All of lore.kernel.org
 help / color / mirror / Atom feed
* + mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch added to mm-unstable branch
@ 2026-09-02 21:27 Andrew Morton
  0 siblings, 0 replies; only message in thread
From: Andrew Morton @ 2026-09-02 21:27 UTC (permalink / raw)
  To: mm-commits, zhengqi.arch, shakeel.butt, roman.gushchin,
	muchun.song, mhocko, hughd, hannes, david, brauner, baolin.wang,
	qinyuntan, akpm


The patch titled
     Subject: mm/list_lru: disable memcg awareness under cgroup_disable=memory
has been added to the -mm mm-unstable branch.  Its filename is
     mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch

This patch will shortly appear at
     https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch

This patch will later appear in the mm-unstable branch at
    git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm

Before you just go and hit "reply", please:
   a) Consider who else should be cc'ed
   b) Prefer to cc a suitable mailing list as well
   c) Ideally: find the original patch on the mailing list and do a
      reply-to-all to that, adding suitable additional cc's

*** Remember to use Documentation/process/submit-checklist.rst when testing your code ***

The -mm tree is included into linux-next via various
branches at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
and is updated there most days

------------------------------------------------------
From: Qinyun Tan <qinyuntan@linux.alibaba.com>
Subject: mm/list_lru: disable memcg awareness under cgroup_disable=memory
Date: Wed, 2 Sep 2026 17:32:02 +0800

__list_lru_init() only collapses a memcg-aware list_lru into plain
per-node lists when kmem accounting is disabled (cgroup.memory=nokmem). 
When the memory controller is disabled entirely (cgroup_disable=memory),
mem_cgroup_kmem_disabled() is false, so the lru stays memcg aware even
though no object will ever be charged to a memcg.

This is more than a semantic inconsistency.  folio_memcg_list_lru_alloc()
trusts list_lru_memcg_aware() and dereferences the folio's memcg, which is
always NULL with the controller disabled.  The only mainline caller,
folio_memcg_alloc_deferred(), papers over this with an explicit
mem_cgroup_disabled() check.  The shmem unused-huge shrinker conversion
("mm: shmem: make unused huge shrinker memcg aware") adds a second caller
without such a guard, so booting with cgroup_disable=memory and writing to
a huge=always tmpfs oopses:

  BUG: unable to handle page fault for address: 0000000000000488
  RIP: 0010:folio_memcg_list_lru_alloc+0x41/0xf0
  Call Trace:
   <TASK>
   shmem_get_folio_gfp+0x1cd/0x7c0
   shmem_write_begin+0x5d/0x100
   generic_perform_write+0x89/0x2a0
   shmem_file_write_iter+0x82/0x90
   vfs_write+0x256/0x410
   ksys_write+0x61/0xe0
   do_syscall_64+0x8d/0x460
   entry_SYSCALL_64_after_hwframe+0x76/0x7e

The faulting address is the offset of mem_cgroup->kmemcg_id, dereferenced
on a NULL memcg in memcg_list_lru_allocated():

  folio_memcg_list_lru_alloc()
    list_lru_memcg_aware()               <- true, only nokmem checked
    memcg = folio_memcg(folio)           <- NULL
    memcg_list_lru_allocated(memcg, lru)
      memcg->kmemcg_id                   <- NULL pointer dereference

Check mem_cgroup_disabled() in __list_lru_init() so that all list_lrus
fall back to plain per-node lists when the controller is disabled,
matching what the shrinker side already does (shrinker_memcg_alloc() bails
out on mem_cgroup_disabled()).  This makes the mem_cgroup_disabled() check
in callers unnecessary rather than mandatory.

Link: https://lore.kernel.org/20260902093202.609559-1-qinyuntan@linux.alibaba.com
Signed-off-by: Qinyun Tan <qinyuntan@linux.alibaba.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Christian Brauner <brauner@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Hugh Dickins <hughd@google.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Qi Zheng <zhengqi.arch@bytedance.com>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---

 mm/list_lru.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/mm/list_lru.c~mm-shmem-make-unused-huge-shrinker-memcg-aware-fix
+++ a/mm/list_lru.c
@@ -671,7 +671,7 @@ int __list_lru_init(struct list_lru *lru
 	else
 		lru->shrinker_id = -1;
 
-	if (mem_cgroup_kmem_disabled())
+	if (mem_cgroup_disabled() || mem_cgroup_kmem_disabled())
 		memcg_aware = false;
 #endif
 
_

Patches currently in -mm which might be from qinyuntan@linux.alibaba.com are

mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch
mm-list_lru-dont-copy-stale-shrinker-id-from-non-memcg-aware-shrinkers.patch


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-02 21:27 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 21:27 + mm-shmem-make-unused-huge-shrinker-memcg-aware-fix.patch added to mm-unstable branch Andrew Morton

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.