From nobody Tue Sep 29 08:22:56 2026 Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B944941B8DC for ; Mon, 10 Aug 2026 16:28:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=82.195.75.108 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786379289; cv=none; b=T/HmNBfiCMMyiL8EXyxRj+YzRbqDAVQWpWkryZIXxod3WC5r5YTTzVR2eDgdh6Z6RJHzPyMcs3gDgWj/IO4/37uBQOXZivkCNX2m6v+kxiKILp2LQtRoY8tg/7EbVyH7I5JDev9Ms5fOWjPzTrzBLMzQ3DzYRhumlDPPiRy4Wew= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786379289; c=relaxed/simple; bh=xkXi9fgJ7KrcCeZFprZs/+gSFahKcbk7Esh+oPKGx4o=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=AZGzxSCSSP7OxbKASdcyrKTg0jjbrRNNFCvC3KYcLNlTlV3V71DZVeVHV7Rx/Ghn9wtsb5HCHSyTkBeypwMpEeU0mGglxRd/c1WgGtd90BFf0Y2ONWs8n5mg2SVAs6IHTeKbcFwoODPCgonJ864W7ls4kFxlSTDen47j7xLOeHE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=debian.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b=tL1zRUNp; arc=none smtp.client-ip=82.195.75.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=debian.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="tL1zRUNp" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Cc:To:In-Reply-To:References: Message-Id:Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date: From:Reply-To:Content-ID:Content-Description; bh=X260Hjv1Vm1+CEj2cIe0a1PWTJRFadqLD8eHwG/NZfU=; b=tL1zRUNpp3afizNL+2uKCvqgav br5f6vl8elgVUmpe6csLrT3hZ6en1h2jFwx9kl2TnVmGsDlWqcHLo9thWg5oR1WHeXZadQgQtAi7O 1uC5a+GzzutAlpQi1IErIbficuV9v4nKDuDV6kG1vunLmUQ+ID4zxfCsvfLg+jkua5feS4plS/F31 q6bEthbhCK99TuKavmLGjTwMhc6BRvLgh/if25ocv0wsluJpKSCz+EKvQkRk+LN80O+DWqEqCJaQU gE22eN7KsD5pnOAlOlEYBlMaMcpIog0eP0+RlH0OE41G7B2TII9Stmw4iNpaX+EG4yRF2l48RwjRm EyYxAGKA==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1wtSqg-002ufA-1m; Mon, 10 Aug 2026 16:27:39 +0000 From: Breno Leitao Date: Mon, 10 Aug 2026 09:26:49 -0700 Subject: [PATCH 1/3] mm, swap: ratelimit bad swap entry reports in get_swap_device() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260810-swap-v1-1-375ef0767206@debian.org> References: <20260810-swap-v1-0-375ef0767206@debian.org> In-Reply-To: <20260810-swap-v1-0-375ef0767206@debian.org> To: Andrew Morton , Chris Li , Kairui Song , Kemeng Shi , Nhat Pham , Baoquan He , Barry Song , Youngjun Park , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Jann Horn , Pedro Falcato , Hugh Dickins , Baolin Wang , Peter Xu , Johannes Weiner , Yosry Ahmed , Chengming Zhou Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, kernel-team@meta.com, Breno Leitao X-Mailer: b4 0.16-dev-f8e9d X-Developer-Signature: v=1; a=openpgp-sha256; l=976; i=leitao@debian.org; h=from:subject:message-id; bh=xkXi9fgJ7KrcCeZFprZs/+gSFahKcbk7Esh+oPKGx4o=; b=owEBbQKS/ZANAwAIATWjk5/8eHdtAcsmYgBqefvpln63mQ6+J5NEbzNRv+b2ue7YHSg/NdBrc ElVPwjOUWqJAjMEAAEIAB0WIQSshTmm6PRnAspKQ5s1o5Of/Hh3bQUCann76QAKCRA1o5Of/Hh3 bYaTEACOQAJ6NERN3M8O1i9zp/4Q3IVATkjnbEjHEtTQBrzn7eMbezJsCH+ViJmjDytGWrbddMU jsB4bupJbIV2TeXU3k1cKkVFXVdlwVc8Htn4WVKMI++tbPtif390U6S9bJTkO3b6yYGkixpxHkK AqYG5nTKaZnXj6yg5iKow670eLywodVVwWr1TRz6Z/WP7ph/yE0wzuu+POvx4eHkngNy2M8EZBP aNDjQg3S+JY5BaY8VMfO9t5yHfleT2+ElNHx+4U0Pn872VxZCCZIwd2ygZXQYzVVJ6xSNvTxGU5 O5eWjBE6SUmpVFxJtV4y02vbVAWPQfj0C5pboZcb4/nOhUrT9Q08czl8mVypCJto7Mqv0Bw6bb6 /5FBDlXf3C5fy2DEfzBBfTZ8q7Jsv4Jy/yQXKdqzoE30ox6Na674oKSsG43HiG/j/qOJJ4UatVn VY9aXRdDcXkkzeFxBunYw+XiBZzKsKx2zIKzSNMnvKGjauWwAWig4MUID3zjNrTXNaiFe3LogMB c8XR7gfoC5cb+yl2k7aUmW0WV3bzGWrgwsNKyYYgf0CwSQ8UVRXc0U4H1oc4/SuroYqf0OP4kQO mK+9LVPkubcYQHhXWvUXs7Uh6TtQwLSM2RD3e4JqKfA/CWc2bH5+AuZ+tWnBHhRXDOlIrHFqFJP 2IDb/9QEHNO80eg== X-Developer-Key: i=leitao@debian.org; a=openpgp; fpr=AC8539A6E8F46702CA4A439B35A3939FFC78776D X-Debian-User: leitao A corrupt page table hands the same bogus entry to get_swap_device() on every access to the mapping, and every rejection is logged. One machine logged 6185620 copies of the same line in a few hours. Rate limit both prints. Signed-off-by: Breno Leitao --- mm/swapfile.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/mm/swapfile.c b/mm/swapfile.c index 4d4e3e3059f6b..9ab11dc24e4f1 100644 --- a/mm/swapfile.c +++ b/mm/swapfile.c @@ -1899,11 +1899,11 @@ struct swap_info_struct *get_swap_device(swp_entry_= t entry) =20 return si; bad_nofile: - pr_err("%s: %s%08lx\n", __func__, Bad_file, entry.val); + pr_err_ratelimited("%s: %s%08lx\n", __func__, Bad_file, entry.val); out: return NULL; put_out: - pr_err("%s: %s%08lx\n", __func__, Bad_offset, entry.val); + pr_err_ratelimited("%s: %s%08lx\n", __func__, Bad_offset, entry.val); percpu_ref_put(&si->users); return NULL; } --=20 2.53.0-Meta From nobody Tue Sep 29 08:22:56 2026 Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BBAC441D12D for ; Mon, 10 Aug 2026 16:28:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=82.195.75.108 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786379296; cv=none; b=fgab+1RhfzgqDmsV0m5ym+WbpvzIRddkcGkC/PuwU2sIAqsD0CcdiJ6ak43zdvBGev4JnqaXC1lzaTlqycluVmOUj4MTCaRE4eAFg1IboG3OyH0PlPlXmR3i+cdJUZmJzOdv0QijcZIq7CzUjZeegjP3GcxHrcj0+NSD5lnuqAQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786379296; c=relaxed/simple; bh=MqqCc24oSI55SE/DlZ1XKDzsXt4cdmCRfefdgxzpBK0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=sf8NB1PzxsD1AVOxuBwMc+GK3Lu9MU8MZ9qO/Z6wOdUnrNAZoVH66w6y+2ZcGS5MZE9f2nGAr+o88iphpDW2XcbJgLrt89KyZXpleIkQtsTT3gv3qwxUgmtWKTu3I7p/yaf1y0n8oHb6PsCNZVUaHQ/YlBV07xgL0hWoSOqTXp0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=debian.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b=AB6MGyo3; arc=none smtp.client-ip=82.195.75.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=debian.