mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 10:00:03 -04:00
mm/memory-failure: add panic option for unrecoverable pages
Add a sysctl panic_on_unrecoverable_memory_failure (disabled by default) that triggers a kernel panic when memory_failure() encounters pages that cannot be recovered. This provides a clean crash with useful debug information rather than allowing silent data corruption or a delayed crash at an unrelated code path. Panic eligibility is intentionally narrow: only MF_MSG_KERNEL with result == MF_IGNORED panics. After the previous patch, MF_MSG_KERNEL covers PG_reserved pages and the kernel-owned pages promoted from get_hwpoison_page() via -ENOTRECOVERABLE (slab, page tables, large-kmalloc). All other action types are excluded: - MF_MSG_GET_HWPOISON and MF_MSG_KERNEL_HIGH_ORDER can be reached by transient refcount races with the page allocator (an in-flight buddy allocation has refcount 0 and is no longer on the buddy free list, briefly), and panicking on them would risk killing the box for what is actually a recoverable userspace page. - MF_MSG_UNKNOWN means identify_page_state() could not classify the page; that is precisely the wrong basis for a panic decision. Link: https://lore.kernel.org/20260630-ecc_panic-v10-4-c6ed5b62eea2@debian.org Signed-off-by: Breno Leitao <leitao@debian.org> Acked-by: Miaohe Lin <linmiaohe@huawei.com> Cc: David Hildenbrand (Arm) <david@kernel.org> Cc: Jonathan Corbet <corbet@lwn.net> Cc: Lance Yang <lance.yang@linux.dev> Cc: Liam R. Howlett <liam@infradead.org> Cc: Lorenzo Stoakes <ljs@kernel.org> Cc: "Masami Hiramatsu (Google)" <mhiramat@kernel.org> Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com> Cc: Michal Hocko <mhocko@suse.com> Cc: Mike Rapoport <rppt@kernel.org> Cc: Naoya Horiguchi <nao.horiguchi@gmail.com> Cc: Shuah Khan <shuah@kernel.org> Cc: Steven Rostedt <rostedt@goodmis.org> Cc: Suren Baghdasaryan <surenb@google.com> Cc: Vlastimil Babka <vbabka@kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
This commit is contained in:
committed by
Andrew Morton
parent
737a97548c
commit
3e0659f93b
@@ -75,6 +75,8 @@ static int sysctl_memory_failure_recovery __read_mostly = 1;
|
||||
|
||||
static int sysctl_enable_soft_offline __read_mostly = 1;
|
||||
|
||||
static int sysctl_panic_on_unrecoverable_mf __read_mostly;
|
||||
|
||||
atomic_long_t num_poisoned_pages __read_mostly = ATOMIC_LONG_INIT(0);
|
||||
|
||||
static bool hw_memory_failure __read_mostly;
|
||||
@@ -156,6 +158,15 @@ static const struct ctl_table memory_failure_table[] = {
|
||||
.proc_handler = proc_dointvec_minmax,
|
||||
.extra1 = SYSCTL_ZERO,
|
||||
.extra2 = SYSCTL_ONE,
|
||||
},
|
||||
{
|
||||
.procname = "panic_on_unrecoverable_memory_failure",
|
||||
.data = &sysctl_panic_on_unrecoverable_mf,
|
||||
.maxlen = sizeof(sysctl_panic_on_unrecoverable_mf),
|
||||
.mode = 0644,
|
||||
.proc_handler = proc_dointvec_minmax,
|
||||
.extra1 = SYSCTL_ZERO,
|
||||
.extra2 = SYSCTL_ONE,
|
||||
}
|
||||
};
|
||||
|
||||
@@ -1256,6 +1267,15 @@ static void update_per_node_mf_stats(unsigned long pfn,
|
||||
++mf_stats->total;
|
||||
}
|
||||
|
||||
static bool panic_on_unrecoverable_mf(enum mf_action_page_type type,
|
||||
enum mf_result result)
|
||||
{
|
||||
if (!sysctl_panic_on_unrecoverable_mf)
|
||||
return false;
|
||||
|
||||
return type == MF_MSG_KERNEL && result == MF_IGNORED;
|
||||
}
|
||||
|
||||
/*
|
||||
* "Dirty/Clean" indication is not 100% accurate due to the possibility of
|
||||
* setting PG_dirty outside page lock. See also comment above set_page_dirty().
|
||||
@@ -1273,6 +1293,9 @@ static int action_result(unsigned long pfn, enum mf_action_page_type type,
|
||||
pr_err("%#lx: recovery action for %s: %s\n",
|
||||
pfn, action_page_types[type], action_name[result]);
|
||||
|
||||
if (panic_on_unrecoverable_mf(type, result))
|
||||
panic("Memory failure: %#lx: unrecoverable page", pfn);
|
||||
|
||||
return (result == MF_RECOVERED || result == MF_DELAYED) ? 0 : -EBUSY;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user