From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755589AbdBGWeJ (ORCPT ); Tue, 7 Feb 2017 17:34:09 -0500 Received: from Galois.linutronix.de ([146.0.238.70]:52445 "EHLO Galois.linutronix.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752108AbdBGWeI (ORCPT ); Tue, 7 Feb 2017 17:34:08 -0500 Date: Tue, 7 Feb 2017 22:53:01 +0100 (CET) From: Thomas Gleixner To: Dmitry Vyukov cc: Vlastimil Babka , Tejun Heo , Christoph Lameter , "linux-mm@kvack.org" , LKML , Ingo Molnar , Peter Zijlstra , syzkaller , Mel Gorman , Michal Hocko , Andrew Morton Subject: Re: mm: deadlock between get_online_cpus/pcpu_alloc In-Reply-To: Message-ID: References: User-Agent: Alpine 2.20 (DEB 67 2015-01-07) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, 6 Feb 2017, Dmitry Vyukov wrote: > On Mon, Jan 30, 2017 at 4:48 PM, Dmitry Vyukov wrote: > Unfortunately it does not seem to help. > Fuzzer now runs on 510948533b059f4f5033464f9f4a0c32d4ab0c08 of > mmotm/auto-latest > (git://git.kernel.org/pub/scm/linux/kernel/git/mhocko/mm.git): > > commit 510948533b059f4f5033464f9f4a0c32d4ab0c08 > Date: Thu Feb 2 10:08:47 2017 +0100 > mmotm: userfaultfd-non-cooperative-add-event-for-memory-unmaps-fix > > The commit you referenced is already there: > > commit 806b158031ca0b4714e775898396529a758ebc2c > Date: Thu Feb 2 08:53:16 2017 +0100 > mm, page_alloc: use static global work_struct for draining per-cpu pages > Chain exists of: > Possible unsafe locking scenario: > > CPU0 CPU1 > ---- ---- > lock(pcpu_alloc_mutex); > lock(cpu_hotplug.lock); > lock(pcpu_alloc_mutex); > lock(cpu_hotplug.dep_map); And that's exactly what happens: cpu_up() alloc_percpu() lock(hotplug.lock) lock(&pcpu_alloc_mutex) .. alloc_percpu() drain_all_pages() lock(&pcpu_alloc_mutex) get_online_cpus() lock(hotplug.lock) Classic deadlock, i.e. you _cannot_ call get_online_cpus() while holding pcpu_alloc_mutex. Alternatively you can forbid to do per cpu alloc/free while holding hotplug.lock. I doubt that this will make people happy :) Thanks, tglx