From nobody Mon Sep 28 12:33:49 2026 Received: from mail-qk1-f179.google.com (mail-qk1-f179.google.com [209.85.222.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7BC79249EB for ; Fri, 21 Aug 2026 14:50:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787323810; cv=none; b=UV1o950sAGgH7zJXf4R/AXXVmm8BkfrvK0VfMYMertTPAwzy1px5+TqCt26k1+NQtTmaXBK9stSf4mo7Pivg06ef6VO5MopKvBL3LMwvDpKEBSvWuMLiiQOfQ8xG8s3pZQNFEKwqnjeeuUaKINRwgrQF6ee8ywMmqYy96j/xdTk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787323810; c=relaxed/simple; bh=3ccu2HigfgWBB9U+SNgXKO8NWiZvt5CXi/rwUSTZJRc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=edXhPUc+dfw5idNcw+T+uBUqIs1BSnGbUOWncOpWwVJztPOWKwEMgP+CHUns/LqRwlyDBZ8hTxvj4A0oJOt/uKBiHuMs6JtBXF26hU9kYmWOZ2dcORXg7L9T168XyPtBjdA28pPXSCxfJCOlF4vt6SUf18ul79raQ6eqYteVwa0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=gourry.net; spf=pass smtp.mailfrom=gourry.net; dkim=pass (2048-bit key) header.d=gourry.net header.i=@gourry.net header.b=SFgF1uUo; arc=none smtp.client-ip=209.85.222.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=gourry.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gourry.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gourry.net header.i=@gourry.net header.b="SFgF1uUo" Received: by mail-qk1-f179.google.com with SMTP id af79cd13be357-936dfd009d1so171651185a.1 for ; Fri, 21 Aug 2026 07:50:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gourry.net; s=google; t=1787323807; x=1787928607; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YBxF99leEnpt7qYGsswqI3Af5X25GbnSBysudSQY9XU=; b=SFgF1uUo2s1on3oIidEsRW/f/moAJnQBVLhefgVWSbRKyaSBVxYfxgfh40eLa9Rzwf IiV8IeZceZyVgZjJKjzDGUjlbqu07svw1GhnBjpI7lpPLv8R1iy6qGDDk81TNJMZ7B4H sz7jhTgWujVe3L4Uh2Gl7I5e5vQ075r5S8IHv1W2DnpHJyamk2T204Czm4lk1wclhno6 ZDdeytzxKS8qxi6NXrpUVdY+MYXglPUhU8Sm6KcDX8427iO/R3WKTkFcGrvF6ATruwqS TNdUhUIw+hTLnhhkv2kRWwjKHU9XZh1r6KJ/vMVcG10pXUVYkPqqGz2TSHXe24CJG07W 5H7w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787323807; x=1787928607; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=YBxF99leEnpt7qYGsswqI3Af5X25GbnSBysudSQY9XU=; b=keF++mpGL5hRbWP9z6+yrbqUOn9ujvZKfWSPgrSfQ9BpPVvGpXU9cxmn7eJOu1bjy/ ieQfrgq+yoe6X9lOv1lagz/GkKIbY+C2Fvf98t9iDic+jjw6SOoHYMCPIsgkfw9JFJ28 vcZYE9U9HFk7jcev6eYtCeBDI10eT9H4pnvEFHrgaSTaggLjYnDUMVXjibjxzqgwVeUo uxkGq+aKosJ16mE5bdoRtE5JLfsIOk4ZTXzHTUdmdDHAfcOVzNotC5hLft1WyMm2kNLh 9DjE/jx0kV/CUExIVL6b2/5eaU91rrMA+2Z/VcKhzI/rjQzz2ZPq3mKojxFQeZ/0WE4C BnWA== X-Gm-Message-State: AOJu0Yy59tcyIup1PpJU56blsgUoWVfovAQWZj3jwZMmFfiBSHiUGI7N 3MGeZ3TkdHwPWLYAWClwGGlgeNyb1FR/ydlb7GexRX0KaMSsv0sc95TFGB2YBBPd2GY= X-Gm-Gg: AR+sD11yUb9FwhQyfVtESC0xNooGkPMYZ8wF1DMsVrBZ5ax2T8qxtG69AwTPL5D5HfL 1mmxT5Of+GOkX271KpZj44FZ9nYAPWh9lEApXKK7AjHey0ocMrNNpHLgL3JHy0mxZuyFtxrHco0 kju+U0H1C61gbU+BRPoyiDgmea8pNrG8bpB/yhGzRcT0wonnMoCTCSgIBmw9gqLWFXBXzaYi5Fh