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="AB6MGyo3" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Cc:To:In-Reply-To:References: Message-Id:Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date: From:Reply-To:Content-ID:Content-Description; bh=OSmw4/JATZovKQ82nG8xj7k3y5w0Jj+3EtzqrkfFalA=; b=AB6MGyo3gw+2RDp5miWNY20TK6 pJAKLOjit0gHXPP9YB2LYkP4Yyd1Fd+gDj4OdnSs7dwu8joPMpKM2R7cecwRtp/ROdOyx3J1qzUle z0VFdpXoZ8aY3adq30wDtDWDPdwcLGnOYG7CJIHp1eLrmmnNF/E7oexhzC2fRBFsN+eyfeYfFD2TA JmHdNnTvAPa5QuUvXzgNqs4E71UF4Jey+NvsfxOKmMAgR0/b5aHSW3K/E9iODpOPhFkiy6k8XbJo/ WgXd+DhbNFcgp0oZwQlaf2oIXJo0d48RyYL9ECLUw8KRbEEe/uORMAqSmFjF+zqwjxFOxiJG2UdmG NYStYK1A==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1wtSqv-002ufJ-0j; Mon, 10 Aug 2026 16:27:54 +0000 From: Breno Leitao Date: Mon, 10 Aug 2026 09:26:50 -0700 Subject: [PATCH 2/3] mm, swap: distinguish a malformed swap entry from a dying device Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260810-swap-v1-2-375ef0767206@debian.org> References: <20260810-swap-v1-0-375ef0767206@debian.org> In-Reply-To: <20260810-swap-v1-0-375ef0767206@debian.org> To: Andrew Morton , Chris Li , Kairui Song , Kemeng Shi , Nhat Pham , Baoquan He , Barry Song , Youngjun Park , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Jann Horn , Pedro Falcato , Hugh Dickins , Baolin Wang , Peter Xu , Johannes Weiner , Yosry Ahmed , Chengming Zhou Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, kernel-team@meta.com, Breno Leitao X-Mailer: b4 0.16-dev-f8e9d X-Developer-Signature: v=1; a=openpgp-sha256; l=5482; i=leitao@debian.org; h=from:subject:message-id; bh=MqqCc24oSI55SE/DlZ1XKDzsXt4cdmCRfefdgxzpBK0=; b=owEBbQKS/ZANAwAIATWjk5/8eHdtAcsmYgBqefvp5TjJccBIh+J0r6eZ4piAUO/GtD+HNrZmI 4QZrutDYe+JAjMEAAEIAB0WIQSshTmm6PRnAspKQ5s1o5Of/Hh3bQUCann76QAKCRA1o5Of/Hh3 bb2VD/9Vxf3WlBBc2dcGI4uVUmsmR7oy86IfaeOP4RDEzioh21udsESJl837Ovv5AO0oPcp7xF4 AAW6ZgWuN+avbIsYeuFdvqsRnTusqWbNVqKb44YKTv8VWAxbL6Qfu0DRKUB4HHGvm6y/qYlVKAQ xirzjsPSgLnbgz59SVclw+kDPssDXX+ut5/S8VQWgNb5Jvvc6V4jepCcRBq4dPrkP23Lbf9WOI/ RbXTt0VtoYM0MmprrESBwNXumNFBvcQj+YmvdEG55hZWwwjv63qV+q5RkWK0PlD5sB3hcQH4shS /9SoPlqn7Q5boo0JBOtdPkahbJdeKrP+mkwwGFdViT7Gb+F4pez1wv/52qoGrE0wxxlgfYV2NaS +3NES/FWfzgE0KT+M8G8FRBloANBMM8/hSAXWq7i4n5pD3R5QrxasSUvzh7ymSJ9GyxN0Wf4Fr7 PdR/u3eMWkB9q3XO0Caq/S2mv96+fgZF5rVM7h/A36QlYZW8PnR71n5nDYiOuEFQjsXglJmSke5 neqf3Atzo+YwAIn32kd3d1ZNhxTuWfvOWPAk/qoInl24R/Vt6vtyQfj0oBP7oDf5WSXOMBKRGMq OilHxNFDDESrauSetRj+/t+iJB99ZOqZ9tG5KbvGvV6I4rQYzbJ7huLa8xjUiVHQCgL2ASvxDOa uaQhHQYgEW4cYYw== X-Developer-Key: i=leitao@debian.org; a=openpgp; fpr=AC8539A6E8F46702CA4A439B35A3939FFC78776D X-Debian-User: leitao get_swap_device() returns NULL both for an entry that can never name a slot on any device and for a device that swapoff is taking away. The first never becomes valid, the second does, and callers cannot tell them apart. Return ERR_PTR(-EINVAL) for the two malformed cases and keep NULL for swapoff. Callers bail out on failure either way, so switch them to IS_ERR_OR_NULL() and clear si where the cleanup path would otherwise put an ERR_PTR. No functional change. Signed-off-by: Breno Leitao --- mm/memory.c | 4 +++- mm/mincore.c | 2 +- mm/shmem.c | 2 +- mm/swap_state.c | 4 ++-- mm/swapfile.c | 13 ++++++++----- mm/userfaultfd.c | 3 ++- mm/zswap.c | 2 +- 7 files changed, 18 insertions(+), 12 deletions(-) diff --git a/mm/memory.c b/mm/memory.c index d9cf941967cf0..4238778b66c42 