From nobody Mon Jun 8 05:24:49 2026 Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 636453B95FD for ; Tue, 2 Jun 2026 22:24:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780439046; cv=none; b=JYSBIkOiqbMfi7Rm19gKtW8w+14gZp1oEvWUcJgKjydxcmsl3kdrEY0ZS37IvzHECcZtSdFGfpZw+2gX1RnHuF3lhgN3S/vKDm7IzK1dbMkKg9ukggN1qBPLBWEJaHD9htd8443KRCjH/irsNQ1Gjcn+i3OGFYvR2XX25GB80uI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780439046; c=relaxed/simple; bh=KFBVO6QyzdW4ZTmOdrPRQeIRnCIg49mEfVFjUotbCP0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Y9kQfGeKURApfKPOvNARYabx1B3PEU5XB4xsijauPQ7jfYulvqbSnUeFgIWxs1YRPWbnCd162Txzvnnkt0jdVzrUf44CcAZZGAZMDFZp5oq8NCrmoxDec9hOCHe2LruvMaO5suVhDldDHZ0ClH9/fJcTLxOyGgk4EX65utNHUqo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nFRmSn4M; arc=none smtp.client-ip=209.85.128.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nFRmSn4M" Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-490af320e2aso20441205e9.2 for ; Tue, 02 Jun 2026 15:24:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780439042; x=1781043842; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=muTnxhGqlYOE/TlItGjvUxPhQ3HFtb72AnUGbvWcFwM=; b=nFRmSn4MzrLEITRsHzfZf0E+2I4gVE/Ps95QxQPrS0HY9dJVvi7XUE9uu0Fg2Elp1B MLYr3UqrWR+s+rKdFVA8MjcLae9esAZT7W2oTEGtvFdAZSECyNQbL4CTMwSmxaPru5Rd CEYAFot246PtxunfpwYx0Zdtes6GxjuBRilN4I4PcSpKRyVIbciaLZg7yjTFNPFwMgnp Z3xcEiAaWnmRSiGCL/ZmIIxY0TeWFISbHmagg6WNOlotztg+Fps/g4zoTR2kSG97Ru8T jrp8iWsnTfNtPoVY78Fv3ysp2ldx0lJSrq9X2DO0llRhIj9txo54S5xvxsEa1xk5k8gM Kbtw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780439042; x=1781043842; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=muTnxhGqlYOE/TlItGjvUxPhQ3HFtb72AnUGbvWcFwM=; b=SfkjnHc84JS9XQs170KwZ4R6EUrbJ0u2jLvjh+dlvWJZbhI9lj6/nZcRVqtlCSuV52 izCITRvtnkNc2t9BvCbA55DpoS1AumKNjU71MozSEd37/B5Lf5HYRlOrY+ER4dxRMAfM MuebGOH6SJvFHhic8ay98IlGcprEJ6/VoDeIjy799foqiklfAFTTQyK2n/RjjLAxNHd7 rpl6Axo6r4qTiIr0pDcLDxWh62MXl+bv9q/cmd49NslMAaoTzW0oflFoTe/ewBfW5eya F1KTH5N1iGxJryBkutounemEHuzLcM8S8kvLBKSFeFBVCMcOireK8EA3OR33hi8MhMcd iKUQ== X-Forwarded-Encrypted: i=1; AFNElJ+TN6bpYwEBjqRaj99mNyqFrMwJbM/vVLxmJP92b8Hknvd2/V6kPFSHSFFgPZ7ioUL3oGiX9jfechnsIYM=@vger.kernel.org X-Gm-Message-State: AOJu0YymXohzUc15FTSglCWTavQQ1ogWXzlzO7+Nz+B6nYGjKh2saV4I Y/gQY0tX+W2kIZ0ENC40kF5Y+gbkq4MwR8n0E8rdKu0bCnMqrRicn7Xb X-Gm-Gg: Acq92OFp17qqKM4Aknh/QMOCAUYkRAeZqOsj8c3s+o0FSNdZI4Vvk1E5Ed7ZlCsTHfP UnwzCZRKKUle7yufR+WPZrBr3AEMb7wUgkcgIJH3E27icVUtNQQ3ua76oi980HTB1Wkjl9o4q2t TePnb1YG9wRH/abMkBaUf3LpC2w/vaFkray5qJCCLUgoebmJXoXEFAzuNEyhxUa4oOAMDruVrft FeAek66HTgEdNzN7K7AQo5p1FAIS3SKPjAGHc70k9a9UoPFKcumImf/dRWdJCrL3NyU3uNf6Bx+ DWPhsBLlxP+56+C+I7tLoQn67Si5h2ynnpLoodHQbzGlVP7DwXsmoLJJctOWUnI/1fcysoODBL6 egZQDblUFTKYAmCkvwfUxQrsJscE6m21dekGvYBT8ZxxClukCxOX+1sReFCyxPtQqdB+9Im4O69 nMgpjOJ3bGtQEX94nLTF7wdChRUUyLGr5fqimwJp4IUNO3PERo27LcmTeRLy+o7lKVPW63H1mrq +sfY0LS79D7cENDYgUcKw== X-Received: by 2002:a05:600c:3e0c:b0:48f:e1ac:c94f with SMTP id 5b1f17b1804b1-490b5ea86d9mr9922945e9.10.1780439041650; Tue, 02 Jun 2026 15:24:01 -0700 (PDT) Received: from dohko.chello.ie (188-141-5-72.dynamic.upc.ie. [188.141.5.72]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-490b60f6d5asm10362265e9.0.2026.06.02.15.24.