w8MsianstmogYZBERk3jtgLDIM1ual2+agEIzN81lovzwpqlRpRD2GShkBfrUEQD6FGX3LDpjDO T+0TgUfRL5sZTJJAF4KS8z0yNJ2epTND1y+qVTaurKu4MDXE3ktEjw6EL1epchUOZw+r7SF/9KT K+J7WWiSromb9dvI0JhoaZjTLWO3lkPKa6rbdCD/7yVENGnc6wQ9JqXQBux8TeDBobmGcL1+5pP bodMzbpAJ75LBiSF6tcuT3KR1cL+5F396aFwAbVrUaFBSuTniHIZ1i9F+8ZpY3Cd+SSZP9yfUyX E/LDyXFmRTPvzfVf/Gl1iq1/Nndh3gmE0MjPPZjumRqQiYq/zVPod3TImxQ X-Received: by 2002:a05:620a:44d1:b0:936:e84a:b983 with SMTP id af79cd13be357-9373977c305mr408285485a.6.1787323807059; Fri, 21 Aug 2026 07:50:07 -0700 (PDT) Received: from gourry-fedora-PF4VCD3F.lan (pool-173-79-60-52.washdc.fios.verizon.net. [173.79.60.52]) by smtp.gmail.com with ESMTPSA id af79cd13be357-93720493f35sm609512385a.9.2026.08.21.07.50.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 07:50:06 -0700 (PDT) From: Gregory Price To: linux-mm@kvack.org Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com, akpm@linux-foundation.org, liam@infradead.org, ljs@kernel.org, david@kernel.org, vbabka@kernel.org, jannh@google.com, ziy@nvidia.com, matthew.brost@intel.com, joshua.hahnjy@gmail.com, rakie.kim@sk.com, byungchul@sk.com, gourry@gourry.net, ying.huang@linux.alibaba.com, apopple@nvidia.com, peterx@redhat.com, jgg@ziepe.ca, sashiko-bot , stable@vger.kernel.org Subject: [PATCH 1/2] mm/mempolicy: use vm_normal_folio_pmd() in queue_folios_pmd() Date: Fri, 21 Aug 2026 10:49:46 -0400 Message-ID: <20260821144947.167382-2-gourry@gourry.net> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260821144947.167382-1-gourry@gourry.net> References: <20260821144947.167382-1-gourry@gourry.net> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mmap a VM_PFNMAP region whose ->huge_fault installs a PMD through vmf_insert_pfn_pmd() - a vfio-pci MMIO BAR does this - then mbind(p, len, MPOL_BIND, &mask, maxnode, MPOL_MF_STRICT); With a stand-in module for the driver: BUG: unable to handle page fault for address: fffff96dc0000008 RIP: 0010:queue_folios_pte_range+0xaf/0x440 walk_pgd_range+0x52b/0xaf0 __walk_page_range+0x6a/0x1d0 walk_page_range_mm_unsafe+0x193/0x230 queue_pages_range+0x64/0xa0 do_mbind+0x25e/0x640 queue_folios_pmd(), inlined above, calls pmd_folio() on that PMD. The pfn is raw MMIO with no memmap entry, so the folio lands in unpopulated vmemmap. Neither guard stops the walk: walk_page_test() skips VM_PFNMAP, but queue_pages_walk_ops supplies ->test_walk, so it never runs queue_pages_test_walk() honours vma_migratable(), but only while MPOL_MF_STRICT is clear A VM_MIXEDMAP vma needs neither flag, being vma_migratable(), so plain mbind(MPOL_MF_MOVE) reaches this too - and there the bad folio carries on into migrate_folio_add() and folio_isolate_lru(). mshv_vtl_low is such a mapping. Use vm_normal_folio_pmd() and skip on NULL, as the PTE loop in queue_folios_pte_range() already does with vm_normal_folio(). The huge zero PMD moves ahead of the lookup, since vm_normal_folio_pmd() returns NULL for it and its ACTION_CONTINUE would be lost. mbind(MPOL_MF_STRICT) over a PMD mapped VM_PFNMAP region now returns 0 rather than -EIO. The PTE loop already returned 0 there. Fixes: 3c8e44c9b369 ("mm: mark special bits for huge pfn mappings when inje= ct") Reported-by: sashiko-bot Closes: https://sashiko.dev/#/patchset/20260817220810.1175596-1-gourry%40go= urry.net Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Gregory Price (Meta) Acked-by: David Hildenbrand (Arm) --- mm/mempolicy.c | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/mm/mempolicy.c b/mm/mempolicy.c index f1aba551f9f1..85803c845965 100644 --- a/mm/mempolicy.c +++ b/mm/mempolicy.c @@ -650,7 +650,8 @@ static inline bool queue_folio_required(struct folio *f= olio, return node_isset(nid, *qp->nmask) =3D=3D !(flags & MPOL_MF_INVERT); } =20 -static void queue_folios_pmd(pmd_t *pmd, struct mm_walk *walk) +static void queue_folios_pmd(pmd_t *pmd, unsigned long addr, + struct mm_walk *walk) { struct folio *folio; struct queue_pages *qp =3D walk->private; @@ -661,13 +662,15 @@ static void queue_folios_pmd(pmd_t *pmd, struct mm_wa= lk *walk) qp->nr_failed++; return; } - folio =3D pmd_folio(pmdval); - if (folio_is_zone_device(folio)) - return; - if (is_huge_zero_folio(folio)) { + if (is_huge_zero_pmd(pmdval)) { walk->action =3D ACTION_CONTINUE; return; } + folio =3D vm_normal_folio_pmd(walk->vma, addr, pmdval); + if (!folio) + return; + if (folio_is_zone_device(folio)) + return; if (!queue_folio_required(folio, qp)) return; if (!(qp->flags & (MPOL_MF_MOVE | MPOL_MF_MOVE_ALL)) || @@ -700,7 +703,7 @@ static int queue_folios_pte_range(pmd_t *pmd, unsigned = long addr, =20 ptl =3D pmd_trans_huge_lock(pmd, vma); if (ptl) { - queue_folios_pmd(pmd, walk); + queue_folios_pmd(pmd, addr, walk); spin_unlock(ptl); goto out; } --=20 2.55.0 From nobody Mon Sep 28 12:33:49 2026 Received: from mail-qk1-f180.google.com (mail-qk1-f180.google.com [209.85.222.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 14E3E4399C6 for ; Fri, 21 Aug 2026 14:50:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787323811; cv=none; b=BGdgw9ntyus/Rtc79HXSN/ES8sUP2wQhYfHDgXjWssZouthsMdj6LaD9nq3gXfYpoZyojhnZCU7xSJLLYqCMBSwFcBtCKuYXMXgH6zGjv8oNQeRak9l0xwVaqeDb7EubdHMiOGj3gStGH+i9FbWqDOz9Pe4Y6EuQxgGKk8AUvLo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787323811; c=relaxed/simple; bh=iklPJf6SRkdTgIf0pIUi3KtDJ+NhLLaqrV1rClnN86I=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rMkzU1eOE/7xPQb17C4b+QHWFBNigjBdrhpoMlZOKW3P35J6UFH8gfp6X73lGL150AMBHtOhfgQsWYRntY1T+7JBr1h6Srrel+troiXyEpS2g4q7q4Lgb+EcLmMqZ/ck/M9kTFWXpRPXyYaUlY75XrHjn7uVqrtnnsD179YRR+U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=gourry.net; spf=pass smtp.mailfrom=gourry.net; dkim=pass (2048-bit key) header.d=gourry.net header.i=@gourry.net header.b=mIfkXN7v; arc=none smtp.client-ip=209.85.222.