From nobody Sat Sep 26 23:51:52 2026 Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 98ABE41C6A for ; Fri, 28 Aug 2026 05:59:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787896794; cv=none; b=Sl/TKamjwEyY4h6wrtZXMmCk+Kb3JEgtVwGQalHqEChKeNHzrcWfpfbY+yHVLwKrSzWKQ+07dHWIg09SF4ryqe0r/V3EBI0hCnzWislMO/rIsi3882el+Mw7QyKGeaS3XNsOE5vUIUI0/riO6Whl3PioUYDA2AUxGy9TfGuxLNY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787896794; c=relaxed/simple; bh=fb1Dg6UJ5xV3K13FUqbr+ufWbZWL87oJPMlhvOJgiKg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EfnGMOI5Qbj+nXSIMBbVoegB2ZJUCtYyjFr8uO8O5eAbtOoj40VY+ZCs1jAulZ4IgybpJhi6L7NEfmP3OlNdA9RPkR5Q77bRT4E1WrqJ1GgqVWWULyTNdwTNlmoJ4EwGX2MPPUOJegTSTTLw0X84F6tq5zdSk9ry5HmtDcJEZmI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OIXNMYfn; arc=none smtp.client-ip=209.85.216.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OIXNMYfn" Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-3969e82ff8fso619162a91.0 for ; Thu, 27 Aug 2026 22:59:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787896793; x=1788501593; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=W67g2+Dtuws6uyQi/Oz6Kv22fM7UlvitqiW6NCwEKwg=; b=OIXNMYfnmYEh2T4adY6Wvk397NssYgrFi9HjSz43+1w1+GGthJmSlrcow795FqLzv0 ck8u3AFSxs39PzqFScXkOSix6AHy4FeFOflj9SJqtzVVNgIdTllAq5QlIF17wiaHyveV RhKzEwr8yk+0x92rEym/vbgCDcy4owwPbI0d4r4imYc2fxxfsCiIiC9eFOQ4EXwiWmyT LOfjOkS8mzhl8j82CZE0armprY2PSJRHAzx4xz+yz8Yzrs3WT9IJCqyFkyOgEiSyfbtt y51RciL/N6b4GT/Ibcd5byDQrc55OTOQCwJuVPEjZxfs7R+4kNzTgf2h9Vd4VE3R1xQR zP2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787896793; x=1788501593; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=W67g2+Dtuws6uyQi/Oz6Kv22fM7UlvitqiW6NCwEKwg=; b=bm5h6JFySmUxnWjubyuR8a5mjqkYKELka7yjFO6um9+F9DjTrkrxa3f+c6Y2us0/Rx qG31VcZY+WZ4dL0HOjpDoqL4WpTs5nn3dkMjWQ8MvpxCKQVJHnCcifUm8Sc3F/Xs8frR po9cLQOvzgimwyXbRVqOiRWZe9aYonbrKW4zcvZo+5FUfrsdH/OKuXTuvEYKzdrvRHNp wugqJ4jDq6GKt8gUE3JJw0sE4T0EmrKc+P1M0mKJNtnFq4YOiY8m113SOFP+iJCwMlwY rpZxjpbStsKJSLbuJzrI/Li8JNwM1ARY3AS16Hk9rdjhgxqmLsRHaWmkQTTNAZDYWB4i CqCw== X-Forwarded-Encrypted: i=1; AHgh+RqupDuBZ7fQpvvmxf9sk+E+avzOoFlZkEgTUysmpxLOk5O6i6sjMumUk21CsQ1eESkSPHhsOeMGGXO7i18=@vger.kernel.org X-Gm-Message-State: AFuF++lpxjMMStOsxSpdfqBSiI07ewYH3vWDPfKQVo6MyeR5ThZMriab 1rfxNfpSDCycdUANR8btmgXxiIlOCYevwQhaz51bTjPp5jCj+xC0OaW0 X-Gm-Gg: AR+sD12FO40KDN89vx2mWy5ZhwHwF143/VXy1YyPNctviRQ1u1fEIc2/mJinqdohlCW vscA3ROLMIxfgrbSrN/nedXza5UcKGduzOzP2CZcxdLKFTdep3lJoFGwiIOZBudrTSaACNjvfOC iJveoCS8EcGABeLUzNcGuqzDicGlt8RhGQk1zNAT8sPi0eO9L/uxn3d0QwznmpQ5X8hGP9GavRj S05bHX5/6/1OkyFkT6px5S1T4lzlpnejDi2+La6jQOoFVw8czsbv15vCs1XmxhqUhYdbMY98OhP shk0GRHYt/2ianAVGCv03dbq8QRO9lMIbPefmI4tRfM2IdudkDZkjxNqQFhf36XMG5WiC8YraY1 X3VJFgKz5NZOP2D3UWCEJBwDLC5c6u/E2sGmfTxrreyGc9m0hxrJV9vdKVnQSPR9giH5FnROygh pV0/3GpaBWpaCRjH0ILn0TIlSO4I1DwA0CA8QVqO9FDLuPilj8f3HXt+F/1LH2or4Ly6FqzQDbT 1d/TAYHdKegHQ== X-Received: by 2002:a17:90b:5405:b0:38e:67e1:15b with SMTP id 98e67ed59e1d1-396d0de4c19mr9263684a91.6.1787896792757; Thu, 27 Aug 2026 22:59:52 -0700 (PDT) Received: from localhost.localdomain ([240e:b8f:1df9:a600:c693:b19f:ada0:748]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-396b0ea808csm5826241a91.2.2026.08.27.22.59.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Aug 2026 22:59:52 -0700 (PDT) From: Vernon Yang To: akpm@linux-foundation.org, david@kernel.org, ljs@kernel.org Cc: nico.pache@linux.dev, ryan.roberts@arm.com, dev.jain@arm.com, baohua@kernel.org, lance.yang@linux.dev, usama.arif@linux.dev, zokeefe@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, stable@vger.kernel.org, Vernon Yang Subject: [PATCH v4 1/3] mm: khugepaged: fix swap entry value to folio_pfn() Date: Fri, 28 Aug 2026 13:59:24 +0800 Message-ID: <20260828055926.346744-2-vernon2gm@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260828055926.346744-1-vernon2gm@gmail.com> References: <20260828055926.346744-1-vernon2gm@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vernon Yang When the swap entries found exceed max_ptes_swap, the loop is left via break with folio still holding the xarray value that encodes the swap entry, not valid folio pointer. That value is passed to trace_mm_khugepaged_scan_file(), which feeds it to folio_pfn(). On FLATMEM and SPARSEMEM_VMEMMAP, the page_to_pfn() is plain pointer arithmetic, so the trace event merely prints bogus scan_pfn. On classic SPARSEMEM, the page_to_pfn() reads page->flags, dereferencing the tiny encoded integer and oopsing khugepaged whenever the trace event is enabled. So when folio is the swap entry value, simply set pfn to -1, just like exhausted scan naturally. And the folio_put() has maybe dropped the last reference of folio. The trace_mm_khugepaged_scan_file() is left with a dangling folio pointer. so using the folio_pfn() before dropping the reference, closing use-after-free window. About calling the respective trace_xxx() functions separately on success and failure, refer to [1]. [1] https://lore.kernel.org/linux-mm/ao6jVbVHLUmuY2UA@gremlin/ Fixes: d41fd2016ed0 ("mm/khugepaged: add tracepoint to hpage_collapse_scan_= file()") Cc: stable@vger.kernel.org Signed-off-by: Vernon Yang Acked-by: David Hildenbrand (Arm) --- include/trace/events/huge_memory.h | 6 +++--- mm/khugepaged.c | 11 ++++++++++- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/include/trace/events/huge_memory.h b/include/trace/events/huge= _memory.h index 5a48c5406cce..7b526528f85b 100644 --- a/include/trace/events/huge_memory.h +++ b/include/trace/events/huge_memory.h @@ -178,10 +178,10 @@ TRACE_EVENT(mm_collapse_huge_page_swapin, =20 TRACE_EVENT(mm_khugepaged_scan_file, =20 - TP_PROTO(struct mm_struct *mm, struct folio *folio, struct file *file, + TP_PROTO(struct mm_struct *mm, unsigned long pfn, struct file *file, int present, int swap, int result), =20 - TP_ARGS(mm, folio, file, present, swap, result), + TP_ARGS(mm, pfn, file, present, swap, result), =20 TP_STRUCT__entry( __field(struct mm_struct *, mm) @@ -194,7 +194,7 @@ TRACE_EVENT(mm_khugepaged_scan_file, =20 TP_fast_assign( __entry->mm =3D mm; - __entry->pfn =3D folio ? folio_pfn(folio) : -1; + __entry->pfn =3D pfn; __assign_str(filename); __entry->present =3D present; __entry->swap =3D swap; diff --git a/mm/khugepaged.c b/mm/khugepaged.c index 75639298efc2..b597a3e68606 100644 --- a/mm/khugepaged.c +++ b/mm/khugepaged.c @@ -2683,6 +2683,7 @@ static enum scan_result collapse_scan_file(struct mm_= struct *mm, int present, swap; int node =3D NUMA_NO_NODE; enum scan_result result =3D SCAN_SUCCEED; + unsigned long failed_pfn =3D -1; =20 present =3D 0; swap =3D 0; @@ -2715,6 +2716,7 @@ static enum scan_result collapse_scan_file(struct mm_= struct *mm, =20 if (is_pmd_order(folio_order(folio))) { result =3D SCAN_PTE_MAPPED_HUGEPAGE; + failed_pfn =3D folio_pfn(folio); /* * PMD-sized THP implies that we can only try * retracting the PTE table. @@ -2726,6 +2728,7 @@ static enum scan_result collapse_scan_file(struct mm_= struct *mm, node =3D folio_nid(folio); if (collapse_scan_abort(node, cc)) { result =3D SCAN_SCAN_ABORT; + failed_pfn =3D folio_pfn(folio); folio_put(folio); break; } @@ -2733,12 +2736,14 @@ static enum scan_result collapse_scan_file(struct m= m_struct *mm, =20 if (!folio_test_lru(folio)) { result =3D SCAN_PAGE_LRU; + failed_pfn =3D folio_pfn(folio); folio_put(folio); break; } =20 if (folio_expected_ref_count(folio) + 1 !=3D folio_ref_count(folio)) { result =3D SCAN_PAGE_COUNT; + failed_pfn =3D folio_pfn(folio); folio_put(folio); break; } @@ -2771,9 +2776,13 @@ static enum scan_result collapse_scan_file(struct mm= _struct *mm, } else { result =3D collapse_file(mm, addr, file, start, cc); } + trace_mm_khugepaged_scan_file(mm, -1, file, present, swap, + SCAN_SUCCEED); + } else { + trace_mm_khugepaged_scan_file(mm, failed_pfn, file, present, + swap, result); } =20 - trace_mm_khugepaged_scan_file(mm, folio, file, present, swap, result); return result; } =20 --=20 2.53.0 From nobody Sat Sep 26 23:51:52 2026 Received: from mail-pj1-f47.google.com (mail-pj1-f47.google.com [209.85.216.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D886241C6A for ; Fri, 28 Aug 2026 05:59:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787896800; cv=none; b=JjykCCtQbFIGwcMheyjfajvJ43Oi3q2Epzjt/Ps9AtvQs/fWN05QifrFC0f41FplzSkAQRgQKJOthDa3kkRvQ7w29V9406rdZixwidQTrQH6MxrRjtijYPwaz0n/gW5AfXPBAPB5TxSTBI4Gj0lWLa1pSVmKS3wPtu807nSc6sw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787896800; c=relaxed/simple; bh=xqzn9VzOzXthsGZCeQ/UCMTMeDqmtcMCdFN82+11dso=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=sz+N0BNfzSm5sRMzAhpl0nEmVcSjidNpfIVFULQJcc0DeYMJ2jxkeHMhfec+DYr6b1av7We6ICsr6is4mi8TVq3M+7Y/S9Co5FSuXhXyrMbQk0h2oclKb+Hrr77DnP9NrviVL/hw5Cm4Swmv79XDv6nnqWq2xkv2DID2AUMTeB4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nWTvH3Rb; arc=none smtp.client-ip=209.85.216.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nWTvH3Rb" Received: by mail-pj1-f47.google.com with SMTP id 98e67ed59e1d1-381b831d535so1317936a91.0 for ; Thu, 27 Aug 2026 22:59:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787896798; x=1788501598; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=v7VK6Qr7VyOU0DiKXFkET6z2QkJwdvjQa2S5pL5XscY=; b=nWTvH3RbXCZV/Ec7kh4pJbPbxzVeTiNJBs1rht4tZ/wseSyYzLb+9ULfyIA6FGlBOi S/jlnPByXn74M/kHiCCZEtmfxBCKBhoriAIhO11Du8hY13XYuJSgwczUu5UkVMnusFPG EKmpEdBtM6k6icmC9M5nu3VxXkQJgSRVMzid4Q+rpa4r7ViKng0AD5NADL0zp/I/2tGD VE8SKOmgHEhrmM6F+lsixorN+UffHOnF89NJ+5HxCiV7Pd3eSOO62Gd/HFjZ5jQLZQcc XXL0vVS607KDe9D5ZIT7IILee4FCPLvs7V9XGpOkLmFMn0VwYDb2dxFdkes6foTwgRLc csjg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787896798; x=1788501598; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=v7VK6Qr7VyOU0DiKXFkET6z2QkJwdvjQa2S5pL5XscY=; b=Lb0u4kYwklQZ3OBmDxPCNKi3CTsLEXEl8nSZZOJ5l/NQunD3lZ4au5CKFQYVGOZWig 2J12fptw4BHWs/AQKL9VaFXV0Amr7xIHzf+CgnWueuK319rK5Zue2I6MNaU/UQoCh6lz ciTlyZahRislAN+8zN7uKkWEDzo0QOKt0fTnMF1CnqV72wg6x1NPssM0Ec+uS07n2Vku vnFFZxAMftdQY2hvCQAI9dIua/5PZUj+/7MofKzbwB2NKtcSGkq0A6AjdV0h2/ekJkOe L87i8wjrswP3Q/nFV0Cwv721zZvSl3hV9f+rQCETRUuQwtwJ5h1GKvvlnsKqXc92vFLm Rz1A== X-Forwarded-Encrypted: i=1; AHgh+RpWpf+gJSKodawP580jV/0khuzcYqPWuP3agcom51OOyd3x/ywHR9ScA9ObdigJX7jQoJqFSxzj/mf77F4=@vger.kernel.org X-Gm-Message-State: AFuF++lV5KmGNGOgkJfT/5hwKCUup1WlgV44Wn5N4Yp/4Hp9t05Gk9TO NflrC5Sa+vY4wxQ0W7yXV/Yqfd6XCvN/L53WwabczNgI/AUKMUtGBtwU X-Gm-Gg: AR+sD12CxaSrpPXHYJeHjGrb1PbAQn/EPmxEG/RAzHFsVZJ553Y6YTkK2/ki9poBXft 7/XVhs7G6KpukorKX/g5uxA+Ry9DjzBLOMUbk0CeEeruHpAoJs0SpKN3hPj8dgY7d/q/qBP1M68 K7kUtuC6tknvRL/Gs//b8ruoy2s6+gnPtJ/28yW7rtAd6jDBsrkieDxH/HWANjlRHNVGa0ZBU6i yaTN60itsX9Wfq2KqOJ4I9GJ6XY90j+aOI9fBOnnOxVsvRYJOs3c1evz9zbiled+oLbucjF7B17 cOHXWVfUkqBj0JI5Ms8fpzkZ8iERMiZryOCTH8/ayCUrHV851RzJ2RzWF3Vc0pUbMytDQ0HNN4f UpRjOmECdu8ApKKB6ogrAbFCF/L2DmC/KUtWIciSwvig6dxSqI0QWShKH0vuPnx+W1GtfOIv/KT KfFb65e5Xiahkwxk9icTS9v0fwfvqFTZOIJC6ZY2KI15wTnejW8YcUVz0OtnMvJOrB+N8FsXmEl HLr X-Received: by 2002:a17:90b:51d2:b0:38f:26c7:165e with SMTP id 98e67ed59e1d1-396d0f8ffdamr9816307a91.9.1787896798256; Thu, 27 Aug 2026 22:59:58 -0700 (PDT) Received: from localhost.localdomain ([240e:b8f:1df9:a600:c693:b19f:ada0:748]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-396b0ea808csm5826241a91.2.2026.08.27.22.59.