From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-wm0-f43.google.com (mail-wm0-f43.google.com [74.125.82.43]) by kanga.kvack.org (Postfix) with ESMTP id B76796B0005 for ; Sun, 24 Jan 2016 18:04:25 -0500 (EST) Received: by mail-wm0-f43.google.com with SMTP id u188so45571238wmu.1 for ; Sun, 24 Jan 2016 15:04:25 -0800 (PST) Received: from mail-wm0-x22c.google.com (mail-wm0-x22c.google.com. [2a00:1450:400c:c09::22c]) by mx.google.com with ESMTPS id in5si21635084wjb.155.2016.01.24.15.04.24 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 24 Jan 2016 15:04:24 -0800 (PST) Received: by mail-wm0-x22c.google.com with SMTP id r129so44133575wmr.0 for ; Sun, 24 Jan 2016 15:04:24 -0800 (PST) Date: Mon, 25 Jan 2016 01:04:22 +0200 From: "Kirill A. Shutemov" Subject: Re: mm: WARNING in __delete_from_page_cache Message-ID: <20160124230422.GA8439@node.shutemov.name> References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Sender: owner-linux-mm@kvack.org List-ID: To: Dmitry Vyukov , Matthew Wilcox Cc: Alexander Viro , "linux-fsdevel@vger.kernel.org" , LKML , Andrew Morton , Michal Hocko , Jan Kara , Vlastimil Babka , "Kirill A. Shutemov" , Matthew Wilcox , Junichi Nomura , Greg Thelen , Dave Hansen , "linux-mm@kvack.org" , syzkaller , Kostya Serebryany , Alexander Potapenko , Sasha Levin On Sun, Jan 24, 2016 at 11:48:21AM +0100, Dmitry Vyukov wrote: > Hello, > > The following program triggers WARNING in __delete_from_page_cache: > > ------------[ cut here ]------------ > WARNING: CPU: 0 PID: 7676 at mm/filemap.c:217 > __delete_from_page_cache+0x9f6/0xb60() > Modules linked in: > CPU: 0 PID: 7676 Comm: a.out Not tainted 4.4.0+ #276 > Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 > 00000000ffffffff ffff88006d3f7738 ffffffff82999e2d 0000000000000000 > ffff8800620a0000 ffffffff86473d20 ffff88006d3f7778 ffffffff81352089 > ffffffff81658d36 ffffffff86473d20 00000000000000d9 ffffea0000009d60 > Call Trace: > [< inline >] __dump_stack lib/dump_stack.c:15 > [] dump_stack+0x6f/0xa2 lib/dump_stack.c:50 > [] warn_slowpath_common+0xd9/0x140 kernel/panic.c:482 > [] warn_slowpath_null+0x29/0x30 kernel/panic.c:515 > [] __delete_from_page_cache+0x9f6/0xb60 mm/filemap.c:217 > [] delete_from_page_cache+0x112/0x200 mm/filemap.c:244 > [] __dax_fault+0x859/0x1800 fs/dax.c:487 > [] blkdev_dax_fault+0x26/0x30 fs/block_dev.c:1730 > [< inline >] wp_pfn_shared mm/memory.c:2208 > [] do_wp_page+0xc85/0x14f0 mm/memory.c:2307 > [< inline >] handle_pte_fault mm/memory.c:3323 > [< inline >] __handle_mm_fault mm/memory.c:3417 > [] handle_mm_fault+0x2483/0x4640 mm/memory.c:3446 > [] __do_page_fault+0x376/0x960 arch/x86/mm/fault.c:1238 > [] trace_do_page_fault+0xe8/0x420 arch/x86/mm/fault.c:1331 > [] do_async_page_fault+0x14/0xd0 arch/x86/kernel/kvm.c:264 > [] async_page_fault+0x28/0x30 arch/x86/entry/entry_64.S:986 > [] entry_SYSCALL_64_fastpath+0x16/0x7a > arch/x86/entry/entry_64.S:185 > ---[ end trace dae21e0f85f1f98c ]--- > > > // autogenerated by syzkaller (http://github.com/google/syzkaller) > #include > #include > #include > #include > #include > #include > > int main() > { > syscall(SYS_mmap, 0x20000000ul, 0x10000ul, 0x3ul, 0x32ul, -1, 0x0ul); > int fd = syscall(SYS_open, "/dev/ram1", O_RDWR); > syscall(SYS_mmap, 0x20a31000ul, 0x3000ul, 0x3ul, 0xb011ul, fd, 0x0ul); > *(uint64_t*)0x20003000 = 1; > syscall(SYS_write, fd, 0x20003000ul, 0x78ul, 0, 0, 0); > syscall(SYS_getresuid, 0x20000688ul, 0x200008f2ul, 0x20a31000ul, 0, 0, 0); > return 0; > } > > On commit 30f05309bde49295e02e45c7e615f73aa4e0ccc2. Reduced and human readable test case: #include #include #include int main() { int fd; char *p; fd = open("/dev/ram0", O_RDWR); p = mmap(NULL, 4096, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); write(fd, "1", 1); *p = 1; return 0; } Looks like DAX doesn't expect to see something except hole-page in the radix tree. This expectation is [probably] true for files on DAX-enabled filesystems, but it seems broken for ramdisks. Matthew? -- Kirill A. Shutemov -- To unsubscribe, send a message with 'unsubscribe linux-mm' in the body to majordomo@kvack.org. For more info on Linux MM, see: http://www.linux-mm.org/ . Don't email: email@kvack.org