From: Andrew Morton <akpm@linux-foundation.org>
To: akpm@linux-foundation.org, bhsharma@redhat.com,
catalin.marinas@arm.com, hannes@cmpxchg.org, james.morse@arm.com,
linux-mm@kvack.org, mark.rutland@arm.com, mhocko@suse.com,
mm-commits@vger.kernel.org, pkushwaha@marvell.com,
torvalds@linux-foundation.org, vdavydov.dev@gmail.com,
will@kernel.org
Subject: [patch 05/15] mm/memcontrol: fix OOPS inside mem_cgroup_get_nr_swap_pages()
Date: Thu, 23 Jul 2020 21:15:21 -0700 [thread overview]
Message-ID: <20200724041521.QuyWRTbix%akpm@linux-foundation.org> (raw)
In-Reply-To: <20200723211432.b31831a0df3bc2cbdae31b40@linux-foundation.org>
From: Bhupesh Sharma <bhsharma@redhat.com>
Subject: mm/memcontrol: fix OOPS inside mem_cgroup_get_nr_swap_pages()
Prabhakar reported an OOPS inside mem_cgroup_get_nr_swap_pages() function
in a corner case seen on some arm64 boards when kdump kernel runs with
"cgroup_disable=memory" passed to the kdump kernel via bootargs.
The root-cause behind the same is that currently mem_cgroup_swap_init()
function is implemented as a subsys_initcall() call instead of a
core_initcall(), this means 'cgroup_memory_noswap' still remains set to
the default value (false) even when memcg is disabled via
"cgroup_disable=memory" boot parameter.
This may result in premature OOPS inside mem_cgroup_get_nr_swap_pages()
function in corner cases:
[ 0.265617] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000188
[ 0.274495] Mem abort info:
[ 0.277311] ESR = 0x96000006
[ 0.280389] EC = 0x25: DABT (current EL), IL = 32 bits
[ 0.285751] SET = 0, FnV = 0
[ 0.288830] EA = 0, S1PTW = 0
[ 0.291995] Data abort info:
[ 0.294897] ISV = 0, ISS = 0x00000006
[ 0.298765] CM = 0, WnR = 0
[ 0.301757] [0000000000000188] user address but active_mm is swapper
[ 0.308174] Internal error: Oops: 96000006 [#1] SMP
[ 0.313097] Modules linked in:
<..snip..>
[ 0.331384] pstate: 00400009 (nzcv daif +PAN -UAO BTYPE=--)
[ 0.337014] pc : mem_cgroup_get_nr_swap_pages+0x9c/0xf4
[ 0.342289] lr : mem_cgroup_get_nr_swap_pages+0x68/0xf4
[ 0.347564] sp : fffffe0012b6f800
[ 0.350905] x29: fffffe0012b6f800 x28: fffffe00116b3000
[ 0.356268] x27: fffffe0012b6fb00 x26: 0000000000000020
[ 0.361631] x25: 0000000000000000 x24: fffffc00723ffe28
[ 0.366994] x23: fffffe0010d5b468 x22: fffffe00116bfa00
[ 0.372357] x21: fffffe0010aabda8 x20: 0000000000000000
[ 0.377720] x19: 0000000000000000 x18: 0000000000000010
[ 0.383082] x17: 0000000043e612f2 x16: 00000000a9863ed7
[ 0.388445] x15: ffffffffffffffff x14: 202c303d70617773
[ 0.393808] x13: 6f6e5f79726f6d65 x12: 6d5f70756f726763
[ 0.399170] x11: 2073656761705f70 x10: 6177735f726e5f74
[ 0.404533] x9 : fffffe00100e9580 x8 : fffffe0010628160
[ 0.409895] x7 : 00000000000000a8 x6 : fffffe00118f5e5e
[ 0.415258] x5 : 0000000000000001 x4 : 0000000000000000
[ 0.420621] x3 : 0000000000000000 x2 : 0000000000000000
[ 0.425983] x1 : 0000000000000000 x0 : fffffc0060079000
[ 0.431346] Call trace:
[ 0.433809] mem_cgroup_get_nr_swap_pages+0x9c/0xf4
[ 0.438735] shrink_lruvec+0x404/0x4f8
[ 0.442516] shrink_node+0x1a8/0x688
[ 0.446121] do_try_to_free_pages+0xe8/0x448
[ 0.450429] try_to_free_pages+0x110/0x230
[ 0.454563] __alloc_pages_slowpath.constprop.106+0x2b8/0xb48
[ 0.460366] __alloc_pages_nodemask+0x2ac/0x2f8
[ 0.464938] alloc_page_interleave+0x20/0x90
[ 0.469246] alloc_pages_current+0xdc/0xf8
[ 0.473379] atomic_pool_expand+0x60/0x210
[ 0.477514] __dma_atomic_pool_init+0x50/0xa4
[ 0.481910] dma_atomic_pool_init+0xac/0x158
[ 0.486220] do_one_initcall+0x50/0x218
[ 0.490091] kernel_init_freeable+0x22c/0x2d0
[ 0.494489] kernel_init+0x18/0x110
[ 0.498007] ret_from_fork+0x10/0x18
[ 0.501614] Code: aa1403e3 91106000 97f82a27 14000011 (f940c663)
[ 0.507770] ---[ end trace 9795948475817de4 ]---
[ 0.512429] Kernel panic - not syncing: Fatal exception
[ 0.517705] Rebooting in 10 seconds..
Link: http://lkml.kernel.org/r/1593641660-13254-2-git-send-email-bhsharma@redhat.com
Fixes: eccb52e78809 ("mm: memcontrol: prepare swap controller setup for integration")
Signed-off-by: Bhupesh Sharma <bhsharma@redhat.com>
Reported-by: Prabhakar Kushwaha <pkushwaha@marvell.com>
Acked-by: Michal Hocko <mhocko@suse.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Vladimir Davydov <vdavydov.dev@gmail.com>
Cc: James Morse <james.morse@arm.com>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
mm/memcontrol.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
--- a/mm/memcontrol.c~mm-memcontrol-fix-oops-inside-mem_cgroup_get_nr_swap_pages
+++ a/mm/memcontrol.c
@@ -7186,6 +7186,13 @@ static struct cftype memsw_files[] = {
{ }, /* terminate */
};
+/*
+ * If mem_cgroup_swap_init() is implemented as a subsys_initcall()
+ * instead of a core_initcall(), this could mean cgroup_memory_noswap still
+ * remains set to false even when memcg is disabled via "cgroup_disable=memory"
+ * boot parameter. This may result in premature OOPS inside
+ * mem_cgroup_get_nr_swap_pages() function in corner cases.
+ */
static int __init mem_cgroup_swap_init(void)
{
/* No memory control -> no swap control */
@@ -7200,6 +7207,6 @@ static int __init mem_cgroup_swap_init(v
return 0;
}
-subsys_initcall(mem_cgroup_swap_init);
+core_initcall(mem_cgroup_swap_init);
#endif /* CONFIG_MEMCG_SWAP */
_
next prev parent reply other threads:[~2020-07-24 4:15 UTC|newest]
Thread overview: 86+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-07-24 4:14 incoming Andrew Morton
2020-07-24 4:15 ` [patch 01/15] mm/memory.c: avoid access flag update TLB flush for retried page fault Andrew Morton
[not found] ` <30cf7356-bef1-c621-60cb-e12a8bd9111d@linux.alibaba.com>
2020-07-24 4:56 ` Andrew Morton
2020-07-24 4:15 ` [patch 02/15] mm/mmap.c: close race between munmap() and expand_upwards()/downwards() Andrew Morton
2020-07-24 4:15 ` [patch 03/15] vfs/xattr: mm/shmem: kernfs: release simple xattr entry in a right way Andrew Morton
2020-07-24 4:15 ` [patch 04/15] mm: initialize return of vm_insert_pages Andrew Morton
2020-07-24 4:15 ` Andrew Morton [this message]
2020-07-24 4:15 ` [patch 06/15] mm/memcg: fix refcount error while moving and swapping Andrew Morton
2020-07-24 4:15 ` [patch 07/15] mm: memcg/slab: fix memory leak at non-root kmem_cache destroy Andrew Morton
2020-07-24 4:15 ` [patch 08/15] mm/hugetlb: avoid hardcoding while checking if cma is enabled Andrew Morton
2020-07-24 4:15 ` [patch 09/15] khugepaged: fix null-pointer dereference due to race Andrew Morton
2020-07-24 4:15 ` [patch 10/15] mailmap: add entry for Mike Rapoport Andrew Morton
2020-07-24 4:15 ` [patch 11/15] squashfs: fix length field overlap check in metadata reading Andrew Morton
2020-07-24 4:15 ` [patch 12/15] scripts/decode_stacktrace: strip basepath from all paths Andrew Morton
2020-07-24 4:15 ` [patch 13/15] io-mapping: indicate mapping failure Andrew Morton
2020-07-24 4:15 ` [patch 14/15] MAINTAINERS: add KCOV section Andrew Morton
2020-07-24 4:15 ` [patch 15/15] scripts/gdb: fix lx-symbols 'gdb.error' while loading modules Andrew Morton
2020-07-27 19:47 ` + mm-remove-unnecessary-wrapper-function-do_mmap_pgoff.patch added to -mm tree Andrew Morton
2020-07-27 19:56 ` + nilfs2-only-call-unlock_new_inode-if-i_new.patch " Andrew Morton
2020-07-27 19:57 ` + nilfs2-convert-__nilfs_msg-to-integrate-the-level-and-format.patch " Andrew Morton
2020-07-27 19:57 ` + nilfs2-use-a-more-common-logging-style.patch " Andrew Morton
2020-07-27 19:58 ` + checkpatch-add-test-for-repeated-words.patch " Andrew Morton
2020-07-27 20:05 ` + ocfs2-replace-http-links-with-https-ones.patch " Andrew Morton
2020-07-27 20:09 ` + ocfs2-fix-unbalanced-locking.patch " Andrew Morton
2020-07-27 20:10 ` + kernelh-remove-duplicate-include-of-asm-div64h.patch " Andrew Morton
2020-07-27 20:11 ` + tools-replace-http-links-with-https-ones.patch " Andrew Morton
2020-07-27 20:12 ` + lib-replace-http-links-with-https-ones.patch " Andrew Morton
2020-07-27 20:12 ` + include-replace-http-links-with-https-ones.patch " Andrew Morton
2020-07-27 20:34 ` + mm-make-mm-locked_vm-an-atomic64-counter.patch " Andrew Morton
2020-07-27 20:34 ` + mm-util-account_locked_vm-does-not-hold-mmap_lock.patch " Andrew Morton
2020-07-27 20:37 ` + cg_read_strcmp-fix-null-pointer-dereference.patch " Andrew Morton
2020-07-27 20:51 ` + mm-hugetlb-add-mempolicy-check-in-the-reservation-routine.patch " Andrew Morton
2020-07-27 20:52 ` [withdrawn] checkpatch-support-deprecated-terms-checking.patch removed from " Andrew Morton
2020-07-27 23:47 ` [obsolete] scripts-deprecated_terms-recommend-denylist-allowlist-instead-of-blacklist-whitelist.patch " Andrew Morton
2020-07-27 23:50 ` [obsolete] scripts-deprecated_terms-sync-with-inclusive-terms.patch " Andrew Morton
2020-07-28 0:18 ` [failures] mm-hugetlb-add-mempolicy-check-in-the-reservation-routine.patch " Andrew Morton
2020-07-28 1:19 ` mmotm 2020-07-27-18-18 uploaded Andrew Morton
[not found] ` <ae87385b-f830-dbdf-ebc7-1afb82a7fed0@infradead.org>
2020-07-28 21:55 ` mmotm 2020-07-27-18-18 uploaded (mm/page_alloc.c) Andrew Morton
[not found] ` <20200729082053.6c2fb654@canb.auug.org.au>
2020-07-28 22:31 ` Andrew Morton
[not found] ` <048cef07-ad4b-8788-94a4-e144de731ab6@infradead.org>
2020-07-29 1:44 ` Andrew Morton
2020-07-28 20:53 ` + mm-mempolicy-fix-kerneldoc-of-numa_map_to_online_node.patch added to -mm tree Andrew Morton
2020-07-28 20:53 ` + mm-mmu_notifier-fix-and-extend-kerneldoc.patch " Andrew Morton
2020-07-28 20:54 ` + mm-swap-fix-kerneldoc-of-swap_vma_readahead.patch " Andrew Morton
2020-07-28 20:58 ` + mm-memcontrol-dont-count-limit-setting-reclaim-as-memory-pressure.patch " Andrew Morton
2020-07-28 21:01 ` + mm-memcontrol-restore-proper-dirty-throttling-when-memoryhigh-changes.patch " Andrew Morton
2020-07-28 22:06 ` + mm-compaction-correct-the-comments-of-compact_defer_shift.patch " Andrew Morton
2020-07-28 22:09 ` + selftests-add-mincore-tests.patch " Andrew Morton
2020-07-28 22:16 ` + proc-pid-smaps-consistent-whitespace-output-format.patch " Andrew Morton
2020-07-28 22:21 ` + xtensa-switch-to-generic-version-of-pte-allocation-fix.patch " Andrew Morton
2020-07-28 22:21 ` Andrew Morton
2020-07-29 21:49 ` + mm-slab-avoid-the-use-of-one-element-array-and-use-struct_size-helper.patch " Andrew Morton
2020-07-29 23:52 ` [obsolete] mm-slab-avoid-the-use-of-one-element-array-and-use-struct_size-helper.patch removed from " Andrew Morton
2020-07-31 19:24 ` + kasan-dont-tag-stacks-allocated-with-pagealloc.patch added to " Andrew Morton
2020-07-31 19:24 ` + kasan-arm64-dont-instrument-functions-that-enable-kasan.patch " Andrew Morton
2020-07-31 19:24 ` + kasan-allow-enabling-stack-tagging-for-tag-based-mode.patch " Andrew Morton
2020-07-31 19:24 ` + kasan-adjust-kasan_stack_oob-for-tag-based-mode.patch " Andrew Morton
2020-07-31 20:00 ` [obsolete] mmhwpoison-rework-soft-offline-for-in-use-pages-fix.patch removed from " Andrew Morton
2020-07-31 20:05 ` + mmhwpoison-cleanup-unused-pagehuge-check.patch added to " Andrew Morton
2020-07-31 20:05 ` + mm-hwpoison-remove-recalculating-hpage.patch " Andrew Morton
2020-07-31 20:05 ` + mmmadvise-call-soft_offline_page-without-mf_count_increased.patch " Andrew Morton
2020-07-31 20:05 ` + mmmadvise-refactor-madvise_inject_error.patch " Andrew Morton
2020-07-31 20:05 ` + mmhwpoison-inject-dont-pin-for-hwpoison_filter.patch " Andrew Morton
2020-07-31 20:05 ` + mmhwpoison-un-export-get_hwpoison_page-and-make-it-static.patch " Andrew Morton
2020-07-31 20:05 ` + mmhwpoison-kill-put_hwpoison_page.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-remove-mf_count_increased.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-remove-flag-argument-from-soft-offline-functions.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-unify-thp-handling-for-hard-and-soft-offline.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-rework-soft-offline-for-free-pages.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-rework-soft-offline-for-in-use-pages.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-refactor-soft_offline_huge_page-and-__soft_offline_page.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-return-0-if-the-page-is-already-poisoned-in-soft-offline.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-introduce-mf_msg_unsplit_thp.patch " Andrew Morton
2020-07-31 20:06 ` + mmhwpoison-double-check-page-count-in-__get_any_page.patch " Andrew Morton
2020-07-31 20:23 ` + mm-gup-restrict-cma-region-by-using-allocation-scope-api.patch " Andrew Morton
2020-07-31 20:23 ` + mm-hugetlb-make-hugetlb-migration-callback-cma-aware.patch " Andrew Morton
2020-07-31 20:23 ` + mm-gup-use-a-standard-migration-target-allocation-callback.patch " Andrew Morton
2020-07-31 20:25 ` + mm-migrate-make-a-standard-migration-target-allocation-function-fix.patch " Andrew Morton
2020-07-31 20:26 ` + mm-memcontrol-decouple-reference-counting-from-page-accounting-fix.patch " Andrew Morton
2020-07-31 20:32 ` + mm-dmapoolc-add-warn_on-in-dma_pool_destroy.patch " Andrew Morton
2020-07-31 20:49 ` + kstrto-correct-documentation-references-to-simple_strto.patch " Andrew Morton
2020-07-31 20:49 ` + kstrto-do-not-describe-simple_strto-as-obsolete-replaced.patch " Andrew Morton
2020-07-31 20:57 ` + mm-hugetlb-fix-calculation-of-adjust_range_if_pmd_sharing_possible.patch " Andrew Morton
2020-07-31 20:59 ` + poison-remove-obsolete-comment.patch " Andrew Morton
2020-07-31 21:02 ` + cma-dont-quit-at-first-error-when-activating-reserved-areas.patch " Andrew Morton
2020-07-31 21:10 ` [nacked] mm-dmapoolc-add-warn_on-in-dma_pool_destroy.patch removed from " Andrew Morton
2020-07-31 23:46 ` mmotm 2020-07-31-16-45 uploaded Andrew Morton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200724041521.QuyWRTbix%akpm@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=bhsharma@redhat.com \
--cc=catalin.marinas@arm.com \
--cc=hannes@cmpxchg.org \
--cc=james.morse@arm.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mark.rutland@arm.com \
--cc=mhocko@suse.com \
--cc=mm-commits@vger.kernel.org \
--cc=pkushwaha@marvell.com \
--cc=torvalds@linux-foundation.org \
--cc=vdavydov.dev@gmail.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox