IGhlbHAgdXMgZGVidWcgdGhpczoNCiBQb3NzaWJsZSB1bnNhZmUgbG9ja2luZyBzY2VuYXJp bzoNCg0KICAgICAgIENQVTANCiAgICAgICAtLS0tDQogIGxvY2soJm1tLT5tbWFwX3NlbSk7DQog IGxvY2soJm1tLT5tbWFwX3NlbSk7DQoNCiAqKiogREVBRExPQ0sgKioqDQoNCiBNYXkgYmUgZHVl IHRvIG1pc3NpbmcgbG9jayBuZXN0aW5nIG5vdGF0aW9uDQoNCjEgbG9jayBoZWxkIGJ5IG9vbS10 ZXN0LzY2Og0KICMwOiAgKCZtbS0+bW1hcF9zZW0peysrKyt9LCBhdDogWzw4MDIxMDI4YT5dIGRv X3BhZ2VfZmF1bHQrMHg5ZS8weDJhMA0KDQpzdGFjayBiYWNrdHJhY2U6DQpDUFU6IDAgUElEOiA2 NiBDb21tOiBvb20tdGVzdCBOb3QgdGFpbnRlZCA0LjE0LjE5ICMyDQoNClN0YWNrIFRyYWNlOg0K ICBhcmNfdW53aW5kX2NvcmUuY29uc3Rwcm9wLjErMHhkNC8weGY4DQogIF9fbG9ja19hY3F1aXJl KzB4NTgyLzB4MTQ5NA0KICBsb2NrX2FjcXVpcmUrMHgzYy8weDU4DQogIGRvd25fcmVhZCsweDFh LzB4MjgNCiAgZG9fZXhpdCsweDQ0NC8weDdmOA0KICBkb19ncm91cF9leGl0KzB4MjYvMHg4Yw0K ICBnZXRfc2lnbmFsKzB4MWFhLzB4N2Q0DQogIGRvX3NpZ25hbCsweDMwLzB4MjIwDQogIHJlc3Vt ZV91c2VyX21vZGVfYmVnaW4rMHg5MC8weGQ4DQotLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLT44LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLQ0KDQpMb29raW5nIGF0IG91ciBjb2RlIGluICJhcmNoL2FyYy9tbS9mYXVsdC5jIiBJIG1h eSBzZWUgd2h5ICJtbS0+bW1hcF9zZW0iIGlzIG5vdCByZWxlYXNlZDoNCjEuIGZhdGFsX3NpZ25h bF9wZW5kaW5nKGN1cnJlbnQpIHJldHVybnMgbm9uLXplcm8gdmFsdWUNCjIuICgoZmF1bHQgJiBW TV9GQVVMVF9FUlJPUikgJiYgIShmYXVsdCAmIFZNX0ZBVUxUX1JFVFJZKSkgaXMgZmFsc2UgdGh1 cyB1cF9yZWFkKCZtbS0+bW1hcF9zZW0pDQogICBpcyBub3QgZXhlY3V0ZWQuDQozLiBJdCB3YXMg YSB1c2VyLXNwYWNlIHByb2Nlc3MgdGh1cyB3ZSBzaW1wbHkgcmV0dXJuIFt3aXRoICJtbS0+bW1h cF9zZW0iIHN0aWxsIGhlbGRdLg0KDQpTZWUgdGhlIGNvZGUgc25pcHBldCBiZWxvdzoNCi0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tPjgtLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tDQoJLyogSWYgUGFnZWZhdWx0IHdhcyBpbnRlcnJ1 cHRlZCBieSBTSUdLSUxMLCBleGl0IHBhZ2UgZmF1bHQgImVhcmx5IiAqLw0KCWlmICh1bmxpa2Vs eShmYXRhbF9zaWduYWxfcGVuZGluZyhjdXJyZW50KSkpIHsNCgkJaWYgKChmYXVsdCAmIFZNX0ZB VUxUX0VSUk9SKSAmJiAhKGZhdWx0ICYgVk1fRkFVTFRfUkVUUlkpKQ0KCQkJdXBfcmVhZCgmbW0t Pm1tYXBfc2VtKTsNCgkJaWYgKHVzZXJfbW9kZShyZWdzKSkNCgkJCXJldHVybjsNCgl9DQotLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLT44LS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLQ0KDQpUaGVuIHdlIGxlYXZlIHBhZ2UgZmF1bHQg aGFuZGxlciBhbmQgYmVmb3JlIHJldHVybmluZyB0byB1c2VyLXNwYWNlIHdlDQpwcm9jZXNzIHBl bmRpbmcgc2lnbmFsIHdoaWNoIGhhcHBlbiB0byBiZSBhIGRlYXRoIHNpZ25hbCBhbmQgc28gd2Ug ZW5kLXVwIGV4ZWN1dGluZyB0aGUNCmZvbGxvd2luZyBjb2RlLXBhdGggKHNlZSBzdGFjayB0cmFj ZSBhYm92ZSk6DQogICAgZG9fZXhpdCgpIC0+IGV4aXRfbW0oKSAtPiBkb3duX3JlYWQoJm1tLT5t bWFwX3NlbSkgPC0tIEFuZCBoZXJlIHdlIGdvIGxvY2tpbmcgb3Vyc2VsdmVzIGZvciBnb29kLg0K DQpXaGF0J3MgaW50ZXJlc3RpbmcgbW9zdCBpZiBub3QgYWxsIGFyY2hpdGVjdHVyZXMgcmV0dXJu IGZyb20gcGFnZSBmYXVsdCBoYW5kbGVyIHdpdGgNCiJtbS0+bW1hcF9zZW0iIGhlbGQgaW4gY2Fz ZSBvZiBmYXRhbF9zaWduYWxfcGVuZGluZygpLiBTbyBJIHdvdWxkIGV4cGVjdCB0aGUgc2FtZSBm YWlsdXJlIGFzIEkgc2VlIG9uIEFSQw0KdG8gaGFwcGVuIG9uIG90aGVyIGFyY2hlcyB0b28uLi4g dGhvdWdoIEkgd2FzIG5vdCBhYmxlIHRvIHRyaWdnZXIgdGhhdCBvbiBBUk0gKFdhbmRCb2FyZCBR dWFkKS4NCg0KSSB0aGluayBiZWNhdXNlIG9uIEFSTSBhbmQgbWFueSBvdGhlcnMgdGhlIGNoZWNr IGlzIGEgYml0IGRpZmZlcmVudDoNCi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tPjgtLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tDQoJ aWYgKChmYXVsdCAmIFZNX0ZBVUxUX1JFVFJZKSAmJiBmYXRhbF9zaWduYWxfcGVuZGluZyhjdXJy ZW50KSkgew0KCQlpZiAoIXVzZXJfbW9kZShyZWdzKSkNCgkJCWdvdG8gbm9fY29udGV4dDsNCgkJ cmV0dXJuIDA7DQoJfQ0KLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0+OC0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0NCg0KU28gdG8g Z2V0IGludG8gcHJvYmxlbWF0aWMgY29kZS1wYXRoIChpLmUuIGV4aXQgd2l0aCAibW0tPm1tYXBf c2VtIiBzdGlsbCBoZWxkKSB3ZSBuZWVkDQpfX2RvX3BhZ2VfZmF1bHQoKSB0byByZXR1cm4gVk1f RkFVTFRfUkVUUlkuIFdoaWNoIG1ha2VzIHJlcHJvZHVjdGlvbiBldmVuIG1vcmUgY29tcGxpY2F0 ZWQgYnV0DQpJIHRoaW5rIGl0J3Mgc3RpbGwgZG9hYmxlIDopDQoNClRoZSBzaW1wbGVzdCBzb2x1 dGlvbiBoZXJlIHNlZW1zIHRvIGJlIHVuY29uZGl0aW9uYWwgdXBfcmVhZCgmbW0tPm1tYXBfc2Vt KSBiZWZvcmUgcmV0dXJuIGJ1dA0KdGhhdCdzIHNvIHN0cmFuZ2UgaXQgd2FzIG5vdCBkb25lIGJ5 IHRoYXQgdGltZS4gQW55d2F5cyBhbnkgdGhvdWdodCBhcmUgdmVyeSB3ZWxjb21lIQ0KDQotQWxl eGV5 From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alexey.Brodkin@synopsys.com (Alexey Brodkin) Date: Fri, 16 Feb 2018 12:40:30 +0000 Subject: arc: mm->mmap_sem gets locked in do_page_fault() in case of OOM killer invocation List-ID: Message-ID: <1518784830.3544.33.camel@synopsys.com> To: linux-snps-arc@lists.infradead.org Hi Vineet, While playing with OOM killer I bumped in a pure software deadlock on ARC which is even observed in simulation (i.e. it has nothing to do with HW peculiarities). What's nice kernel even sees that lock-up if "Lock Debugging" is enabled. That's what I see: -------------------------------------------->8------------------------------------------- # /home/oom-test 450 & /home/oom-test 450 oom-test invoked oom-killer: gfp_mask=0x14200ca(GFP_HIGHUSER_MOVABLE), nodemask=(null), order=0, oom_score_adj=0 CPU: 0 PID: 67 Comm: oom-test Not tainted 4.14.19 #2 Stack Trace: arc_unwind_core.constprop.1+0xd4/0xf8 dump_header.isra.6+0x84/0x2f8 oom_kill_process+0x258/0x7c8 out_of_memory+0xb8/0x5e0 __alloc_pages_nodemask+0x922/0xd28 handle_mm_fault+0x284/0xd90 do_page_fault+0xf6/0x2a0 ret_from_exception+0x0/0x8 Mem-Info: active_anon:62276 inactive_anon:341 isolated_anon:0 active_file:0 inactive_file:0 isolated_file:0 unevictable:0 dirty:0 writeback:0 unstable:0 slab_reclaimable:26 slab_unreclaimable:196 mapped:105 shmem:578 pagetables:263 bounce:0 free:344 free_pcp:39 free_cma:0 Node 0 active_anon:498208kB inactive_anon:2728kB active_file:0kB inactive_file:0kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:840kB dirty: 0kB writeback:0kB shmem:4624kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no Normal free:2752kB min:2840kB low:3544kB high:4248kB active_anon:498208kB inactive_anon:2728kB active_file:0kB inactive_file:0kB unevictable:0kB writependin g:0kB present:524288kB managed:508584kB mlocked:0kB kernel_stack:240kB pagetables:2104kB bounce:0kB free_pcp:312kB local_pcp:312kB free_cma:0kB lowmem_reserve[]: 0 0 Normal: 0*8kB 0*16kB 0*32kB 1*64kB (M) 1*128kB (M) 0*256kB 1*512kB (M) 0*1024kB 1*2048kB (M) 0*4096kB 0*8192kB = 2752kB 578 total pagecache pages 65536 pages RAM 0 pages HighMem/MovableOnly 1963 pages reserved [ pid ] uid tgid total_vm rss nr_ptes nr_pmds swapents oom_score_adj name [ 41] 0 41 157 103 3 0 0 0 syslogd [ 43] 0 43 156 106 3 0 0 0 klogd [ 63] 0 63 157 99 3 0 0 0 getty [ 64] 0 64 159 118 3 0 0 0 sh [ 66] 0 66 115291 31094 124 0 0 0 oom-test [ 67] 0 67 115291 31004 124 0 0 0 oom-test Out of memory: Kill process 66 (oom-test) score 476 or sacrifice