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Aug 2026 22:59:57 -0700 (PDT) From: Vernon Yang To: akpm@linux-foundation.org, david@kernel.org, ljs@kernel.org Cc: nico.pache@linux.dev, ryan.roberts@arm.com, dev.jain@arm.com, baohua@kernel.org, lance.yang@linux.dev, usama.arif@linux.dev, zokeefe@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, stable@vger.kernel.org, Vernon Yang Subject: [PATCH v4 2/3] mm: khugepaged: fix folio is used after pte_unmap_unlock() Date: Fri, 28 Aug 2026 13:59:25 +0800 Message-ID: <20260828055926.346744-3-vernon2gm@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260828055926.346744-1-vernon2gm@gmail.com> References: <20260828055926.346744-1-vernon2gm@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vernon Yang After the page table lock has dropped, the folio can be freed concurrently. The trace_mm_khugepaged_scan_pmd() is left with a dangling folio pointer. So using the folio_pfn() before dropping the page table lock, closing use-after-free window. And other pre-existing bug, When the `for (i =3D 0; i < HPAGE_PMD_NR; i++)` iteration to terminate and the folio operation preceding is normal, but pfn will be incorrect. so we really only trace the PFN if it really was problematic. About calling the respective trace_xxx() functions separately on success and failure, refer to [1]. [1] https://lore.kernel.org/linux-mm/ao6jVbVHLUmuY2UA@gremlin/ Acked-by: Lorenzo Stoakes (ARM) Fixes: 7d2eba0557c1 ("mm: add tracepoint for scanning pages") Cc: stable@vger.kernel.org Signed-off-by: Vernon Yang Acked-by: David Hildenbrand (Arm) --- include/trace/events/huge_memory.h | 6 +++--- mm/khugepaged.c | 17 ++++++++++++++--- 2 files changed, 17 insertions(+), 6 deletions(-) diff --git a/include/trace/events/huge_memory.h b/include/trace/events/huge= _memory.h index 7b526528f85b..fa828967e1fb 100644 --- a/include/trace/events/huge_memory.h +++ b/include/trace/events/huge_memory.h @@ -55,10 +55,10 @@ SCAN_STATUS =20 TRACE_EVENT(mm_khugepaged_scan_pmd, =20 - TP_PROTO(struct mm_struct *mm, struct folio *folio, + TP_PROTO(struct mm_struct *mm, unsigned long pfn, int referenced, int none_or_zero, int status, int unmapped), =20 - TP_ARGS(mm, folio, referenced, none_or_zero, status, unmapped), + TP_ARGS(mm, pfn, referenced, none_or_zero, status, unmapped), =20 TP_STRUCT__entry( __field(struct mm_struct *, mm) @@ -71,7 +71,7 @@ TRACE_EVENT(mm_khugepaged_scan_pmd, =20 TP_fast_assign( __entry->mm =3D mm; - __entry->pfn =3D folio ? folio_pfn(folio) : -1; + __entry->pfn =3D pfn; __entry->referenced =3D referenced; __entry->none_or_zero =3D none_or_zero; __entry->status =3D status; diff --git a/mm/khugepaged.c b/mm/khugepaged.c index b597a3e68606..4d360ae87769 100644 --- a/mm/khugepaged.c +++ b/mm/khugepaged.c @@ -1612,6 +1612,7 @@ static enum scan_result collapse_scan_pmd(struct mm_s= truct *mm, enum scan_result result =3D SCAN_FAIL; struct page *page =3D NULL; struct folio *folio =3D NULL; + unsigned long failed_pfn =3D -1; unsigned long addr; unsigned long enabled_orders; spinlock_t *ptl; @@ -1706,11 +1707,13 @@ static enum scan_result collapse_scan_pmd(struct mm= _struct *mm, if (cc->is_khugepaged && !