42ef73fe13
On -rt we were seeing spurious bad page states like: Bad page state in process 'firefox' page:c1bc2380 flags:0x40000000 mapping:c1bc2390 mapcount:0 count:0 Trying to fix it up, but a reboot is needed Backtrace: Pid: 503, comm: firefox Not tainted 2.6.26.8-rt13 #3 [<c043d0f3>] ? printk+0x14/0x19 [<c0272d4e>] bad_page+0x4e/0x79 [<c0273831>] free_hot_cold_page+0x5b/0x1d3 [<c02739f6>] free_hot_page+0xf/0x11 [<c0273a18>] __free_pages+0x20/0x2b [<c027d170>] __pte_alloc+0x87/0x91 [<c027d25e>] handle_mm_fault+0xe4/0x733 [<c043f680>] ? rt_mutex_down_read_trylock+0x57/0x63 [<c043f680>] ? rt_mutex_down_read_trylock+0x57/0x63 [<c0218875>] do_page_fault+0x36f/0x88a This is the case where a concurrent fault already installed the PTE and we get to free the newly allocated one. This is due to pgtable_page_ctor() doing the spin_lock_init(&page->ptl) which is overlaid with the {private, mapping} struct. union { struct { unsigned long private; struct address_space *mapping; }; spinlock_t ptl; struct kmem_cache *slab; struct page *first_page; }; Normally the spinlock is small enough to not stomp on page->mapping, but PREEMPT_RT=y has huge 'spin'locks. But lockdep kernels should also be able to trigger this splat, as the lock tracking code grows the spinlock to cover page->mapping. The obvious fix is calling pgtable_page_dtor() like the regular pte free path __pte_free_tlb() does. It seems all architectures except x86 and nm10300 already do this, and nm10300 doesn't seem to use pgtable_page_ctor(), which suggests it doesn't do SMP or simply doesnt do MMU at all or something. Signed-off-by: Peter Zijlstra <a.p.zijlsta@chello.nl> Signed-off-by: Ingo Molnar <mingo@elte.hu> Cc: <stable@kernel.org> |
||
---|---|---|
.. | ||
bigsmp | ||
es7000 | ||
mach-default | ||
mach-generic | ||
mach-rdc321x | ||
mach-voyager | ||
numaq | ||
summit | ||
uv | ||
visws | ||
xen | ||
a.out-core.h | ||
a.out.h | ||
acpi.h | ||
agp.h | ||
alternative-asm.h | ||
alternative.h | ||
amd_iommu_types.h | ||
amd_iommu.h | ||
apic.h | ||
apicdef.h | ||
arch_hooks.h | ||
asm.h | ||
atomic_32.h | ||
atomic_64.h | ||
atomic.h | ||
auxvec.h | ||
bios_ebda.h | ||
bitops.h | ||
boot.h | ||
bootparam.h | ||
bug.h | ||
bugs.h | ||
byteorder.h | ||
cache.h | ||
cacheflush.h | ||
calgary.h | ||
calling.h | ||
checksum_32.h | ||
checksum_64.h | ||
checksum.h | ||
cmpxchg_32.h | ||
cmpxchg_64.h | ||
cmpxchg.h | ||
compat.h | ||
cpu.h | ||
cpufeature.h | ||
cputime.h | ||
current.h | ||
debugreg.h | ||
delay.h | ||
desc_defs.h | ||
desc.h | ||
device.h | ||
div64.h | ||
dma-mapping.h | ||
dma.h | ||
dmi.h | ||
ds.h | ||
dwarf2.h | ||
e820.h | ||
edac.h | ||
efi.h | ||
elf.h | ||
emergency-restart.h | ||
errno.h | ||
fb.h | ||
fcntl.h | ||
fixmap_32.h | ||
fixmap_64.h | ||
fixmap.h | ||
floppy.h | ||
frame.h | ||
ftrace.h | ||
futex.h | ||
gart.h | ||
genapic_32.h | ||
genapic_64.h | ||
genapic.h | ||
geode.h | ||
gpio.h | ||
hardirq_32.h | ||
hardirq_64.h | ||
hardirq.h | ||
highmem.h | ||
hpet.h | ||
hugetlb.h | ||
hw_irq.h | ||
hypertransport.h | ||
hypervisor.h | ||
i387.h | ||
