From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f172.google.com (mail-pg1-f172.google.com [209.85.215.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C5B99EEC0 for ; Fri, 9 Jan 2026 15:32:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767972778; cv=none; b=GomMYTvuWCiTZImwR98Pxqazgow156my4lCmO1Qzxm8QW3TlOOL9E96N+4NOsUNR0iBGp5nEiFavlq6k9lGf9MW3SFbnqkNFLWburSlCzgW94iSvMtvDTKUSxFUyEm6+Sulb3y8FJLJJSLT7Bxs7wjQHHqsbZGgDpZROxeiwPpk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767972778; c=relaxed/simple; bh=rcP44lARjzTBJMae0TBMy8XMB/EHBGzjwZeXEP3THdg=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=SAhbCnqVFGWawhhenx0EHMtn2CPSUaNDAav65Wp3P1HtsVXjynHKsNr0vcIdqKqtXHrqxGClybE7vF4+xH1to36758Ov7n3UeW5ZfKvHJZyoNLS6vAbJ67hm2GcPzOUYq0GI61HXpx6cHf7DIbohPLaVFU08WrxjTcGnEmkvgcw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=S0sED7AM; arc=none smtp.client-ip=209.85.215.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="S0sED7AM" Received: by mail-pg1-f172.google.com with SMTP id 41be03b00d2f7-bc2abdcfc6fso1752706a12.2 for ; Fri, 09 Jan 2026 07:32:56 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1767972776; x=1768577576; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=pi9MBBtLQ+Z6Az6ZIrDOMPEc6YOFfVuBvcpyenL6HZw=; b=S0sED7AMjxS8Ds92GowZe3ABvqBfQYMqIQEOpd34D429Kfde2u8sgIu2HpwQQdUlNA BiKsG68gU0p9ffH5fad7YYqSC4OJdCah9uTfNvWwTbfdJUSW3PAo2IPADLIrrYEBUGrE eGSP9bYOKM6hr2KYZwsVDcCiDoVkMHFSGoRefy25W4bx86pUv2ZFhfnazkvJOj+1XuMj +OsHaDV5zi6KuzZbPqNOsUSqwwJ5emdRd9EoiKPxm1Z2HMZ5QcUwl8pm/oD/jnrp4XEu JaQd+7V9+4CGbDwW16HgrURkXQw9PBhOdNACF3KACeLODRxx/6plGSskJBsFvFzGgbth U8ZA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767972776; x=1768577576; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=pi9MBBtLQ+Z6Az6ZIrDOMPEc6YOFfVuBvcpyenL6HZw=; b=OfYuN34hf+y+yTylj1TFtj2oKAm5IOSWywaYc4boA2ElU//5qHwQgUcqTO2F5pXkWU CuPxEafJWsyoOpgtXOqRRtS48U3ZJ7d+O0poj5ef6XWL1L24fsKWX4DvKkG8TU6qUNkl 22ntJhao71raAVEXJN2Ui+i6oildAlEXckVEoSqrM/IlSzAKnCYAHz5DtITrYAD+SUnG 0/yjbPVDcTgdj8b+PVcicRNzEOthYFzChbhBqvCUTFy4iMZSCR3v4cZvKiJs+b1DY91T 1hNmJG5GsUlVt+BRduxpRM0TyMBuAaV/bOwJwNd75S7hKBuy5vi5Ejtqgyie8ZgjHTA/ ZcdQ== X-Forwarded-Encrypted: i=1; AJvYcCXo+gPflG39QAMwv7ghAuK+Zyja8+GDsnshd1tqRND5XHa0pKdHZz4OdMc9RL3dnG7roAeuUjnFc3Q2Sts=@vger.kernel.org X-Gm-Message-State: AOJu0YzfTnga+DcaKVrr1o307s8icdbtViCfjZXsGzorKlSExwWGIaYq z4jLBdfZY6pQ1ZVHAgDElXlvbdcl9VJyjJ1n/vpXHnLtiehpRt7bjvW0 X-Gm-Gg: AY/fxX5SOAorA0MSx919zYsVOzSO9FNFTPfLzJx/uLt7qDQERri2MLk1syY52RUpioO xV9WUowExItE86NsGtt+gMcOhVOH+etYOnPph81G5F1Kl+9hg98hl43K08FVFuPTG+nI8pstXNi PfgJa1O7rTvZRykjKF3l+zmoEDkVXLUmkBn7PIsh4FaD63Z6QlgrLVZGdisDkVQLhXUzXKe1w4W yNL+4iCD7oCidUErG+P0qELj4DUIKnFapU7C655j1ggbyJ1XlPNlp03C0g0JsUFnoabCyINeVTX bMcF5CpHSs9/7UoUMYbhRhRB++/xJl4d3Ay6YaEkF2hnKqEflg7H4fe3SuFKfY2/WLS7cVd1o1c DGBy/VnZwL4m2EHOxcXju4kqgmdzstbsFHQI9wt9yyrYqcH7okQ+4+i1HOtHmbIJSiEIOZEb6Fk ndf0A= X-Google-Smtp-Source: AGHT+IHcrtzAO+bIMCp7VJf6cVvYL7KCtM3NjFt78OIqdmkQu1Q/tiqyGp2Jn9iJI2z7jDarLLplnw== X-Received: by 2002:a17:90b:4986:b0:330:bca5:13d9 with SMTP id 98e67ed59e1d1-34f68cee7f2mr8136123a91.32.1767972775949; Fri, 09 Jan 2026 07:32:55 -0800 (PST) Received: from localhost ([2a12:a304:100::105b]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-34f6b9602d4sm3055529a91.12.2026.01.09.07.32.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 09 Jan 2026 07:32:55 -0800 (PST) Date: Fri, 9 Jan 2026 23:32:50 +0800 From: Jinchao Wang To: "David Hildenbrand (Red Hat)" Cc: Matthew Wilcox , Andrew Morton , Zi Yan , Matthew Brost , Joshua Hahn , Rakie Kim , Byungchul Park , Gregory Price , Ying Huang , Alistair Popple , linux-mm@kvack.org, linux-kernel@vger.kernel.org, syzbot+2d9c96466c978346b55f@syzkaller.appspotmail.com Subject: Re: [PATCH] mm/migrate: fix hugetlbfs deadlock by respecting lock ordering Message-ID: References: <20260109034723.1342798-1-wangjinchao600@gmail.com> <920c641e-e092-46f0-89cb-0f1c130d979a@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: On Fri, Jan 09, 2026 at 03:18:37PM +0100, David Hildenbrand (Red Hat) wrote: > On 1/9/26 15:16, Jinchao Wang wrote: > > On Fri, Jan 09, 2026 at 02:39:08PM +0100, David Hildenbrand (Red Hat) wrote: > > > On 1/9/26 04:47, Jinchao Wang wrote: > > > > Fix an AB-BA deadlock between hugetlbfs_punch_hole() and page migration. > > > > > > > > The deadlock occurs because migration violates the lock ordering defined > > > > in mm/rmap.c for hugetlbfs: > > > > > > > > * hugetlbfs PageHuge() take locks in this order: > > > > * hugetlb_fault_mutex > > > > * vma_lock > > > > * mapping->i_mmap_rwsem > > > > * folio_lock > > > > > > > > The following trace illustrates the inversion: > > > > > > > > Task A (punch_hole): Task B (migration): > > > > -------------------- ------------------- > > > > 1. i_mmap_lock_write(mapping) 1. folio_lock(folio) > > > > 2. folio_lock(folio) 2. i_mmap_lock_read(mapping) > > > > (blocks waiting for B) (blocks waiting for A) > > > > > > > > Task A is blocked in the punch-hole path: > > > > hugetlbfs_fallocate > > > > hugetlbfs_punch_hole > > > > hugetlbfs_zero_partial_page > > > > folio_lock > > > > > > > > Task B is blocked in the migration path: > > > > migrate_pages > > > > unmap_and_move_huge_page > > > > remove_migration_ptes > > > > __rmap_walk_file > > > > i_mmap_lock_read > > > > > > > > To fix this, adjust unmap_and_move_huge_page() to respect the established > > > > hierarchy. If i_mmap_rwsem is acquired during try_to_migrate(), hold it > > > > > > > > > I'm confused. Isn't it unmap_and_move_huge_page() that grabs the > > > i_mmap_rwsem during hugetlb_page_mapping_lock_write() (where we do a > > > try-lock)? > > Yes, but the lock is released before remove_migration_ptes(). > > > > Task A can enter the race window between > > i_mmap_unlock_write(mapping) > > and > > remove_migration_ptes() -> i_mmap_lock_read(mapping). > > > > This window was introduced by the change below: > > https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/diff/mm/migrate.c?id=336bf30eb765 > > try_to_migrate() is not the problem, but remove_migration_ptes() ? > > Anyhow, I saw that Willy sent out a version. Thank you for letting me know. > > -- > Cheers > > David