Path: csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod From: Michal Hocko Newsgroups: linux.kernel Subject: Re: [PATCH -mm v2 3/3] mm/oom_kill: fix the wrong task->mm == mm checks in oom_kill_process() Date: Thu, 01 Oct 2015 15:00:02 +0200 Message-ID: References: X-Original-To: Oleg Nesterov X-Google-Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=date:from:to:cc:subject:message-id:references:mime-version :content-type:content-disposition:in-reply-to:user-agent; bh=Qn9IvR3yJOl7c+RnO8ljW9GwkjXIjz8H5KTz7Txjmu0=; b=PhlteStMdYuZl+5a9KUT1e31PuHaRjiECAMTh10QOH9r3MZSy3MeWdaLkFVXMSl46D csd2UtVc9wHX0YGvVUTgi2/ZeQbL83IkTCBm8ugkkSzFWz+xRYnoWc/nbFgkOjNTfCBU dQuAkkhHfKZlsCpp67OKX7+U1uEXF5bDBf2aekMD8v368YlMclEFq7jhPwnfryfTCivc +QVXoL7sKmK5T3eU2wTUzu9820f9fUAbi6kZ0uHLHL/K9uok2/DBqfZyc6PPYtpKxPVK ZebtEWB974pMe8vm5GVi4/MgVjp2NbLEP3HOfJPdFwMTdnveN86hoLrDUeUlOHjCknda kNKg== X-Received: by 10.180.106.66 with SMTP id gs2mr3310925wib.14.1443704209488; Thu, 01 Oct 2015 05:56:49 -0700 (PDT) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.23 (2014-03-12) Sender: robomod@news.nic.it List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Approved: robomod@news.nic.it Lines: 70 Organization: linux.* mail to news gateway X-Original-Cc: Andrew Morton , David Rientjes , Kyle Walker , Stanislav Kozina , Tetsuo Handa , linux-kernel@vger.kernel.org X-Original-Date: Thu, 1 Oct 2015 14:56:48 +0200 X-Original-Message-ID: <20151001125647.GE24077@dhcp22.suse.cz> X-Original-References: <20150930182341.GA15047@redhat.com> <20150930182411.GA15250@redhat.com> X-Original-Sender: linux-kernel-owner@vger.kernel.org Xref: csiph.com linux.kernel:1237403 On Wed 30-09-15 20:24:11, Oleg Nesterov wrote: > Both "child->mm == mm" and "p->mm != mm" checks in oom_kill_process() > are wrong. task->mm can be NULL if the task is the exited group leader. > This means in particular that "kill sharing same memory" loop can miss > a process with a zombie leader which uses the same ->mm. > > Note: the process_has_mm(child, p->mm) check is still not 100% correct, > p->mm can be NULL too. This is minor, but probably deserves a fix or a > comment anyway. > > Signed-off-by: Oleg Nesterov Acked-by: Michal Hocko > --- > mm/oom_kill.c | 16 ++++++++++++++-- > 1 file changed, 14 insertions(+), 2 deletions(-) > > diff --git a/mm/oom_kill.c b/mm/oom_kill.c > index c189ee5..034d219 100644 > --- a/mm/oom_kill.c > +++ b/mm/oom_kill.c > @@ -483,6 +483,18 @@ void oom_killer_enable(void) > oom_killer_disabled = false; > } > > +static bool process_shares_mm(struct task_struct *p, struct mm_struct *mm) > +{ > + struct task_struct *t; > + > + for_each_thread(p, t) { > + struct mm_struct *t_mm = READ_ONCE(t->mm); > + if (t_mm) > + return t_mm == mm; > + } > + return false; > +} > + > #define K(x) ((x) << (PAGE_SHIFT-10)) > /* > * Must be called while holding a reference to p, which will be released upon > @@ -530,7 +542,7 @@ void oom_kill_process(struct oom_control *oc, struct task_struct *p, > list_for_each_entry(child, &t->children, sibling) { > unsigned int child_points; > > - if (child->mm == p->mm) > + if (process_shares_mm(child, p->mm)) > continue; > /* > * oom_badness() returns 0 if the thread is unkillable > @@ -584,7 +596,7 @@ void oom_kill_process(struct oom_control *oc, struct task_struct *p, > */ > rcu_read_lock(); > for_each_process(p) { > - if (p->mm != mm) > + if (!process_shares_mm(p, mm)) > continue; > if (same_thread_group(p, victim)) > continue; > -- > 2.4.3 -- Michal Hocko SUSE Labs -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/