From: Minchan Kim <minchan@kernel.org>
To: "Kirill A. Shutemov" <kirill@shutemov.name>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>,
Andrew Morton <akpm@linux-foundation.org>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
Huang Ying <ying.huang@intel.com>,
Dave Hansen <dave.hansen@intel.com>
Subject: Re: [PATCH] thp, mm: Fix crash due race in MADV_FREE handling
Date: Thu, 29 Jun 2017 17:40:42 +0900 [thread overview]
Message-ID: <20170629084042.GA22335@bbox> (raw)
In-Reply-To: <20170628101550.7uybtgfaejtxd7jv@node.shutemov.name>
On Wed, Jun 28, 2017 at 01:15:50PM +0300, Kirill A. Shutemov wrote:
> On Wed, Jun 28, 2017 at 01:12:49PM +0300, Kirill A. Shutemov wrote:
> > Reinette reported following crash:
> >
> > BUG: Bad page state in process log2exe pfn:57600
> > page:ffffea00015d8000 count:0 mapcount:0 mapping: (null) index:0x20200
> > flags: 0x4000000000040019(locked|uptodate|dirty|swapbacked)
> > raw: 4000000000040019 0000000000000000 0000000000020200 00000000ffffffff
> > raw: ffffea00015d8020 ffffea00015d8020 0000000000000000 0000000000000000
> > page dumped because: PAGE_FLAGS_CHECK_AT_FREE flag(s) set
> > bad because of flags: 0x1(locked)
> > Modules linked in: rfcomm 8021q bnep intel_rapl x86_pkg_temp_thermal coretemp efivars btusb btrtl btbcm pwm_lpss_pci snd_hda_codec_hdmi btintel pwm_lpss snd_hda_codec_realtek snd_soc_skl snd_hda_codec_generic snd_soc_skl_ipc spi_pxa2xx_platform snd_soc_sst_ipc snd_soc_sst_dsp i2c_designware_platform i2c_designware_core snd_hda_ext_core snd_soc_sst_match snd_hda_intel snd_hda_codec mei_me snd_hda_core mei snd_soc_rt286 snd_soc_rl6347a snd_soc_core efivarfs
> > CPU: 1 PID: 354 Comm: log2exe Not tainted 4.12.0-rc7-test-test #19
> > Hardware name: Intel corporation NUC6CAYS/NUC6CAYB, BIOS AYAPLCEL.86A.0027.2016.1108.1529 11/08/2016
> > Call Trace:
> > dump_stack+0x95/0xeb
> > bad_page+0x16a/0x1f0
> > free_pages_check_bad+0x117/0x190
> > ? rcu_read_lock_sched_held+0xa8/0x130
> > free_hot_cold_page+0x7b1/0xad0
> > __put_page+0x70/0xa0
> > madvise_free_huge_pmd+0x627/0x7b0
> > madvise_free_pte_range+0x6f8/0x1150
> > ? debug_check_no_locks_freed+0x280/0x280
> > ? swapin_walk_pmd_entry+0x380/0x380
> > __walk_page_range+0x6b5/0xe30
> > walk_page_range+0x13b/0x310
> > madvise_free_page_range.isra.16+0xad/0xd0
> > ? force_swapin_readahead+0x110/0x110
> > ? swapin_walk_pmd_entry+0x380/0x380
> > ? lru_add_drain_cpu+0x160/0x320
> > madvise_free_single_vma+0x2e4/0x470
> > ? madvise_free_page_range.isra.16+0xd0/0xd0
> > ? vmacache_update+0x100/0x130
> > ? find_vma+0x35/0x160
> > SyS_madvise+0x8ce/0x1450
> >
> > If somebody frees the page under us and we hold the last reference to
> > it, put_page() would attempt to free the page before unlocking it.
> >
> > The fix is trivial reorder of operations.
> >
> > Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
> > Reported-by: Reinette Chatre <reinette.chatre@intel.com>
> > Fixes: 9818b8cde622 ("madvise_free, thp: fix madvise_free_huge_pmd return value after splitting")
>
> Sorry, the wrong Fixes. The right one:
>
> Fixes: b8d3c4c3009d ("mm/huge_memory.c: don't split THP page when MADV_FREE syscall is called")
>
Acked-by: Minchan Kim <minchan@kernel.org>
Thanks.
--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org. For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
next prev parent reply other threads:[~2017-06-29 8:40 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-06-28 10:12 [PATCH] thp, mm: Fix crash due race in MADV_FREE handling Kirill A. Shutemov
2017-06-28 10:15 ` Kirill A. Shutemov
2017-06-29 8:40 ` Minchan Kim [this message]
2017-06-29 20:50 ` Andrew Morton
2017-06-30 3:30 ` Kirill A. Shutemov
2017-06-28 14:26 ` Dave Hansen
2017-06-29 15:46 ` Michal Hocko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170629084042.GA22335@bbox \
--to=minchan@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=dave.hansen@intel.com \
--cc=kirill.shutemov@linux.intel.com \
--cc=kirill@shutemov.name \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ying.huang@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).