child Killed process 66 (oom-test) total-vm:922328kB, anon-rss:248328kB, file-rss:0kB, shmem-rss:424kB ============================================ WARNING: possible recursive locking detected 4.14.19 #2 Not tainted -------------------------------------------- oom-test/66 is trying to acquire lock: (&mm->mmap_sem){++++}, at: [<80217d50>] do_exit+0x444/0x7f8 but task is already holding lock: (&mm->mmap_sem){++++}, at: [<8021028a>] do_page_fault+0x9e/0x2a0 other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(&mm->mmap_sem); lock(&mm->mmap_sem); *** DEADLOCK *** May be due to missing lock nesting notation 1 lock held by oom-test/66: #0: (&mm->mmap_sem){++++}, at: [<8021028a>] do_page_fault+0x9e/0x2a0 stack backtrace: CPU: 0 PID: 66 Comm: oom-test Not tainted 4.14.19 #2 Stack Trace: arc_unwind_core.constprop.1+0xd4/0xf8 __lock_acquire+0x582/0x1494 lock_acquire+0x3c/0x58 down_read+0x1a/0x28 do_exit+0x444/0x7f8 do_group_exit+0x26/0x8c get_signal+0x1aa/0x7d4 do_signal+0x30/0x220 resume_user_mode_begin+0x90/0xd8 -------------------------------------------->8------------------------------------------- Looking at our code in "arch/arc/mm/fault.c" I may see why "mm->mmap_sem" is not released: 1. fatal_signal_pending(current) returns non-zero value 2. ((fault & VM_FAULT_ERROR) && !(fault & VM_FAULT_RETRY)) is false thus up_read(&mm->mmap_sem) is not executed. 3. It was a user-space process thus we simply return [with "mm->mmap_sem" still held]. See the code snippet below: -------------------------------------------->8------------------------------------------- /* If Pagefault was interrupted by SIGKILL, exit page fault "early" */ if (unlikely(fatal_signal_pending(current))) { if ((fault & VM_FAULT_ERROR) && !(fault & VM_FAULT_RETRY)) up_read(&mm->mmap_sem); if (user_mode(regs)) return; } -------------------------------------------->8------------------------------------------- Then we leave page fault handler and before returning to user-space we process pending signal which happen to be a death signal and so we end-up executing the following code-path (see stack trace above): do_exit() -> exit_mm() -> down_read(&mm->mmap_sem) <-- And here we go locking ourselves for good. What's interesting most if not all architectures return from page fault handler with "mm->mmap_sem" held in case of fatal_signal_pending(). So I would expect the same failure as I see on ARC to happen on other arches too... though I was not able to trigger that on ARM (WandBoard Quad). I think because on ARM and many others the check is a bit different: -------------------------------------------->8------------------------------------------- if ((fault & VM_FAULT_RETRY) && fatal_signal_pending(current)) { if (!user_mode(regs)) goto no_context; return 0; } -------------------------------------------->8------------------------------------------- So to get into problematic code-path (i.e. exit with "mm->mmap_sem" still held) we need __do_page_fault() to return VM_FAULT_RETRY. Which makes reproduction even more complicated but I think it's still doable :) The simplest solution here seems to be unconditional up_read(&mm->mmap_sem) before return but that's so strange it was not done by that time. Anyways any thought are very welcome! -Alexey