From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9C8AEC3F6B0 for ; Tue, 16 Aug 2022 07:04:16 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 1D2318D0002; Tue, 16 Aug 2022 03:04:16 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 15ADE8D0001; Tue, 16 Aug 2022 03:04:16 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id F3C9E8D0002; Tue, 16 Aug 2022 03:04:15 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id DD48B8D0001 for ; Tue, 16 Aug 2022 03:04:15 -0400 (EDT) Received: from smtpin28.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay01.hostedemail.com (Postfix) with ESMTP id B74391C61D2 for ; Tue, 16 Aug 2022 07:04:15 +0000 (UTC) X-FDA: 79804566870.28.7999C3C Received: from szxga01-in.huawei.com (szxga01-in.huawei.com [45.249.212.187]) by imf19.hostedemail.com (Postfix) with ESMTP id DC8801A0059 for ; Tue, 16 Aug 2022 07:04:13 +0000 (UTC) Received: from dggpemm500020.china.huawei.com (unknown [172.30.72.57]) by szxga01-in.huawei.com (SkyGuard) with ESMTP id 4M6MVp1Pd5zkWQm; Tue, 16 Aug 2022 15:00:50 +0800 (CST) Received: from dggpemm500014.china.huawei.com (7.185.36.153) by dggpemm500020.china.huawei.com (7.185.36.49) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2375.24; Tue, 16 Aug 2022 15:04:09 +0800 Received: from [10.174.178.120] (10.174.178.120) by dggpemm500014.china.huawei.com (7.185.36.153) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2375.24; Tue, 16 Aug 2022 15:04:09 +0800 Message-ID: Date: Tue, 16 Aug 2022 15:04:08 +0800 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.1.0 From: mawupeng Subject: Re: [PATCH stable 4.14,4.19 1/1] mm: Fix page counter mismatch in shmem_mfill_atomic_pte To: CC: , , , , , , , , References: <20220802013251.3022141-1-mawupeng1@huawei.com> <09129cd3-7363-3079-bd57-dde9c73684f1@huawei.com> Content-Language: en-US In-Reply-To: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 7bit X-Originating-IP: [10.174.178.120] X-ClientProxiedBy: dggems706-chm.china.huawei.com (10.3.19.183) To dggpemm500014.china.huawei.com (7.185.36.153) X-CFilter-Loop: Reflected ARC-Authentication-Results: i=1; imf19.hostedemail.com; dkim=none; spf=pass (imf19.hostedemail.com: domain of mawupeng1@huawei.com designates 45.249.212.187 as permitted sender) smtp.mailfrom=mawupeng1@huawei.com; dmarc=pass (policy=quarantine) header.from=huawei.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1660633454; a=rsa-sha256; cv=none; b=BktZWUh0UP7CvKsrF3+XJMjCrpZtWW1cJoqjT1adApTuqluW1IiTK787N5zk9q8ZMF53jL 5hMZKwb+MoOt90HTQcH7IbI+e0n1ojyy3NUqnllmXcrcoXDNcQ8udCLX/4J1UcMO96RgvH +sMrotzClSr/lwWjgl/GRLpB3h2Z3UM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1660633454; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=h4zeuf6R51xdOk+TRpgSwO72TQwQQYogtekikKRcbr0=; b=5L6HubEFs8X/jbzGTBYeKcgFc0jMAheBOaw+sQg+ZNrL1u4w8TYmp/t5Nby81YJBspOs7N A61WH1Q4OES4JQ+yv1KcEw4hDL37miVQ5nIg1Lz1ZuE4/BPlbmaPhZU2PmUWb9AV3aLFC/ ng7QusGq+qw7pK46Q5KcgkI9bAViJ6w= X-Stat-Signature: a1fst6rrfw9kpnznf4imqj1jtumjb74p X-Rspamd-Queue-Id: DC8801A0059 X-Rspamd-Server: rspam08 Authentication-Results: imf19.hostedemail.com; dkim=none; spf=pass (imf19.hostedemail.com: domain of mawupeng1@huawei.com designates 45.249.212.187 as permitted sender) smtp.mailfrom=mawupeng1@huawei.com; dmarc=pass (policy=quarantine) header.from=huawei.com X-Rspam-User: X-HE-Tag: 1660633453-227027 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On 2022/8/16 13:31, Greg KH wrote: > On Tue, Aug 16, 2022 at 11:27:08AM +0800, mawupeng wrote: >> Cc Greg > > Cc Greg for what? I have no context here at all as to what you want me > to do.. We found a bug related to memory cgroup counter in stable 4.14/4.19. shmem_mfill_atomic_pte() wrongly called mem_cgroup_cancel_charge() in "success" path, it should mem_cgroup_uncharge() to dec memory counter instead. mem_cgroup_cancel_charge() should only be used if this transaction is unsuccessful and mem_cgroup_uncharge() is used to do this if this transaction succeed. Commit 3fea5a499d57 ("mm: memcontrol: convert page cache to a new mem_cgroup_charge() API") in v5.8-rc1 change is charge/uncharge/cancel logic so don't have this problem. This counter will underflow to negative maximum value and trigger oom to kill all process include sshd and leave system unaccessible. The reason cc you is that we want to merge this bugfix into stable 4.14/4.19. The error call trace: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 17127 at mm/page_counter.c:62 page_counter_cancel+0x57/0x90 RIP: 0010:page_counter_cancel+0x57/0x90 Call Trace: page_counter_uncharge+0x33/0x60 uncharge_batch+0xb5/0x5f0 mem_cgroup_uncharge_list+0x102/0x170 release_pages+0x814/0xcc0 tlb_flush_mmu_free+0xa9/0x140 arch_tlb_finish_mmu+0xa4/0x140 tlb_finish_mmu+0x90/0xf0 exit_mmap+0x264/0x4b0 > > totally confused, > > greg k-h