All of lore.kernel.org
 help / color / mirror / Atom feed
From: Andrew Morton <akpm@linux-foundation.org>
To: mm-commits@vger.kernel.org,zokeefe@google.com,ziy@nvidia.com,stable@vger.kernel.org,shy828301@gmail.com,ryan.roberts@arm.com,ljs@kernel.org,liam@infradead.org,lance.yang@linux.dev,kas@kernel.org,hughd@google.com,dev.jain@arm.com,david@kernel.org,baolin.wang@linux.alibaba.com,baohua@kernel.org,jthoughton@google.com,akpm@linux-foundation.org
Subject: [to-be-updated] mm-khugepaged-dont-install-pmds-in-uffd-minor-registered-vmas.patch removed from -mm tree
Date: Thu, 10 Sep 2026 16:25:35 -0700	[thread overview]
Message-ID: <20260910232536.2CC4D1F000FF@smtp.kernel.org> (raw)


The quilt patch titled
     Subject: mm/khugepaged: don't install PMDs in uffd-minor-registered VMAs
has been removed from the -mm tree.  Its filename was
     mm-khugepaged-dont-install-pmds-in-uffd-minor-registered-vmas.patch

This patch was dropped because an updated version will be issued

------------------------------------------------------
From: James Houghton <jthoughton@google.com>
Subject: mm/khugepaged: don't install PMDs in uffd-minor-registered VMAs
Date: Fri, 28 Aug 2026 22:26:40 +0000

Userfaultfd minor faults provides userspace with the ability to manually
install PTEs with UFFDIO_CONTINUE.  Right now, khugepaged collapse can map
holes in the VMA when a naturally-aligned THP is present without explicit
action from userspace.

This is a problem, as it bypasses userfaultfd minor faults that userspace
is expecting to handle.

If userspace implements post-copy live migration using userfaultfd minor
faults, this situation is currently possible:
1. The VMA for guest memory is userfaultfd-minor-registered and nothing
   is mapped in the page tables.
2. A stale copy of a page is present in a naturally-aligned THP (from
   pre-copy live migration).
3. khugepaged collapses the mapping of the THP, installs a PMD.
4. The VM now has access to the stale contents => VM is broken.
5. After installing the correct contents, userspace attempts to map the
   page with UFFDIO_CONTINUE; it gets EEXIST, indicating that something
   unexpectedly mapped the page.

The naturally-aligned THP case is the only case where this is a problem. 
khugepaged otherwise requires all PTEs to be present for
userfaultfd-registered VMAs (i.e., max none PTEs is 0), which is correct. 
This check is essentially bypassed for naturally-aligned THPs.

No changes are needed for file_backed_vma_is_retractable(), as zapping
PTEs is safe.  Userspace must already handle cases where PTEs are zapped
without explicit action (e.g.  due to reclaim).

A reproducer for this issue is at
https://gist.github.com/48ca/d399bf534158e80241fb4937ef1ff664

Link: https://lore.kernel.org/20260828222640.1638457-1-jthoughton@google.com
Fixes: 58ac9a8993a1 ("mm/khugepaged: attempt to map file/shmem-backed pte-mapped THPs by pmds")
Signed-off-by: James Houghton <jthoughton@google.com>
Suggested-by: Lance Yang <lance.yang@linux.dev>
Tested-by: Lance Yang <lance.yang@linux.dev>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Kiryl Shutsemau <kas@kernel.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Yang Shi <shy828301@gmail.com>
Cc: Zach O'Keefe <zokeefe@google.com>
Cc: Zi Yan <ziy@nvidia.com>
Cc: <stable@vger.kernel.org> # 6.1
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---

 mm/khugepaged.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/mm/khugepaged.c~mm-khugepaged-dont-install-pmds-in-uffd-minor-registered-vmas
+++ a/mm/khugepaged.c
@@ -1902,6 +1902,13 @@ static enum scan_result try_collapse_pte
 	if (userfaultfd_protected(vma))
 		return SCAN_PTE_UFFD;
 
+	/*
+	 * Userfaultfd-minor-registered VMAs should not be collapsed, as
+	 * userspace is expecting to explicitly install PTEs.
+	 */
+	if (userfaultfd_minor(vma))
+		return SCAN_PTE_UFFD;
+
 	folio = filemap_lock_folio(vma->vm_file->f_mapping,
 			       linear_page_index(vma, haddr));
 	if (IS_ERR(folio))
_

Patches currently in -mm which might be from jthoughton@google.com are

mm-khugepaged-never-install-pmds-in-uffd-minor-registered-vmas.patch
mm-selftests-adjust-the-madv_collapse-uffd-minor-selftests.patch


                 reply	other threads:[~2026-09-10 23:25 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260910232536.2CC4D1F000FF@smtp.kernel.org \
    --to=akpm@linux-foundation.org \
    --cc=baohua@kernel.org \
    --cc=baolin.wang@linux.alibaba.com \
    --cc=david@kernel.org \
    --cc=dev.jain@arm.com \
    --cc=hughd@google.com \
    --cc=jthoughton@google.com \
    --cc=kas@kernel.org \
    --cc=lance.yang@linux.dev \
    --cc=liam@infradead.org \
    --cc=ljs@kernel.org \
    --cc=mm-commits@vger.kernel.org \
    --cc=ryan.roberts@arm.com \
    --cc=shy828301@gmail.com \
    --cc=stable@vger.kernel.org \
    --cc=ziy@nvidia.com \
    --cc=zokeefe@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.