From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
To: akpm@linux-foundation.org, rppt@kernel.org
Cc: peterx@redhat.com, surenb@google.com, aarcange@redhat.com,
david@kernel.org, ljs@kernel.org, liam@infradead.org,
vbabka@kernel.org, mhocko@suse.com, shuah@kernel.org,
kas@kernel.org, linux-mm@kvack.org,
linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org,
donggeunyoo.kernel@gmail.com
Subject: [PATCH v4 0/2] userfaultfd: clear the inherited uffd bit in move_swap_pte()
Date: Sat, 3 Oct 2026 19:30:28 +0900 [thread overview]
Message-ID: <20261003103030.63380-1-donggeunyoo.kernel@gmail.com> (raw)
UFFDIO_MOVE on a swapped-out page installs the source PTE at the
destination unchanged, so a uffd bit set on a write-protected or
RWP-protected source lands in a destination VMA that was never
registered for either, and nothing clears it afterwards. Patch 1 clears
the bit, then re-arms it if the destination is RWP-registered, which is
what the present-page and zeropage move paths already do. Patch 2 adds
the tests that catch it.
v1: https://lore.kernel.org/all/20260919004630.1159895-1-donggeunyoo.kernel@gmail.com/
v2: https://lore.kernel.org/all/20260925042907.2330519-1-donggeunyoo.kernel@gmail.com/
v3: https://lore.kernel.org/all/20260926124145.2878520-1-donggeunyoo.kernel@gmail.com/
Changes in v4:
- patch 1: add Acked-by from David Hildenbrand and Mike Rapoport; no
code change
- patch 2: protect the source right after registering it, open pagemap
at the top, and use a designated initializer for the move (David
Hildenbrand)
- patch 2: fail only the test case, not the whole run, when UFFDIO_MOVE
fails (David Hildenbrand)
Changes in v3:
- patch 1: describe the userspace-visible effects and the backport
(Andrew Morton, David Hildenbrand)
- patch 2: drop the MADV_PAGEOUT retry loop (David Hildenbrand)
- patch 2: add an RWP case (David Hildenbrand)
Changes in v2:
- patch 1: clear the bit unconditionally (Kiryl Shutsemau)
- patch 1: rewrite the changelog for readability (Mike Rapoport)
- add Assisted-by: LLM (Mike Rapoport)
x86_64 defconfig plus USERFAULTFD, TRANSPARENT_HUGEPAGE,
PAGE_TABLE_CHECK_ENFORCED and a swap device, under QEMU, on
6812ce4e4379:
uffd-unit-tests before after
move-swap-wp on anon not ok ok
move-swap-rwp on anon not ok ok
the other 103 unit tests ok ok
uffd-wp-mremap, 38 tests ok ok
11 unit tests skip on both, as CONFIG_GUP_TEST is not set.
With UFFDIO_MOVE forced to fail (len = page_size + 1, local change only),
v3 aborts the run after 15 of 116 tests; v4 reports the two move-swap
cases as failed and runs the rest.
pagemap bit 57 at the destination before after
swapped page, dst not armed set clear
swapped page, dst WP-armed set clear
swapped page, dst RWP-armed set set
resident page, dst WP-armed clear clear
MADV_COLLAPSE over 2 MB at dst EINVAL 0
fault on the moved page at dst WARNING none
Donggeun Yoo (2):
userfaultfd: clear the inherited uffd bit in move_swap_pte()
selftests/mm: add tests for UFFDIO_MOVE of a uffd-protected swap entry
mm/userfaultfd.c | 1 +
tools/testing/selftests/mm/uffd-unit-tests.c | 84 ++++++++++++++++++++
2 files changed, 85 insertions(+)
--
2.53.0
next reply other threads:[~2026-10-03 10:30 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 10:30 Donggeun Yoo [this message]
2026-10-03 10:30 ` [PATCH v4 1/2] userfaultfd: clear the inherited uffd bit in move_swap_pte() Donggeun Yoo
2026-10-03 10:30 ` [PATCH v4 2/2] selftests/mm: add tests for UFFDIO_MOVE of a uffd-protected swap entry Donggeun Yoo
2026-10-05 10:43 ` David Hildenbrand (Arm)
2026-10-05 11:50 ` Donggeun Yoo
2026-10-07 10:03 ` David Hildenbrand (Arm)
2026-10-04 20:07 ` [PATCH v4 0/2] userfaultfd: clear the inherited uffd bit in move_swap_pte() Andrew Morton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003103030.63380-1-donggeunyoo.kernel@gmail.com \
--to=donggeunyoo.kernel@gmail.com \
--cc=aarcange@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=david@kernel.org \
--cc=kas@kernel.org \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=mhocko@suse.com \
--cc=peterx@redhat.com \
--cc=rppt@kernel.org \
--cc=shuah@kernel.org \
--cc=surenb@google.com \
--cc=vbabka@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.