From: Balbir Singh <balbirs@nvidia.com>
To: Zi Yan <ziy@nvidia.com>,
"David Hildenbrand (Arm)" <david@kernel.org>,
Andrew Morton <akpm@linux-foundation.org>,
Arvind Yadav <arvind.yadav@intel.com>
Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org,
matthew.brost@intel.com, joshua.hahnjy@gmail.com,
rakie.kim@sk.com, byungchul@sk.com, gourry@gourry.net,
ying.huang@linux.alibaba.com, apopple@nvidia.com
Subject: Re: [PATCH v2] mm/migrate_device: Clear stale mapping after freeing swapcache
Date: Mon, 27 Jul 2026 10:38:21 +1000 [thread overview]
Message-ID: <c3532789-6b6f-4cc7-9d4e-cfb05cc88264@nvidia.com> (raw)
In-Reply-To: <DK7YH5O0FS58.3OTH04TI72U0Q@nvidia.com>
On 7/26/26 7:05 AM, Zi Yan wrote:
> On Sat Jul 25, 2026 at 3:36 PM EDT, David Hildenbrand (Arm) wrote:
>> On 7/25/26 06:43, Andrew Morton wrote:
>>> On Fri, 24 Jul 2026 13:57:02 +0530 Arvind Yadav <arvind.yadav@intel.com> wrote:
>>>
>>>> __migrate_device_pages() reads the folio mapping before calling
>>>> folio_free_swap(). When folio_free_swap() succeeds, the folio is removed
>>>> from the swap cache, but the saved mapping still points to swap_space.
>>>>
>>>> Passing the stale mapping to folio_migrate_mapping() makes it take the
>>>> mapped-folio path after the swapcache reference has been dropped. This can
>>>> cause an invalid swap_space lock access followed by a folio reference
>>>> count BUG.
>>>>
>>>> Refresh the saved mapping after folio_free_swap() so the current folio
>>>> state is used during migration.
>>>>
>>>
>>> Thanks. AI review might have found an issue with this. And one
>>> possible pre-existing issue in the code which Alistair and Balbir
>>> worked on.
>>>
>>> https://sashiko.dev/#/patchset/20260724082702.2531024-1-arvind.yadav@intel.com
>>
>> Yeah, this might need another careful look.
>
> It seems that the pre-existing issue can be fixed by resetting nr to 1
> after split is successful. It should also complete this patch. Something
> like this:
>
>
> diff --git a/mm/migrate_device.c b/mm/migrate_device.c
> index 18d097c388530..4a77b6c86ae4f 100644
> --- a/mm/migrate_device.c
> +++ b/mm/migrate_device.c
> @@ -1193,6 +1193,11 @@ static void __migrate_device_pages(unsigned long *src_pfns,
> MIGRATE_PFN_COMPOUND);
> goto next;
> }
> + /*
> + * reset nr so that only first after-split folio
> + * is processed below
> + */
> + nr = 1;
> } else if ((src_pfns[i] & MIGRATE_PFN_MIGRATE) &&
> (dst_pfns[i] & MIGRATE_PFN_COMPOUND) &&
> !(src_pfns[i] & MIGRATE_PFN_COMPOUND)) {
>
>
Hmm.. I don't this error condition possible, migrate_vma_split_unmapped_folio()
will VM_WARN_ON non anonymous folios, but the design contract is for anonymous
folios only. The enforcement comes from the callers of migrate_vma_pages() and
migrate_device_pages(). Also __folio_freeze_and_split_unmapped() checks if the
folio has a swapcache and mapping associated with it, prior to split. I think
this is a false positive
Balbir
next prev parent reply other threads:[~2026-07-27 0:38 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-24 8:27 [PATCH v2] mm/migrate_device: Clear stale mapping after freeing swapcache Arvind Yadav
2026-07-24 14:00 ` Zi Yan
2026-07-25 4:43 ` Andrew Morton
2026-07-25 19:36 ` David Hildenbrand (Arm)
2026-07-25 21:05 ` Zi Yan
2026-07-27 0:38 ` Balbir Singh [this message]
2026-07-27 1:46 ` Zi Yan
2026-07-27 2:24 ` Balbir Singh
2026-07-27 5:06 ` Yadav, Arvind
2026-07-27 3:06 ` Balbir Singh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c3532789-6b6f-4cc7-9d4e-cfb05cc88264@nvidia.com \
--to=balbirs@nvidia.com \
--cc=akpm@linux-foundation.org \
--cc=apopple@nvidia.com \
--cc=arvind.yadav@intel.com \
--cc=byungchul@sk.com \
--cc=david@kernel.org \
--cc=gourry@gourry.net \
--cc=joshua.hahnjy@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=matthew.brost@intel.com \
--cc=rakie.kim@sk.com \
--cc=ying.huang@linux.alibaba.com \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.