From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from canpmsgout12.his.huawei.com (canpmsgout12.his.huawei.com [113.46.200.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F04F637FF43 for ; Tue, 24 Feb 2026 12:58:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.227 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771937919; cv=none; b=Ma3soMRT+fsGdRjA8AOcbyDUmAKmoKOLTxSfmGnN5JOCGupqhDbOW5x0Ir1CgrHlxE5rafIo7Hvqh7hR6HP41Wjg+eFK/lywlzSkU23QWE7tbIFzziEH+gDxpyQP9r7NaiU/NE+MPtJ/0YdJ3Nd+1w62g6zLEcJQGdhMFP+Lb8c= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771937919; c=relaxed/simple; bh=mLlKDOwDH8+xB/Qxx/mYYhogwv56FYyWX9tmP+4x3Wc=; h=Message-ID:Date:MIME-Version:Subject:To:CC:References:From: In-Reply-To:Content-Type; b=i9iwWTGZWIn12sZZSHm9K3ECJhDWddN8Qtb/OqCxOKq8SBfw6Sqz/NXiFuaRip/JC2pTNM8HaEEBYdjKaPS1TM67TJH7BMSEsRWwJA5qvj1A3/HRdDP0j4Km2tF80dbDrJ8iHwodza94LcL0THTWTT+tgYXLrYl2g4uGA1xI1E0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=0Dri22NS; arc=none smtp.client-ip=113.46.200.227 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="0Dri22NS" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=Fue2tVU858LZ38elo14sVk6gqI1+tCuiftRGjcHag5M=; b=0Dri22NSRpnz5eN6q+1zdlhweMT9s4WRiPZ+j7U3LnNHQbyH8uZMWvPcuFL8IJQPUtAn1joPc Abh8ITRNQNBs+9wdYrIk/vvx94LLo7DY90heyih62XOOVHGvJ1+CrETObVn50aAnXaKFuiGNYbB Kvp8fs8gXTVCEl2lU+Fross= Received: from mail.maildlp.com (unknown [172.19.163.163]) by canpmsgout12.his.huawei.com (SkyGuard) with ESMTPS id 4fKyMh4WzfznTWL; Tue, 24 Feb 2026 20:53:52 +0800 (CST) Received: from dggpemf100008.china.huawei.com (unknown [7.185.36.138]) by mail.maildlp.com (Postfix) with ESMTPS id D068140565; Tue, 24 Feb 2026 20:58:33 +0800 (CST) Received: from [10.174.177.243] (10.174.177.243) by dggpemf100008.china.huawei.com (7.185.36.138) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Tue, 24 Feb 2026 20:58:32 +0800 Message-ID: <64357180-b91a-4319-bd0f-5f09e38cebdb@huawei.com> Date: Tue, 24 Feb 2026 20:58:30 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: mm: Regression with v7.0-rc1 on RISC-V To: Ron Economos , , , CC: , , , , , , , , , , , Mark Brown , , References: <1b17c38f-30d3-4bb4-a7e1-e74b19ada885@w6rz.net> Content-Language: en-US From: Kefeng Wang In-Reply-To: <1b17c38f-30d3-4bb4-a7e1-e74b19ada885@w6rz.net> Content-Type: text/plain; charset="UTF-8"; format=flowed Content-Transfer-Encoding: 8bit X-ClientProxiedBy: kwepems200002.china.huawei.com (7.221.188.68) To dggpemf100008.china.huawei.com (7.185.36.138) On 2026/2/24 16:37, Ron Economos wrote: > I'm getting a BUG dump during shutdown with Linux v7.0-rc1 on RISC-V. > > [  OK  ] Reached target shutdown.target - System Shutdown. > [  OK  ] Reached target final.target - Late Shutdown Services. > [  OK  ] Finished systemd-reboot.service - System Reboot. > [  OK  ] Reached target reboot.target - System Reboot. > [  173.985249] BUG: Bad page state in process shutdown  pfn:f8850 > [  173.985311] page: refcount:1 mapcount:0 mapping:0000000000000000 > index:0x0 pfn:0xf8850 > [  173.985336] flags: 0xffff80000000000(node=0|zone=0| > lastcpupid=0x1ffff) CMA > [  173.985365] raw: 0ffff80000000000 ffffffc501e21448 ffffffc600f2ae88 > 0000000000000000 > [  173.985386] raw: 0000000000000000 0000000000000000 00000001ffffffff > 0000000000000000 > [  173.985403] page dumped because: nonzero _refcount The refcount set to 1 when cma_alloc() by set_page_refcounted(), and it will be dec to 0 in cma_release() by put_page_testzero(), there may be a problem somewhere else? Could you enable CONFIG_DEBUG_VM and CONFIG_DEBUG_PAGE_REF, and try to track down page reference manipulation by tracepoint? or for CMA-related pages, introduce explicit printk both increments and decrements of the page reference count to identify the root cause of the issue.