From: Andrew Morton <akpm@linux-foundation.org>
To: mm-commits@vger.kernel.org,zokeefe@google.com,ziy@nvidia.com,stable@vger.kernel.org,shy828301@gmail.com,ryan.roberts@arm.com,ljs@kernel.org,liam@infradead.org,lance.yang@linux.dev,kas@kernel.org,hughd@google.com,dev.jain@arm.com,david@kernel.org,baolin.wang@linux.alibaba.com,baohua@kernel.org,jthoughton@google.com,akpm@linux-foundation.org
Subject: [to-be-updated] mm-khugepaged-dont-install-pmds-in-uffd-minor-registered-vmas.patch removed from -mm tree
Date: Thu, 10 Sep 2026 16:25:35 -0700 [thread overview]
Message-ID: <20260910232536.2CC4D1F000FF@smtp.kernel.org> (raw)
The quilt patch titled
Subject: mm/khugepaged: don't install PMDs in uffd-minor-registered VMAs
has been removed from the -mm tree. Its filename was
mm-khugepaged-dont-install-pmds-in-uffd-minor-registered-vmas.patch
This patch was dropped because an updated version will be issued
------------------------------------------------------
From: James Houghton <jthoughton@google.com>
Subject: mm/khugepaged: don't install PMDs in uffd-minor-registered VMAs
Date: Fri, 28 Aug 2026 22:26:40 +0000
Userfaultfd minor faults provides userspace with the ability to manually
install PTEs with UFFDIO_CONTINUE. Right now, khugepaged collapse can map
holes in the VMA when a naturally-aligned THP is present without explicit
action from userspace.
This is a problem, as it bypasses userfaultfd minor faults that userspace
is expecting to handle.
If userspace implements post-copy live migration using userfaultfd minor
faults, this situation is currently possible:
1. The VMA for guest memory is userfaultfd-minor-registered and nothing
is mapped in the page tables.
2. A stale copy of a page is present in a naturally-aligned THP (from
pre-copy live migration).
3. khugepaged collapses the mapping of the THP, installs a PMD.
4. The VM now has access to the stale contents => VM is broken.
5. After installing the correct contents, userspace attempts to map the
page with UFFDIO_CONTINUE; it gets EEXIST, indicating that something
unexpectedly mapped the page.
The naturally-aligned THP case is the only case where this is a problem.
khugepaged otherwise requires all PTEs to be present for
userfaultfd-registered VMAs (i.e., max none PTEs is 0), which is correct.
This check is essentially bypassed for naturally-aligned THPs.
No changes are needed for file_backed_vma_is_retractable(), as zapping
PTEs is safe. Userspace must already handle cases where PTEs are zapped
without explicit action (e.g. due to reclaim).
A reproducer for this issue is at
https://gist.github.com/48ca/d399bf534158e80241fb4937ef1ff664
Link: https://lore.kernel.org/20260828222640.1638457-1-jthoughton@google.com
Fixes: 58ac9a8993a1 ("mm/khugepaged: attempt to map file/shmem-backed pte-mapped THPs by pmds")
Signed-off-by: James Houghton <jthoughton@google.com>
Suggested-by: Lance Yang <lance.yang@linux.dev>
Tested-by: Lance Yang <lance.yang@linux.dev>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Kiryl Shutsemau <kas@kernel.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Yang Shi <shy828301@gmail.com>
Cc: Zach O'Keefe <zokeefe@google.com>
Cc: Zi Yan <ziy@nvidia.com>
Cc: <stable@vger.kernel.org> # 6.1
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
mm/khugepaged.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/mm/khugepaged.c~mm-khugepaged-dont-install-pmds-in-uffd-minor-registered-vmas
+++ a/mm/khugepaged.c
@@ -1902,6 +1902,13 @@ static enum scan_result try_collapse_pte
if (userfaultfd_protected(vma))
return SCAN_PTE_UFFD;
+ /*
+ * Userfaultfd-minor-registered VMAs should not be collapsed, as
+ * userspace is expecting to explicitly install PTEs.
+ */
+ if (userfaultfd_minor(vma))
+ return SCAN_PTE_UFFD;
+
folio = filemap_lock_folio(vma->vm_file->f_mapping,
linear_page_index(vma, haddr));
if (IS_ERR(folio))
_
Patches currently in -mm which might be from jthoughton@google.com are
mm-khugepaged-never-install-pmds-in-uffd-minor-registered-vmas.patch
mm-selftests-adjust-the-madv_collapse-uffd-minor-selftests.patch
reply other threads:[~2026-09-10 23:25 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910232536.2CC4D1F000FF@smtp.kernel.org \
--to=akpm@linux-foundation.org \
--cc=baohua@kernel.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=david@kernel.org \
--cc=dev.jain@arm.com \
--cc=hughd@google.com \
--cc=jthoughton@google.com \
--cc=kas@kernel.org \
--cc=lance.yang@linux.dev \
--cc=liam@infradead.org \
--cc=ljs@kernel.org \
--cc=mm-commits@vger.kernel.org \
--cc=ryan.roberts@arm.com \
--cc=shy828301@gmail.com \
--cc=stable@vger.kernel.org \
--cc=ziy@nvidia.com \
--cc=zokeefe@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.