Re: [PATCH v6 9/9] mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()
From: Zi Yan
Date: Mon Jul 13 2026 - 21:57:01 EST
On 13 Jul 2026, at 21:51, Ye Liu wrote:
> print_page_owner_memcg() takes a snapshot of page->memcg_data via
> READ_ONCE at the top of the function and guards against tail pages and
> NULL memcg_data. However, it later calls two functions that re-read
> page->memcg_data locklessly:
>
> 1) page_memcg_check(page) — re-reads page->memcg_data;
> 2) PageMemcgKmem(page) — calls folio_memcg_kmem(), which re-reads
> folio->memcg_data and folio->page->compound_head, wrapping both
> in VM_BUG_ON assertions:
>
> VM_BUG_ON_PGFLAGS(PageTail(&folio->page), &folio->page);
> VM_BUG_ON_FOLIO(folio->memcg_data & MEMCG_DATA_OBJEXTS, folio);
>
> If the page is concurrently freed and reallocated as a THP tail page
> or a slab page between the initial guards and these later calls, the
> VM_BUG_ON assertions can fire on debug builds (CONFIG_DEBUG_VM=y),
> causing a kernel panic.
>
> Fix both TOCTOU issues by using the memcg_data snapshot throughout:
> - Extract objcg from the snapshot via objcg = (void *)(memcg_data &
> ~OBJEXTS_FLAGS_MASK) instead of calling page_memcg_check(page);
> - Test (memcg_data & MEMCG_DATA_KMEM) instead of calling
> PageMemcgKmem(page), which is semantically equivalent:
> PageMemcgKmem()->folio_memcg_kmem()->folio->memcg_data &
> MEMCG_DATA_KMEM.
> - When memcg_data has MEMCG_DATA_OBJEXTS set, early-return after
> printing "Slab cache page\n" since objcg != memcg for slab pages
> and there is no meaningful cgroup to look up.
>
> This avoids both TOCTOU windows and the assertions entirely.
>
> Signed-off-by: Ye Liu <ye.liu@xxxxxxxxx>
> ---
> Changes in v6:
> - Rename patch to cover both TOCTOU fixes rather than only
> PageMemcgKmem().
> - Also replace page_memcg_check(page) with extracting objcg from the
> memcg_data snapshot to fix a second TOCTOU issue.
> - Add early return for the MEMCG_DATA_OBJEXTS (slab) case since
> objcg != memcg for slab pages and there is no cgroup to look up.
> - Update commit message to cover all changes.
> - Link: https://lore.kernel.org/all/20260701061101.344679-10-ye.liu@xxxxxxxxx/
> mm/page_owner.c | 10 +++++++---
> 1 file changed, 7 insertions(+), 3 deletions(-)
>
LGTM. Thanks.
Reviewed-by: Zi Yan <ziy@xxxxxxxxxx>
Best Regards,
Yan, Zi