From nobody Fri Jul 24 21:27:06 2026 Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 50923459AC8 for ; Fri, 24 Jul 2026 19:52:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784922775; cv=none; b=Ox/Oa0rur2N4v5BmsDrfzwlj1aiyDQfkwsCyAum3dfacrOG003PIKVghGkoTqTeTNo+Ig8bJ7oyZCRkrxfQAkasQ7p5UqL6cDBMBUb1L+v9YHjp8hi8ON+YzMJ3h8ud6U/Z/aeXOUiWMi/rhhu+Mzp8il+fzMCcnJiqY5E8++Jw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784922775; c=relaxed/simple; bh=YUytcI+m4jOaLSW6byh3vqrNZyJkPkPMPzL2oPZDyG0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=agZr5VOyZAUsUI/OcHvxM6gU29Y7K7jUphUKdITYFd3X0/VWEqygpHhYvEkKfzmLmkocgj8TA0JqOX/LiJzMBc53fv5Sif9Pm31B8eIOxDCYgYJjuk8UKjZ8G1nUc07dLfZwLbeDGmtes6J7vlWkGo8YZYPrAfgh5gDaa+yVseA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=readmodwrite.com; spf=none smtp.mailfrom=readmodwrite.com; dkim=pass (2048-bit key) header.d=readmodwrite-com.20251104.gappssmtp.com header.i=@readmodwrite-com.20251104.gappssmtp.com header.b=i/s5DoQk; arc=none smtp.client-ip=209.85.221.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=readmodwrite.com Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=readmodwrite.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=readmodwrite-com.20251104.gappssmtp.com header.i=@readmodwrite-com.20251104.gappssmtp.com header.b="i/s5DoQk" Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-47362928f65so768723f8f.2 for ; Fri, 24 Jul 2026 12:52:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=readmodwrite-com.20251104.gappssmtp.com; s=20251104; t=1784922771; x=1785527571; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=NC+t0PVzM1V3bCRy8dl7R5jb/yivKWdDFY9rHZ/PNfY=; b=i/s5DoQkz2nvj42iNsKDSouT6CHxJU75FI4V7MTG+qguTV4iZ5YiAEcJmeo4zjsGbZ yMytC0TsJDoT4K/hci0unVU305ryMDAgqaEYvAZlveeF2a5ALF+IFbeV1+E9FUSX9IQw u+N/YdisuT/+E+wwG0aIOfslMk/Q8coDC70er405R2oAz++IFece+7iw2SjCp4nguwe9 eeSjbKHsHQNr9o8EW0SJ9qPjw9WUemP34owhlS3tcsRF9pz1urBJRQ1alh28G7S1GFin b4DnTVHMRZFGvj+IXUOvk9EBHsO69p0iXOd3F22P8hWcizbdKHJcL6wDuhT7Rh7H4CPg EpiQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784922771; x=1785527571; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NC+t0PVzM1V3bCRy8dl7R5jb/yivKWdDFY9rHZ/PNfY=; b=m96c8MLehCbG6AK7/LfHjZc/I57QLxCVR6SSkW/mVRDXQTYJaPH+pZLEjfbmX49kdM 88DD0tLSZ8s5xCHcy7lp/78eTdJoJ5ksR3KLFDu35zlbGp+1L9y9MzJcY7Wf79GCssXM UoyvgCbiyHFu/flNk/kcnz30tYkkvxy12xEyeyoFe7rB6FLLjCQbQrxhwdU9xptTboRr 4AxqTxqSZUVGgUvy0AtxJPSHIyEJG3Pvx3IJ/AtFiW0k+23U5M7dNvHeQYYROZ1nMOpO dFTW8Z7nHW/6yyEeCxjMRSZ+UeP9pZiX6hlHgdokaZmpZ7KFqV79LZCQHnNdhtiya36N fqZQ== X-Forwarded-Encrypted: i=1; AHgh+Rp80th3+M2n1vn9Z/CrERgRK3g3rnV6K6iLbEfsMrjn0+EY4Xyb9+DPDlhxQCID6c9E9+QtKInVqq33KdM=@vger.kernel.org X-Gm-Message-State: AOJu0YwQJMGqK5NVK9iEdxZsu6zgD19+HzWT27m3pDeH7JiyXGLVxc0j jZxFWhUVSgiwh4uFHOPRSo8iAY65whxBer4Ig9PpK8Fbp4fjbg3kVypg4OJ/p+GetxQ= X-Gm-Gg: AR+sD10HM90qk6WbEA/XyIoRsCnkpyZoKy7LKi/G0jY/uvLKycnerDMflugIUQPQ9La Iyijnz5DuSHOs6wxD3jtSBFEVwu0QKoRhCQYurIuY6BszcMYDR8iyZRCdPikir1iXQWCams7G2b Rq6phh8h5pWi2bY/5lqnBFsxcad6IUDWjbVpPleeMusbhJaNqRDl/mwHaagcIpyVlng6RY5LefT l7DSHY2k5LJNr6KB6ChRCC3VicfDo5FgYYdllmqFRWL62tUjvawgU1P0c/YtdIZvYttFWj+CmlW G0hjqYHRotgi0D/BzfFtnnGG+elqKrKFeWQxEekJUg4VP8cyjNn4iHxMOzk5KosU0C9809Zk41r kEvTo/98Nt5zLr6QWSmTwjtnIvbDEhyzdu3Gu9QPquanw1mhISJ5dscZTw+zIIXQlsAbSWJr5yv 1azi3z X-Received: by 2002:a05:6000:25c3:b0:47f:6fd1:d399 with SMTP id ffacd0b85a97d-47f8d76ebd3mr11047801f8f.51.1784922771364; Fri, 24 Jul 2026 12:52:51 -0700 (PDT) Received: from matt-Precision-5490.. ([2a09:bac6:37a8:294b::41d:2d]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f85c6287csm26605268f8f.25.2026.07.24.12.52.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 24 Jul 2026 12:52:50 -0700 (PDT) From: Matt Fleming To: Andrew Morton Cc: David Hildenbrand , Lorenzo Stoakes , Zi Yan , Baolin Wang , "Liam R . Howlett" , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Lance Yang , Dave Chinner , Qi Zheng , Roman Gushchin , Muchun Song , Kairui Song , Shakeel Butt , Matthew Wilcox , syzbot+c5b060ce82921a2fd500@syzkaller.appspotmail.com, stable@vger.kernel.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, kernel-team@cloudflare.com, Matt Fleming Subject: [PATCH] mm/huge_memory: Initialise workingset state before folio split Date: Fri, 24 Jul 2026 20:52:44 +0100 Message-ID: <20260724195244.3715130-1-matt@readmodwrite.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Matt Fleming xas_try_split() adds __GFP_ACCOUNT for page-cache xa_nodes, but __folio_split() leaves the xa_state's xa_lru unset. That lets a live, memcg-charged xa_node exist without being linked into the mapping's shadow_nodes list_lru; when reclaim later walks the list_lru it trips VM_WARN_ON(!css_is_dying()). Use mapping_set_update() to install both the workingset update callback and the shadow_nodes list_lru on the xa_state. Reported-by: syzbot+c5b060ce82921a2fd500@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3Dc5b060ce82921a2fd500 Fixes: 58729c04cf10 ("mm/huge_memory: add buddy allocator like (non-uniform= ) folio_split()") Cc: stable@vger.kernel.org Signed-off-by: Matt Fleming --- mm/huge_memory.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/mm/huge_memory.c b/mm/huge_memory.c index b5d1e9d4463d..12d0e0b14e83 100644 --- a/mm/huge_memory.c +++ b/mm/huge_memory.c @@ -4033,7 +4033,8 @@ static int __folio_split(struct folio *folio, unsigne= d int new_order, gfp_t gfp; =20 mapping =3D folio->mapping; - min_order =3D mapping_min_folio_order(folio->mapping); + mapping_set_update(&xas, mapping); + min_order =3D mapping_min_folio_order(mapping); if (new_order < min_order) { ret =3D -EINVAL; goto out; --=20 2.43.0