Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2 0/4] mm: Fix page-table teardown during memory hot-remove
@ 2026-10-10 11:24 Muchun Song
  2026-10-10 11:24 ` [PATCH v2 1/4] mm: fix missing page-table destructor in pagetable_free() Muchun Song
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Muchun Song @ 2026-10-10 11:24 UTC (permalink / raw)
  To: Andrew Morton
  Cc: David Hildenbrand, Oscar Salvador, Dave Hansen, Paul Walmsley,
	Palmer Dabbelt, Albert Ou, Alexandre Ghiti, Björn Töpel,
	Catalin Marinas, Will Deacon, Mark Rutland, Kevin Brodsky,
	Alexander Gordeev, Alistair Popple, linux-mm, linux-riscv,
	linux-arm-kernel, linux-kernel, stable, Muchun Song, Muchun Song

Memory hot-remove can free page-table pages allocated through paths with
different constructor state. Some paths run the page-table constructor,
while generic sparse-vmemmap population may not. The x86, RISC-V, and
arm64 teardown paths did not handle that distinction consistently,
leaving constructor/destructor accounting unbalanced.

Make pagetable_free() test PageTable() and run the destructor only when
the constructor initialized the page. The RISC-V and arm64 fixes then
use this common helper for their memory-hot-remove paths.

The architecture fixes depend on the common MM change in patch 1, so
this remains a single series. I expect it to go through the MM tree,
with review or acks from the relevant architecture maintainers.

Changes since v1:
- Move the destructor decision from x86 into pagetable_free(), as
  suggested by David Hildenbrand.
- Use pagetable_free() for non-reserved RISC-V page-table pages and
  simplify reserved-page handling.
- Collect David Hildenbrand's Acked-by on the RISC-V PUD fix.
- Use pagetable_free() for arm64 intermediate page-table pages, as
  suggested by David Hildenbrand.
- Trim and update the commit messages, as requested by Dave Hansen.

Muchun Song (4):
  mm: fix missing page-table destructor in pagetable_free()
  riscv/mm: fix hotplug page-table destructor handling
  riscv/mm: fix missing destructor for hotplug PUD tables
  arm64/mm: fix destructor for unconstructed hotplug page tables

 arch/arm64/mm/mmu.c  |  3 +--
 arch/riscv/mm/init.c | 32 +++++++++++++-------------------
 include/linux/mm.h   | 37 ++++++++++++++++++++-----------------
 3 files changed, 34 insertions(+), 38 deletions(-)


base-commit: 8b38ed9ab5b09c8ba168cbcc49524e9b380ee5c4
-- 
2.54.0



^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v2 1/4] mm: fix missing page-table destructor in pagetable_free()
  2026-10-10 11:24 [PATCH v2 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
@ 2026-10-10 11:24 ` Muchun Song
  2026-10-10 11:24 ` [PATCH v2 2/4] riscv/mm: fix hotplug page-table destructor handling Muchun Song
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: Muchun Song @ 2026-10-10 11:24 UTC (permalink / raw)
  To: Andrew Morton
  Cc: David Hildenbrand, Oscar Salvador, Dave Hansen, Paul Walmsley,
	Palmer Dabbelt, Albert Ou, Alexandre Ghiti, Björn Töpel,
	Catalin Marinas, Will Deacon, Mark Rutland, Kevin Brodsky,
	Alexander Gordeev, Alistair Popple, linux-mm, linux-riscv,
	linux-arm-kernel, linux-kernel, stable, Muchun Song, Muchun Song

Since commit 49f599666420 ("mm: call ctor/dtor for kernel PTEs"),
pte_alloc_one_kernel() runs the page-table constructor for kernel PTE
tables.

HVO (HugeTLB Vmemmap Optimization) uses pte_alloc_one_kernel() when
splitting a PMD. Restoring the vmemmap backing pages does not collapse
the PTE table, so a later memory hot-remove eventually frees it through
pagetable_free() on x86-64. That releases the page without running the
matching destructor and leaves NR_PAGETABLE elevated.

Make pagetable_free() detect constructor-backed pages and run the
destructor before releasing their memory to fix the problem.

Fixes: 49f599666420 ("mm: call ctor/dtor for kernel PTEs")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
---
v2:
- Move destructor handling from x86 into pagetable_free() (suggested by
  David Hildenbrand)
- Trim and update the commit message (requested by Dave Hansen)
---
 include/linux/mm.h | 37 ++++++++++++++++++++-----------------
 1 file changed, 20 insertions(+), 17 deletions(-)

diff --git a/include/linux/mm.h b/include/linux/mm.h
index 5cca90fc1df6..771a7d60b0a5 100644
--- a/include/linux/mm.h
+++ b/include/linux/mm.h
@@ -3969,23 +3969,6 @@ static inline void pagetable_free_kernel(struct ptdesc *pt)
 	__pagetable_free(pt);
 }
 #endif
-/**
- * pagetable_free - Free pagetables
- * @pt:	The page table descriptor
- *
- * pagetable_free frees the memory of all page tables described by a page
- * table descriptor and the memory for the descriptor itself.
- */
-static inline void pagetable_free(struct ptdesc *pt)
-{
-	if (ptdesc_test_kernel(pt)) {
-		ptdesc_clear_kernel(pt);
-		pagetable_free_kernel(pt);
-	} else {
-		__pagetable_free(pt);
-	}
-}
-
 #if defined(CONFIG_SPLIT_PTE_PTLOCKS)
 #if ALLOC_SPLIT_PTLOCKS
 void __init ptlock_cache_init(void);
@@ -4078,6 +4061,26 @@ static inline void pagetable_dtor(struct ptdesc *ptdesc)
 	lruvec_stat_sub_folio(folio, NR_PAGETABLE);
 }
 
+/**
+ * pagetable_free - Free pagetables
+ * @pt:	The page table descriptor
+ *
+ * pagetable_free frees the memory of all page tables described by a page
+ * table descriptor and the memory for the descriptor itself.
+ */
+static inline void pagetable_free(struct ptdesc *pt)
+{
+	if (PageTable(ptdesc_page(pt)))
+		pagetable_dtor(pt);
+
+	if (ptdesc_test_kernel(pt)) {
+		ptdesc_clear_kernel(pt);
+		pagetable_free_kernel(pt);
+	} else {
+		__pagetable_free(pt);
+	}
+}
+
 static inline void pagetable_dtor_free(struct ptdesc *ptdesc)
 {
 	pagetable_dtor(ptdesc);
-- 
2.54.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH v2 2/4] riscv/mm: fix hotplug page-table destructor handling
  2026-10-10 11:24 [PATCH v2 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
  2026-10-10 11:24 ` [PATCH v2 1/4] mm: fix missing page-table destructor in pagetable_free() Muchun Song
@ 2026-10-10 11:24 ` Muchun Song
  2026-10-10 11:24 ` [PATCH v2 3/4] riscv/mm: fix missing destructor for hotplug PUD tables Muchun Song
  2026-10-10 11:24 ` [PATCH v2 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables Muchun Song
  3 siblings, 0 replies; 5+ messages in thread
From: Muchun Song @ 2026-10-10 11:24 UTC (permalink / raw)
  To: Andrew Morton
  Cc: David Hildenbrand, Oscar Salvador, Dave Hansen, Paul Walmsley,
	Palmer Dabbelt, Albert Ou, Alexandre Ghiti, Björn Töpel,
	Catalin Marinas, Will Deacon, Mark Rutland, Kevin Brodsky,
	Alexander Gordeev, Alistair Popple, linux-mm, linux-riscv,
	linux-arm-kernel, linux-kernel, stable, Muchun Song, Muchun Song

RISC-V uses the same memory-hotplug teardown code for linear-map and
vmemmap page tables. Late linear-map allocations run page-table
constructors, while vmemmap and early allocations may not.

free_pte_table() unconditionally calls pagetable_dtor(), corrupting
NR_PAGETABLE accounting for constructor-free tables. free_pmd_table()
avoids that for vmemmap using is_vmemmap, but mapping type is not a
reliable proxy for constructor state. In particular, it becomes invalid
once runtime vmemmap tables use the normal pgalloc helpers.

Introduce free_pgtable_page() to select free_reserved_page() for reserved
pages and pagetable_free() otherwise. The latter runs the destructor only
when PageTable() is set, handling both constructor-backed and
constructor-free tables.

