From: David Carlier <devnexen@gmail.com>
To: linux-mm@kvack.org, akpm@linux-foundation.org
Cc: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com,
kasong@tencent.com, bhe@redhat.com, chrisl@kernel.org,
baohua@kernel.org, nphamcs@gmail.com, shikemeng@huaweicloud.com,
hughd@google.com, baolin.wang@linux.alibaba.com,
David Carlier <devnexen@gmail.com>,
syzbot+23b25ba3c6bf971f9c57@syzkaller.appspotmail.com
Subject: [PATCH] mm/shmem: don't release a swapin-error marker as a swap entry
Date: Sun, 20 Sep 2026 16:50:02 +0100 [thread overview]
Message-ID: <20260920155002.1030454-1-devnexen@gmail.com> (raw)
A failed shmem swapin frees the swap slot and leaves a PTE_MARKER_POISONED
entry in the page cache. On truncate or eviction shmem_free_swap() passes
that marker to swap_put_entries_direct(), which warns because it is not a
swap entry. There is nothing left to release either way.
Skip the release for non-swap entries, as every other caller already does.
Reported-by: syzbot+23b25ba3c6bf971f9c57@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=23b25ba3c6bf971f9c57
Fixes: ac2d3268284b ("mm/swapfile.c: remove the unneeded checking")
Signed-off-by: David Carlier <devnexen@gmail.com>
---
mm/shmem.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/mm/shmem.c b/mm/shmem.c
index b572c60f2af8..94f2c59c8cfc 100644
--- a/mm/shmem.c
+++ b/mm/shmem.c
@@ -1184,6 +1184,7 @@ static long shmem_free_swap(struct address_space *mapping,
pgoff_t index, pgoff_t end, void *radswap)
{
XA_STATE(xas, &mapping->i_pages, index);
+ const softleaf_t swp = radix_to_swp_entry(radswap);
unsigned int nr_pages = 0;
pgoff_t base;
void *entry;
@@ -1200,8 +1201,9 @@ static long shmem_free_swap(struct address_space *mapping,
}
xas_unlock_irq(&xas);
- if (nr_pages)
- swap_put_entries_direct(radix_to_swp_entry(radswap), nr_pages);
+ /* A swapin-error marker holds no swap slot, so just drop it. */
+ if (nr_pages && softleaf_is_swap(swp))
+ swap_put_entries_direct(swp, nr_pages);
return nr_pages;
}
--
2.55.0
next reply other threads:[~2026-09-20 15:50 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-20 15:50 David Carlier [this message]
2026-09-20 20:04 ` [PATCH] mm/shmem: don't release a swapin-error marker as a swap entry Andrew Morton
2026-09-21 2:45 ` Baolin Wang
2026-09-22 21:03 ` David CARLIER
2026-09-23 1:34 ` Baolin Wang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260920155002.1030454-1-devnexen@gmail.com \
--to=devnexen@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=baohua@kernel.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=bhe@redhat.com \
--cc=chrisl@kernel.org \
--cc=hughd@google.com \
--cc=kasong@tencent.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=nphamcs@gmail.com \
--cc=shikemeng@huaweicloud.com \
--cc=syzbot+23b25ba3c6bf971f9c57@syzkaller.appspotmail.com \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.