From: Hui Su <sh_def@163.com>
To: "David Hildenbrand (Arm)" <david@kernel.org>
Cc: Matthew Brost <matthew.brost@intel.com>,
Andrew Morton <akpm@linux-foundation.org>,
Balbir Singh <balbirs@nvidia.com>, Zhi Wang <ziy@nvidia.com>,
Joshua Hahn <joshua.hahnjy@gmail.com>,
Rakie Kim <rakie.kim@sk.com>, Byungchul Park <byungchul@sk.com>,
Gourry <gourry@gourry.net>,
Ying Huang <ying.huang@linux.alibaba.com>,
Alex Popple <apopple@nvidia.com>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
Hui Su <sh_def@163.com>
Subject: Re: [PATCH v2] mm/migrate_device: avoid out-of-bounds writes for compound folios
Date: Fri, 11 Sep 2026 14:40:15 +0900 [thread overview]
Message-ID: <c1ef3ed47d2403fbc23a6032ca54a872.sh_def@163.com> (raw)
In-Reply-To: <c99ca53a-73ef-4a0c-8738-eba1cc89bea2@kernel.org>
On Wed, Sep 09, 2026 at 03:43:03PM +0200, David Hildenbrand (Arm) wrote:
> Yes, and please clean up the code in any case; the duplication should be avoided.
Hi David, Matthew,
I reran the original HMM migrate_anon_huge_zero reproducer on current
mainline.
The private-device case passes, and I could not reproduce the original
KASAN out-of-bounds write. I also instrumented the truncated
compound-folio case, and that condition was not hit. The coherent-device
case was skipped on this setup.
So for the follow-up cleanup, I don't plan to add a Fixes tag or Cc
stable. It only consolidates the duplicated compound-folio handling,
uses memset() for the tail entries, and adds WARN_ON_ONCE() for the
caller invariant discussed here.
The original stable Cc was based on the KASAN OOB I observed on the tree
I tested at the time.
I'll send the cleanup as a separate patch.
Thanks,
Hui
prev parent reply other threads:[~2026-09-11 5:40 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 12:08 [PATCH v2] mm/migrate_device: avoid out-of-bounds writes for compound folios Hui Su
2026-08-17 18:21 ` Andrew Morton
2026-08-18 11:13 ` Balbir Singh
2026-08-27 15:14 ` David Hildenbrand (Arm)
2026-08-28 4:44 ` Matthew Brost
2026-09-07 12:23 ` David Hildenbrand (Arm)
2026-09-09 11:20 ` Hui Su
2026-09-09 13:43 ` David Hildenbrand (Arm)
2026-09-11 5:40 ` Hui Su [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c1ef3ed47d2403fbc23a6032ca54a872.sh_def@163.com \
--to=sh_def@163.com \
--cc=akpm@linux-foundation.org \
--cc=apopple@nvidia.com \
--cc=balbirs@nvidia.com \
--cc=byungchul@sk.com \
--cc=david@kernel.org \
--cc=gourry@gourry.net \
--cc=joshua.hahnjy@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=matthew.brost@intel.com \
--cc=rakie.kim@sk.com \
--cc=ying.huang@linux.alibaba.com \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.