* + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch
@ 2026-06-25 0:54 Andrew Morton
2026-06-25 2:49 ` Muchun Song
0 siblings, 1 reply; 3+ messages in thread
From: Andrew Morton @ 2026-06-25 0:54 UTC (permalink / raw)
To: mm-commits, vbabka, stable, osalvador, muchun.song, kas, david,
mclapinski, akpm
The patch titled
Subject: mm/hugetlb: init tails before init_migratetype
has been added to the -mm mm-hotfixes-unstable branch. Its filename is
mm-hugetlb-init-tails-before-init_migratetype.patch
This patch will shortly appear at
https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-hugetlb-init-tails-before-init_migratetype.patch
This patch will later appear in the mm-hotfixes-unstable branch at
git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
Before you just go and hit "reply", please:
a) Consider who else should be cc'ed
b) Prefer to cc a suitable mailing list as well
c) Ideally: find the original patch on the mailing list and do a
reply-to-all to that, adding suitable additional cc's
*** Remember to use Documentation/process/submit-checklist.rst when testing your code ***
The -mm tree is included into linux-next via various
branches at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
and is updated there most days
------------------------------------------------------
From: Michal Clapinski <mclapinski@google.com>
Subject: mm/hugetlb: init tails before init_migratetype
Date: Mon, 22 Jun 2026 12:19:01 +0200
Currently, if you enable HVO, DEFERRED_STRUCT_PAGE_INIT and VM_DEBUG the
kernel will crash with the following stack trace
get_pfnblock_bitmap_bitidx
__set_pfnblock_flags_mask
hugetlb_bootmem_init_migratetype
prep_and_add_bootmem_folios
gather_bootmem_prealloc_node
gather_bootmem_prealloc_parallel
padata_do_multithreaded
gather_bootmem_prealloc
hugetlb_init
on this code
VM_BUG_ON_PAGE(!zone_spans_pfn(page_zone(page), pfn), page);
This code looks inside the struct page which will be uninitialized
for hugetlb tail pages, which will cause a false positive.
So let's initialize the tail pages before this happens.
Link: https://lore.kernel.org/20260622101901.223961-1-mclapinski@google.com
Fixes: 622026e87c40 ("mm/hugetlb: remove fake head pages")
Signed-off-by: Michal Clapinski <mclapinski@google.com>
Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Tested-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Michal Clapinski <mclapinski@google.com>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
mm/hugetlb.c | 1 +
mm/hugetlb_vmemmap.c | 14 +++++++++-----
mm/hugetlb_vmemmap.h | 5 +++++
3 files changed, 15 insertions(+), 5 deletions(-)
--- a/mm/hugetlb.c~mm-hugetlb-init-tails-before-init_migratetype
+++ a/mm/hugetlb.c
@@ -4127,6 +4127,7 @@ static int __init hugetlb_init(void)
}
hugetlb_init_hstates();
+ hugetlb_vmemmap_init_tails();
gather_bootmem_prealloc();
report_hugepages();
--- a/mm/hugetlb_vmemmap.c~mm-hugetlb-init-tails-before-init_migratetype
+++ a/mm/hugetlb_vmemmap.c
@@ -867,14 +867,10 @@ static const struct ctl_table hugetlb_vm
},
};
-static int __init hugetlb_vmemmap_init(void)
+void __init hugetlb_vmemmap_init_tails(void)
{
- const struct hstate *h;
struct zone *zone;
- /* HUGETLB_VMEMMAP_RESERVE_SIZE should cover all used struct pages */
- BUILD_BUG_ON(__NR_USED_SUBPAGE > HUGETLB_VMEMMAP_RESERVE_PAGES);
-
for_each_zone(zone) {
for (int i = 0; i < NR_VMEMMAP_TAILS; i++) {
struct page *tail, *p;
@@ -890,6 +886,14 @@ static int __init hugetlb_vmemmap_init(v
init_compound_tail(p + j, NULL, order, zone);
}
}
+}
+
+static int __init hugetlb_vmemmap_init(void)
+{
+ const struct hstate *h;
+
+ /* HUGETLB_VMEMMAP_RESERVE_SIZE should cover all used struct pages */
+ BUILD_BUG_ON(__NR_USED_SUBPAGE > HUGETLB_VMEMMAP_RESERVE_PAGES);
for_each_hstate(h) {
if (hugetlb_vmemmap_optimizable(h)) {
--- a/mm/hugetlb_vmemmap.h~mm-hugetlb-init-tails-before-init_migratetype
+++ a/mm/hugetlb_vmemmap.h
@@ -20,6 +20,7 @@
#define HUGETLB_VMEMMAP_RESERVE_PAGES (HUGETLB_VMEMMAP_RESERVE_SIZE / sizeof(struct page))
#ifdef CONFIG_HUGETLB_PAGE_OPTIMIZE_VMEMMAP
+void hugetlb_vmemmap_init_tails(void);
int hugetlb_vmemmap_restore_folio(const struct hstate *h, struct folio *folio);
long hugetlb_vmemmap_restore_folios(const struct hstate *h,
struct list_head *folio_list,
@@ -72,6 +73,10 @@ static inline void hugetlb_vmemmap_optim
{
}
+static inline void hugetlb_vmemmap_init_tails(void)
+{
+}
+
static inline void hugetlb_vmemmap_optimize_bootmem_folios(struct hstate *h,
struct list_head *folio_list)
{
_
Patches currently in -mm which might be from mclapinski@google.com are
mm-hugetlb-init-tails-before-init_migratetype.patch
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch
2026-06-25 0:54 + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch Andrew Morton
@ 2026-06-25 2:49 ` Muchun Song
2026-06-25 3:03 ` Andrew Morton
0 siblings, 1 reply; 3+ messages in thread
From: Muchun Song @ 2026-06-25 2:49 UTC (permalink / raw)
To: Andrew Morton, mclapinski
Cc: mm-commits, vbabka, stable, osalvador, kas, david
> On Jun 25, 2026, at 08:54, Andrew Morton <akpm@linux-foundation.org> wrote:
>
>
> The patch titled
> Subject: mm/hugetlb: init tails before init_migratetype
> has been added to the -mm mm-hotfixes-unstable branch. Its filename is
> mm-hugetlb-init-tails-before-init_migratetype.patch
>
> This patch will shortly appear at
> https://git.kernel.org/pub/scm/linux/kernel/git/akpm/25-new.git/tree/patches/mm-hugetlb-init-tails-before-init_migratetype.patch
>
> This patch will later appear in the mm-hotfixes-unstable branch at
> git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
>
> Before you just go and hit "reply", please:
> a) Consider who else should be cc'ed
> b) Prefer to cc a suitable mailing list as well
> c) Ideally: find the original patch on the mailing list and do a
> reply-to-all to that, adding suitable additional cc's
>
> *** Remember to use Documentation/process/submit-checklist.rst when testing your code ***
>
> The -mm tree is included into linux-next via various
> branches at git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
> and is updated there most days
>
> ------------------------------------------------------
> From: Michal Clapinski <mclapinski@google.com>
> Subject: mm/hugetlb: init tails before init_migratetype
> Date: Mon, 22 Jun 2026 12:19:01 +0200
>
> Currently, if you enable HVO, DEFERRED_STRUCT_PAGE_INIT and VM_DEBUG the
> kernel will crash with the following stack trace
>
> get_pfnblock_bitmap_bitidx
> __set_pfnblock_flags_mask
> hugetlb_bootmem_init_migratetype
> prep_and_add_bootmem_folios
> gather_bootmem_prealloc_node
> gather_bootmem_prealloc_parallel
> padata_do_multithreaded
> gather_bootmem_prealloc
> hugetlb_init
>
> on this code
>
> VM_BUG_ON_PAGE(!zone_spans_pfn(page_zone(page), pfn), page);
>
> This code looks inside the struct page which will be uninitialized
> for hugetlb tail pages, which will cause a false positive.
>
> So let's initialize the tail pages before this happens.
>
> Link: https://lore.kernel.org/20260622101901.223961-1-mclapinski@google.com
> Fixes: 622026e87c40 ("mm/hugetlb: remove fake head pages")
> Signed-off-by: Michal Clapinski <mclapinski@google.com>
> Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
> Tested-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
> Cc: David Hildenbrand <david@kernel.org>
> Cc: Michal Clapinski <mclapinski@google.com>
> Cc: Muchun Song <muchun.song@linux.dev>
> Cc: Oscar Salvador <osalvador@suse.de>
> Cc: Vlastimil Babka <vbabka@kernel.org>
> Cc: <stable@vger.kernel.org>
> Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Hi Andrew,
Just a quick heads-up — this bug was actually already fixed in my patch #1 of
patchset [1]. Since both patches address the same issue, I'd suggest picking
mine to avoid unnecessary merge conflicts when the rest of my series gets applied.
Thanks to Michal for also taking a look at this — always good to have extra eyes
on the same problem.
[1] https://lore.kernel.org/linux-mm/20260612035903.2468601-2-songmuchun@bytedance.com/
Muchun,
Thanks.
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch
2026-06-25 2:49 ` Muchun Song
@ 2026-06-25 3:03 ` Andrew Morton
0 siblings, 0 replies; 3+ messages in thread
From: Andrew Morton @ 2026-06-25 3:03 UTC (permalink / raw)
To: Muchun Song; +Cc: mclapinski, mm-commits, vbabka, stable, osalvador, kas, david
On Thu, 25 Jun 2026 10:49:25 +0800 Muchun Song <muchun.song@linux.dev> wrote:
> > VM_BUG_ON_PAGE(!zone_spans_pfn(page_zone(page), pfn), page);
> >
> > This code looks inside the struct page which will be uninitialized
> > for hugetlb tail pages, which will cause a false positive.
> >
> > So let's initialize the tail pages before this happens.
> >
>
> ...
>
>
> Hi Andrew,
>
> Just a quick heads-up — this bug was actually already fixed in my patch #1 of
> patchset [1].
OK, thanks. I work through backlog in reverse time order, so that's
still 800 emails away ;)
> Since both patches address the same issue, I'd suggest picking
> mine to avoid unnecessary merge conflicts when the rest of my series gets applied.
>
> Thanks to Michal for also taking a look at this — always good to have extra eyes
> on the same problem.
>
> [1] https://lore.kernel.org/linux-mm/20260612035903.2468601-2-songmuchun@bytedance.com/
That's a very different change.
I expect I'll need to separate your [01/19] out of the series and make
it a hotfix.
Oh well, thanks, I'll leave a note against
mm-hugetlb-init-tails-before-init_migratetype.patch for now.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-06-25 3:03 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-25 0:54 + mm-hugetlb-init-tails-before-init_migratetype.patch added to mm-hotfixes-unstable branch Andrew Morton
2026-06-25 2:49 ` Muchun Song
2026-06-25 3:03 ` Andrew Morton
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.