i8253.h | ||
i8259.h | ||
ia32_unistd.h | ||
ia32.h | ||
idle.h | ||
intel_arch_perfmon.h | ||
io_32.h | ||
io_64.h | ||
io_apic.h | ||
io.h | ||
ioctl.h | ||
ioctls.h | ||
iomap.h | ||
iommu.h | ||
ipcbuf.h | ||
ipi.h | ||
irq_regs_32.h | ||
irq_regs_64.h | ||
irq_regs.h | ||
irq_remapping.h | ||
irq_vectors.h | ||
irq.h | ||
irqflags.h | ||
ist.h | ||
k8.h | ||
Kbuild | ||
kdebug.h | ||
kexec.h | ||
kgdb.h | ||
kmap_types.h | ||
kprobes.h | ||
kvm_host.h | ||
kvm_para.h | ||
kvm_x86_emulate.h | ||
kvm.h | ||
ldt.h | ||
lguest_hcall.h | ||
lguest.h | ||
linkage.h | ||
local.h | ||
math_emu.h | ||
mc146818rtc.h | ||
mca_dma.h | ||
mca.h | ||
mce.h | ||
microcode.h | ||
mman.h | ||
mmconfig.h | ||
mmu_context_32.h | ||
mmu_context_64.h | ||
mmu_context.h | ||
mmu.h | ||
mmx.h | ||
mmzone_32.h | ||
mmzone_64.h | ||
mmzone.h | ||
module.h | ||
mpspec_def.h | ||
mpspec.h | ||
msgbuf.h | ||
msidef.h | ||
msr-index.h | ||
msr.h | ||
mtrr.h | ||
mutex_32.h | ||
mutex_64.h | ||
mutex.h | ||
nmi.h | ||
nops.h | ||
numa_32.h | ||
numa_64.h | ||
numa.h | ||
numaq.h | ||
olpc.h | ||
page_32.h | ||
page_64.h | ||
page.h | ||
param.h | ||
paravirt.h | ||
parport.h | ||
pat.h | ||
pci_32.h | ||
pci_64.h | ||
pci_x86.h | ||
pci-direct.h | ||
pci.h | ||
pda.h | ||
percpu.h | ||
pgalloc.h | ||
pgtable_32.h | ||
pgtable_64.h | ||
pgtable-2level-defs.h | ||
pgtable-2level.h | ||
pgtable-3level-defs.h | ||
pgtable-3level.h | ||
pgtable.h | ||
poll.h | ||
posix_types_32.h | ||
posix_types_64.h | ||
posix_types.h | ||
prctl.h | ||
processor-cyrix.h | ||
processor-flags.h | ||
processor.h | ||
proto.h | ||
ptrace-abi.h | ||
ptrace.h | ||
pvclock-abi.h | ||
pvclock.h | ||
reboot_fixups.h | ||
reboot.h | ||
required-features.h | ||
resource.h | ||
resume-trace.h | ||
rio.h | ||
rtc.h | ||
rwlock.h | ||
rwsem.h | ||
scatterlist.h | ||
seccomp_32.h | ||
seccomp_64.h | ||
seccomp.h | ||
sections.h | ||
segment.h | ||
sembuf.h | ||
serial.h | ||
setup.h | ||
shmbuf.h | ||
shmparam.h | ||
sigcontext32.h | ||
sigcontext.h | ||
sigframe.h | ||
siginfo.h | ||
signal.h | ||
smp.h | ||
socket.h | ||
sockios.h | ||
sparsemem.h | ||
spinlock_types.h | ||
spinlock.h | ||
srat.h | ||
stacktrace.h | ||
stat.h | ||
statfs.h | ||
string_32.h | ||
string_64.h | ||
string.h | ||
suspend_32.h | ||
suspend_64.h | ||
suspend.h | ||
svm.h | ||
swab.h | ||
swiotlb.h | ||
sync_bitops.h | ||
sys_ia32.h | ||
syscall.h | ||
syscalls.h | ||
system_64.h | ||
system.h | ||
tce.h | ||
termbits.h | ||
termios.h | ||
therm_throt.h | ||
thread_info.h | ||
time.h | ||
timer.h | ||
timex.h | ||
tlb.h | ||
tlbflush.h | ||
topology.h | ||
trampoline.h | ||
traps.h | ||
tsc.h | ||
types.h | ||
uaccess_32.h | ||
uaccess_64.h | ||
uaccess.h | ||
ucontext.h | ||
unaligned.h | ||
unistd_32.h | ||
unistd_64.h | ||
unistd.h | ||
user32.h | ||
user_32.h | ||
user_64.h | ||
user.h | ||
vdso.h | ||
vga.h | ||
vgtod.h | ||
vic.h | ||
virtext.h | ||
vm86.h | ||
vmi_time.h | ||
vmi.h | ||
vmware.h | ||
vmx.h | ||
voyager.h | ||
vsyscall.h | ||
xcr.h | ||
xor_32.h | ||
xor_64.h | ||
xor.h | ||
xsave.h |