From: sashiko-bot@kernel.org
To: "Shakeel Butt" <shakeel.butt@linux.dev>,
"Muchun Song" <muchun.song@linux.dev>,
"Liam R. Howlett" <liam@infradead.org>,
"Matthew Wilcox (Oracle)" <willy@infradead.org>,
"Suren Baghdasaryan" <surenb@google.com>,
"Nico Pache" <nico.pache@linux.dev>,
"Johannes Weiner" <hannes@cmpxchg.org>,
"Gregory Price" <gourry@gourry.net>,
"Kairui Song" <kasong@tencent.com>,
"David Hildenbrand" <david@kernel.org>,
"Michal Hocko" <mhocko@suse.com>,
"Alistair Popple" <apopple@nvidia.com>,
"Baolin Wang" <baolin.wang@linux.alibaba.com>,
"Vlastimil Babka" <vbabka@kernel.org>, "Zi Yan" <ziy@nvidia.com>,
"Lance Yang" <lance.yang@linux.dev>,
"Lorenzo Stoakes" <ljs@kernel.org>,
"Andrew Morton" <akpm@linux-foundation.org>,
"Barry Song" <baohua@kernel.org>,
"Ryan Roberts" <ryan.roberts@arm.com>,
"Qi Zheng" <qi.zheng@linux.dev>, "Dev Jain" <dev.jain@arm.com>,
"Ying Huang" <ying.huang@linux.alibaba.com>,
"Usama Arif" <usama.arif@linux.dev>,
"Mike Rapoport" <rppt@kernel.org>
Cc: "Jan Kara" <jack@suse.cz>, "Jonathan Corbet" <corbet@lwn.net>,
"Pasha Tatashin" <pasha.tatashin@soleen.com>,
linux-mm@kvack.org,
"Mathieu Desnoyers" <mathieu.desnoyers@efficios.com>,
kexec@lists.infradead.org,
"Masami Hiramatsu" <mhiramat@kernel.org>,
"Pratyush Yadav" <pratyush@kernel.org>,
linux-doc@vger.kernel.org, linux-trace-kernel@vger.kernel.org,
"Baoquan He" <baoquan.he@linux.dev>,
linux-kernel@vger.kernel.org,
"Dave Young" <ruirui.yang@linux.dev>,
"Steven Rostedt" <rostedt@goodmis.org>,
"Shuah Khan" <skhan@linuxfoundation.org>,
linux-fsdevel@vger.kernel.org
Subject: Re: [PATCH v5 17/17] mm/page-flags: remove PG_private
Date: Mon, 21 Sep 2026 02:55:20 +0000 [thread overview]
Message-ID: <20260921025520.628971F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260920-remove-pg_private-v5-17-bb68b6a21869@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] mm: silent memory leak masking due to PG_private removal
--
commit aee12ed3446e69cb6eee57384ca09e768dab36dd
Author: Zi Yan <ziy@nvidia.com>
mm/page-flags: remove PG_private
This commit removes the PG_private page flag and replaces its usage with
checking if folio->private != NULL. The space left by PG_private is
reserved as PG_folio for future use.
> diff --git a/include/linux/page-flags.h b/include/linux/page-flags.h
> index 7080a6a1a79e7..b0ddc652e76cc 100644
> --- a/include/linux/page-flags.h
> +++ b/include/linux/page-flags.h
[ ... ]
> @@ -1169,7 +1175,7 @@ static __always_inline void __ClearPageAnonExclusive(struct page *page)
> */
> #define PAGE_FLAGS_CHECK_AT_FREE \
> (1UL << PG_lru | 1UL << PG_locked | \
> - 1UL << PG_private | 1UL << PG_private_2 | \
> + 1UL << PG_private_2 | \
[Severity: Medium]
Since PG_private is removed from PAGE_FLAGS_CHECK_AT_FREE, does this bypass
the safety check that ensures a page doesn't have uncleared private data?
Looking at __free_pages_prepare() in mm/page_alloc.c:
page_cpupid_reset_last(page);
page->flags.f &= ~PAGE_FLAGS_CHECK_AT_PREP;
page->private = 0;
reset_page_owner(page, order);
The head page's private field is silently zeroed here without any prior
verification that it was NULL. Previously, free_page_is_bad() would catch
and report leaked data via a bad_page() warning using
PAGE_FLAGS_CHECK_AT_FREE.
Now, if a buggy filesystem fails to detach and free folio->private data
before freeing the page, will this result in silent memory leaks?
> 1UL << PG_writeback | 1UL << PG_reserved | \
> 1UL << PG_active | \
> 1UL << PG_unevictable | __PG_MLOCKED | LRU_GEN_MASK)
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260920-remove-pg_private-v5-0-bb68b6a21869@nvidia.com?part=17
next prev parent reply other threads:[~2026-09-21 2:55 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 2:27 [PATCH v5 00/17] Remove PG_private by using page/folio->private checks instead Zi Yan
2026-09-21 2:28 ` [PATCH v5 17/17] mm/page-flags: remove PG_private Zi Yan
2026-09-21 2:55 ` sashiko-bot [this message]
2026-09-21 15:36 ` Zi Yan
2026-09-21 4:08 ` [PATCH v5 00/17] Remove PG_private by using page/folio->private checks instead Andrew Morton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921025520.628971F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=apopple@nvidia.com \
--cc=baohua@kernel.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=baoquan.he@linux.dev \
--cc=corbet@lwn.net \
--cc=david@kernel.org \
--cc=dev.jain@arm.com \
--cc=gourry@gourry.net \
--cc=hannes@cmpxchg.org \
--cc=jack@suse.cz \
--cc=kasong@tencent.com \
--cc=kexec@lists.infradead.org \
--cc=lance.yang@linux.dev \
--cc=liam@infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=ljs@kernel.org \
--cc=mathieu.desnoyers@efficios.com \
--cc=mhiramat@kernel.org \
--cc=mhocko@suse.com \
--cc=muchun.song@linux.dev \
--cc=nico.pache@linux.dev \
--cc=pasha.tatashin@soleen.com \
--cc=pratyush@kernel.org \
--cc=qi.zheng@linux.dev \
--cc=rostedt@goodmis.org \
--cc=rppt@kernel.org \
--cc=ruirui.yang@linux.dev \
--cc=ryan.roberts@arm.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=shakeel.butt@linux.dev \
--cc=skhan@linuxfoundation.org \
--cc=surenb@google.com \
--cc=usama.arif@linux.dev \
--cc=vbabka@kernel.org \
--cc=willy@infradead.org \
--cc=ying.huang@linux.alibaba.com \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox