Linux MM tree latest commits
 help / color / mirror / Atom feed
From: akpm@linux-foundation.org
To: torvalds@linux-foundation.org, mm-commits@vger.kernel.org,
	akpm@linux-foundation.org, santosh.shilimkar@oracle.com,
	a.p.zijlstra@chello.nl, axboe@fb.com, davem@davemloft.net,
	hughd@google.com, joe@perches.com, mgorman@suse.de,
	mhocko@suse.com, riel@redhat.com, stable@vger.kernel.org,
	viro@zeniv.linux.org.uk
Subject: [patch 09/20] mm: fix the page_swap_info() BUG_ON check
Date: Mon, 19 Sep 2016 15:12:23 -0700	[thread overview]
Message-ID: <57e062c7.IDXXzliSLybD7o7t%akpm@linux-foundation.org> (raw)

From: Santosh Shilimkar <santosh.shilimkar@oracle.com>
Subject: mm: fix the page_swap_info() BUG_ON check

62c230bc1790 ("mm: add support for a filesystem to activate swap files and
use direct_IO for writing swap pages") replaced swap_aops dirty hook from
__set_page_dirty_no_writeback() to swap_set_page_dirty().  As such for
normal cases without these special SWP flags code path falls back to
__set_page_dirty_no_writeback() so behaviour is expected to be same as
before.

But swap_set_page_dirty() makes use of helper page_swap_info() to get
sis(swap_info_struct) to check for the flags like SWP_FILE, SWP_BLKDEV etc
as desired for those features.  This helper has
BUG_ON(!PageSwapCache(page)) which is racy and safe only for
set_page_dirty_lock() path.  For set_page_dirty() path which is often
needed for cases to be called from irq context, kswapd() can togele the
flag behind the back while the call is getting executed when system is low
on memory and heavy swapping is ongoing.

This ends up with undesired kernel panic.  Patch just moves the check
outside the helper to its users appropriately to fix kernel panic for the
described path.  Couple of users of helpers already take care of SwapCache
condition so I skipped them.

Link: http://lkml.kernel.org/r/1473460718-31013-1-git-send-email-santosh.shilimkar@oracle.com
Signed-off-by: Santosh Shilimkar <santosh.shilimkar@oracle.com>
Cc: Mel Gorman <mgorman@suse.de>
Cc: Joe Perches <joe@perches.com>
Cc: Peter Zijlstra <a.p.zijlstra@chello.nl>
Cc: Rik van Riel <riel@redhat.com>
Cc: David S. Miller <davem@davemloft.net>
Cc: Jens Axboe <axboe@fb.com>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: <stable@vger.kernel.org>	[4.7.x]
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---

 mm/page_io.c  |    3 +++
 mm/swapfile.c |    1 -
 2 files changed, 3 insertions(+), 1 deletion(-)

diff -puN mm/page_io.c~mm-fix-the-page_swap_info-bug_on-check mm/page_io.c
--- a/mm/page_io.c~mm-fix-the-page_swap_info-bug_on-check
+++ a/mm/page_io.c
@@ -264,6 +264,7 @@ int __swap_writepage(struct page *page,
 	int ret;
 	struct swap_info_struct *sis = page_swap_info(page);
 
+	BUG_ON(!PageSwapCache(page));
 	if (sis->flags & SWP_FILE) {
 		struct kiocb kiocb;
 		struct file *swap_file = sis->swap_file;
@@ -337,6 +338,7 @@ int swap_readpage(struct page *page)
 	int ret = 0;
 	struct swap_info_struct *sis = page_swap_info(page);
 
+	BUG_ON(!PageSwapCache(page));
 	VM_BUG_ON_PAGE(!PageLocked(page), page);
 	VM_BUG_ON_PAGE(PageUptodate(page), page);
 	if (frontswap_load(page) == 0) {
@@ -386,6 +388,7 @@ int swap_set_page_dirty(struct page *pag
 
 	if (sis->flags & SWP_FILE) {
 		struct address_space *mapping = sis->swap_file->f_mapping;
+		BUG_ON(!PageSwapCache(page));
 		return mapping->a_ops->set_page_dirty(page);
 	} else {
 		return __set_page_dirty_no_writeback(page);
diff -puN mm/swapfile.c~mm-fix-the-page_swap_info-bug_on-check mm/swapfile.c
--- a/mm/swapfile.c~mm-fix-the-page_swap_info-bug_on-check
+++ a/mm/swapfile.c
@@ -2724,7 +2724,6 @@ int swapcache_prepare(swp_entry_t entry)
 struct swap_info_struct *page_swap_info(struct page *page)
 {
 	swp_entry_t swap = { .val = page_private(page) };
-	BUG_ON(!PageSwapCache(page));
 	return swap_info[swp_type(swap)];
 }
 
_

             reply	other threads:[~2016-09-19 22:12 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-09-19 22:12 akpm [this message]
  -- strict thread matches above, loose matches on Subject: below --
2016-09-19 21:44 [patch 09/20] mm: fix the page_swap_info() BUG_ON check akpm

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=57e062c7.IDXXzliSLybD7o7t%akpm@linux-foundation.org \
    --to=akpm@linux-foundation.org \
    --cc=a.p.zijlstra@chello.nl \
    --cc=axboe@fb.com \
    --cc=davem@davemloft.net \
    --cc=hughd@google.com \
    --cc=joe@perches.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mgorman@suse.de \
    --cc=mhocko@suse.com \
    --cc=mm-commits@vger.kernel.org \
    --cc=riel@redhat.com \
    --cc=santosh.shilimkar@oracle.com \
    --cc=stable@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox