Skip to content

Commit 2d0db02

Browse files
Sahitya Tummalagregkh
authored andcommitted
mm/list_lru.c: fix list_lru_count_node() to be race free
commit 2c80cd57c74339889a8752b20862a16c28929c3a upstream. list_lru_count_node() iterates over all memcgs to get the total number of entries on the node but it can race with memcg_drain_all_list_lrus(), which migrates the entries from a dead cgroup to another. This can return incorrect number of entries from list_lru_count_node(). Fix this by keeping track of entries per node and simply return it in list_lru_count_node(). Link: http://lkml.kernel.org/r/1498707555-30525-1-git-send-email-stummala@codeaurora.org Signed-off-by: Sahitya Tummala <stummala@codeaurora.org> Acked-by: Vladimir Davydov <vdavydov.dev@gmail.com> Cc: Jan Kara <jack@suse.cz> Cc: Alexander Polakov <apolyakov@beget.ru> Cc: Al Viro <viro@zeniv.linux.org.uk> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 717ce69 commit 2d0db02

2 files changed

Lines changed: 7 additions & 8 deletions

File tree

include/linux/list_lru.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,7 @@ struct list_lru_node {
4444
/* for cgroup aware lrus points to per cgroup lists, otherwise NULL */
4545
struct list_lru_memcg *memcg_lrus;
4646
#endif
47+
long nr_items;
4748
} ____cacheline_aligned_in_smp;
4849

4950
struct list_lru {

mm/list_lru.c

Lines changed: 6 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -117,6 +117,7 @@ bool list_lru_add(struct list_lru *lru, struct list_head *item)
117117
l = list_lru_from_kmem(nlru, item);
118118
list_add_tail(item, &l->list);
119119
l->nr_items++;
120+
nlru->nr_items++;
120121
spin_unlock(&nlru->lock);
121122
return true;
122123
}
@@ -136,6 +137,7 @@ bool list_lru_del(struct list_lru *lru, struct list_head *item)
136137
l = list_lru_from_kmem(nlru, item);
137138
list_del_init(item);
138139
l->nr_items--;
140+
nlru->nr_items--;
139141
spin_unlock(&nlru->lock);
140142
return true;
141143
}
@@ -183,15 +185,10 @@ EXPORT_SYMBOL_GPL(list_lru_count_one);
183185

184186
unsigned long list_lru_count_node(struct list_lru *lru, int nid)
185187
{
186-
long count = 0;
187-
int memcg_idx;
188+
struct list_lru_node *nlru;
188189

189-
count += __list_lru_count_one(lru, nid, -1);
190-
if (list_lru_memcg_aware(lru)) {
191-
for_each_memcg_cache_index(memcg_idx)
192-
count += __list_lru_count_one(lru, nid, memcg_idx);
193-
}
194-
return count;
190+
nlru = &lru->node[nid];
191+
return nlru->nr_items;
195192
}
196193
EXPORT_SYMBOL_GPL(list_lru_count_node);
197194

@@ -226,6 +223,7 @@ __list_lru_walk_one(struct list_lru *lru, int nid, int memcg_idx,
226223
assert_spin_locked(&nlru->lock);
227224
case LRU_REMOVED:
228225
isolated++;
226+
nlru->nr_items--;
229227
/*
230228
* If the lru lock has been dropped, our list
231229
* traversal is now invalid and so we have to

0 commit comments

Comments
 (0)