Received: by 2002:ab2:6f44:0:b0:1fd:c486:4f03 with SMTP id l4csp239006lqq; Thu, 13 Jun 2024 01:21:47 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCWJpc7dEaM3jnZRRKFwZ1ZYZvg8bfd1t33WalD1NQaQf63h1hEPvztkCqWl+1va3GvcRZqMy13GzTFecmBVJ+P5jU6+/t5Ro/gjxjYHfA== X-Google-Smtp-Source: AGHT+IFjfZDHKVnZ5zpotur+1xX0QxGm3Fzni9FOVtas8ZRPxwB0aByeEKmcQU7ONgPzR5c+bRLd X-Received: by 2002:a50:8d4f:0:b0:57c:68fd:2bc6 with SMTP id 4fb4d7f45d1cf-57caa9ba4f7mr2444757a12.26.1718266906887; Thu, 13 Jun 2024 01:21:46 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1718266906; cv=pass; d=google.com; s=arc-20160816; b=lrfDvJfdebPqX8W50T1foeRucYaKlWIkcQ/bziTsyPw/C7Kj55h4rvA4DtBykCdt/4 /AN5mAKKy6fBImoMRRnN4CcHWQ2D0l5+TT6Pm5abVrjddhfP78kDyYuV+1zOkU47nCbW hyQeReAWZWqvxB+NAwuxUeYjKqHSTps3d6Vy3mZ/LFOU7aKz1DUd6sAUaVCrTtAvId6q 0Hm7Et1Gfq/vnJ+rqSXpXOxhzNVPtmUiCJziUTmYvGVBGmygYGAu6u0sTw+CpwKaKRnR hIe4dTEDYdGwUvRwvSJXsKUVXhmDo8RXTs1zc6LUNB81l4qTR9rZTVQ7oTHWd7izT8d9 nswQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:message-id:date:subject:cc:to :from:dkim-signature; bh=0QrNpcoNy4k31Qxi3z0ZW2oJXA9rvfY0thkoxU4Y00M=; fh=mOWGASwEr/ObJAzhFz1UZMEoOCJGhNWxk5EyFG5zLGw=; b=iW97Hig/Sf0ftH/S6zo9dg3LDfOh1cHV1Gr6ZZFiWgWjfXjlwZFxD7gCf+Bs+KAXzA oRjQnuZpY701jj8PbyS9yQRMhEMVWEsdvmHI7zL+Z0aniJHk3qJkshO96uqfMmKJLCE6 z53r2+3wtUEuKI19Hs9XCywmJrBhml3t6/Jf2iWu0F/fKM/w+GRH5DXHAIi6Hws2gwE2 wKfUgw7mKM1EyKnX9XUaTlenhf4+/m0ejp1n+UbAE5EOw6ScVZcBfGPFOkj+T10lCCAi rpkiVO1+S1NIoVRAeLDYkY0dmi81BtY+q4tXrJLDJORu+f04iLGU8cOsD7mcuXIc3zbg 0MIw==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@linux.alibaba.com header.s=default header.b=x97J06L5; arc=pass (i=1 spf=pass spfdomain=linux.alibaba.com dkim=pass dkdomain=linux.alibaba.com dmarc=pass fromdomain=linux.alibaba.com); spf=pass (google.com: domain of linux-kernel+bounces-212793-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-212793-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.alibaba.com Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id 4fb4d7f45d1cf-57cb742cbe2si476399a12.334.2024.06.13.01.21.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 13 Jun 2024 01:21:46 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-212793-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; dkim=pass header.i=@linux.alibaba.com header.s=default header.b=x97J06L5; arc=pass (i=1 spf=pass spfdomain=linux.alibaba.com dkim=pass dkdomain=linux.alibaba.com dmarc=pass fromdomain=linux.alibaba.com); spf=pass (google.com: domain of linux-kernel+bounces-212793-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-212793-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.alibaba.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 6DFEE1F25723 for ; Thu, 13 Jun 2024 08:21:46 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 5AC6613D507; Thu, 13 Jun 2024 08:21:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.alibaba.com header.i=@linux.alibaba.com header.b="x97J06L5" Received: from out30-132.freemail.mail.aliyun.com (out30-132.freemail.mail.aliyun.com [115.124.30.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87F7B13D273 for ; Thu, 13 Jun 2024 08:21:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=115.124.30.132 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718266899; cv=none; b=vE+0KHgFFYIzXa87Tv38KOl/b0WUQTN+gKozy1ChMDvDYZEuhdu6OknKyoogbRlYoOhhrwHDlxFU61VJBdEPYKeo5oXUtPjFuO7G5pXv9fKvm0DZdYATvPsiDAmYSEk1W85uPvNzpJc4nRR/JK+n9TtewRtMA2tNH9+eKpeuYM4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718266899; c=relaxed/simple; bh=rrXcE+O9VN4XI0wCp0Jqru/S9cQsl0yPrjLzUve4IeU=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=tWh15gRy9c7y64XKPA9oTIvs+FAjkmFRzGLkVM38pxA4YPm0GP80JwzCrkoqLmEeqoXnO8He1gELZ7a3tGs680MRxRT+T8cGQj1ukyAYRD/fZJh8GMrQwNITcf0IYDflB4OHW8Nd7W4u64D244RUgsKvAkfKuzMtmGJ/P6eXkEQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.alibaba.com; spf=pass smtp.mailfrom=linux.alibaba.com; dkim=pass (1024-bit key) header.d=linux.alibaba.com header.i=@linux.alibaba.com header.b=x97J06L5; arc=none smtp.client-ip=115.124.30.132 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.alibaba.