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=gourry.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gourry.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gourry.net header.i=@gourry.net header.b="mIfkXN7v" Received: by mail-qk1-f180.google.com with SMTP id af79cd13be357-936c02e58dfso65231485a.3 for ; Fri, 21 Aug 2026 07:50:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gourry.net; s=google; t=1787323809; x=1787928609; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xsVHSsNBVmunDbjw2peBUvjMtVALhYSkX0xXozMheRU=; b=mIfkXN7vCh0Fr9TLCuumrtWEMWt+/1WoES3IW4MAuZO0l0FRW2Gy7n6y1jTLO+N9U9 1bW77xLNKE0PYMXFAjHFEgtPfdXuUwMU+5O422gI/QZk3DHWmanLxuiInN9JrTP7bKYe koofAGVLXohTxvARlaQLd8zpAvrpOluiwiXv4TQEY/9L3VUmHrIzwSg8nfMjE6HNP6EH hAcwyE6+neK2Ec5FOUUdM7ip2y5vBXkJKK0cW1SzEOpQAGyrOTe9we8R0gJmRRrWvJRc rP78Gg1LpZzDbEZgRvO3y0Gz+MG8jMu5HOC0+9nTSjL8ACAXxuqtsceSsJBunyuZjfTB b1dQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787323809; x=1787928609; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=xsVHSsNBVmunDbjw2peBUvjMtVALhYSkX0xXozMheRU=; b=FZ2/LffHlcbyDf1Dzkd7MgDzsRspB3m114MMTo8eeu86CW2zAm7WJic645IOfIGecs kIJTSf3si4suIDQOgrjPHISEqnVSilo0HvhRJ7wA1vMOzVIR2vf2TbJdvoEWCt7qYPcO 9VkI0aLRQzolqUlFZMFwY4DpGyJov8E1fsEl+g5SQUMHL8gYigLRmF0hdUKRWVVar5Gs 9kVloWsSLMUsKmoOBmoVWSZqVchMbbJL9JitxemXr64hikd8KVMO3BWwvnRseCXZeSgD wpDrxNpg+yfttDGvV9YYdRaPb2Clkcqy3Qfqf8yDsx5cw8jnYIS5doxKvZse5gR48y/U /0vg== X-Gm-Message-State: AOJu0YxZP9XiZ5x5YLE6FrY8XRwmwIWo0ZUaLFUz3wMzGAok78ytYSqN I8LZFn8sqbdT9CB69DyoffLxU9f441znP8AgKXBkNp/WeDGjN64WpeCThNClO0tXBiQ= X-Gm-Gg: AR+sD11fQlUU/Efo+UWa8woK82A02nnArXCD9++YnwT5d1IB+orh7l+FLDr568JovLc KeestDkb2i8wb0QWiTAuHwsR8nJb9u6K2B/Q2s8naY87Zk+5oYpXkANthgfkwgz8rqhb+/5mBkK QZsjA6yBqyTJM7D0tLQagrBHbaw6ll4Vr7VYy9/B3O4ua9X/gGO3+AeASjF7CRnKBmm/95PutJC +FiZRt88iv4o0ZxzbYeDWufnoevVtsT4vWGoFW79N5SI0si3mNEXHvWDjh5Mss6s0uVdFcGWr7Q zTTjW8wssJecFXcDPM/lhiU6Jout1IJdnwHKI1irFVC8rM8yAC76IQM07oqW3/LnEQgwcfp3vSv lO2Q3JC0tZR4xvyXn8h/KVMyGuHPqZsUkBMytVwzByFHYSWRCvlzCzWF3ch9S1EfjRcmIQuM32Z WZeSo94vrCjIEUd2WnVzjiPw2ebNZGIjZTxzQmAIdxkD+RlmKCcq/matUHy4RgPr8ixcaQQD8e4 d0rONhjsDvLFNwPsvRDvnezjQvFjMqiECYRYZPTXTMFzshPog== X-Received: by 2002:a05:620a:70f2:b0:92e:603f:1f20 with SMTP id af79cd13be357-937394e9257mr431611785a.2.1787323808787; Fri, 21 Aug 2026 07:50:08 -0700 (PDT) Received: from gourry-fedora-PF4VCD3F.lan (pool-173-79-60-52.washdc.fios.verizon.net. [173.79.60.52]) by smtp.gmail.com with ESMTPSA id af79cd13be357-93720493f35sm609512385a.9.2026.08.21.07.50.