(vma->vm_flags & VM_DROPPABLE) && folio_test_lazyfree(folio) && !pte_dirty(pteval)) { result =3D SCAN_PAGE_LAZYFREE; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 if (!folio_test_anon(folio)) { result =3D SCAN_PAGE_ANON; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 @@ -1721,6 +1724,7 @@ static enum scan_result collapse_scan_pmd(struct mm_s= truct *mm, if (folio_maybe_mapped_shared(folio)) { if (++shared > max_ptes_shared) { result =3D SCAN_EXCEED_SHARED_PTE; + failed_pfn =3D folio_pfn(folio); count_collapse_event(HPAGE_PMD_ORDER, THP_SCAN_EXCEED_SHARED_PTE, MTHP_STAT_COLLAPSE_EXCEED_SHARED); goto out_unmap; @@ -1738,15 +1742,18 @@ static enum scan_result collapse_scan_pmd(struct mm= _struct *mm, node =3D folio_nid(folio); if (collapse_scan_abort(node, cc)) { result =3D SCAN_SCAN_ABORT; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } cc->node_load[node]++; if (!folio_test_lru(folio)) { result =3D SCAN_PAGE_LRU; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } if (folio_test_locked(folio)) { result =3D SCAN_PAGE_LOCK; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 @@ -1759,6 +1766,7 @@ static enum scan_result collapse_scan_pmd(struct mm_s= truct *mm, */ if (folio_expected_ref_count(folio) !=3D folio_ref_count(folio)) { result =3D SCAN_PAGE_COUNT; + failed_pfn =3D folio_pfn(folio); goto out_unmap; } =20 @@ -1782,10 +1790,13 @@ static enum scan_result collapse_scan_pmd(struct mm= _struct *mm, unmapped, cc, enabled_orders); /* mmap_lock was released above, set lock_dropped */ *lock_dropped =3D true; - } + trace_mm_khugepaged_scan_pmd(mm, -1, referenced, none_or_zero, + SCAN_SUCCEED, unmapped); + } else { out: - trace_mm_khugepaged_scan_pmd(mm, folio, referenced, - none_or_zero, result, unmapped); + trace_mm_khugepaged_scan_pmd(mm, failed_pfn, referenced, + none_or_zero, result, unmapped); + } return result; } =20 --=20 2.53.0 From nobody Sat Sep 26 23:51:52 2026 Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4E45437F331 for ; Fri, 28 Aug 2026 06:00:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787896804; cv=none; b=h3fW0YqHcKILdNr+yPh5WS6cij3RG6yAzH/WUUhUAnVUgeg3ZCbOItH6lmjM1kLgIbNlWT1Hc8PoBnpTg4NiSj425dvVyk67Vcw8oNJFwrDUKDtwvYviTsXX6mEA2Z4v7WGsos2Ugd+Oc3Ops4tlq0Qg+kHdncm+W/n/QUPeHmw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787896804; c=relaxed/simple; bh=Y3Pxlkk3hzSYzpWCXoMK+05Swu3IcTLWgfLRWxwUd4g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=SWYxRjhZ0hE02tC+04gHGhKOv+TUeOPLt8czrXyWxvxhtgWkE6HPvOWEkcg+2hIYr6iY9hTqXiPJhcAyfNyfiruPLZqejv99MePSaVsFDzWXEWDUQA9NKOpYFy9GPvJ6KDyfrpG8LSZb7aEu2tyrfsOl8L8pIX156ATklk87Xu8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XjMg8G76; arc=none smtp.client-ip=209.85.214.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XjMg8G76" Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2d71a50caa9so8314755ad.0 for ; Thu, 27 Aug 2026 23:00:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787896803; x=1788501603; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CxXRXO9cihd6J9ek1BtX6/zY0HVJ8iMxbQFVA3IYgog=; b=XjMg8G76FUW7yVRFQqU1SDmLhsJsOwW45apqogrsrFWo/aYUSy1XgQhM0c+Y40rJpF Zr1TQPAEYDuQZcCghWFKdkSktxfmUSbwRRgycQdlMsuwzAQY0xER8FJSJz1qZtbtyA/Y rJ3R0hAis0TutAI+XL6gaSbsLFjf8xlDsTKXTWryf9ZnwpEvqCqIZ0hblVL9h5IdA1x3 SkG6hSbCtFPszh7AwrCaNk4Xc6goiygHv4acyCi3IkPaTyBIIauo/k+yxv5FOjB2I/hc KDlukGYCsSm7UROFHDJjIPVMEYjA/oTzAYipo/hdgXRMMHJe+npEIk+C5Pk7PBdhifxK l3hw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787896803; x=1788501603; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=CxXRXO9cihd6J9ek1BtX6/zY0HVJ8iMxbQFVA3IYgog=; b=pJNJyOS//XM38bJdG/kAIowtb16ru9cbXtw90CgBsV4wvesYiWXBo2jRwDWUSEMnPg KHr0ANcSfrO9Z++9SZKEtj5Mx9oT9UwBVAH18mUK7pxLui5KnPYcVTq6okgT35h1kp4c Z7tu51ExC9WoiqdM/JO2uX+f6hSU9gnCLaOzBPYIOcrXBbRuw7tPwLNtwGhvsTQUHoW4 OyK4yZMVBlNT5DtlkgYRAuslg+vckUK0iqNDwG1qpN0Fmgaoe+D7DdOdBW6Tj9AISlE9 s/dq2YMsiDpUgbMZokJuW89M1Tm+qYAmwy5zyC8GWwdKf3MAHXkqTieeFvpnLpQUe1jn MH0A== X-Forwarded-Encrypted: i=1; AHgh+RocucAFJcQRmL8NzT2mDVzNFxkZj5SwXsvTboKjH2PQi9ZgN6rgjs/H5TJ17JvH2V8BK1C54Ef2IZAd+SQ=@vger.kernel.org X-Gm-Message-State: AFuF++meSH8SWhDPKLD85gsHTLas6TOJ88c0UOn5Fc+E7S86cHAkuA7H 5/52DD7OadOn2kzNrKDQvlvTR06Vjx6GXuVycTiXYoJTMNnTEjC/RuxS X-Gm-Gg: AR+sD12tc3zJshofPJi8jWkPvtpMWuypcvRDv9AHjV7qdxHRpvvoyyLpM2YeWC+xPLm YI5R+a9elify9mfoCU7pSqN3NqeYiC2XaVMSIbFHhjEyCryZnD2uq0ZqZo/k/5zffhAE5D5QDPs sgEbBuYFC/w2yjIe0yKwd0VHgnFCXW0hHdk82k9GK8ItRXMOAxwMWFM8muIPkOul8Zz2wW6JBOI 4gGlklxTwrBohpAYr2BE2w8lw7W0gBjfRB1C+Twku3ezhCyI8iWxEuXuNt9H187dYRi5ly93eyB 2klpH+8Ck/DNCeh9Ha/11Fix290UoRAsWKZPWOxOe6/Myn54cg5Gmwf1mRoXGjLApjDnc5OM6mW yE18gBFcKW4BzKOW8BH9diFjw4ieLDJOjmus/SvYq9fXMcTxiqv0/9x6reAd4KvcrLQQ83S7HF2 33xVgYQ3RC8g+lzT2F2mJFxh8TyAYzJtWO7AARgesh8wbE9zo7yzyzg2Yr2yM6kD8ksNAUmTvLm gk= X-Received: by 2002:a17:90b:264c:b0:396:61f1:da5c with SMTP id 98e67ed59e1d1-396d0e86577mr9497339a91.4.1787896802700; Thu, 27 Aug 2026 23:00:02 -0700 (PDT) Received: from localhost.localdomain ([240e:b8f:1df9:a600:c693:b19f:ada0:748]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-396b0ea808csm5826241a91.2.2026.08.27.22.59.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Aug 2026 23:00:02 -0700 (PDT) From: Vernon Yang To: akpm@linux-foundation.org, david@kernel.org, ljs@kernel.org Cc: nico.pache@linux.dev, ryan.roberts@arm.com, dev.jain@arm.com, baohua@kernel.org, lance.yang@linux.dev, usama.arif@linux.dev, zokeefe@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, stable@vger.kernel.org, Vernon Yang Subject: [PATCH v4 3/3] mm: khugepaged: fix folio is used after folio_put/unlock() Date: Fri, 28 Aug 2026 13:59:26 +0800 Message-ID: <20260828055926.346744-4-vernon2gm@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260828055926.346744-1-vernon2gm@gmail.com> References: <20260828055926.346744-1-vernon2gm@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vernon Yang On the rollback path, folio_put() has already dropped the last reference of new_folio. On the success path, new_folio is already unlocked and can be freed concurrently. The trace_mm_khugepaged_collapse_file() is left with a dangling folio pointer. So using the folio_pfn() before dropping the reference, closing use-after-free window. Acked-by: Lorenzo Stoakes (ARM) Fixes: 4c9473e87e75 ("mm/khugepaged: add tracepoint to collapse_file()") Cc: stable@vger.kernel.org Signed-off-by: Vernon Yang Acked-by: David Hildenbrand (Arm) --- include/trace/events/huge_memory.h | 6 +++--- mm/khugepaged.c | 4 +++- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/include/trace/events/huge_memory.h b/include/trace/events/huge= _memory.h index fa828967e1fb..5fb4d92cfd84 100644 --- a/include/trace/events/huge_memory.h +++ b/include/trace/events/huge_memory.h @@ -211,10 +211,10 @@ TRACE_EVENT(mm_khugepaged_scan_file, ); =20 TRACE_EVENT(mm_khugepaged_collapse_file, - TP_PROTO(struct mm_struct *mm, struct folio *new_folio, pgoff_t index, + TP_PROTO(struct mm_struct *mm, unsigned long new_pfn, pgoff_t index, unsigned long addr, bool is_shmem, struct file *file, int nr, int result), - TP_ARGS(mm, new_folio, index, addr, is_shmem, file, nr, result), + TP_ARGS(mm, new_pfn, index, addr, is_shmem, file, nr, result), TP_STRUCT__entry( __field(struct mm_struct *, mm) __field(unsigned long, hpfn) @@ -228,7 +228,7 @@ TRACE_EVENT(mm_khugepaged_collapse_file, =20 TP_fast_assign( __entry->mm =3D mm; - __entry->hpfn =3D new_folio ? folio_pfn(new_folio) : -1; + __entry->hpfn =3D new_pfn; __entry->index =3D index; __entry->addr =3D addr; __entry->is_shmem =3D is_shmem; diff --git a/mm/khugepaged.c b/mm/khugepaged.c index 4d360ae87769..52b4476898d9 100644 --- a/mm/khugepaged.c +++ b/mm/khugepaged.c @@ -2256,6 +2256,7 @@ static enum scan_result collapse_file(struct mm_struc= t *mm, unsigned long addr, struct address_space *mapping =3D file->f_mapping; struct page *dst; struct folio *folio, *tmp, *new_folio; + unsigned long new_pfn =3D -1; pgoff_t index =3D 0, end =3D start + HPAGE_PMD_NR; LIST_HEAD(pagelist); XA_STATE_ORDER(xas, &mapping->i_pages, start, HPAGE_PMD_ORDER); @@ -2275,6 +2276,7 @@ static enum scan_result collapse_file(struct mm_struc= t *mm, unsigned long addr, result =3D alloc_charge_folio(&new_folio, mm, cc, HPAGE_PMD_ORDER); if (result !=3D SCAN_SUCCEED) goto out; + new_pfn =3D folio_pfn(new_folio); =20 mapping_set_update(&xas, mapping); =20 @@ -2678,7 +2680,7 @@ static enum scan_result collapse_file(struct mm_struc= t *mm, unsigned long addr, folio_put(new_folio); out: VM_BUG_ON(!list_empty(&pagelist)); - trace_mm_khugepaged_collapse_file(mm, new_folio, index, addr, is_shmem, f= ile, HPAGE_PMD_NR, result); + trace_mm_khugepaged_collapse_file(mm, new_pfn, index, addr, is_shmem, fil= e, HPAGE_PMD_NR, result); return result; } =20 --=20 2.53.0