From: Andrew Morton <akpm@linux-foundation.org>
To: Deepanshu Kartikey <kartikey406@gmail.com>,
muchun.song@linux.dev, osalvador@suse.de, david@kernel.org,
linux-kernel@vger.kernel.org, linux-mm@kvack.org,
syzbot+226c1f947186f8fef796@syzkaller.appspotmail.com,
Mina Almasry <almasrymina@google.com>
Subject: Re: [PATCH] mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
Date: Sat, 25 Apr 2026 07:57:53 -0700 [thread overview]
Message-ID: <20260425075753.eab83d221fd6ad59241e0f1d@linux-foundation.org> (raw)
In-Reply-To: <20260330131525.630b8ff8913ade1e0e5c2054@linux-foundation.org>
On Mon, 30 Mar 2026 13:15:25 -0700 Andrew Morton <akpm@linux-foundation.org> wrote:
> On Sat, 28 Mar 2026 12:25:34 +0530 Deepanshu Kartikey <kartikey406@gmail.com> wrote:
>
> > In alloc_hugetlb_folio(), a single h_cg pointer is used for both
> > the rsvd and non-rsvd hugetlb cgroup charges. When map_chg is set,
> > hugetlb_cgroup_charge_cgroup_rsvd() stores the charged cgroup in
> > h_cg, but the immediately following hugetlb_cgroup_charge_cgroup()
> > overwrites h_cg with the non-rsvd cgroup pointer.
> >
> > As a result, hugetlb_cgroup_commit_charge_rsvd() stores the wrong
> > (non-rsvd) cgroup pointer into the folio's rsvd slot.
> >
> > When the folio is later freed, free_huge_folio() unconditionally
> > calls both hugetlb_cgroup_uncharge_folio() and
> > hugetlb_cgroup_uncharge_folio_rsvd(). The rsvd uncharge reads back
> > the wrong cgroup from the folio and decrements a counter that was
> > never charged for that cgroup, causing a page_counter underflow:
> >
> > page_counter underflow: -512 nr_pages=512
> > WARNING: mm/page_counter.c:61 at page_counter_cancel
> >
> > Fix this by introducing a separate h_cg_rsvd pointer exclusively
> > for the rsvd charge path, keeping the rsvd and non-rsvd charges
> > fully independent through their charge, commit, and error uncharge
> > paths.
>
> Thanks.
>
> > Fixes: 08cf9faf7558 ("hugetlb_cgroup: support noreserve mappings")
>
> Merged in 2020!
>
> Could reviewers please give consideration to whether we should backport
> this?
>
OK, then ;)
I'll queue this up and shall add the cc:stable - that underflow warning
needs to be addressed.
I'll add a needs-review note-to-self.
From: Deepanshu Kartikey <kartikey406@gmail.com>
Subject: mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
Date: Sat, 28 Mar 2026 12:25:34 +0530
In alloc_hugetlb_folio(), a single h_cg pointer is used for both the rsvd
and non-rsvd hugetlb cgroup charges. When map_chg is set,
hugetlb_cgroup_charge_cgroup_rsvd() stores the charged cgroup in h_cg, but
the immediately following hugetlb_cgroup_charge_cgroup() overwrites h_cg
with the non-rsvd cgroup pointer.
As a result, hugetlb_cgroup_commit_charge_rsvd() stores the wrong
(non-rsvd) cgroup pointer into the folio's rsvd slot.
When the folio is later freed, free_huge_folio() unconditionally calls
both hugetlb_cgroup_uncharge_folio() and
hugetlb_cgroup_uncharge_folio_rsvd(). The rsvd uncharge reads back the
wrong cgroup from the folio and decrements a counter that was never
charged for that cgroup, causing a page_counter underflow:
page_counter underflow: -512 nr_pages=512
WARNING: mm/page_counter.c:61 at page_counter_cancel
Fix this by introducing a separate h_cg_rsvd pointer exclusively for the
rsvd charge path, keeping the rsvd and non-rsvd charges fully independent
through their charge, commit, and error uncharge paths.
Link: https://lore.kernel.org/20260328065534.346053-1-kartikey406@gmail.com
Fixes: 08cf9faf7558 ("hugetlb_cgroup: support noreserve mappings")
Reported-by: syzbot+226c1f947186f8fef796@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=226c1f947186f8fef796
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Mina Almasry <almasrymina@google.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
mm/hugetlb.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/mm/hugetlb.c~mm-hugetlb-fix-hugetlb-cgroup-rsvd-charge-uncharge-mismatch
+++ a/mm/hugetlb.c
@@ -2879,6 +2879,7 @@ struct folio *alloc_hugetlb_folio(struct
map_chg_state map_chg;
int ret, idx;
struct hugetlb_cgroup *h_cg = NULL;
+ struct hugetlb_cgroup *h_cg_rsvd = NULL;
gfp_t gfp = htlb_alloc_mask(h) | __GFP_RETRY_MAYFAIL;
idx = hstate_index(h);
@@ -2929,7 +2930,7 @@ struct folio *alloc_hugetlb_folio(struct
*/
if (map_chg) {
ret = hugetlb_cgroup_charge_cgroup_rsvd(
- idx, pages_per_huge_page(h), &h_cg);
+ idx, pages_per_huge_page(h), &h_cg_rsvd);
if (ret)
goto out_subpool_put;
}
@@ -2971,7 +2972,7 @@ struct folio *alloc_hugetlb_folio(struct
*/
if (map_chg) {
hugetlb_cgroup_commit_charge_rsvd(idx, pages_per_huge_page(h),
- h_cg, folio);
+ h_cg_rsvd, folio);
}
spin_unlock_irq(&hugetlb_lock);
@@ -3023,7 +3024,7 @@ out_uncharge_cgroup:
out_uncharge_cgroup_reservation:
if (map_chg)
hugetlb_cgroup_uncharge_cgroup_rsvd(idx, pages_per_huge_page(h),
- h_cg);
+ h_cg_rsvd);
out_subpool_put:
/*
* put page to subpool iff the quota of subpool's rsv_hpages is used
_
next prev parent reply other threads:[~2026-04-25 14:57 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-28 6:55 [PATCH] mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch Deepanshu Kartikey
2026-03-30 20:15 ` Andrew Morton
2026-04-25 14:57 ` Andrew Morton [this message]
2026-04-26 3:47 ` Muchun Song
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260425075753.eab83d221fd6ad59241e0f1d@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=almasrymina@google.com \
--cc=david@kernel.org \
--cc=kartikey406@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=muchun.song@linux.dev \
--cc=osalvador@suse.de \
--cc=syzbot+226c1f947186f8fef796@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox