From: Andrew Morton <akpm@linux-foundation.org>
To: ackerleytng@google.com
Cc: Ackerley Tng via B4 Relay
<devnull+ackerleytng.google.com@kernel.org>,
Alex Shi <alexs@kernel.org>, David Hildenbrand <david@kernel.org>,
Dongliang Mu <dzm91@hust.edu.cn>,
Hongxiang Lou <louhongxiang@huawei.com>,
Johannes Weiner <hannes@cmpxchg.org>,
Jonathan Corbet <corbet@lwn.net>,
Joshua Hahn <joshua.hahnjy@gmail.com>,
"Liam R. Howlett" <liam@infradead.org>,
Lorenzo Stoakes <ljs@kernel.org>,
Miaohe Lin <linmiaohe@huawei.com>,
Michal Hocko <mhocko@kernel.org>, Mike Rapoport <rppt@kernel.org>,
Muchun Song <muchun.song@linux.dev>,
Nhat Pham <nphamcs@gmail.com>, Oscar Salvador <osalvador@suse.de>,
Peter Xu <peterx@redhat.com>,
Randy Dunlap <rdunlap@infradead.org>,
Roman Gushchin <roman.gushchin@linux.dev>,
Shakeel Butt <shakeel.butt@linux.dev>,
Shuah Khan <skhan@linuxfoundation.org>,
Suren Baghdasaryan <surenb@google.com>,
Usama Arif <usama.arif@linux.dev>,
Vlastimil Babka <vbabka@kernel.org>,
Wupeng Ma <mawupeng1@huawei.com>,
Yanteng Si <si.yanteng@linux.dev>,
fvdl@google.com, jthoughton@google.com, rientjes@google.com,
vannapurve@google.com, linux-doc@vger.kernel.org,
linux-kernel@vger.kernel.org, linux-mm@kvack.org,
stable@vger.kernel.org
Subject: Re: [PATCH v2 0/4] Fix HugeTLB subpool used_hpages tracking
Date: Wed, 9 Sep 2026 15:50:03 -0700 [thread overview]
Message-ID: <20260909155003.e6c2f4fe3c0bbee3b34578fd@linux-foundation.org> (raw)
In-Reply-To: <20260909-hugetlb-subpool-always-track-used-v2-0-30c5d83b572a@google.com>
On Wed, 09 Sep 2026 14:49:25 -0700 Ackerley Tng via B4 Relay <devnull+ackerleytng.google.com@kernel.org> wrote:
> HugeTLB subpools currently only track used_hpages when the user configures
> a size limit.
>
> This is buggy since when there are existing allocations from the subpool
> that would have satisfied the minimum reservations,
> hugepage_subpool_put_pages() will still restore a reservation to the
> subpool. See below for an example of a false reservation.
That sounds annoying, although isn't clear how this affects end-users.
> In addition, the subpool is considered free prematurely, is freed, and this
> ends up causing a use-after-free.
That sounds alarming.
Do you think it's best for us to submit [1-3] for -stable backporting?
Is it feasible to come up with a set of small little fixes to get
-stable out of trouble and then to prepare broader updates for our
ongoing mainline development?
If it's "shut up Andrew you're always saying that" then OK, I can take
that :)
next prev parent reply other threads:[~2026-09-09 22:50 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 21:49 [PATCH v2 0/4] Fix HugeTLB subpool used_hpages tracking Ackerley Tng
2026-09-09 21:49 ` Ackerley Tng via B4 Relay
2026-09-09 21:49 ` [PATCH v2 1/4] mm: hugetlb: Track used_hpages when getting/putting pages from subpool Ackerley Tng
2026-09-09 21:49 ` Ackerley Tng via B4 Relay
2026-09-11 14:08 ` Joshua Hahn
2026-09-14 16:12 ` Ackerley Tng
2026-09-09 21:49 ` [PATCH v2 2/4] mm: hugetlb: Fix out_put_pages subpool reserve calculation Ackerley Tng
2026-09-09 21:49 ` Ackerley Tng via B4 Relay
2026-09-11 14:37 ` Joshua Hahn
2026-09-14 16:00 ` Ackerley Tng
2026-09-09 21:49 ` [PATCH v2 3/4] mm: hugetlb: Fix subpool usage leak on allocation failure Ackerley Tng
2026-09-09 21:49 ` Ackerley Tng via B4 Relay
2026-09-09 22:54 ` Andrew Morton
2026-09-10 19:57 ` Joshua Hahn
2026-09-14 15:26 ` Ackerley Tng
2026-09-11 14:45 ` Joshua Hahn
2026-09-09 21:49 ` [PATCH v2 4/4] mm: hugetlb: Avoid re-allocating global reservations on region add failure Ackerley Tng
2026-09-09 21:49 ` Ackerley Tng via B4 Relay
2026-09-11 14:49 ` Joshua Hahn
2026-09-14 16:03 ` Ackerley Tng
2026-09-09 22:50 ` Andrew Morton [this message]
2026-09-14 15:56 ` [PATCH v2 0/4] Fix HugeTLB subpool used_hpages tracking Ackerley Tng
2026-09-14 16:30 ` Ackerley Tng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909155003.e6c2f4fe3c0bbee3b34578fd@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=ackerleytng@google.com \
--cc=alexs@kernel.org \
--cc=corbet@lwn.net \
--cc=david@kernel.org \
--cc=devnull+ackerleytng.google.com@kernel.org \
--cc=dzm91@hust.edu.cn \
--cc=fvdl@google.com \
--cc=hannes@cmpxchg.org \
--cc=joshua.hahnjy@gmail.com \
--cc=jthoughton@google.com \
--cc=liam@infradead.org \
--cc=linmiaohe@huawei.com \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=louhongxiang@huawei.com \
--cc=mawupeng1@huawei.com \
--cc=mhocko@kernel.org \
--cc=muchun.song@linux.dev \
--cc=nphamcs@gmail.com \
--cc=osalvador@suse.de \
--cc=peterx@redhat.com \
--cc=rdunlap@infradead.org \
--cc=rientjes@google.com \
--cc=roman.gushchin@linux.dev \
--cc=rppt@kernel.org \
--cc=shakeel.butt@linux.dev \
--cc=si.yanteng@linux.dev \
--cc=skhan@linuxfoundation.org \
--cc=stable@vger.kernel.org \
--cc=surenb@google.com \
--cc=usama.arif@linux.dev \
--cc=vannapurve@google.com \
--cc=vbabka@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.