From: Matthew Wilcox <willy@infradead.org>
To: Sergey Senozhatsky <senozhatsky@chromium.org>
Cc: Andrew Morton <akpm@linux-foundation.org>,
Mike Kravetz <mike.kravetz@oracle.com>,
Minchan Kim <minchan@kernel.org>,
linux-kernel@vger.kernel.org, linux-mm@kvack.org
Subject: Re: [PATCHv2 0/4] zsmalloc: make zspage chain size configurable
Date: Sun, 15 Jan 2023 13:04:36 +0000 [thread overview]
Message-ID: <Y8P55Ks8p8SL56VR@casper.infradead.org> (raw)
In-Reply-To: <Y8Oo3+9UmZ4ac8sW@google.com>
On Sun, Jan 15, 2023 at 04:18:55PM +0900, Sergey Senozhatsky wrote:
> So this warning is move_to_new_folio() being called on un-isolated
> src folio. I had DEBUG_VM disabled so VM_BUG_ON_FOLIO(!folio_test_isolated(src))
> did nothing, however after mops->migrate_page() it would trigger WARN_ON()
> because it evaluates folio_test_isolated(src) one more time:
>
> [ 59.500580] page:0000000097d97a42 refcount:2 mapcount:1665 mapping:0000000000000000 index:0xffffea00185ce940 pfn:0x113dc4
> [ 59.503239] flags: 0x8000000000000001(locked|zone=2)
> [ 59.505060] raw: 8000000000000001 ffffea00044f70c8 ffffc90000ba7c20 ffffffff81c22582
> [ 59.507288] raw: ffffea00185ce940 ffff88809183fdb0 0000000200000680 0000000000000000
That is quite the messed-up page. mapcount is positive, but higher than
refcount. And not just a little bit; 1665 vs 2. But mapping is NULL,
so it's not anon or file memory. Makes me think it belongs to a driver
that's using ->mapcount for its own purposes. It's not PageSlab.
Given that you're working on zsmalloc, I took a look and:
static inline void set_first_obj_offset(struct page *page, unsigned int offset)
{
page->page_type = offset;
}
(page_type aliases with mapcount). So I'm pretty sure this is a
zsmalloc page. But mapping should point to zsmalloc_mops. Not
really sure what's going on here. Can you bisect?
> [ 59.509622] page dumped because: VM_BUG_ON_FOLIO(!folio_test_isolated(src))
> [ 59.511845] ------------[ cut here ]------------
> [ 59.513181] kernel BUG at mm/migrate.c:988!
> [ 59.514821] invalid opcode: 0000 [#1] PREEMPT SMP PTI
>
> [ 59.523018] RIP: 0010:move_to_new_folio+0x362/0x3b0
> [ 59.524160] Code: ff ff e9 55 fd ff ff 48 89 df e8 69 d8 ff ff f0 80 60 02 fb 31 c0 e9 65 fd ff ff 48 c7 c6 00 f5 e9 81 48 89 df e8 be c0 f9 ff <0f> 0b 48 c7 c6 00 f5 e9 81 48 89 df e8 ad c0 f9 ff 0f 0b b8 f5 ff
> [ 59.528349] RSP: 0018:ffffc90000ba7af8 EFLAGS: 00010246
> [ 59.529551] RAX: 000000000000003f RBX: ffffea00044f7100 RCX: 0000000000000000
> [ 59.531186] RDX: 0000000000000000 RSI: ffffffff81e8dcf1 RDI: 00000000ffffffff
> [ 59.532790] RBP: ffffea00184f1140 R08: 00000000ffffbfff R09: 00000000ffffbfff
> [ 59.534392] R10: ffff888621ca0000 R11: ffff888621ca0000 R12: 8000000000000001
> [ 59.536026] R13: 0000000000000001 R14: 0000000000000000 R15: ffffea00184f1140
> [ 59.537646] FS: 0000000000000000(0000) GS:ffff888626a00000(0000) knlGS:0000000000000000
> [ 59.539484] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [ 59.540785] CR2: 00007ff7fbed8000 CR3: 0000000101a26001 CR4: 0000000000770ee0
> [ 59.542412] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> [ 59.544030] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
> [ 59.545637] PKRU: 55555554
> [ 59.546261] Call Trace:
> [ 59.546833] <TASK>
> [ 59.547371] ? lock_is_held_type+0xd9/0x130
> [ 59.548331] migrate_pages_batch+0x650/0xdc0
> [ 59.549326] ? move_freelist_tail+0xc0/0xc0
> [ 59.550281] ? isolate_freepages+0x290/0x290
> [ 59.551289] ? folio_flags.constprop.0+0x50/0x50
> [ 59.552348] migrate_pages+0x3fa/0x4d0
