mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
mem_cgroup_oom() passes an uninitialized "locked" to memcg1_oom_prepare()
and reads it back in memcg1_oom_finish():
bool locked, ret;
...
if (!memcg1_oom_prepare(memcg, &locked))
return false;
ret = mem_cgroup_out_of_memory(memcg, mask, order);
memcg1_oom_finish(memcg, locked);
This relies on memcg1_oom_prepare() setting *locked whenever it returns
true. The CONFIG_MEMCG_V1=y version does, but the stub used when
CONFIG_MEMCG_V1=n returns true without touching *locked, so
memcg1_oom_finish() consumes an uninitialized value. On a memcg OOM this
is reported by UBSAN:
UBSAN: invalid-load in mm/memcontrol.c:1932:27
load of value 0 is not a valid value for type 'bool' (aka '_Bool')
Initialize *locked to false in the stub; with cgroup v1 compiled out there
is no OOM lock to take.
Link: https://lore.kernel.org/20260716-memcg-oom-uninit-locked-v2-1-63631d878eb4@debian.org
Fixes: e93d4166b4 ("mm: memcg: put cgroup v1-specific code under a config option")
Signed-off-by: Breno Leitao <leitao@debian.org>
Reviewed-by: Joshua Hahn <joshua.hahnjy@gmail.com>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Reviewed-by: SeongJae Park <sj@kernel.org>
Acked-by: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
136 lines
4.7 KiB
C
136 lines
4.7 KiB
C
/* SPDX-License-Identifier: GPL-2.0-or-later */
|
|
|
|
#ifndef __MM_MEMCONTROL_V1_H
|
|
#define __MM_MEMCONTROL_V1_H
|
|
|
|
#include <linux/cgroup-defs.h>
|
|
|
|
/* Cgroup v1 and v2 common declarations */
|
|
|
|
/*
|
|
* Iteration constructs for visiting all cgroups (under a tree). If
|
|
* loops are exited prematurely (break), mem_cgroup_iter_break() must
|
|
* be used for reference counting.
|
|
*/
|
|
#define for_each_mem_cgroup_tree(iter, root) \
|
|
for (iter = mem_cgroup_iter(root, NULL, NULL); \
|
|
iter != NULL; \
|
|
iter = mem_cgroup_iter(root, iter, NULL))
|
|
|
|
#define for_each_mem_cgroup(iter) \
|
|
for (iter = mem_cgroup_iter(NULL, NULL, NULL); \
|
|
iter != NULL; \
|
|
iter = mem_cgroup_iter(NULL, iter, NULL))
|
|
|
|
void drain_all_stock(struct mem_cgroup *root_memcg);
|
|
|
|
unsigned long memcg_events(struct mem_cgroup *memcg, int event);
|
|
int memory_stat_show(struct seq_file *m, void *v);
|
|
|
|
struct mem_cgroup *mem_cgroup_private_id_get_online(struct mem_cgroup *memcg,
|
|
unsigned int n);
|
|
|
|
/* Cgroup v1-specific declarations */
|
|
#ifdef CONFIG_MEMCG_V1
|
|
|
|
/* Whether legacy memory+swap accounting is active */
|
|
static inline bool do_memsw_account(void)
|
|
{
|
|
return !cgroup_subsys_on_dfl(memory_cgrp_subsys);
|
|
}
|
|
|
|
unsigned long memcg_events_local(struct mem_cgroup *memcg, int event);
|
|
unsigned long memcg_page_state_local(struct mem_cgroup *memcg, int idx);
|
|
unsigned long memcg_page_state_local_output(struct mem_cgroup *memcg, int item);
|
|
bool memcg1_alloc_events(struct mem_cgroup *memcg);
|
|
void memcg1_free_events(struct mem_cgroup *memcg);
|
|
|
|
void memcg1_memcg_init(struct mem_cgroup *memcg);
|
|
void memcg1_remove_from_trees(struct mem_cgroup *memcg);
|
|
|
|
static inline void memcg1_soft_limit_reset(struct mem_cgroup *memcg)
|
|
{
|
|
WRITE_ONCE(memcg->soft_limit, PAGE_COUNTER_MAX);
|
|
}
|
|
|
|
struct cgroup_taskset;
|
|
void memcg1_css_offline(struct mem_cgroup *memcg);
|
|
|
|
/* for encoding cft->private value on file */
|
|
enum res_type {
|
|
_MEM,
|
|
_MEMSWAP,
|
|
_KMEM,
|
|
_TCP,
|
|
};
|
|
|
|
bool memcg1_oom_prepare(struct mem_cgroup *memcg, bool *locked);
|
|
void memcg1_oom_finish(struct mem_cgroup *memcg, bool locked);
|
|
void memcg1_oom_recover(struct mem_cgroup *memcg);
|
|
|
|
void memcg1_commit_charge(struct folio *folio, struct mem_cgroup *memcg);
|
|
void memcg1_uncharge_batch(struct mem_cgroup *memcg, unsigned long pgpgout,
|
|
unsigned long nr_memory, int nid);
|
|
|
|
void memcg1_stat_format(struct mem_cgroup *memcg, struct seq_buf *s);
|
|
void reparent_memcg1_state_local(struct mem_cgroup *memcg, struct mem_cgroup *parent);
|
|
void reparent_memcg1_lruvec_state_local(struct mem_cgroup *memcg, struct mem_cgroup *parent);
|
|
|
|
void reparent_memcg_state_local(struct mem_cgroup *memcg,
|
|
struct mem_cgroup *parent, int idx);
|
|
void reparent_memcg_lruvec_state_local(struct mem_cgroup *memcg,
|
|
struct mem_cgroup *parent, int idx);
|
|
|
|
void memcg1_account_kmem(struct mem_cgroup *memcg, int nr_pages);
|
|
static inline bool memcg1_tcpmem_active(struct mem_cgroup *memcg)
|
|
{
|
|
return memcg->tcpmem_active;
|
|
}
|
|
bool memcg1_charge_skmem(struct mem_cgroup *memcg, unsigned int nr_pages,
|
|
gfp_t gfp_mask);
|
|
static inline void memcg1_uncharge_skmem(struct mem_cgroup *memcg, unsigned int nr_pages)
|
|
{
|
|
page_counter_uncharge(&memcg->tcpmem, nr_pages);
|
|
}
|
|
|
|
extern struct cftype memsw_files[];
|
|
extern struct cftype mem_cgroup_legacy_files[];
|
|
|
|
#else /* CONFIG_MEMCG_V1 */
|
|
|
|
static inline bool do_memsw_account(void) { return false; }
|
|
static inline bool memcg1_alloc_events(struct mem_cgroup *memcg) { return true; }
|
|
static inline void memcg1_free_events(struct mem_cgroup *memcg) {}
|
|
|
|
static inline void memcg1_memcg_init(struct mem_cgroup *memcg) {}
|
|
static inline void memcg1_remove_from_trees(struct mem_cgroup *memcg) {}
|
|
static inline void memcg1_soft_limit_reset(struct mem_cgroup *memcg) {}
|
|
static inline void memcg1_css_offline(struct mem_cgroup *memcg) {}
|
|
|
|
static inline bool memcg1_oom_prepare(struct mem_cgroup *memcg, bool *locked)
|
|
{
|
|
*locked = false;
|
|
return true;
|
|
}
|
|
static inline void memcg1_oom_finish(struct mem_cgroup *memcg, bool locked) {}
|
|
static inline void memcg1_oom_recover(struct mem_cgroup *memcg) {}
|
|
|
|
static inline void memcg1_commit_charge(struct folio *folio,
|
|
struct mem_cgroup *memcg) {}
|
|
|
|
static inline void memcg1_uncharge_batch(struct mem_cgroup *memcg,
|
|
unsigned long pgpgout,
|
|
unsigned long nr_memory, int nid) {}
|
|
|
|
static inline void memcg1_stat_format(struct mem_cgroup *memcg, struct seq_buf *s) {}
|
|
|
|
static inline void memcg1_account_kmem(struct mem_cgroup *memcg, int nr_pages) {}
|
|
static inline bool memcg1_tcpmem_active(struct mem_cgroup *memcg) { return false; }
|
|
static inline bool memcg1_charge_skmem(struct mem_cgroup *memcg, unsigned int nr_pages,
|
|
gfp_t gfp_mask) { return true; }
|
|
static inline void memcg1_uncharge_skmem(struct mem_cgroup *memcg, unsigned int nr_pages) {}
|
|
|
|
#endif /* CONFIG_MEMCG_V1 */
|
|
|
|
#endif /* __MM_MEMCONTROL_V1_H */
|