100644 --- a/mm/memory.c +++ b/mm/memory.c @@ -4956,8 +4956,10 @@ vm_fault_t do_swap_page(struct vm_fault *vmf) =20 /* Prevent swapoff from happening to us. */ si =3D get_swap_device(entry); - if (unlikely(!si)) + if (IS_ERR_OR_NULL(si)) { + si =3D NULL; goto out; + } =20 folio =3D swap_cache_get_folio(entry); if (folio) diff --git a/mm/mincore.c b/mm/mincore.c index ff4ac82817683..c086836bc4bcc 100644 --- a/mm/mincore.c +++ b/mm/mincore.c @@ -71,7 +71,7 @@ static unsigned char mincore_swap(swp_entry_t entry, bool= shmem) */ if (shmem) { si =3D get_swap_device(entry); - if (!si) + if (IS_ERR_OR_NULL(si)) return 0; } folio =3D swap_cache_get_folio(entry); diff --git a/mm/shmem.c b/mm/shmem.c index 65572cbf1bd3c..d0a9f52bfed71 100644 --- a/mm/shmem.c +++ b/mm/shmem.c @@ -2276,7 +2276,7 @@ static int shmem_swapin_folio(struct inode *inode, pg= off_t index, =20 si =3D get_swap_device(index_entry); order =3D shmem_confirm_swap(mapping, index, index_entry); - if (unlikely(!si)) { + if (IS_ERR_OR_NULL(si)) { if (order < 0) return -EEXIST; else diff --git a/mm/swap_state.c b/mm/swap_state.c index 4b7a3303c463b..f2e86d6626ecc 100644 --- a/mm/swap_state.c +++ b/mm/swap_state.c @@ -715,7 +715,7 @@ struct folio *read_swap_cache_async(struct swap_io_ctx = *ctx, swp_entry_t entry, struct folio *folio; =20 si =3D get_swap_device(entry); - if (!si) + if (IS_ERR_OR_NULL(si)) return NULL; =20 mpol =3D get_vma_policy(vma, addr, 0, &ilx); @@ -951,7 +951,7 @@ static struct folio *swap_vma_readahead(swp_entry_t tar= g_entry, gfp_t gfp_mask, */ if (swp_type(entry) !=3D swp_type(targ_entry)) { si =3D get_swap_device(entry); - if (!si) + if (IS_ERR_OR_NULL(si)) continue; } folio =3D swap_cache_read_folio(&ctx, entry, gfp_mask, mpol, ilx, diff --git a/mm/swapfile.c b/mm/swapfile.c index 9ab11dc24e4f1..29612a0cf7afa 100644 --- a/mm/swapfile.c +++ b/mm/swapfile.c @@ -1504,7 +1504,7 @@ int swap_retry_table_alloc(swp_entry_t entry, gfp_t g= fp) unsigned long offset =3D swp_offset(entry); =20 si =3D get_swap_device(entry); - if (!si) + if (IS_ERR_OR_NULL(si)) return 0; =20 ci =3D __swap_offset_to_cluster(si, offset); @@ -1859,7 +1859,9 @@ void folio_put_swap(struct folio *folio, struct page = *page) * Check whether swap entry is valid in the swap device. If so, * return pointer to swap_info_struct, and keep the swap entry valid * via preventing the swap device from being swapoff, until - * put_swap_device() is called. Otherwise return NULL. + * put_swap_device() is called. Return NULL for an empty entry or a + * device that is going away, and ERR_PTR(-EINVAL) if the entry itself + * is malformed and can never name a slot on any device. * * Notice that swapoff or swapoff+swapon can still happen before the * percpu_ref_tryget_live() in get_swap_device() or after the @@ -1900,12 +1902,13 @@ struct swap_info_struct *get_swap_device(swp_entry_= t entry) return si; bad_nofile: pr_err_ratelimited("%s: %s%08lx\n", __func__, Bad_file, entry.val); + return ERR_PTR(-EINVAL); out: return NULL; put_out: pr_err_ratelimited("%s: %s%08lx\n", __func__, Bad_offset, entry.val); percpu_ref_put(&si->users); - return NULL; + return ERR_PTR(-EINVAL); } =20 /* @@ -2001,7 +2004,7 @@ int swp_swapcount(swp_entry_t entry) int count; =20 si =3D get_swap_device(entry); - if (!si) + if (IS_ERR_OR_NULL(si)) return 0; =20 ci =3D swap_cluster_lock(si, swp_offset(entry)); @@ -2127,7 +2130,7 @@ void swap_put_entries_direct(swp_entry_t entry, int n= r) struct swap_info_struct *si; =20 si =3D get_swap_device(entry); - if (WARN_ON_ONCE(!si)) + if (WARN_ON_ONCE(IS_ERR_OR_NULL(si))) return; if (WARN_ON_ONCE(end_offset > si->max)) goto out; diff --git a/mm/userfaultfd.c b/mm/userfaultfd.c index 24a4d92ffa3c2..bf7bc7fb1aa0f 100644 --- a/mm/userfaultfd.c +++ b/mm/userfaultfd.c @@ -1700,7 +1700,8 @@ static long move_pages_ptes(struct mm_struct *mm, pmd= _t *dst_pmd, pmd_t *src_pmd } =20 si =3D get_swap_device(entry); - if (unlikely(!si)) { + if (IS_ERR_OR_NULL(si)) { + si =3D NULL; ret =3D -EAGAIN; goto out; } diff --git a/mm/zswap.c b/mm/zswap.c index f7c9c89f6449c..bc9b931d6f447 100644 --- a/mm/zswap.c +++ b/mm/zswap.c @@ -997,7 +997,7 @@ static int zswap_writeback_entry(struct zswap_entry *en= try, =20 /* try to allocate swap cache folio */ si =3D get_swap_device(swpentry); - if (!si) + if (IS_ERR_OR_NULL(si)) return -EEXIST; =20 mpol =3D get_task_policy(current); --=20 2.53.0-Meta From nobody Tue Sep 29 08:22:56 2026 Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AC3B541B8F7 for ; Mon, 10 Aug 2026 16:28:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=82.195.75.108 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786379306; cv=none; b=VKMcJ5MKt9IVESECGbs4gMCfT2bMtb2bIqEGc9Y5aOujIZdnQ5H9FmnDdjKHMrVvffXh0XCjnU2u5EYe0pw8onNyKC+8WfRe50pXG+DUxaZ0R+Mhxc+Ow8tT6COSfQrhwLRHqYqFyRiHaKVQ016GN47LBgpS1nu3+xhjbVBUExU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786379306; c=relaxed/simple; bh=0eADPU9A+Bin6aphy+90if2YapwKINa2j/tvvdSh++4=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=TgL1qNWCnLJaHB/X9XyVeTZI4xz75pM+G7ddsmECtC+9AhCgtdEQ3mTLNOrDSWifTeVlXpmcHfo+Pui0F30u83uPV6f8nlUmf+ieEmHE0yChV+yicCZ+LMfm1+1db2jY0ULGAPalk7OGlMw3cNy3TZOqna4d/BJJjBP4d9Trako= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=debian.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b=P8Bf3oH0; arc=none smtp.client-ip=82.195.75.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=debian.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="P8Bf3oH0" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Cc:To:In-Reply-To:References: Message-Id:Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date: From:Reply-To:Content-ID:Content-Description; bh=QfzutoXq/QhHceqFzC7g3Uo92nX5QF8uEfbvCV0Qpnk=; b=P8Bf3oH0xACrqWSVqO4gaIQoH6 oWVLgg5NGpmJ+zmFnkycvZlswPi7MCSTJVwXsb76e9db+GwB3J5/UxQAR3evm5U+tHZyBrg18xAHU q8OfPEG7pGXppy/7Bs5bDlSf5DX2h0QJULjB857W6mTg2ewYMkpy1L9a4Cy/obFHaMdDAJEjKbxbT nD2OaKygZ6Uj8wWDrPdcuxpjevu1LdshG2CNWDn+R9MI1pKtVB+hobU0PsTfQ8Nx8IB4UwinjILHw