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 15:24:01 -0700 (PDT) From: David Carlier To: akpm@linux-foundation.org Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, David Carlier , syzbot+deedf22929084640666f@syzkaller.appspotmail.com, stable@vger.kernel.org, Chris Li , Kairui Song , Kemeng Shi , Nhat Pham , Baoquan He , Barry Song , Youngjun Park Subject: [PATCH] mm, swap: free the cluster extend table on teardown Date: Tue, 2 Jun 2026 23:23:57 +0100 Message-ID: <20260602222358.49061-1-devnexen@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" swap_cluster_free_table() frees every per-cluster side table but ci->extend_table. That table is only released by swap_extend_table_try_free(), which the teardown path never calls, so a cluster can be freed with an extend table still attached. It can also linger while the cluster is live. swap_dup_entries_cluster() drops the lock to allocate an extend table when a slot reaches SWP_TB_COUNT_MAX - 1, then retries. If the count dropped in the meantime, the retry takes the normal path and leaves the table behind, all entries zero; only the failure path frees it. Since a swap_cluster_info is reused in place and swap_extend_table_alloc() skips allocation when ci->extend_table is set, the next user of the cluster inherits the stale table and its leftover counts, corrupting the swap count of any slot that overflows. CONFIG_DEBUG_VM catches the dangling table in swap_cluster_assert_empty(); otherwise it is silent. Free it in swap_cluster_free_table(), and also on the swap_dup_entries_cluster() success path to match the failure path. Reported-by: syzbot+deedf22929084640666f@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3Ddeedf22929084640666f Fixes: 0d6af9bcf383 ("mm, swap: use the swap table to track the swap count") Cc: Signed-off-by: David Carlier --- mm/swapfile.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/mm/swapfile.c b/mm/swapfile.c index 615d90867111..a69a26aec4c0 100644 --- a/mm/swapfile.c +++ b/mm/swapfile.c @@ -432,6 +432,9 @@ static void swap_cluster_free_table(struct swap_cluster= _info *ci) ci->zero_bitmap =3D NULL; #endif =20 + kfree(ci->extend_table); + ci->extend_table =3D NULL; + table =3D (struct swap_table *)rcu_access_pointer(ci->table); if (!table) return; @@ -1711,6 +1714,7 @@ static int swap_dup_entries_cluster(struct swap_info_= struct *si, goto failed; } } while (++ci_off < ci_end); + swap_extend_table_try_free(ci); swap_cluster_unlock(ci); return 0; failed: --=20 2.53.0