From nobody Mon Sep 28 06:38:16 2026 Received: from canpmsgout06.his.huawei.com (canpmsgout06.his.huawei.com [113.46.200.221]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2CAED3F54D3 for ; Tue, 25 Aug 2026 12:21:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.221 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787660499; cv=none; b=Fi+khIaHEHf3+c91ldR7Jh6cxLoe/Mn7WoUQQ2kCRewwFCK1DCiOejRppfzNfdnRq1MqYGnreJO4LigMot7rY7Q/jpDJFi+5Rw0CLdXfjgJqjhiTQw6l3CdDca5uRmwM9IEiVWS1jqPVAyIoYIg7+nzS0yaidXrWbr8mNG3AWpY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787660499; c=relaxed/simple; bh=JQdjrxwjpYlvOJ6KyY724/mi0/KMKfdhDXy5gDcDk5M=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=SgPL2kcjdwiMKjHvsyZFd/O8A4G2CorsghUJuZ3kN0KOzZn16/KkJiiS7MpCnDzNx/kva5Giuh4jIa8cpNjfn7ourG56GHdgVyE/YLcvxTonIzpws5JbXSlW90P6wgC/tjuopIjJjaHxohv6Wb5qiMu+H4Z3BQjR549RVdaz20E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=RpHvSnmF; arc=none smtp.client-ip=113.46.200.221 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="RpHvSnmF" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=2+yU2iTET97sRJAGTn5W0IvEia2BUUbmJ1Zs5LLHB3Y=; b=RpHvSnmFdWztqQ06v5lfMfWUFuh3MTIgKMj2yyhUTkGbHpY5ZTxpsFlenNssTOyC0goqcNDq7 PXuxyBfVe1f3HlAz9fzmSDCBsgpQRodPccoYxcEcQ+NbfAxCZmYLgnfmOVS+w2OOKnhZ75JCjFH Q59/nkiFkzqhBli/DwSo/ec= Received: from mail.maildlp.com (unknown [172.19.162.140]) by canpmsgout06.his.huawei.com (SkyGuard) with ESMTPS id 4hTmnt2FJFzRhR0; Tue, 25 Aug 2026 20:10:42 +0800 (CST) Received: from kwepemo200010.china.huawei.com (unknown [7.202.195.178]) by mail.maildlp.com (Postfix) with ESMTPS id 76C6A202E6; Tue, 25 Aug 2026 20:21:25 +0800 (CST) Received: from huawei.com (10.44.142.85) by kwepemo200010.china.huawei.com (7.202.195.178) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Tue, 25 Aug 2026 20:21:24 +0800 From: Qi Xi To: Andrew Morton , Vlastimil Babka CC: Suren Baghdasaryan , Michal Hocko , Brendan Jackman , Johannes Weiner , Zi Yan , , , , , Subject: [PATCH v3 1/2] mm/page_isolation: fix UBSAN shift-out-of-bounds warning Date: Tue, 25 Aug 2026 20:05:48 +0800 Message-ID: <20260825120549.966271-2-xiqi2@huawei.com> X-Mailer: git-send-email 2.33.0 In-Reply-To: <20260825120549.966271-1-xiqi2@huawei.com> References: <20260825120549.966271-1-xiqi2@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems200001.china.huawei.com (7.221.188.67) To kwepemo200010.china.huawei.com (7.202.195.178) Content-Type: text/plain; charset="utf-8" A contig-range allocation racing with buddy allocation on the adjacent pageblock can trigger: UBSAN: shift-out-of-bounds in mm/page_isolation.c:393:15 shift exponent -749042176 is negative Call trace: isolate_single_pageblock start_isolate_page_range alloc_contig_frozen_range_noprof alloc_contig_range_noprof isolate_single_pageblock() first calls set_migratetype_isolate() with zone->lock held, which marks the pageblock MIGRATE_ISOLATE and moves any free page straddling the boundary out of the way. Once the lock is dropped, it scans the MAX_ORDER_NR_PAGES-aligned window [start_pfn, boundary_pfn) locklessly, only to skip the free pages already handled above and to detect in-use pages