mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: Kernel BUG at page_alloc.c:91! (2.4.19)
@ 2002-09-03 17:16 Heiko Carstens
  2002-09-03 17:31 ` Daniel Phillips
  0 siblings, 1 reply; 6+ messages in thread
From: Heiko Carstens @ 2002-09-03 17:16 UTC (permalink / raw)
  To: Daniel Phillips; +Cc: linux-kernel

Hi,

>> Thanks for the patch but unfortunately it doesn't change the behaviour 
at
>> all. This BUG is still 100% reproducible by just having 1 process which
>> allocates memory chunks of 256KB and after each allocation writes to 
each
>> of the pages in order to make them dirty.
>Um, no smp --> no free race anyway.  But try the following instead, to
>start narrowing down the possibilities:

Still the same BUG in __free_pages_ok happens, or in other words both of 
your
checks didn't catch the error...
Any other ideas?

Regards,
Heiko


^ permalink raw reply	[flat|nested] 6+ messages in thread
* Re: Kernel BUG at page_alloc.c:91! (2.4.19)
@ 2002-09-02 12:54 Heiko Carstens
  2002-09-02 19:35 ` Daniel Phillips
  0 siblings, 1 reply; 6+ messages in thread
From: Heiko Carstens @ 2002-09-02 12:54 UTC (permalink / raw)
  To: Daniel Phillips; +Cc: linux-kernel

Hi Daniel,

>> Looks to me that this function itself has a bug: after the drop_pte 
label
>> it is checked if the current page has a mapping. If this is true there 
is
>> ...
>Chances are, you've run into the subtle double-free race I've been 
working
>on for the last few days.  Would you like to try this patch as see if it
>makes a difference?
>http://nl.linux.org/~phillips/patches/lru.race-2.4.19

Thanks for the patch but unfortunately it doesn't change the behaviour at
all. This BUG is still 100% reproducible by just having 1 process which
allocates memory chunks of 256KB and after each allocation writes to each
of the pages in order to make them dirty.

regards,
Heiko


^ permalink raw reply	[flat|nested] 6+ messages in thread
* Kernel BUG at page_alloc.c:91! (2.4.19)
@ 2002-09-02  8:26 Heiko Carstens
  2002-09-02 10:44 ` Daniel Phillips
  0 siblings, 1 reply; 6+ messages in thread
From: Heiko Carstens @ 2002-09-02  8:26 UTC (permalink / raw)
  To: linux-kernel

Hi,

I experienced several kernel BUGs while running the linux kernel version 
2.4.19
on a single cpu s390 machine with 2GB RAM and 256MB of swap space. All of 
these
BUGs happened at page_alloc.c in the function __free_pages_ok. In that 
function
there is the check
if (page->mapping) BUG();
which is exactly what happened. A page had a mapping but __free_pages_ok() 
got
called anyway. Looking at the backtrace I was able to see that this 
specific
BUG() occurred when page_cache_release() was called from the function
try_to_swap_out().

Looks to me that this function itself has a bug: after the drop_pte label 
it is
checked if the current page has a mapping. If this is true there is a jump 
to
the drop_pte label, where without any further checking 
page_cache_release() gets
called which will result in the above described BUG() if page_count(page) 
== 1.

Here is the output of the kernel (I removed all inline statements in 
vmscan.c):

kernel BUG at page_alloc.c:91! 
illegal operation: 0001 
CPU:    0    Not tainted 
           80042730 00000001 013c578c 6ce26e00 
           00000020 575a0001 6ce26e00 00000000 
           013c578c 80042388 80042730 6c7e13c8 
           00000000 00000000 00000000 00000000 
           00000000 00000000 00000000 00000000 
           00000000 00000000 00000000 00000000 
Call Trace: [<000430d2>] [<00040eec>] [<00041088>] [<00041132>] 
            [<000411da>] [<000412cc>] [<000413b0>] [<00041646>] 
Warning (Oops_read): Code line not seen, dumping what data is available

Trace; 000430d2 <__free_pages+52/58>
Trace; 00040eec <try_to_swap_out+224/284>
Trace; 00041088 <swap_out_pmd+13c/178>
Trace; 00041132 <swap_out_pgd+6e/a0>
Trace; 000411da <swap_out_vma+76/bc>
Trace; 000412cc <swap_out_mm+ac/d0>
Trace; 000413b0 <swap_out+c0/150>
Trace; 00041646 <shrink_cache+206/5c8>

regards,
Heiko


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2002-09-03 17:24 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2002-09-03 17:16 Kernel BUG at page_alloc.c:91! (2.4.19) Heiko Carstens
2002-09-03 17:31 ` Daniel Phillips
  -- strict thread matches above, loose matches on Subject: below --
2002-09-02 12:54 Heiko Carstens
2002-09-02 19:35 ` Daniel Phillips
2002-09-02  8:26 Heiko Carstens
2002-09-02 10:44 ` Daniel Phillips

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®