Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: mpenttil@redhat.com
Cc: dri-devel@lists.freedesktop.org, intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v15 05/11] mm/hmm: migrate collection in HMM pagewalk - pte level
Date: Thu, 24 Sep 2026 07:10:25 +0000	[thread overview]
Message-ID: <20260924071025.9477D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924065313.899730-6-mpenttil@redhat.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] mm: livelock in migrate_vma_split_folio() due to folio_get() before folio_lock()
- [High] mm: crash in migrate_vma_split_folio() due to unvalidated non-folio compound page
- [High] mm: valid pages marked with HMM_PFN_ERROR after transient split failure
--

commit 9b874173389a5794c12372b3f46c3c2b4f634054
Author: Mika Penttilä <mpenttil@redhat.com>

mm/hmm: migrate collection in HMM pagewalk - pte level

Implement hmm_vma_handle_migrate_prepare() for migration decisions and
migrate_vma_split_folio() for splitting pte mapped large folios during
HMM pagewalks.

> diff --git a/mm/hmm.c b/mm/hmm.c
> index 25f537c87b5f2..a60b669630496 100644
> --- a/mm/hmm.c
> +++ b/mm/hmm.c

[ ... ]

> +static int migrate_vma_split_folio(struct folio *folio,
> +				   struct page *fault_page,
> +				   struct hmm_vma_walk *hmm_vma_walk,
> +				   pte_t *ptep)
> +{
> +	int ret;
> +	struct folio *fault_folio = fault_page ? page_folio(fault_page) : NULL;
> +	struct folio *new_fault_folio = NULL;
> +
> +	if (folio != fault_folio)
> +		folio_get(folio);
> +
> +	pte_unmap_unlock(ptep, hmm_vma_walk->ptl);
> +	hmm_vma_walk->ptelocked = false;
> +
> +	if (folio != fault_folio)
> +		folio_lock(folio);

[Severity: High]
Can this cause a livelock when splitting the folio?

If multiple threads concurrently fault on the same shared large folio and
enter migrate_vma_split_folio(), they will all acquire a reference via
folio_get() before blocking on folio_lock(). This inflates the refcount,
causing split_folio() to fail with -EAGAIN. Retrying this sequence creates
a permanent livelock.

[ ... ]

> +static int hmm_vma_handle_migrate_prepare(const struct mm_walk *walk,
> +					  pmd_t *pmdp,
> +					  pte_t *ptep,
> +					  unsigned long addr,
> +					  unsigned long *hmm_pfn,
> +					  bool *unmapped)
> +{

[ ... ]

> +		folio = page ? page_folio(page) : NULL;
> +		if (folio && folio_test_large(folio)) {
> +			int ret;
> +
> +			ret = migrate_vma_split_folio(folio,
> +						      migrate->fault_page,
> +						      hmm_vma_walk,
> +						      ptep);
> +			if (ret)
> +				goto out_error;
> +			return -EAGAIN;
> +		}
> +
> +		writable = pte_write(pte);
> +	}
> +
> +	if (!page || !page->mapping)
> +		goto out;

[Severity: High]
Does this code operate on uninitialized folio metadata if a driver maps an
uninitialized compound page to userspace?

If a driver allocates a compound page without folio initialization and maps
it, hmm_range_fault() walking the VMA will see PG_head set, and
folio_test_large() will succeed. Because the !page->mapping validation check
is deferred until after the split attempt, this passes the uninitialized
compound page to migrate_vma_split_folio(), which can crash when calling
folio_lock() and split_folio().

[ ... ]

> +out:
>  	return 0;
> +out_error:
> +	return -EFAULT;
>  }

[Severity: High]
Can a transient split failure result in valid pages being falsely marked as
inaccessible?

If migrate_vma_split_folio() fails due to a transient refcount elevation,
hmm_vma_handle_migrate_prepare() returns -EFAULT. When hmm_vma_walk_pmd()
catches this non -EAGAIN error, it breaks the loop and calls
hmm_pfns_fill(..., HMM_PFN_ERROR) for the entire remainder of the PMD.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924065313.899730-1-mpenttil@redhat.com?part=5

  reply	other threads:[~2026-09-24  7:10 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24  6:53 [PATCH v15 00/11] migrate on fault for device pages mpenttil
2026-09-24  6:53 ` [PATCH v15 01/11] mm/Kconfig: changes for " mpenttil
2026-09-24  7:11   ` sashiko-bot
2026-09-24  6:53 ` [PATCH v15 02/11] mm: add helper to convert HMM pfn to migrate pfn mpenttil
2026-09-24  6:53 ` [PATCH v15 03/11] mm/hmm: preparations for HMM to participate in migration mpenttil
2026-09-24  7:09   ` sashiko-bot
2026-09-24  6:53 ` [PATCH v15 04/11] mm/hmm: do the plumbing " mpenttil
2026-09-24  6:53 ` [PATCH v15 05/11] mm/hmm: migrate collection in HMM pagewalk - pte level mpenttil
2026-09-24  7:10   ` sashiko-bot [this message]
2026-09-24  6:53 ` [PATCH v15 06/11] mm/hmm: migrate collection in HMM pagewalk - pmd level mpenttil
2026-09-24  7:09   ` sashiko-bot
2026-09-24  6:53 ` [PATCH v15 07/11] mm/hmm: add lazy MMU mode support for migration in HMM pagewalk mpenttil
2026-09-24  6:53 ` [PATCH v15 08/11] mm/hmm: implement rollback for device page " mpenttil
2026-09-24  7:16   ` sashiko-bot
2026-09-24  6:53 ` [PATCH v15 09/11] mm: enable device page migration from " mpenttil
2026-09-24  6:53 ` [PATCH v15 10/11] lib/test_hmm: add a new testcase for the migrate on fault mpenttil
2026-09-24  7:27   ` sashiko-bot
2026-09-24  6:53 ` [PATCH v15 11/11] Documentation/mm/hmm: document migration through hmm_range_fault() mpenttil
2026-09-24  7:28 ` ✗ CI.checkpatch: warning for Migrate on fault for device pages (rev7) Patchwork
2026-09-24  7:30 ` ✓ CI.KUnit: success " Patchwork
2026-09-24  7:46 ` ✗ CI.checksparse: warning " Patchwork
2026-09-24  8:09 ` ✓ Xe.CI.BAT: success " Patchwork
2026-09-24 21:10 ` ✗ Xe.CI.FULL: failure " Patchwork
2026-09-25  9:07 ` [PATCH v15 00/11] migrate on fault for device pages Christoph Hellwig
2026-09-25 10:23   ` Mika Penttilä
2026-09-25 12:47     ` Jason Gunthorpe
2026-09-25 13:22       ` Mika Penttilä

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924071025.9477D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=mpenttil@redhat.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox