From: Andrew Morton <akpm@linux-foundation.org>
To: mm-commits@vger.kernel.org,zhengqi.arch@bytedance.com,shakeel.butt@linux.dev,roman.gushchin@linux.dev,muchun.song@linux.dev,mhocko@kernel.org,hughd@google.com,hannes@cmpxchg.org,david@kernel.org,brauner@kernel.org,baolin.wang@linux.alibaba.com,qinyuntan@linux.alibaba.com,akpm@linux-foundation.org
Subject: + mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch added to mm-unstable branch
Date: Wed, 02 Sep 2026 14:27:51 -0700 [thread overview]
Message-ID: <20260902212751.6FFE71F000E9@smtp.kernel.org> (raw)
The patch titled
Subject: mm/list_lru: disable memcg awareness under cgroup_disable=memory
has been added to the -mm mm-unstable branch. Its filename is
mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch
This patch will shortly appear at
https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch
This patch will later appear in the mm-unstable branch at
git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
Before you just go and hit "reply", please:
a) Consider who else should be cc'ed
b) Prefer to cc a suitable mailing list as well
c) Ideally: find the original patch on the mailing list and do a
reply-to-all to that, adding suitable additional cc's
*** Remember to use Documentation/process/submit-checklist.rst when testing your code ***
The -mm tree is included into linux-next via various
branches at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
and is updated there most days
------------------------------------------------------
From: Qinyun Tan <qinyuntan@linux.alibaba.com>
Subject: mm/list_lru: disable memcg awareness under cgroup_disable=memory
Date: Wed, 2 Sep 2026 17:32:02 +0800
__list_lru_init() only collapses a memcg-aware list_lru into plain
per-node lists when kmem accounting is disabled (cgroup.memory=nokmem).
When the memory controller is disabled entirely (cgroup_disable=memory),
mem_cgroup_kmem_disabled() is false, so the lru stays memcg aware even
though no object will ever be charged to a memcg.
This is more than a semantic inconsistency. folio_memcg_list_lru_alloc()
trusts list_lru_memcg_aware() and dereferences the folio's memcg, which is
always NULL with the controller disabled. The only mainline caller,
folio_memcg_alloc_deferred(), papers over this with an explicit
mem_cgroup_disabled() check. The shmem unused-huge shrinker conversion
("mm: shmem: make unused huge shrinker memcg aware") adds a second caller
without such a guard, so booting with cgroup_disable=memory and writing to
a huge=always tmpfs oopses:
BUG: unable to handle page fault for address: 0000000000000488
RIP: 0010:folio_memcg_list_lru_alloc+0x41/0xf0
Call Trace:
<TASK>
shmem_get_folio_gfp+0x1cd/0x7c0
shmem_write_begin+0x5d/0x100
generic_perform_write+0x89/0x2a0
shmem_file_write_iter+0x82/0x90
vfs_write+0x256/0x410
ksys_write+0x61/0xe0
do_syscall_64+0x8d/0x460
entry_SYSCALL_64_after_hwframe+0x76/0x7e
The faulting address is the offset of mem_cgroup->kmemcg_id, dereferenced
on a NULL memcg in memcg_list_lru_allocated():
folio_memcg_list_lru_alloc()
list_lru_memcg_aware() <- true, only nokmem checked
memcg = folio_memcg(folio) <- NULL
memcg_list_lru_allocated(memcg, lru)
memcg->kmemcg_id <- NULL pointer dereference
Check mem_cgroup_disabled() in __list_lru_init() so that all list_lrus
fall back to plain per-node lists when the controller is disabled,
matching what the shrinker side already does (shrinker_memcg_alloc() bails
out on mem_cgroup_disabled()). This makes the mem_cgroup_disabled() check
in callers unnecessary rather than mandatory.
Link: https://lore.kernel.org/20260902093202.609559-1-qinyuntan@linux.alibaba.com
Signed-off-by: Qinyun Tan <qinyuntan@linux.alibaba.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Christian Brauner <brauner@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Hugh Dickins <hughd@google.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Qi Zheng <zhengqi.arch@bytedance.com>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
mm/list_lru.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/list_lru.c~mm-shmem-make-unused-huge-shrinker-memcg-aware-fix
+++ a/mm/list_lru.c
@@ -671,7 +671,7 @@ int __list_lru_init(struct list_lru *lru
else
lru->shrinker_id = -1;
- if (mem_cgroup_kmem_disabled())
+ if (mem_cgroup_disabled() || mem_cgroup_kmem_disabled())
memcg_aware = false;
#endif
_
Patches currently in -mm which might be from qinyuntan@linux.alibaba.com are
mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch
mm-list_lru-dont-copy-stale-shrinker-id-from-non-memcg-aware-shrinkers.patch
reply other threads:[~2026-09-02 21:27 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902212751.6FFE71F000E9@smtp.kernel.org \
--to=akpm@linux-foundation.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=brauner@kernel.org \
--cc=david@kernel.org \
--cc=hannes@cmpxchg.org \
--cc=hughd@google.com \
--cc=mhocko@kernel.org \
--cc=mm-commits@vger.kernel.org \
--cc=muchun.song@linux.dev \
--cc=qinyuntan@linux.alibaba.com \
--cc=roman.gushchin@linux.dev \
--cc=shakeel.butt@linux.dev \
--cc=zhengqi.arch@bytedance.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.