mm/swapfile.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-)
A corrupt page table hands the same bogus entry to get_swap_device() on
every access to the mapping, and every rejection is logged. One machine
logged 6185620 copies of the same line in a few hours.
swap_dup_entry_direct() prints the same message from the fork path, once
per call: the WARN_ON_ONCE() guarding it warns once, the pr_err() inside
does not.
Rate limit all three prints.
Cc: stable@vger.kernel.org
Fixes: 23b230ba8ac3 ("mm/swap: print bad swap offset entry in get_swap_device")
Reviewed-by: Barry Song <baohua@kernel.org>
Reviewed-by: Nhat Pham <nphamcs@gmail.com>
Acked-by: Kairui Song <kasong@tencent.com>
Signed-off-by: Breno Leitao <leitao@debian.org>
---
mm/swapfile.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/mm/swapfile.c b/mm/swapfile.c
index dacef34a3ed7a..53bf01d5f7f11 100644
--- a/mm/swapfile.c
+++ b/mm/swapfile.c
@@ -1899,11 +1899,11 @@ struct swap_info_struct *get_swap_device(swp_entry_t entry)
return si;
bad_nofile:
- pr_err("%s: %s%08lx\n", __func__, Bad_file, entry.val);
+ pr_err_ratelimited("%s: %s%08lx\n", __func__, Bad_file, entry.val);
out:
return NULL;
put_out:
- pr_err("%s: %s%08lx\n", __func__, Bad_offset, entry.val);
+ pr_err_ratelimited("%s: %s%08lx\n", __func__, Bad_offset, entry.val);
percpu_ref_put(&si->users);
return NULL;
}
@@ -3883,7 +3883,7 @@ int swap_dup_entry_direct(swp_entry_t entry)
si = swap_entry_to_info(entry);
if (WARN_ON_ONCE(!si)) {
- pr_err("%s%08lx\n", Bad_file, entry.val);
+ pr_err_ratelimited("%s%08lx\n", Bad_file, entry.val);
return -EINVAL;
}
---
base-commit: e6664f2b33db9b6811eb4cec109f06cb2b4f458d
change-id: 20260818-swap_part_one-1ad0fe65809e
Best regards,
--
Breno Leitao <leitao@debian.org>
On Tue, 18 Aug 2026 02:03:40 -0700 Breno Leitao <leitao@debian.org> wrote: > A corrupt page table hands the same bogus entry to get_swap_device() on > every access to the mapping, and every rejection is logged. One machine > logged 6185620 copies of the same line in a few hours. > > swap_dup_entry_direct() prints the same message from the fork path, once > per call: the WARN_ON_ONCE() guarding it warns once, the pr_err() inside > does not. > > Rate limit all three prints. Sashiko suggests that ratelimiting these might cause pre-existing problems to become worse: https://sashiko.dev/#/patchset/20260818-swap_part_one-v1-1-a4fc58119fc0@debian.org The problem it's identifying does require that unrelated things go wrong first - get_swap_device() failed, swap_retry_table_alloc() did a retry. So presumably you wouldn't have hit this in testing. Sigh, so much to fix.
On 8/18/26 21:28, Andrew Morton wrote: > On Tue, 18 Aug 2026 02:03:40 -0700 Breno Leitao <leitao@debian.org> wrote: > >> A corrupt page table hands the same bogus entry to get_swap_device() on >> every access to the mapping, and every rejection is logged. One machine >> logged 6185620 copies of the same line in a few hours. >> >> swap_dup_entry_direct() prints the same message from the fork path, once >> per call: the WARN_ON_ONCE() guarding it warns once, the pr_err() inside >> does not. >> >> Rate limit all three prints. > > Sashiko suggests that ratelimiting these might cause pre-existing > problems to become worse: > https://sashiko.dev/#/patchset/20260818-swap_part_one-v1-1-a4fc58119fc0@debian.org > The fist problem it raises is actually fixed by the other patchset this was split off from. I didn't look into the other case. > The problem it's identifying does require that unrelated things go > wrong first - As described above: "A corrupt page table hands the same bogus entry to get_swap_device()", that requires something in the caller to go wrong (page table corruption, similar to how we handle it in other places for present ptes) -- Cheers, David
On 8/18/26 11:03, Breno Leitao wrote:
> A corrupt page table hands the same bogus entry to get_swap_device() on
> every access to the mapping, and every rejection is logged. One machine
> logged 6185620 copies of the same line in a few hours.
>
> swap_dup_entry_direct() prints the same message from the fork path, once
> per call: the WARN_ON_ONCE() guarding it warns once, the pr_err() inside
> does not.
>
> Rate limit all three prints.
>
> Cc: stable@vger.kernel.org
> Fixes: 23b230ba8ac3 ("mm/swap: print bad swap offset entry in get_swap_device")
> Reviewed-by: Barry Song <baohua@kernel.org>
> Reviewed-by: Nhat Pham <nphamcs@gmail.com>
> Acked-by: Kairui Song <kasong@tencent.com>
> Signed-off-by: Breno Leitao <leitao@debian.org>
> ---
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
--
Cheers,
David
© 2016 - 2026 Red Hat, Inc.