From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 51488389104; Wed, 30 Sep 2026 17:01:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790787671; cv=none; b=Cm392R3ygoioPl9WSTwgY8xG4iJ+6Ar4/lSWyfiYFb+UZMhfWHsM0xZzNfxYIENR0akih3CUB86NBsdx/t29dRqhkUOmyrb+3mQHORHqwkqIUGkZJ5Gt22rM6ph3T9zERmhPrAI4EklkIw+pdylySknUXoQt5J1Sqi8ZtrQktmo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790787671; c=relaxed/simple; bh=WUNhV7CbV7R0l2rs6hJG3cErX2ZT58vVjMb8wG/XUBg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HkXLoRk6pE2d0256gnwaS4aWUygG+DDMEdJ8sGGlv9hSvT7bMuHNe0EQ/K/13gGf+KpxQVb99++dF6ViLLmvagHh4G4nfMqveKgLeEBjlW0w64bXCu3TvsxM18sadEW3Kg7KqrcxyaLhO/YXDQbBW1sBxUCml+TLW4QeRL6PbO4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=2kia4NXk; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="2kia4NXk" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B06701F000FF; Wed, 30 Sep 2026 17:01:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790787670; bh=ndU7jVExNEOllHRMwdD1NUyCPk7nshdLuvFvTI7zTZk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=2kia4NXkzQzzY4C0LfBkBWPIG+eqWfpNiYHG8PTk/CGwn3FrpmhHC37M4A2wBGtEL fYDxTGHYSlCb7dJEq7dT2bIehGM4oEY6sHJ0kg6MLdDL/NQxO0YB9sOo2Hn39WO72M 4uKbSPtLoRX/UQBfeM7aOu83KYnNOmrybUeg+JQg= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Jaewook You , Andrew Morton , "David Hildenbrand (Arm)" , Johan Hovold , Muchun Song , Oscar Salvador Subject: [PATCH 7.2 313/457] mm/hugetlb: preserve mremap address delta when skipping page tables Date: Wed, 30 Sep 2026 17:26:58 +0200 Message-ID: <20260930152352.780428358@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152346.024115587@linuxfoundation.org> References: <20260930152346.024115587@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Jaewook You commit 9bdad082d44bdcf93716973dcba6be77e8a06e7b upstream. move_hugetlb_page_tables() optimizes mremap() by advancing to the last entry in the page table when the source page table does not exist, either initially or after unsharing a PMD table. The common loop increment then steps to the first entry in the next page table. However, the code advances both the source and destination addresses to the last entries in their respective page tables, which is wrong. The destination address must be advanced only by the same amount as the source address. If the source and destination offsets within their page tables differ, the destination address can be advanced too far, causing follow-up issues. Fix this by advancing the destination address by the source advance distance. With a reproducer, we were able to trigger a kernel panic on x86-64. With this fix in place, we can no longer reproduce the issue. Link: https://lore.kernel.org/20260914132352.472-1-jaewook376@gmail.com Fixes: e95a9851787b ("hugetlb: skip to end of PT page mapping when pte not present") Fixes: 4ddb4d91b82f ("hugetlb: do not update address in huge_pmd_unshare") Signed-off-by: Jaewook You Signed-off-by: Andrew Morton Acked-by: David Hildenbrand (Arm) Cc: Johan Hovold Cc: Muchun Song Cc: Oscar Salvador Cc: Assisted-by: LLM Signed-off-by: Greg Kroah-Hartman --- mm/hugetlb.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) --- a/mm/hugetlb.c +++ b/mm/hugetlb.c @@ -5143,18 +5143,21 @@ int move_hugetlb_page_tables(struct vm_a hugetlb_vma_lock_write(vma); i_mmap_lock_write(mapping); for (; old_addr < old_end; old_addr += sz, new_addr += sz) { + const unsigned long offset_to_last_entry = + (old_addr | last_addr_mask) - old_addr; + src_pte = hugetlb_walk(vma, old_addr, sz); if (!src_pte) { - old_addr |= last_addr_mask; - new_addr |= last_addr_mask; + old_addr += offset_to_last_entry; + new_addr += offset_to_last_entry; continue; } if (huge_pte_none(huge_ptep_get(mm, old_addr, src_pte))) continue; if (huge_pmd_unshare(&tlb, vma, old_addr, src_pte)) { - old_addr |= last_addr_mask; - new_addr |= last_addr_mask; + old_addr += offset_to_last_entry; + new_addr += offset_to_last_entry; continue; }