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.alibaba.com DKIM-Signature:v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1718266887; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=0QrNpcoNy4k31Qxi3z0ZW2oJXA9rvfY0thkoxU4Y00M=; b=x97J06L5rUOfMEXaIn8DKz60p5ZhveRfjlSeBDLCikNDLvOgdmta0rAEnmA5Wubb8AiEng8bbmtpGWc3PmdrIKjPjHAbMSgMG955mvlYJ7xo9myVOUDYh1z5BOPwko2kvXJXstsCfQBOZMOkaOArHuxHPlAH5mxD9ZnFVInnruw= X-Alimail-AntiSpam:AC=PASS;BC=-1|-1;BR=01201311R711e4;CH=green;DM=||false|;DS=||;FP=0|-1|-1|-1|0|-1|-1|-1;HT=maildocker-contentspam033037067110;MF=baolin.wang@linux.alibaba.com;NM=1;PH=DS;RN=7;SR=0;TI=SMTPD_---0W8NU4tU_1718266886; Received: from localhost(mailfrom:baolin.wang@linux.alibaba.com fp:SMTPD_---0W8NU4tU_1718266886) by smtp.aliyun-inc.com; Thu, 13 Jun 2024 16:21:27 +0800 From: Baolin Wang To: akpm@linux-foundation.org, hughd@google.com Cc: hannes@cmpxchg.org, nphamcs@gmail.com, baolin.wang@linux.alibaba.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org Subject: [PATCH] mm: shmem: fix getting incorrect lruvec when replacing a shmem folio Date: Thu, 13 Jun 2024 16:21:19 +0800 Message-Id: <3c11000dd6c1df83015a8321a859e9775ebbc23e.1718266112.git.baolin.wang@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When testing shmem swapin, I encountered the warning below on my machine. The reason is that replacing an old shmem folio with a new one causes mem_cgroup_migrate() to clear the old folio's memcg data. As a result, the old folio cannot get the correct memcg's lruvec needed to remove itself from the LRU list when it is being freed. This could lead to possible serious problems, such as LRU list crashes due to holding the wrong LRU lock, and incorrect LRU statistics. To fix this issue, we can fallback to use the mem_cgroup_replace_folio() to replace the old shmem folio. [ 5241.100311] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x5d9960 [ 5241.100317] head: order:4 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 5241.100319] flags: 0x17fffe0000040068(uptodate|lru|head|swapbacked|node=0|zone=2|lastcpupid=0x3ffff) [ 5241.100323] raw: 17fffe0000040068 fffffdffd6687948 fffffdffd69ae008 0000000000000000 [ 5241.100325] raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 5241.100326] head: 17fffe0000040068 fffffdffd6687948 fffffdffd69ae008 0000000000000000 [ 5241.100327] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 5241.100328] head: 17fffe0000000204 fffffdffd6665801 ffffffffffffffff 0000000000000000 [ 5241.100329] head: 0000000a00000010 0000000000000000 00000000ffffffff 0000000000000000 [ 5241.100330] page dumped because: VM_WARN_ON_ONCE_FOLIO(!memcg && !mem_cgroup_disabled()) [ 5241.100338] ------------[ cut here ]------------ [ 5241.100339] WARNING: CPU: 19 PID: 78402 at include/linux/memcontrol.h:775 folio_lruvec_lock_irqsave+0x140/0x150 [...] [ 5241.100374] pc : folio_lruvec_lock_irqsave+0x140/0x150 [ 5241.100375] lr : folio_lruvec_lock_irqsave+0x138/0x150 [ 5241.100376] sp : ffff80008b38b930 [...] [ 5241.100398] Call trace: [ 5241.100399] folio_lruvec_lock_irqsave+0x140/0x150 [ 5241.100401] __page_cache_release+0x90/0x300 [ 5241.100404] __folio_put+0x50/0x108 [ 5241.100406] shmem_replace_folio+0x1b4/0x240 [ 5241.100409] shmem_swapin_folio+0x314/0x528 [ 5241.100411] shmem_get_folio_gfp+0x3b4/0x930 [ 5241.100412] shmem_fault+0x74/0x160 [ 5241.100414] __do_fault+0x40/0x218 [ 5241.100417] do_shared_fault+0x34/0x1b0 [ 5241.100419] do_fault+0x40/0x168 [ 5241.100420] handle_pte_fault+0x80/0x228 [ 5241.100422] __handle_mm_fault+0x1c4/0x440 [ 5241.100424] handle_mm_fault+0x60/0x1f0 [ 5241.100426] do_page_fault+0x120/0x488 [ 5241.100429] do_translation_fault+0x4c/0x68 [ 5241.100431] do_mem_abort+0x48/0xa0 [ 5241.100434] el0_da+0x38/0xc0 [ 5241.100436] el0t_64_sync_handler+0x68/0xc0 [ 5241.100437] el0t_64_sync+0x14c/0x150 [ 5241.100439] ---[ end trace 0000000000000000 ]--- Fixes: 85ce2c517ade ("memcontrol: only transfer the memcg data for migration") Signed-off-by: Baolin Wang --- mm/shmem.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mm/shmem.c b/mm/shmem.c index 99bd3c34f0fb..4acaf02bfe44 100644 --- a/mm/shmem.c +++ b/mm/shmem.c @@ -1908,7 +1908,7 @@ static int shmem_replace_folio(struct folio **foliop, gfp_t gfp, xa_lock_irq(&swap_mapping->i_pages); error = shmem_replace_entry(swap_mapping, swap_index, old, new); if (!error) { - mem_cgroup_migrate(old, new); + mem_cgroup_replace_folio(old, new); __lruvec_stat_mod_folio(new, NR_FILE_PAGES, 1); __lruvec_stat_mod_folio(new, NR_SHMEM, 1); __lruvec_stat_mod_folio(old, NR_FILE_PAGES, -1); -- 2.39.3