straddling the boundary. Since this scan only reads page state to decide how far to skip and returns -EBUSY on a straddling in-use page, it does not take the lock. The window also covers the adjacent pageblock, whose free pages stay on the normal movable/CMA freelist and can be allocated concurrently. So after the scan observes PageBuddy(page), another CPU can allocate the page, leaving a stale value in page->private that makes "1 << order" shift out of range. Use buddy_order_unsafe() with READ_ONCE to read the order, and validate it is within MAX_PAGE_ORDER before shifting to prevent UBSAN warnings. Since pageblock_isolate_and_move_free_pages() already handles free pages straddling boundary_pfn under zone->lock, bail out with -EBUSY instead of VM_WARN_ON_ONCE() when a PageBuddy page appears to cross the boundary during the lockless scan. Fixes: b2c9e2fbba32 ("mm: make alloc_contig_range work at pageblock granula= rity") Cc: stable@vger.kernel.org Reviewed-by: Zi Yan Signed-off-by: Qi Xi --- mm/page_isolation.c | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/mm/page_isolation.c b/mm/page_isolation.c index 32ce8a7d9df3..61efc03500ef 100644 --- a/mm/page_isolation.c +++ b/mm/page_isolation.c @@ -387,13 +387,19 @@ static int isolate_single_pageblock(unsigned long bou= ndary_pfn, } =20 if (PageBuddy(page)) { - int order =3D buddy_order(page); + unsigned int order =3D buddy_order_unsafe(page); =20 - /* pageblock_isolate_and_move_free_pages() handled this */ - VM_WARN_ON_ONCE(pfn + (1 << order) > boundary_pfn); - - pfn +=3D 1UL << order; - continue; + /* buddy_order_unsafe() is racy. Validate the order before shifting. */ + if (order <=3D MAX_PAGE_ORDER && + /* + * pageblock_isolate_and_move_free_pages() splits + * cross-boundary PageBuddy, verify it. + */ + pfn + (1UL << order) <=3D boundary_pfn) { + pfn +=3D 1UL << order; + continue; + } + goto failed; } =20 /* --=20 2.33.0 From nobody Mon Sep 28 06:38:16 2026 Received: from canpmsgout07.his.huawei.com (canpmsgout07.his.huawei.com [113.46.200.222]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9D69A422540 for ; Tue, 25 Aug 2026 12:21:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.222 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787660499; cv=none; b=mpAkAUPcImQ83Xs1pQrvP/hyGrC+3zM+ImJDkcpDp6DIge7WYuDhkuNrd5DQJRQxLcvL/U2Xf+dJwPc5cJ/5RPHd0MtnyiY5WaBr6VBF5dH6dnyjnJ9ikm8RFMA/QCgiGdvnESsc9Rf1/ILZsFfpknZ65zw9ha54nM7XG9Q+o5o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787660499; c=relaxed/simple; bh=jK432yXijioQoBZ2vNiTkaJSO9u67D3xA8SNt0u95XY=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=ii/YgZBm4LxlqNAePdn0JZ0bQaJpfMCnfkaHpiBJv9nGT2W0VCfh2TDhS36oi9f8AbtxGS/IQ5pVOSAa5nbskNNDjWBIdLKCemeQSWj10dQ3CrNa3aSJ70rhJMBry1AkA42eVET4wpCkOkQEGU2b16iqi7umMvWBxE0SyFrAeI8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=QojxQPHB; arc=none smtp.client-ip=113.46.200.222 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="QojxQPHB" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=ZT765UJFYyMTJoOY408mF7kpDLgZOjbYjc0ctgYvIGo=; b=QojxQPHB6N8tDMeJFSG82r1iHX1BVlZHZrbQSWRiFspic1EIA+RwZ0FC0jGJskGYu5RmgraAv