All of lore.kernel.org
 help / color / mirror / Atom feed
* + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch
@ 2026-06-25  0:54 Andrew Morton
  2026-06-25  2:49 ` Muchun Song
  0 siblings, 1 reply; 3+ messages in thread
From: Andrew Morton @ 2026-06-25  0:54 UTC (permalink / raw)
  To: mm-commits, vbabka, stable, osalvador, muchun.song, kas, david,
	mclapinski, akpm


The patch titled
     Subject: mm/hugetlb: init tails before init_migratetype
has been added to the -mm mm-hotfixes-unstable branch.  Its filename is
     mm-hugetlb-init-tails-before-init_migratetype.patch

This patch will shortly appear at
     https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-hugetlb-init-tails-before-init_migratetype.patch

This patch will later appear in the mm-hotfixes-unstable branch at
    git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm

Before you just go and hit "reply", please:
   a) Consider who else should be cc'ed
   b) Prefer to cc a suitable mailing list as well
   c) Ideally: find the original patch on the mailing list and do a
      reply-to-all to that, adding suitable additional cc's

*** Remember to use Documentation/process/submit-checklist.rst when testing your code ***

The -mm tree is included into linux-next via various
branches at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
and is updated there most days

------------------------------------------------------
From: Michal Clapinski <mclapinski@google.com>
Subject: mm/hugetlb: init tails before init_migratetype
Date: Mon, 22 Jun 2026 12:19:01 +0200

Currently, if you enable HVO, DEFERRED_STRUCT_PAGE_INIT and VM_DEBUG the
kernel will crash with the following stack trace

get_pfnblock_bitmap_bitidx
__set_pfnblock_flags_mask
hugetlb_bootmem_init_migratetype
prep_and_add_bootmem_folios
gather_bootmem_prealloc_node
gather_bootmem_prealloc_parallel
padata_do_multithreaded
gather_bootmem_prealloc
hugetlb_init

on this code

VM_BUG_ON_PAGE(!zone_spans_pfn(page_zone(page), pfn), page);

This code looks inside the struct page which will be uninitialized
for hugetlb tail pages, which will cause a false positive.

So let's initialize the tail pages before this happens.

Link: https://lore.kernel.org/20260622101901.223961-1-mclapinski@google.com
Fixes: 622026e87c40 ("mm/hugetlb: remove fake head pages")
Signed-off-by: Michal Clapinski <mclapinski@google.com>
Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Tested-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Michal Clapinski <mclapinski@google.com>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---

 mm/hugetlb.c         |    1 +
 mm/hugetlb_vmemmap.c |   14 +++++++++-----
 mm/hugetlb_vmemmap.h |    5 +++++
 3 files changed, 15 insertions(+), 5 deletions(-)

--- a/mm/hugetlb.c~mm-hugetlb-init-tails-before-init_migratetype
+++ a/mm/hugetlb.c
@@ -4127,6 +4127,7 @@ static int __init hugetlb_init(void)
 	}
 
 	hugetlb_init_hstates();
+	hugetlb_vmemmap_init_tails();
 	gather_bootmem_prealloc();
 	report_hugepages();
 
--- a/mm/hugetlb_vmemmap.c~mm-hugetlb-init-tails-before-init_migratetype
+++ a/mm/hugetlb_vmemmap.c
@@ -867,14 +867,10 @@ static const struct ctl_table hugetlb_vm
 	},
 };
 
-static int __init hugetlb_vmemmap_init(void)
+void __init hugetlb_vmemmap_init_tails(void)
 {
-	const struct hstate *h;
 	struct zone *zone;
 
-	/* HUGETLB_VMEMMAP_RESERVE_SIZE should cover all used struct pages */
-	BUILD_BUG_ON(__NR_USED_SUBPAGE > HUGETLB_VMEMMAP_RESERVE_PAGES);
-
 	for_each_zone(zone) {
 		for (int i = 0; i < NR_VMEMMAP_TAILS; i++) {
 			struct page *tail, *p;
@@ -890,6 +886,14 @@ static int __init hugetlb_vmemmap_init(v
 				init_compound_tail(p + j, NULL, order, zone);
 		}
 	}
+}
+
+static int __init hugetlb_vmemmap_init(void)
+{
+	const struct hstate *h;
+
+	/* HUGETLB_VMEMMAP_RESERVE_SIZE should cover all used struct pages */
+	BUILD_BUG_ON(__NR_USED_SUBPAGE > HUGETLB_VMEMMAP_RESERVE_PAGES);
 
 	for_each_hstate(h) {
 		if (hugetlb_vmemmap_optimizable(h)) {
--- a/mm/hugetlb_vmemmap.h~mm-hugetlb-init-tails-before-init_migratetype
+++ a/mm/hugetlb_vmemmap.h
@@ -20,6 +20,7 @@
 #define HUGETLB_VMEMMAP_RESERVE_PAGES	(HUGETLB_VMEMMAP_RESERVE_SIZE / sizeof(struct page))
 
 #ifdef CONFIG_HUGETLB_PAGE_OPTIMIZE_VMEMMAP
+void hugetlb_vmemmap_init_tails(void);
 int hugetlb_vmemmap_restore_folio(const struct hstate *h, struct folio *folio);
 long hugetlb_vmemmap_restore_folios(const struct hstate *h,
 					struct list_head *folio_list,
@@ -72,6 +73,10 @@ static inline void hugetlb_vmemmap_optim
 {
 }
 
+static inline void hugetlb_vmemmap_init_tails(void)
+{
+}
+
 static inline void hugetlb_vmemmap_optimize_bootmem_folios(struct hstate *h,
 						struct list_head *folio_list)
 {
_

