From: Muchun Song <songmuc...@bytedance.com> [ Upstream commit 2f7659a314736b32b66273dbf91c19874a052fde ]
Consider the following memcg hierarchy. root / \ A B If we failed to get the reference on objcg of memcg A, the get_obj_cgroup_from_current can return the wrong objcg for the root memcg. Link: https://lkml.kernel.org/r/20201029164429.58703-1-songmuc...@bytedance.com Fixes: bf4f059954dc ("mm: memcg/slab: obj_cgroup API") Signed-off-by: Muchun Song <songmuc...@bytedance.com> Acked-by: Roman Gushchin <g...@fb.com> Cc: Johannes Weiner <han...@cmpxchg.org> Cc: Michal Hocko <mho...@kernel.org> Cc: Vladimir Davydov <vdavydov....@gmail.com> Cc: Shakeel Butt <shake...@google.com> Cc: Joonsoo Kim <iamjoonsoo....@lge.com> Cc: Yafang Shao <laoar.s...@gmail.com> Cc: Chris Down <ch...@chrisdown.name> Cc: Christian Brauner <christian.brau...@ubuntu.com> Cc: Peter Zijlstra <pet...@infradead.org> Cc: Ingo Molnar <mi...@kernel.org> Cc: Kees Cook <keesc...@chromium.org> Cc: Thomas Gleixner <t...@linutronix.de> Cc: Eugene Syromiatnikov <e...@redhat.com> Cc: Suren Baghdasaryan <sur...@google.com> Cc: Adrian Reber <are...@redhat.com> Cc: Marco Elver <el...@google.com> Signed-off-by: Andrew Morton <a...@linux-foundation.org> Signed-off-by: Linus Torvalds <torva...@linux-foundation.org> Signed-off-by: Sasha Levin <sas...@kernel.org> --- mm/memcontrol.c | 1 + 1 file changed, 1 insertion(+) diff --git a/mm/memcontrol.c b/mm/memcontrol.c index 29459a6ce1c7a..74b85077f89ad 100644 --- a/mm/memcontrol.c +++ b/mm/memcontrol.c @@ -2987,6 +2987,7 @@ __always_inline struct obj_cgroup *get_obj_cgroup_from_current(void) objcg = rcu_dereference(memcg->objcg); if (objcg && obj_cgroup_tryget(objcg)) break; + objcg = NULL; } rcu_read_unlock(); -- 2.27.0