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 07:50:08 -0700 (PDT) From: Gregory Price To: linux-mm@kvack.org Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com, akpm@linux-foundation.org, liam@infradead.org, ljs@kernel.org, david@kernel.org, vbabka@kernel.org, jannh@google.com, ziy@nvidia.com, matthew.brost@intel.com, joshua.hahnjy@gmail.com, rakie.kim@sk.com, byungchul@sk.com, gourry@gourry.net, ying.huang@linux.alibaba.com, apopple@nvidia.com, peterx@redhat.com, jgg@ziepe.ca, sashiko-bot , stable@vger.kernel.org Subject: [PATCH 2/2] mm/madvise: use vm_normal_folio_pmd() in cold/pageout PMD range Date: Fri, 21 Aug 2026 10:49:47 -0400 Message-ID: <20260821144947.167382-3-gourry@gourry.net> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260821144947.167382-1-gourry@gourry.net> References: <20260821144947.167382-1-gourry@gourry.net> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mmap a VM_MIXEDMAP region whose ->huge_fault installs a PMD through vmf_insert_pfn_pmd() - mshv_vtl_low does this, and needs CAP_SYS_ADMIN to open - then madvise(p, PMD_SIZE, MADV_PAGEOUT); With a stand-in module for the driver: BUG: unable to handle page fault for address: fffff587c0000008 RIP: 0010:madvise_cold_or_pageout_pte_range+0x410/0x9b0 walk_pgd_range+0x52b/0xaf0 __walk_page_range+0x6a/0x1d0 walk_page_range_vma_unsafe+0x8e/0x120 madvise_pageout+0xb2/0x180 madvise_vma_behavior+0x46b/0xa90 do_madvise+0x108/0x190 __x64_sys_madvise+0x26/0x30 Nothing validates the pfn on the way in: can_madv_lru_vma() rejects VM_PFNMAP, but not VM_MIXEDMAP can_fault() *pfn =3D vmf->pgoff & ~(mask >> PAGE_SHIFT); vmf_insert_pfn_pmd() no pfn_valid() check pmd_folio() pfn_to_page() -> unpopulated vmemmap Even with a valid pfn the path is wrong. The mapping carries no rmap, so folio_maybe_mapped_shared() sees mapcount 0, and the walker goes on to folio_deactivate(), or folio_isolate_lru() plus reclaim_pages(), against a folio this mapping does not own. Use vm_normal_folio_pmd() and skip on NULL, as the PTE half of this same walker already does with vm_normal_folio(). The huge zero PMD is already handled further up by is_huge_zero_pmd(). Fixes: 3c8e44c9b369 ("mm: mark special bits for huge pfn mappings when inje= ct") Reported-by: sashiko-bot Closes: https://sashiko.dev/#/patchset/20260817220810.1175596-1-gourry%40go= urry.net Cc: # v6.19+ Assisted-by: Claude:claude-opus-5 Signed-off-by: Gregory Price (Meta) --- mm/madvise.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/mm/madvise.c b/mm/madvise.c index ffd6a68320a8..ab362bc482a5 100644 --- a/mm/madvise.c +++ b/mm/madvise.c @@ -393,7 +393,9 @@ static int madvise_cold_or_pageout_pte_range(pmd_t *pmd, goto huge_unlock; } =20 - folio =3D pmd_folio(orig_pmd); + folio =3D vm_normal_folio_pmd(vma, addr, orig_pmd); + if (!folio) + goto huge_unlock; =20 if (folio_is_zone_device(folio)) goto huge_unlock; --=20 2.55.0