c65bZaRMxp4ipe8VBMIWIkUjlkCaDKLeFIEvCiXFpRgJIqA0s5pxfkPvUyTWbTdfomQ63LlmQhd k+uB+ArmyiEZPXYoTpz7CEs= Received: from mail.maildlp.com (unknown [172.19.163.214]) by canpmsgout07.his.huawei.com (SkyGuard) with ESMTPS id 4hTmnr5Xj8zLlTk; Tue, 25 Aug 2026 20:10:40 +0800 (CST) Received: from kwepemo200010.china.huawei.com (unknown [7.202.195.178]) by mail.maildlp.com (Postfix) with ESMTPS id D27664056C; Tue, 25 Aug 2026 20:21:25 +0800 (CST) Received: from huawei.com (10.44.142.85) by kwepemo200010.china.huawei.com (7.202.195.178) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Tue, 25 Aug 2026 20:21:25 +0800 From: Qi Xi To: Andrew Morton , Vlastimil Babka CC: Suren Baghdasaryan , Michal Hocko , Brendan Jackman , Johannes Weiner , Zi Yan , , , , , Subject: [PATCH v3 2/2] mm/page_isolation: guard compound_order() against racing Date: Tue, 25 Aug 2026 20:05:49 +0800 Message-ID: <20260825120549.966271-3-xiqi2@huawei.com> X-Mailer: git-send-email 2.33.0 In-Reply-To: <20260825120549.966271-1-xiqi2@huawei.com> References: <20260825120549.966271-1-xiqi2@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems200001.china.huawei.com (7.221.188.67) To kwepemo200010.china.huawei.com (7.202.195.178) Content-Type: text/plain; charset="utf-8" The PageCompound branch reads compound_head() without holding a reference. A racing split or free can cause compound_head() to return a stale pointer, and compound_nr() reads the order from that stale head, leading to out-of-range shifts and making the skip distance meaningless. Read the order explicitly with compound_order() and validate it is within MAX_FOLIO_ORDER before shifting. Also verify the derived head_pfn against the legitimate pfn: the head must not be past pfn, must be aligned to nr_pages, and pfn must fall within the compound page. Bail out with -EBUSY if any check fails. Fixes: b2c9e2fbba32 ("mm: make alloc_contig_range work at pageblock granula= rity") Cc: stable@vger.kernel.org Suggested-by: Zi Yan Reviewed-by: Zi Yan Signed-off-by: Qi Xi --- mm/page_isolation.c | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/mm/page_isolation.c b/mm/page_isolation.c index 61efc03500ef..eca6fb78f73a 100644 --- a/mm/page_isolation.c +++ b/mm/page_isolation.c @@ -418,10 +418,28 @@ static int isolate_single_pageblock(unsigned long bou= ndary_pfn, if (PageCompound(page)) { struct page *head =3D compound_head(page); unsigned long head_pfn =3D page_to_pfn(head); - unsigned long nr_pages =3D compound_nr(head); + unsigned int order =3D compound_order(head); + unsigned long nr_pages; + + /* compound_order() is racy. Cap it at MAX_FOLIO_ORDER. */ + if (order > MAX_FOLIO_ORDER) + goto failed; + + nr_pages =3D 1UL << order; + + /* + * compound_head() is also racy, so the derived head_pfn + * needs additional checks to make sure it is valid. + * Otherwise, just fail the check. pfn comes from + * __first_valid_page() as a legitimate PFN, so use it to + * check head_pfn. + */ + if (head_pfn > pfn || !IS_ALIGNED(head_pfn, nr_pages) || + pfn - head_pfn >=3D nr_pages) + goto failed; =20 if (head_pfn + nr_pages <=3D boundary_pfn || - PageHuge(page)) { + PageHuge(head)) { pfn =3D head_pfn + nr_pages; continue; } --=20 2.33.0