From: Greg KH <gregkh@linuxfoundation.org>
To: David Hildenbrand <david@redhat.com>
Cc: Mel Gorman <mgorman@techsingularity.net>,
"Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>,
Michal Hocko <mhocko@suse.com>,
Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>,
Jan Kara <jack@suse.cz>, Andrea Arcangeli <aarcange@redhat.com>,
Dominik Brodowski <linux@dominikbrodowski.net>,
Matthew Wilcox <willy@infradead.org>,
Vratislav Bendel <vbendel@redhat.com>,
Rafael Aquini <aquini@redhat.com>,
Konstantin Khlebnikov <k.khlebnikov@samsung.com>,
Minchan Kim <minchan@kernel.org>,
stable@vger.kernel.org, Andrew Morton <akpm@linux-foundation.org>,
Linus Torvalds <torvalds@linux-foundation.org>
Subject: Re: [PATCH for-4.4-stable] mm: migrate: don't rely on __PageMovable() of newpage after unlocking it
Date: Mon, 4 Feb 2019 10:15:24 +0100 [thread overview]
Message-ID: <20190204091524.GA3432@kroah.com> (raw)
In-Reply-To: <7329b017-3bac-9cc6-022b-48c528371f94@redhat.com>
On Mon, Feb 04, 2019 at 10:05:14AM +0100, David Hildenbrand wrote:
> On 04.02.19 10:00, David Hildenbrand wrote:
> > commit e0a352fabce61f730341d119fbedf71ffdb8663f upstream.
> >
> > We had a race in the old balloon compaction code before b1123ea6d3b3
> > ("mm: balloon: use general non-lru movable page feature") refactored it
> > that became visible after backporting 195a8c43e93d ("virtio-balloon:
> > deflate via a page list") without the refactoring.
> >
> > The bug existed from commit d6d86c0a7f8d ("mm/balloon_compaction:
> > redesign ballooned pages management") till b1123ea6d3b3 ("mm: balloon:
> > use general non-lru movable page feature"). d6d86c0a7f8d
> > ("mm/balloon_compaction: redesign ballooned pages management") was
> > backported to 3.12, so the broken kernels are stable kernels [3.12 -
> > 4.7].
> >
> > There was a subtle race between dropping the page lock of the newpage in
> > __unmap_and_move() and checking for __is_movable_balloon_page(newpage).
> >
> > Just after dropping this page lock, virtio-balloon could go ahead and
> > deflate the newpage, effectively dequeueing it and clearing PageBalloon,
> > in turn making __is_movable_balloon_page(newpage) fail.
> >
> > This resulted in dropping the reference of the newpage via
> > putback_lru_page(newpage) instead of put_page(newpage), leading to
> > page->lru getting modified and a !LRU page ending up in the LRU lists.
> > With 195a8c43e93d ("virtio-balloon: deflate via a page list")
> > backported, one would suddenly get corrupted lists in
> > release_pages_balloon():
> >
> > - WARNING: CPU: 13 PID: 6586 at lib/list_debug.c:59 __list_del_entry+0xa1/0xd0
> > - list_del corruption. prev->next should be ffffe253961090a0, but was dead000000000100
> >
> > Nowadays this race is no longer possible, but it is hidden behind very
> > ugly handling of __ClearPageMovable() and __PageMovable().
> >
> > __ClearPageMovable() will not make __PageMovable() fail, only
> > PageMovable(). So the new check (__PageMovable(newpage)) will still
> > hold even after newpage was dequeued by virtio-balloon.
> >
> > If anybody would ever change that special handling, the BUG would be
> > introduced again. So instead, make it explicit and use the information
> > of the original isolated page before migration.
> >
> > This patch can be backported fairly easy to stable kernels (in contrast
> > to the refactoring).
> >
> > Link: http://lkml.kernel.org/r/20190129233217.10747-1-david@redhat.com
> > Fixes: d6d86c0a7f8d ("mm/balloon_compaction: redesign ballooned pages management")
> > Signed-off-by: David Hildenbrand <david@redhat.com>
> > Reported-by: Vratislav Bendel <vbendel@redhat.com>
> > Acked-by: Michal Hocko <mhocko@suse.com>
> > Acked-by: Rafael Aquini <aquini@redhat.com>
> > Cc: Mel Gorman <mgorman@techsingularity.net>
> > Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
> > Cc: Michal Hocko <mhocko@suse.com>
> > Cc: Naoya Horiguchi <n-horiguchi@ah.jp.nec.com>
> > Cc: Jan Kara <jack@suse.cz>
> > Cc: Andrea Arcangeli <aarcange@redhat.com>
> > Cc: Dominik Brodowski <linux@dominikbrodowski.net>
> > Cc: Matthew Wilcox <willy@infradead.org>
> > Cc: Vratislav Bendel <vbendel@redhat.com>
> > Cc: Rafael Aquini <aquini@redhat.com>
> > Cc: Konstantin Khlebnikov <k.khlebnikov@samsung.com>
> > Cc: Minchan Kim <minchan@kernel.org>
> > Cc: <stable@vger.kernel.org> [3.12 - 4.7]
> > Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
> > Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
>
> Lack of coffee, missed to add my s-o.
>
> Greg, can you add
>
> Signed-off-by: David Hildenbrand <david@redhat.com>
Now added (hint, it's already in the list :)
and queued up, thanks for the backport.
greg k-h
prev parent reply other threads:[~2019-02-04 9:15 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-02-04 6:02 FAILED: patch "[PATCH] mm: migrate: don't rely on __PageMovable() of newpage after" failed to apply to 4.4-stable tree gregkh
2019-02-04 9:00 ` [PATCH for-4.4-stable] mm: migrate: don't rely on __PageMovable() of newpage after unlocking it David Hildenbrand
2019-02-04 9:05 ` David Hildenbrand
2019-02-04 9:15 ` Greg KH [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190204091524.GA3432@kroah.com \
--to=gregkh@linuxfoundation.org \
--cc=aarcange@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=aquini@redhat.com \
--cc=david@redhat.com \
--cc=jack@suse.cz \
--cc=k.khlebnikov@samsung.com \
--cc=kirill.shutemov@linux.intel.com \
--cc=linux@dominikbrodowski.net \
--cc=mgorman@techsingularity.net \
--cc=mhocko@suse.com \
--cc=minchan@kernel.org \
--cc=n-horiguchi@ah.jp.nec.com \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=vbendel@redhat.com \
--cc=willy@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.