Fixes: c75a74f4ba19 ("riscv: mm: Add memory hotplugging support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
---
v2:
- Use pagetable_free() for non-reserved tables (suggested by David
  Hildenbrand)
- Simplify reserved-page handling
---
 arch/riscv/mm/init.c | 27 ++++++++++++---------------
 1 file changed, 12 insertions(+), 15 deletions(-)

diff --git a/arch/riscv/mm/init.c b/arch/riscv/mm/init.c
index 857f9a55039c..151eb197cb09 100644
--- a/arch/riscv/mm/init.c
+++ b/arch/riscv/mm/init.c
@@ -1486,10 +1486,17 @@ struct execmem_info __init *execmem_arch_setup(void)
 #endif /* CONFIG_EXECMEM */
 
 #ifdef CONFIG_MEMORY_HOTPLUG
+static void __meminit free_pgtable_page(struct page *page)
+{
+	if (PageReserved(page))
+		free_reserved_page(page);
+	else
+		pagetable_free(page_ptdesc(page));
+}
+
 static void __meminit free_pte_table(pte_t *pte_start, pmd_t *pmd)
 {
 	struct page *page = pmd_page(*pmd);
-	struct ptdesc *ptdesc = page_ptdesc(page);
 	pte_t *pte;
 	int i;
 
@@ -1499,18 +1506,13 @@ static void __meminit free_pte_table(pte_t *pte_start, pmd_t *pmd)
 			return;
 	}
 
-	pagetable_dtor(ptdesc);
-	if (PageReserved(page))
-		free_reserved_page(page);
-	else
-		pagetable_free(ptdesc);
+	free_pgtable_page(page);
 	pmd_clear(pmd);
 }
 
-static void __meminit free_pmd_table(pmd_t *pmd_start, pud_t *pud, bool is_vmemmap)
+static void __meminit free_pmd_table(pmd_t *pmd_start, pud_t *pud)
 {
 	struct page *page = pud_page(*pud);
-	struct ptdesc *ptdesc = page_ptdesc(page);
 	pmd_t *pmd;
 	int i;
 
@@ -1520,12 +1522,7 @@ static void __meminit free_pmd_table(pmd_t *pmd_start, pud_t *pud, bool is_vmemm
 			return;
 	}
 
-	if (!is_vmemmap)
-		pagetable_dtor(ptdesc);
-	if (PageReserved(page))
-		free_reserved_page(page);
-	else
-		pagetable_free(ptdesc);
+	free_pgtable_page(page);
 	pud_clear(pud);
 }
 
@@ -1645,7 +1642,7 @@ static void __meminit remove_pud_mapping(pud_t *pud_base, unsigned long addr, un
 		remove_pmd_mapping(pmd_base, addr, next, is_vmemmap, altmap);
 
 		if (pgtable_l4_enabled)
-			free_pmd_table(pmd_base, pudp, is_vmemmap);
+			free_pmd_table(pmd_base, pudp);
 	}
 }
 
-- 
2.54.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH v2 3/4] riscv/mm: fix missing destructor for hotplug PUD tables
  2026-10-10 11:24 [PATCH v2 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
  2026-10-10 11:24 ` [PATCH v2 1/4] mm: fix missing page-table destructor in pagetable_free() Muchun Song
  2026-10-10 11:24 ` [PATCH v2 2/4] riscv/mm: fix hotplug page-table destructor handling Muchun Song
@ 2026-10-10 11:24 ` Muchun Song
  2026-10-10 11:24 ` [PATCH v2 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables Muchun Song
  3 siblings, 0 replies; 5+ messages in thread
From: Muchun Song @ 2026-10-10 11:24 UTC (permalink / raw)
  To: Andrew Morton
  Cc: David Hildenbrand, Oscar Salvador, Dave Hansen, Paul Walmsley,
	Palmer Dabbelt, Albert Ou, Alexandre Ghiti, Björn Töpel,
	Catalin Marinas, Will Deacon, Mark Rutland, Kevin Brodsky,
	Alexander Gordeev, Alistair Popple, linux-mm, linux-riscv,
	linux-arm-kernel, linux-kernel, stable, Muchun Song, Muchun Song

Commit 8472cc4503eb ("riscv: mm: call PUD/P4D ctor in special kernel
pgtable alloc") made alloc_pud_late() run the PUD page-table constructor.
However, free_pud_table() still frees non-reserved PUD tables directly
without decrementing NR_PAGETABLE.

Free PUD tables through the common free_pgtable_page() helper so that
constructor-backed tables run the matching destructor before being
freed.

Fixes: 8472cc4503eb ("riscv: mm: call PUD/P4D ctor in special kernel pgtable alloc")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
---
v2:
- Collect Acked-by from David Hildenbrand
---
 arch/riscv/mm/init.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/arch/riscv/mm/init.c b/arch/riscv/mm/init.c
index 151eb197cb09..4914864cb350 100644
--- a/arch/riscv/mm/init.c
+++ b/arch/riscv/mm/init.c
@@ -1538,10 +1538,7 @@ static void __meminit free_pud_table(pud_t *pud_start, p4d_t *p4d)
 			return;
 	}
 
-	if (PageReserved(page))
-		free_reserved_page(page);
-	else
-		__free_pages(page, 0);
+	free_pgtable_page(page);
 	p4d_clear(p4d);
 }
 
-- 
2.54.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH v2 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables
  2026-10-10 11:24 [PATCH v2 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
                   ` (2 preceding siblings ...)
  2026-10-10 11:24 ` [PATCH v2 3/4] riscv/mm: fix missing destructor for hotplug PUD tables Muchun Song
@ 2026-10-10 11:24 ` Muchun Song
  3 siblings, 0 replies; 5+ messages in thread
From: Muchun Song @ 2026-10-10 11:24 UTC (permalink / raw)
  To: Andrew Morton
  Cc: David Hildenbrand, Oscar Salvador, Dave Hansen, Paul Walmsley,
	Palmer Dabbelt, Albert Ou, Alexandre Ghiti, Björn Töpel,
	Catalin Marinas, Will Deacon, Mark Rutland, Kevin Brodsky,
	Alexander Gordeev, Alistair Popple, linux-mm, linux-riscv,
	linux-arm-kernel, linux-kernel, stable, Muchun Song, Muchun Song

Commit c594b83457cc ("arm64: mm: call pagetable dtor when freeing
hot-removed page tables") made free_hotplug_pgtable_page()
unconditionally run the page-table destructor. This matches page tables
allocated by the arm64 mapping code, which runs the corresponding
constructors.

However, arm64 also uses the generic sparse-vmemmap population code.
Runtime intermediate page tables allocated by that code do not run a
page-table constructor. Freeing one during memory hot-remove therefore
runs a destructor without a matching constructor and corrupts
NR_PAGETABLE accounting.

Free intermediate page-table pages through pagetable_free(). It runs the
destructor only for constructor-backed pages and then releases the page
through the page-table freeing path.

Fixes: c594b83457cc ("arm64: mm: call pagetable dtor when freeing hot-removed page tables")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
---
v2:
- Free intermediate tables through pagetable_free() (suggested by David
  Hildenbrand)
- Update the commit message for the page-table freeing path
---
 arch/arm64/mm/mmu.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c
index 7343ac9294f8..26a8c665ae52 100644
--- a/arch/arm64/mm/mmu.c
+++ b/arch/arm64/mm/mmu.c
@@ -1495,8 +1495,7 @@ static void free_hotplug_page_range(struct page *page, size_t size,
 
 static void free_hotplug_pgtable_page(struct page *page)
 {
-	pagetable_dtor(page_ptdesc(page));
-	free_hotplug_page_range(page, PAGE_SIZE, NULL);
+	pagetable_free(page_ptdesc(page));
 }
 
 static bool pgtable_range_aligned(unsigned long start, unsigned long end,
-- 
2.54.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-10 11:26 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-10 11:24 [PATCH v2 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
2026-10-10 11:24 ` [PATCH v2 1/4] mm: fix missing page-table destructor in pagetable_free() Muchun Song
2026-10-10 11:24 ` [PATCH v2 2/4] riscv/mm: fix hotplug page-table destructor handling Muchun Song
2026-10-10 11:24 ` [PATCH v2 3/4] riscv/mm: fix missing destructor for hotplug PUD tables Muchun Song
2026-10-10 11:24 ` [PATCH v2 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables Muchun Song

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox