From: Andrew Morton <akpm@linux-foundation.org>
To: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Cc: rppt@kernel.org, peterx@redhat.com, surenb@google.com,
aarcange@redhat.com, david@kernel.org, ljs@kernel.org,
liam@infradead.org, vbabka@kernel.org, mhocko@suse.com,
shuah@kernel.org, kas@kernel.org, linux-mm@kvack.org,
linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v4 0/2] userfaultfd: clear the inherited uffd bit in move_swap_pte()
Date: Sun, 4 Oct 2026 13:07:51 -0700 [thread overview]
Message-ID: <20261004130751.1cdab825ae521c16e02f66ec@linux-foundation.org> (raw)
In-Reply-To: <20261003103030.63380-1-donggeunyoo.kernel@gmail.com>
On Sat, 3 Oct 2026 19:30:28 +0900 Donggeun Yoo <donggeunyoo.kernel@gmail.com> wrote:
> UFFDIO_MOVE on a swapped-out page installs the source PTE at the
> destination unchanged, so a uffd bit set on a write-protected or
> RWP-protected source lands in a destination VMA that was never
> registered for either, and nothing clears it afterwards. Patch 1 clears
> the bit, then re-arms it if the destination is RWP-registered, which is
> what the present-page and zeropage move paths already do. Patch 2 adds
> the tests that catch it.
Thanks, I updated mm-hotfixes-unstable with this version.
> Changes in v4:
> - patch 1: add Acked-by from David Hildenbrand and Mike Rapoport; no
> code change
> - patch 2: protect the source right after registering it, open pagemap
> at the top, and use a designated initializer for the move (David
> Hildenbrand)
> - patch 2: fail only the test case, not the whole run, when UFFDIO_MOVE
> fails (David Hildenbrand)
Here's how v4 altered mm.git:
tools/testing/selftests/mm/uffd-unit-tests.c | 36 ++++++++---------
1 file changed, 18 insertions(+), 18 deletions(-)
--- a/tools/testing/selftests/mm/uffd-unit-tests.c~b
+++ a/tools/testing/selftests/mm/uffd-unit-tests.c
@@ -2049,28 +2049,29 @@ static void uffd_move_swap_test_common(u
bool rwp)
{
unsigned long page_size = gopts->page_size;
- struct uffdio_move move = { };
- int pagemap_fd;
+ struct uffdio_move move = {
+ .dst = (unsigned long)gopts->area_dst,
+ .src = (unsigned long)gopts->area_src,
+ .len = page_size,
+ };
+ int pagemap_fd = pagemap_open();
if (rwp) {
if (uffd_register_rwp(gopts->uffd, gopts->area_src, page_size))
err("register src failure");
- } else if (uffd_register(gopts->uffd, gopts->area_src, page_size,
- false, true, false)) {
- err("register src failure");
- }
- if (uffd_register(gopts->uffd, gopts->area_dst, page_size,
- true, false, false))
- err("register dst failure");
-
- if (rwp)
rwprotect_range(gopts->uffd, (unsigned long)gopts->area_src,
page_size, true);
- else
+ } else {
+ if (uffd_register(gopts->uffd, gopts->area_src, page_size,
+ false, true, false))
+ err("register src failure");
wp_range(gopts->uffd, (unsigned long)gopts->area_src,
page_size, true);
+ }
+ if (uffd_register(gopts->uffd, gopts->area_dst, page_size,
+ true, false, false))
+ err("register dst failure");
- pagemap_fd = pagemap_open();
if (madvise(gopts->area_src, page_size, MADV_PAGEOUT))
err("MADV_PAGEOUT");
if (!pagemap_is_swapped(pagemap_fd, gopts->area_src)) {
@@ -2078,11 +2079,10 @@ static void uffd_move_swap_test_common(u
goto out;
}
- move.dst = (unsigned long)gopts->area_dst;
- move.src = (unsigned long)gopts->area_src;
- move.len = page_size;
- if (ioctl(gopts->uffd, UFFDIO_MOVE, &move))
- err("UFFDIO_MOVE");
+ if (ioctl(gopts->uffd, UFFDIO_MOVE, &move)) {
+ uffd_test_fail("UFFDIO_MOVE failed: %s", strerror(errno));
+ goto out;
+ }
if (pagemap_get_entry(pagemap_fd, gopts->area_dst) & PM_UFFD_WP)
uffd_test_fail("uffd bit moved into an area registered for missing faults only");
_
prev parent reply other threads:[~2026-10-04 20:07 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 10:30 [PATCH v4 0/2] userfaultfd: clear the inherited uffd bit in move_swap_pte() Donggeun Yoo
2026-10-03 10:30 ` [PATCH v4 1/2] " Donggeun Yoo
2026-10-03 10:30 ` [PATCH v4 2/2] selftests/mm: add tests for UFFDIO_MOVE of a uffd-protected swap entry Donggeun Yoo
2026-10-05 10:43 ` David Hildenbrand (Arm)
2026-10-05 11:50 ` Donggeun Yoo
2026-10-07 10:03 ` David Hildenbrand (Arm)
2026-10-04 20:07 ` Andrew Morton [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004130751.1cdab825ae521c16e02f66ec@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=aarcange@redhat.com \
--cc=david@kernel.org \
--cc=donggeunyoo.kernel@gmail.com \
--cc=kas@kernel.org \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=mhocko@suse.com \
--cc=peterx@redhat.com \
--cc=rppt@kernel.org \
--cc=shuah@kernel.org \
--cc=surenb@google.com \
--cc=vbabka@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.