Patches currently in -mm which might be from mclapinski@google.com are

mm-hugetlb-init-tails-before-init_migratetype.patch


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch
  2026-06-25  0:54 + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch Andrew Morton
@ 2026-06-25  2:49 ` Muchun Song
  2026-06-25  3:03   ` Andrew Morton
  0 siblings, 1 reply; 3+ messages in thread
From: Muchun Song @ 2026-06-25  2:49 UTC (permalink / raw)
  To: Andrew Morton, mclapinski
  Cc: mm-commits, vbabka, stable, osalvador, kas, david



> On Jun 25, 2026, at 08:54, Andrew Morton <akpm@linux-foundation.org> wrote:
> 
> 
> The patch titled
>     Subject: mm/hugetlb: init tails before init_migratetype
> has been added to the -mm mm-hotfixes-unstable branch.  Its filename is
>     mm-hugetlb-init-tails-before-init_migratetype.patch
> 
> This patch will shortly appear at
>     https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-hugetlb-init-tails-before-init_migratetype.patch
> 
> This patch will later appear in the mm-hotfixes-unstable branch at
>    git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
> 
> Before you just go and hit "reply", please:
>   a) Consider who else should be cc'ed
>   b) Prefer to cc a suitable mailing list as well
>   c) Ideally: find the original patch on the mailing list and do a
>      reply-to-all to that, adding suitable additional cc's
> 
> *** Remember to use Documentation/process/submit-checklist.rst when testing your code ***
> 
> The -mm tree is included into linux-next via various
> branches at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
> and is updated there most days
> 
> ------------------------------------------------------
> From: Michal Clapinski <mclapinski@google.com>
> Subject: mm/hugetlb: init tails before init_migratetype
> Date: Mon, 22 Jun 2026 12:19:01 +0200
> 
> Currently, if you enable HVO, DEFERRED_STRUCT_PAGE_INIT and VM_DEBUG the
> kernel will crash with the following stack trace
> 
> get_pfnblock_bitmap_bitidx
> __set_pfnblock_flags_mask
> hugetlb_bootmem_init_migratetype
> prep_and_add_bootmem_folios
> gather_bootmem_prealloc_node
> gather_bootmem_prealloc_parallel
> padata_do_multithreaded
> gather_bootmem_prealloc
> hugetlb_init
> 
> on this code
> 
> VM_BUG_ON_PAGE(!zone_spans_pfn(page_zone(page), pfn), page);
> 
> This code looks inside the struct page which will be uninitialized
> for hugetlb tail pages, which will cause a false positive.
> 
> So let's initialize the tail pages before this happens.
> 
> Link: https://lore.kernel.org/20260622101901.223961-1-mclapinski@google.com
> Fixes: 622026e87c40 ("mm/hugetlb: remove fake head pages")
> Signed-off-by: Michal Clapinski <mclapinski@google.com>
> Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
> Tested-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
> Cc: David Hildenbrand <david@kernel.org>
> Cc: Michal Clapinski <mclapinski@google.com>
> Cc: Muchun Song <muchun.song@linux.dev>
> Cc: Oscar Salvador <osalvador@suse.de>
> Cc: Vlastimil Babka <vbabka@kernel.org>
> Cc: <stable@vger.kernel.org>
> Signed-off-by: Andrew Morton <akpm@linux-foundation.org>

Hi Andrew,

Just a quick heads-up — this bug was actually already fixed in my patch #1 of
patchset [1]. Since both patches address the same issue, I'd suggest picking
mine to avoid unnecessary merge conflicts when the rest of my series gets applied.

Thanks to Michal for also taking a look at this — always good to have extra eyes
on the same problem.

[1] https://lore.kernel.org/linux-mm/20260612035903.2468601-2-songmuchun@bytedance.com/

Muchun,
Thanks.


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch
  2026-06-25  2:49 ` Muchun Song
@ 2026-06-25  3:03   ` Andrew Morton
  0 siblings, 0 replies; 3+ messages in thread
From: Andrew Morton @ 2026-06-25  3:03 UTC (permalink / raw)
  To: Muchun Song; +Cc: mclapinski, mm-commits, vbabka, stable, osalvador, kas, david

On Thu, 25 Jun 2026 10:49:25 +0800 Muchun Song <muchun.song@linux.dev> wrote:

> > VM_BUG_ON_PAGE(!zone_spans_pfn(page_zone(page), pfn), page);
> > 
> > This code looks inside the struct page which will be uninitialized
> > for hugetlb tail pages, which will cause a false positive.
> > 
> > So let's initialize the tail pages before this happens.
> > 
>
> ...
>
> 
> Hi Andrew,
> 
> Just a quick heads-up — this bug was actually already fixed in my patch #1 of
> patchset [1].

OK, thanks.  I work through backlog in reverse time order, so that's
still 800 emails away ;)

> Since both patches address the same issue, I'd suggest picking
> mine to avoid unnecessary merge conflicts when the rest of my series gets applied.
>
> Thanks to Michal for also taking a look at this — always good to have extra eyes
> on the same problem.
> 
> [1] https://lore.kernel.org/linux-mm/20260612035903.2468601-2-songmuchun@bytedance.com/

That's a very different change.

I expect I'll need to separate your [01/19] out of the series and make
it a hotfix.

Oh well, thanks, I'll leave a note against
mm-hugetlb-init-tails-before-init_migratetype.patch for now.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-06-25  3:03 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-25  0:54 + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch Andrew Morton
2026-06-25  2:49 ` Muchun Song
2026-06-25  3:03   ` Andrew Morton

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.