From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 075F92F49F6 for ; Thu, 3 Sep 2026 20:35:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788467730; cv=none; b=IAAjVOl1lIGVkn4B01ckYgmIJmwtxMawaMWfo1s4NIFVaELJjlpu8kKvS+MwmLKsqG7xISttsZjoGdB3n7lBbjOG3IQfyVqIz6cSZiYuexOpDou4lLYDE2fll1T7T/tQDFJ7OdCPtTaMxoOf8dITrTG1j2B5z0zSltiTwEcig6I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788467730; c=relaxed/simple; bh=ntu0Bq0JVTH4wOwCoEIMBAmWIMkCP+cmXP5kSaQFyKw=; h=Date:To:From:Subject:Message-Id; b=s12355U3fvlCLCzj5jIACCXu+ky1RQ7RnLdzgc+AEPXyGL5edk5BvdubnLfKtva0k7kgLSH3ptWU+qKRAnvvMcVy430wszHJ7j8GIYv/BXn5PZmvWOtxLiuaWkCrV/dUMGFgQCBElsCeuKdCVrLySjVkIglsavDJcdNtiuhg/aw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux-foundation.org header.i=@linux-foundation.org header.b=xINFalcZ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux-foundation.org header.i=@linux-foundation.org header.b="xINFalcZ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 852EA1F000E9; Thu, 3 Sep 2026 20:35:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux-foundation.org; s=korg; t=1788467722; bh=JnYAN0c4MGrx1/xYxcMWGjBwVMuIo90P+ps9nCAL+8g=; h=Date:To:From:Subject; b=xINFalcZ3xeG4McZ2Ab4AaIrDDPlAxpgrYl3E/dhc1D3mjolvzG730szSM4MkirUO FZtzuxZVPFBdeWco3Fon7qYxT0ku8KofayYVzSR6rQOwbOwc8RyTSTu9jN1a3rXjh4 ppp9ExiW5M/DgBApndefYrOoVSumec6/LVxs7y+4= Date: Thu, 03 Sep 2026 13:35:22 -0700 To: mm-commits@vger.kernel.org,zhengqi.arch@bytedance.com,shakeel.butt@linux.dev,roman.gushchin@linux.dev,muchun.song@linux.dev,mhocko@kernel.org,hughd@google.com,hannes@cmpxchg.org,david@kernel.org,brauner@kernel.org,baolin.wang@linux.alibaba.com,qinyuntan@linux.alibaba.com,akpm@linux-foundation.org From: Andrew Morton Subject: + mm-list_lru-disable-memcg-awareness-under-cgroup_disable=memory.patch added to mm-unstable branch Message-Id: <20260903203522.852EA1F000E9@smtp.kernel.org> Precedence: bulk X-Mailing-List: mm-commits@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: The patch titled Subject: mm/list_lru: disable memcg awareness under cgroup_disable=memory has been added to the -mm mm-unstable branch. Its filename is mm-list_lru-disable-memcg-awareness-under-cgroup_disable=memory.patch This patch will shortly appear at https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-list_lru-disable-memcg-awareness-under-cgroup_disable=memory.patch This patch will later appear in the mm-unstable branch at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm Before you just go and hit "reply", please: a) Consider who else should be cc'ed b) Prefer to cc a suitable mailing list as well c) Ideally: find the original patch on the mailing list and do a reply-to-all to that, adding suitable additional cc's *** Remember to use Documentation/process/submit-checklist.rst when testing your code *** The -mm tree is included into linux-next via various branches at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm and is updated there most days ------------------------------------------------------ From: Qinyun Tan Subject: mm/list_lru: disable memcg awareness under cgroup_disable=memory Date: Wed, 2 Sep 2026 17:32:02 +0800 __list_lru_init() only collapses a memcg-aware list_lru into plain per-node lists when kmem accounting is disabled (cgroup.memory=nokmem). When the memory controller is disabled entirely (cgroup_disable=memory), mem_cgroup_kmem_disabled() is false, so the lru stays memcg aware even though no object will ever be charged to a memcg. This is more than a semantic inconsistency. folio_memcg_list_lru_alloc() trusts list_lru_memcg_aware() and dereferences the folio's memcg, which is always NULL with the controller disabled. The only mainline caller, folio_memcg_alloc_deferred(), papers over this with an explicit mem_cgroup_disabled() check. The shmem unused-huge shrinker conversion ("mm: shmem: make unused huge shrinker memcg aware") adds a second caller without such a guard, so booting with cgroup_disable=memory and writing to a huge=always tmpfs oopses: BUG: unable to handle page fault for address: 0000000000000488 RIP: 0010:folio_memcg_list_lru_alloc+0x41/0xf0 Call Trace: shmem_get_folio_gfp+0x1cd/0x7c0 shmem_write_begin+0x5d/0x100 generic_perform_write+0x89/0x2a0 shmem_file_write_iter+0x82/0x90 vfs_write+0x256/0x410 ksys_write+0x61/0xe0 do_syscall_64+0x8d/0x460 entry_SYSCALL_64_after_hwframe+0x76/0x7e The faulting address is the offset of mem_cgroup->kmemcg_id, dereferenced on a NULL memcg in memcg_list_lru_allocated(): folio_memcg_list_lru_alloc() list_lru_memcg_aware() <- true, only nokmem checked memcg = folio_memcg(folio) <- NULL memcg_list_lru_allocated(memcg, lru) memcg->kmemcg_id <- NULL pointer dereference Check mem_cgroup_disabled() in __list_lru_init() so that all list_lrus fall back to plain per-node lists when the controller is disabled, matching what the shrinker side already does (shrinker_memcg_alloc() bails out on mem_cgroup_disabled()). This makes the mem_cgroup_disabled() check in callers unnecessary rather than mandatory. Link: https://lore.kernel.org/20260902093202.609559-1-qinyuntan@linux.alibaba.com Signed-off-by: Qinyun Tan Reviewed-by: Baolin Wang Cc: Christian Brauner Cc: David Hildenbrand Cc: Hugh Dickins Cc: Johannes Weiner Cc: Michal Hocko Cc: Muchun Song Cc: Qi Zheng Cc: Roman Gushchin Cc: Shakeel Butt Signed-off-by: Andrew Morton --- mm/list_lru.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/mm/list_lru.c~mm-list_lru-disable-memcg-awareness-under-cgroup_disable=memory +++ a/mm/list_lru.c @@ -671,7 +671,7 @@ int __list_lru_init(struct list_lru *lru else lru->shrinker_id = -1; - if (mem_cgroup_kmem_disabled()) + if (mem_cgroup_disabled() || mem_cgroup_kmem_disabled()) memcg_aware = false; #endif _ Patches currently in -mm which might be from qinyuntan@linux.alibaba.com are mm-list_lru-disable-memcg-awareness-under-cgroup_disable=memory.patch mm-list_lru-dont-copy-stale-shrinker-id-from-non-memcg-aware-shrinkers.patch