> [ 59.553224] ? isolate_freepages+0x290/0x290
> [ 59.554214] ? move_freelist_tail+0xc0/0xc0
> [ 59.555173] compact_zone+0x51b/0x6a0
> [ 59.556031] proactive_compact_node+0x8e/0xe0
> [ 59.557033] kcompactd+0x1c3/0x350
> [ 59.557842] ? swake_up_all+0xe0/0xe0
> [ 59.558699] ? kcompactd_do_work+0x260/0x260
> [ 59.559703] kthread+0xec/0x110
> [ 59.560450] ? kthread_complete_and_exit+0x20/0x20
> [ 59.561582] ret_from_fork+0x1f/0x30
> [ 59.562427] </TASK>
> [ 59.562966] Modules linked in: deflate zlib_deflate zstd zstd_compress zram
> [ 59.564591] ---[ end trace 0000000000000000 ]---
> [ 59.565661] RIP: 0010:move_to_new_folio+0x362/0x3b0
> [ 59.566802] Code: ff ff e9 55 fd ff ff 48 89 df e8 69 d8 ff ff f0 80 60 02 fb 31 c0 e9 65 fd ff ff 48 c7 c6 00 f5 e9 81 48 89 df e8 be c0 f9 ff <0f> 0b 48 c7 c6 00 f5 e9 81 48 89 df e8 ad c0 f9 ff 0f 0b b8 f5 ff
> [ 59.571048] RSP: 0018:ffffc90000ba7af8 EFLAGS: 00010246
> [ 59.572257] RAX: 000000000000003f RBX: ffffea00044f7100 RCX: 0000000000000000
> [ 59.573906] RDX: 0000000000000000 RSI: ffffffff81e8dcf1 RDI: 00000000ffffffff
> [ 59.575544] RBP: ffffea00184f1140 R08: 00000000ffffbfff R09: 00000000ffffbfff
> [ 59.577236] R10: ffff888621ca0000 R11: ffff888621ca0000 R12: 8000000000000001
> [ 59.578893] R13: 0000000000000001 R14: 0000000000000000 R15: ffffea00184f1140
> [ 59.580593] FS: 0000000000000000(0000) GS:ffff888626a00000(0000) knlGS:0000000000000000
> [ 59.582432] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [ 59.583767] CR2: 00007ff7fbed8000 CR3: 0000000101a26001 CR4: 0000000000770ee0
> [ 59.585437] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> [ 59.587082] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
> [ 59.588738] PKRU: 55555554
next prev parent reply other threads:[~2023-01-15 13:04 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-01-09 3:38 Sergey Senozhatsky
2023-01-09 3:38 ` [PATCHv2 1/4] zsmalloc: rework zspage chain size selection Sergey Senozhatsky
2023-01-13 17:32 ` Minchan Kim
2023-01-09 3:38 ` [PATCHv2 2/4] zsmalloc: skip chain size calculation for pow_of_2 classes Sergey Senozhatsky
2023-01-13 17:32 ` Minchan Kim
2023-01-09 3:38 ` [PATCHv2 3/4] zsmalloc: make zspage chain size configurable Sergey Senozhatsky
2023-01-12 7:11 ` Sergey Senozhatsky
2023-01-12 7:14 ` [PATCH] zsmalloc: turn chain size config option into UL constant Sergey Senozhatsky
2023-01-13 19:02 ` [PATCHv2 3/4] zsmalloc: make zspage chain size configurable Minchan Kim
2023-01-09 3:38 ` [PATCHv2 4/4] zsmalloc: set default zspage chain size to 8 Sergey Senozhatsky
2023-01-13 19:02 ` Minchan Kim
2023-01-14 7:28 ` Sergey Senozhatsky
2023-01-13 19:57 ` [PATCHv2 0/4] zsmalloc: make zspage chain size configurable Mike Kravetz
2023-01-14 5:27 ` Sergey Senozhatsky
2023-01-14 6:34 ` Sergey Senozhatsky
2023-01-14 7:08 ` Sergey Senozhatsky
2023-01-14 21:34 ` Mike Kravetz
2023-01-15 4:21 ` Sergey Senozhatsky
2023-01-15 5:32 ` Sergey Senozhatsky
2023-01-15 7:18 ` Sergey Senozhatsky
2023-01-15 8:19 ` Sergey Senozhatsky
2023-01-16 1:27 ` Huang, Ying
2023-01-16 3:46 ` Sergey Senozhatsky
2023-01-15 13:04 ` Matthew Wilcox [this message]
2023-01-15 14:55 ` Sergey Senozhatsky
2023-01-16 3:15 ` Sergey Senozhatsky
2023-01-16 18:34 ` Mike Kravetz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Y8P55Ks8p8SL56VR@casper.infradead.org \
--to=willy@infradead.org \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mike.kravetz@oracle.com \
--cc=minchan@kernel.org \
--cc=senozhatsky@chromium.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox