From: Qinyun Tan <qinyuntan@linux.alibaba.com>
To: Andrew Morton <akpm@linux-foundation.org>
Cc: "Johannes Weiner" <hannes@cmpxchg.org>,
"Michal Koutný" <mkoutny@suse.com>,
"Lance Yang" <lance.yang@linux.dev>,
"Qi Zheng" <qi.zheng@linux.dev>,
"Roman Gushchin" <roman.gushchin@linux.dev>,
"Muchun Song" <muchun.song@linux.dev>,
"Dave Chinner" <david@fromorbit.com>,
"Baolin Wang" <baolin.wang@linux.alibaba.com>,
"David Hildenbrand" <david@kernel.org>,
"Xunlei Pang" <xlpang@linux.alibaba.com>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
"Qinyun Tan" <qinyuntan@linux.alibaba.com>
Subject: [PATCH] mm/list_lru: don't copy stale shrinker id from non-memcg-aware shrinkers
Date: Tue, 1 Sep 2026 19:51:04 +0800 [thread overview]
Message-ID: <20260901115104.2944996-1-qinyuntan@linux.alibaba.com> (raw)
With cgroup.memory=nokmem, shrinker_memcg_alloc() fails with -ENOSYS
for shrinkers without SHRINKER_NONSLAB, and shrinker_alloc() falls
back to a non-memcg-aware shrinker. On this fallback path,
shrinker->id is never assigned and keeps 0 from kzalloc(), which is a
valid id belonging to whichever memcg-aware shrinker registers first.
__list_lru_init() copies shrinker->id unconditionally, so every
list_lru backed by such a fallback shrinker (thp-deferred_split,
zswap-shrinker, workingset shadow nodes, superblock lrus, ...) ends
up with lru->shrinker_id == 0 instead of -1.
Under nokmem the list_lru collapses to the shared per-node lists, but
__list_lru_add() still calls set_shrinker_bit() against the memcg of
the added object. Most list_lru users are unaffected because their
objects resolve to a NULL memcg without kmem accounting, but the THP
deferred split queue holds user folios, which are charged regardless
of nokmem. Since no memcg-aware shrinker can register under nokmem,
shrinker_nr_max stays 0 and every memcg's shrinker_info has
map_nr_max == 0, so the first folio added by khugepaged triggers on
every boot:
WARNING: mm/shrinker.c:212 at set_shrinker_bit+0x99/0xa0
On systems where a SHRINKER_NONSLAB shrinker (btrfs, xfs) did register
and expand the maps, there is no warning; instead bit 0 is set
spuriously for an unrelated shrinker.
shrinker->id is only meaningful while SHRINKER_MEMCG_AWARE is set,
and all readers inside mm/shrinker.c already check the flag before
using the id. Make __list_lru_init() do the same and fall back to -1,
so set_shrinker_bit() is never reached with a bogus id. The stale
shrinker->id itself is left as is; cleaning that up is a separate
topic.
Fixes: 03375203e1da8 ("mm: do not allocate shrinker info with cgroup.memory=nokmem")
Signed-off-by: Qinyun Tan <qinyuntan@linux.alibaba.com>
---
Verified on a machine booting with cgroup.memory=nokmem and
CONFIG_TRANSPARENT_HUGEPAGE=y: the warning fires once per boot from
khugepaged, disappears when nokmem is removed from the command line,
and no longer triggers with this fix applied and nokmem set.
mm/list_lru.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/mm/list_lru.c b/mm/list_lru.c
index 36662d02ff963..96d02ea206a88 100644
--- a/mm/list_lru.c
+++ b/mm/list_lru.c
@@ -666,7 +666,12 @@ int __list_lru_init(struct list_lru *lru, bool memcg_aware, struct shrinker *shr
int i;
#ifdef CONFIG_MEMCG
- if (shrinker)
+ /*
+ * If the shrinker fell back to being non-memcg-aware (e.g. with
+ * cgroup.memory=nokmem), its id was never assigned and holds a
+ * stale 0. Don't let set_shrinker_bit() act on it.
+ */
+ if (shrinker && (shrinker->flags & SHRINKER_MEMCG_AWARE))
lru->shrinker_id = shrinker->id;
else
lru->shrinker_id = -1;
--
2.43.7
next reply other threads:[~2026-09-01 11:51 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 11:51 Qinyun Tan [this message]
2026-09-01 17:29 ` [PATCH] mm/list_lru: don't copy stale shrinker id from non-memcg-aware shrinkers Andrew Morton
2026-09-02 3:20 ` Qinyun Tan
2026-09-02 2:25 ` Muchun Song
2026-09-02 5:30 ` Baolin Wang
2026-09-02 17:17 ` Michal Koutný
2026-09-03 4:06 ` Qinyun Tan
2026-09-03 9:20 ` Michal Koutný
2026-09-04 2:10 ` Qinyun Tan
2026-09-04 4:30 ` Andrew Morton
2026-09-03 20:01 ` Andrew Morton
2026-09-04 19:43 ` Wentao Guan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260901115104.2944996-1-qinyuntan@linux.alibaba.com \
--to=qinyuntan@linux.alibaba.com \
--cc=akpm@linux-foundation.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=david@fromorbit.com \
--cc=david@kernel.org \
--cc=hannes@cmpxchg.org \
--cc=lance.yang@linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mkoutny@suse.com \
--cc=muchun.song@linux.dev \
--cc=qi.zheng@linux.dev \
--cc=roman.gushchin@linux.dev \
--cc=xlpang@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.