o3aWUM84DpCYRaaMPMbvKHkpAzJ7dSmmKDb/66YUsCAZZUr3jV/NqYcKf0xYjrAPKziTZoWy6JTNd eUFRe++Q==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1wtSr6-002ufm-2w; Mon, 10 Aug 2026 16:28:05 +0000 From: Breno Leitao Date: Mon, 10 Aug 2026 09:26:51 -0700 Subject: [PATCH 3/3] mm: fail the fault on a malformed swap entry instead of retrying it Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260810-swap-v1-3-375ef0767206@debian.org> References: <20260810-swap-v1-0-375ef0767206@debian.org> In-Reply-To: <20260810-swap-v1-0-375ef0767206@debian.org> To: Andrew Morton , Chris Li , Kairui Song , Kemeng Shi , Nhat Pham , Baoquan He , Barry Song , Youngjun Park , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Jann Horn , Pedro Falcato , Hugh Dickins , Baolin Wang , Peter Xu , Johannes Weiner , Yosry Ahmed , Chengming Zhou Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, kernel-team@meta.com, Breno Leitao X-Mailer: b4 0.16-dev-f8e9d X-Developer-Signature: v=1; a=openpgp-sha256; l=989; i=leitao@debian.org; h=from:subject:message-id; bh=0eADPU9A+Bin6aphy+90if2YapwKINa2j/tvvdSh++4=; b=owEBbQKS/ZANAwAIATWjk5/8eHdtAcsmYgBqefvpGtHBBh+N6jpzTsBrdYBNmMXi5BcUh3JQQ lHLipIx1UqJAjMEAAEIAB0WIQSshTmm6PRnAspKQ5s1o5Of/Hh3bQUCann76QAKCRA1o5Of/Hh3 bXmiD/9LikOkeDPB49YFIg2IhmzZtXvnNr0DB8lO72WHE1E21H4aVITrHKKdxdxMglgwsd9T2GW QeSKLxSfxsUo95+eCNcHn7StmJbcLjhV9i9zS/qrzpeSMRWlGOhjGJxE3K6LsVno69+3MqSKHXT 8PzHFA/Xn2wUy94vxKXcYAaIsPCqUi+w84pOKYcMKIBfPcaHsm8FXRs2vJdaysU9nsR5Oxg39fN IlEKlObmPKCUHo/ylEKtjyUI6s775g7PCE4oNGDMnczXryYgr77zMJpYzvAF1sWIUph2js4AbDk /UzbhIJPoiDYipq0rlokHYMhhyFSzl2tZ0+cCn5+5vsmXILZvwtBbkvZMX9grBRlhG376hPZTXk NMOBCeu7ZXOQXdxZuUTYHLuJ7Jbdw+KMDh2WzNp28kXzCd5dZwKxh6t78TPFIJF+f1OxjFxEYnw iwNmbBMiA+D/yt6eUfDgxtLib2UuyA3HU9caVBHXEqAaFYRZHKtZK39IRg6FgClcfhDGa3EsM0f N6Clgnwb5OhBxMHU+QUuU8dpW9q4f2FrAQg/hnZ7GHRoxSFj+i6VknaTFC/R1AvSiMLsnJ7VqBw vvS7Eg2QesgK1EkKytzUygFS/K397+yPNVXMfXvOdH2ghcKN3kF7NbiYRvgamOfsOb1/37WGpj1 php6GfsLKC1SmpA== X-Developer-Key: i=leitao@debian.org; a=openpgp; fpr=AC8539A6E8F46702CA4A439B35A3939FFC78776D X-Debian-User: leitao do_swap_page() returns 0 when get_swap_device() fails, which the fault handler reads as "handled". For an entry that can never become valid the retry takes the same fault again, so the thread spins until it is killed. Return VM_FAULT_SIGBUS for a malformed entry, as the sibling arm already does for an unrecognised non-swap entry. A NULL return still means swapoff, which is still worth retrying. Signed-off-by: Breno Leitao --- mm/memory.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/mm/memory.c b/mm/memory.c index 4238778b66c42..2842cd976f1d3 100644 --- a/mm/memory.c +++ b/mm/memory.c @@ -4957,6 +4957,9 @@ vm_fault_t do_swap_page(struct vm_fault *vmf) /* Prevent swapoff from happening to us. */ si =3D get_swap_device(entry); if (IS_ERR_OR_NULL(si)) { + /* A malformed entry never becomes valid, so don't retry it. */ + if (IS_ERR(si)) + ret =3D VM_FAULT_SIGBUS; si =3D NULL; goto out; } --=20 2.53.0-Meta