The patch titled Subject: mm-page_alloc-fix-allocation-imbalances-from-speculative-cache-lookup has been added to the -mm tree. Its filename is mm-page_alloc-fix-allocation-imbalances-from-speculative-cache-lookup.patch This patch should soon appear at https://ozlabs.org/~akpm/mmots/broken-out/mm-page_alloc-fix-allocation-imbalances-from-speculative-cache-lookup.patch and later at https://ozlabs.org/~akpm/mmotm/broken-out/mm-page_alloc-fix-allocation-imbalances-from-speculative-cache-lookup.patch Before you just go and hit "reply", please: a) Consider who else should be cc'ed b) Prefer to cc a suitable mailing list as well c) Ideally: find the original patch on the mailing list and do a reply-to-all to that, adding suitable additional cc's *** Remember to use Documentation/process/submit-checklist.rst when testing your code *** The -mm tree is included into linux-next and is updated there every 3-4 working days ------------------------------------------------------ From: Johannes Weiner <hannes@xxxxxxxxxxx> Subject: mm-page_alloc-fix-allocation-imbalances-from-speculative-cache-lookup fixes suggested by Hugh Link: https://lkml.kernel.org/r/YFo7SOni0s0TbXUm@xxxxxxxxxxx Fixes: e320d3012d25 mm/page_alloc.c: fix freeing non-compound pages Signed-off-by: Johannes Weiner <hannes@xxxxxxxxxxx> Reported-by: Hugh Dickins <hughd@xxxxxxxxxx> Reported-by: Matthew Wilcox <willy@xxxxxxxxxxxxx> Acked-by: Hugh Dickins <hughd@xxxxxxxxxx> Reviewed-by: Matthew Wilcox (Oracle) <willy@xxxxxxxxxxxxx> Acked-by: Hugh Dickins <hughd@xxxxxxxxxx> Acked-by: Michal Hocko <mhocko@xxxxxxxx> Cc: Zhou Guanghui <zhouguanghui1@xxxxxxxxxx> Cc: Zi Yan <ziy@xxxxxxxxxx> Cc: Shakeel Butt <shakeelb@xxxxxxxxxx> Cc: Roman Gushchin <guro@xxxxxx> Signed-off-by: Andrew Morton <akpm@xxxxxxxxxxxxxxxxxxxx> --- mm/page_alloc.c | 26 +++++++++++++++++--------- 1 file changed, 17 insertions(+), 9 deletions(-) --- a/mm/page_alloc.c~mm-page_alloc-fix-allocation-imbalances-from-speculative-cache-lookup +++ a/mm/page_alloc.c @@ -5083,6 +5083,8 @@ static inline void free_the_page(struct */ void __free_pages(struct page *page, unsigned int order) { + bool compound = PageHead(page); + /* * Drop the base reference from __alloc_pages and free. In * case there is an outstanding speculative reference, from @@ -5094,18 +5096,24 @@ void __free_pages(struct page *page, uns } /* - * The speculative reference will put and free the page. + * Ok, the speculative reference will put and free the page. + * + * - If this was an order-0 page, we're done. + * + * - If the page was compound, the other side will free the + * entire page and we're done here as well. Just note that + * freeing clears PG_head, so it can only be read reliably + * before the put_page_testzero(). * - * However, if the speculation was into a higher-order page - * chunk that isn't marked compound, the other side will know - * nothing about our buddy pages and only free the order-0 - * page at the start of our chunk! We must split off and free - * the buddy pages here. + * - If the page was of higher order but NOT marked compound, + * the other side will know nothing about our buddy pages + * and only free the order-0 page at the start of our block. + * We must split off and free the buddy pages here. * - * The buddy pages aren't individually refcounted, so they - * can't have any pending speculative references themselves. + * The buddy pages aren't individually refcounted, so they + * can't have any pending speculative references themselves. */ - if (!PageHead(page) && order > 0) { + if (order > 0 && !compound) { split_page_memcg(page, 1 << order); while (order-- > 0) free_the_page(page + (1 << order), order); _ Patches currently in -mm which might be from hannes@xxxxxxxxxxx are mm-page_alloc-fix-memcg-accounting-leak-in-speculative-cache-lookup.patch mm-page_alloc-fix-allocation-imbalances-from-speculative-cache-lookup.patch mm-page-writeback-simplify-memcg-handling-in-test_clear_page_writeback.patch mm-memcontrol-fix-cpuhotplug-statistics-flushing.patch mm-memcontrol-kill-mem_cgroup_nodeinfo.patch mm-memcontrol-privatize-memcg_page_state-query-functions.patch cgroup-rstat-support-cgroup1.patch cgroup-rstat-punt-root-level-optimization-to-individual-controllers.patch mm-memcontrol-switch-to-rstat.patch mm-memcontrol-switch-to-rstat-fix-2.patch mm-memcontrol-consolidate-lruvec-stat-flushing.patch kselftests-cgroup-update-kmem-test-for-new-vmstat-implementation.patch