From: sashiko-bot@kernel.org
To: mpenttil@redhat.com
Cc: dri-devel@lists.freedesktop.org, intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v15 05/11] mm/hmm: migrate collection in HMM pagewalk - pte level
Date: Thu, 24 Sep 2026 07:10:25 +0000 [thread overview]
Message-ID: <20260924071025.9477D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924065313.899730-6-mpenttil@redhat.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] mm: livelock in migrate_vma_split_folio() due to folio_get() before folio_lock()
- [High] mm: crash in migrate_vma_split_folio() due to unvalidated non-folio compound page
- [High] mm: valid pages marked with HMM_PFN_ERROR after transient split failure
--
commit 9b874173389a5794c12372b3f46c3c2b4f634054
Author: Mika Penttilä <mpenttil@redhat.com>
mm/hmm: migrate collection in HMM pagewalk - pte level
Implement hmm_vma_handle_migrate_prepare() for migration decisions and
migrate_vma_split_folio() for splitting pte mapped large folios during
HMM pagewalks.
> diff --git a/mm/hmm.c b/mm/hmm.c
> index 25f537c87b5f2..a60b669630496 100644
> --- a/mm/hmm.c
> +++ b/mm/hmm.c
[ ... ]
> +static int migrate_vma_split_folio(struct folio *folio,
> + struct page *fault_page,
> + struct hmm_vma_walk *hmm_vma_walk,
> + pte_t *ptep)
> +{
> + int ret;
> + struct folio *fault_folio = fault_page ? page_folio(fault_page) : NULL;
> + struct folio *new_fault_folio = NULL;
> +
> + if (folio != fault_folio)
> + folio_get(folio);
> +
> + pte_unmap_unlock(ptep, hmm_vma_walk->ptl);
> + hmm_vma_walk->ptelocked = false;
> +
> + if (folio != fault_folio)
> + folio_lock(folio);
[Severity: High]
Can this cause a livelock when splitting the folio?
If multiple threads concurrently fault on the same shared large folio and
enter migrate_vma_split_folio(), they will all acquire a reference via
folio_get() before blocking on folio_lock(). This inflates the refcount,
causing split_folio() to fail with -EAGAIN. Retrying this sequence creates
a permanent livelock.
[ ... ]
> +static int hmm_vma_handle_migrate_prepare(const struct mm_walk *walk,
> + pmd_t *pmdp,
> + pte_t *ptep,
> + unsigned long addr,
> + unsigned long *hmm_pfn,
> + bool *unmapped)
> +{
[ ... ]
> + folio = page ? page_folio(page) : NULL;
> + if (folio && folio_test_large(folio)) {
> + int ret;
> +
> + ret = migrate_vma_split_folio(folio,
> + migrate->fault_page,
> + hmm_vma_walk,
> + ptep);
> + if (ret)
> + goto out_error;
> + return -EAGAIN;
> + }
> +
> + writable = pte_write(pte);
> + }
> +
> + if (!page || !page->mapping)
> + goto out;
[Severity: High]
Does this code operate on uninitialized folio metadata if a driver maps an
uninitialized compound page to userspace?
If a driver allocates a compound page without folio initialization and maps
it, hmm_range_fault() walking the VMA will see PG_head set, and
folio_test_large() will succeed. Because the !page->mapping validation check
is deferred until after the split attempt, this passes the uninitialized
compound page to migrate_vma_split_folio(), which can crash when calling
folio_lock() and split_folio().
[ ... ]
> +out:
> return 0;
> +out_error:
> + return -EFAULT;
> }
[Severity: High]
Can a transient split failure result in valid pages being falsely marked as
inaccessible?
If migrate_vma_split_folio() fails due to a transient refcount elevation,
hmm_vma_handle_migrate_prepare() returns -EFAULT. When hmm_vma_walk_pmd()
catches this non -EAGAIN error, it breaks the loop and calls
hmm_pfns_fill(..., HMM_PFN_ERROR) for the entire remainder of the PMD.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924065313.899730-1-mpenttil@redhat.com?part=5
next prev parent reply other threads:[~2026-09-24 7:10 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 6:53 [PATCH v15 00/11] migrate on fault for device pages mpenttil
2026-09-24 6:53 ` [PATCH v15 01/11] mm/Kconfig: changes for " mpenttil
2026-09-24 7:11 ` sashiko-bot
2026-09-24 6:53 ` [PATCH v15 02/11] mm: add helper to convert HMM pfn to migrate pfn mpenttil
2026-09-24 6:53 ` [PATCH v15 03/11] mm/hmm: preparations for HMM to participate in migration mpenttil
2026-09-24 7:09 ` sashiko-bot
2026-09-24 6:53 ` [PATCH v15 04/11] mm/hmm: do the plumbing " mpenttil
2026-09-24 6:53 ` [PATCH v15 05/11] mm/hmm: migrate collection in HMM pagewalk - pte level mpenttil
2026-09-24 7:10 ` sashiko-bot [this message]
2026-09-24 6:53 ` [PATCH v15 06/11] mm/hmm: migrate collection in HMM pagewalk - pmd level mpenttil
2026-09-24 7:09 ` sashiko-bot
2026-09-24 6:53 ` [PATCH v15 07/11] mm/hmm: add lazy MMU mode support for migration in HMM pagewalk mpenttil
2026-09-24 6:53 ` [PATCH v15 08/11] mm/hmm: implement rollback for device page " mpenttil
2026-09-24 7:16 ` sashiko-bot
2026-09-24 6:53 ` [PATCH v15 09/11] mm: enable device page migration from " mpenttil
2026-09-24 6:53 ` [PATCH v15 10/11] lib/test_hmm: add a new testcase for the migrate on fault mpenttil
2026-09-24 7:27 ` sashiko-bot
2026-09-24 6:53 ` [PATCH v15 11/11] Documentation/mm/hmm: document migration through hmm_range_fault() mpenttil
2026-09-24 7:28 ` ✗ CI.checkpatch: warning for Migrate on fault for device pages (rev7) Patchwork
2026-09-24 7:30 ` ✓ CI.KUnit: success " Patchwork
2026-09-24 7:46 ` ✗ CI.checksparse: warning " Patchwork
2026-09-24 8:09 ` ✓ Xe.CI.BAT: success " Patchwork
2026-09-24 21:10 ` ✗ Xe.CI.FULL: failure " Patchwork
2026-09-25 9:07 ` [PATCH v15 00/11] migrate on fault for device pages Christoph Hellwig
2026-09-25 10:23 ` Mika Penttilä
2026-09-25 12:47 ` Jason Gunthorpe
2026-09-25 13:22 ` Mika Penttilä
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924071025.9477D1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=mpenttil@redhat.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox