From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ABBAF3ACEE9 for ; Thu, 26 Feb 2026 14:15:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.176 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772115314; cv=none; b=TRUKDb8/WFVqHtSLNJGQc6jcrKPAz71blTp5BBmKlCxU1WpevyNk9AjvDSvGDyOdT2TL9mcEEPSYY7zAgttKxrpT2qfWtMB16dpFTnh0/Zhf70s24JQuHAKnDjREB+1Tu3/fGourztzKKlA3tzC7kknSuADahczcnvvUj9xFKuw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772115314; c=relaxed/simple; bh=fAV9q3PRVVSAs45bjKEg29Ft0mUObDJosrrYhqpDFo4=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=eKnB/9zIHk0YKDWewgGAkUfbTTKZqyh3SCAkGvCVGShc+RpGdlpa4WDfqQCTh3IKnMKc1l/XXsf1TyOO65YVz/yhlsYkpBiOyYD5979vS29GSECYDly2iBO/4mi/OlnTpnpm+MO5UIyDKgrNjTEIFQILzlu7zoKdSIC6L6PLdTw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=chrisdown.name; spf=pass smtp.mailfrom=chrisdown.name; dkim=pass (1024-bit key) header.d=chrisdown.name header.i=@chrisdown.name header.b=auAcNGba; arc=none smtp.client-ip=209.85.210.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=chrisdown.name Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=chrisdown.name Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=chrisdown.name header.i=@chrisdown.name header.b="auAcNGba" Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-824adc96ad2so967028b3a.3 for ; Thu, 26 Feb 2026 06:15:12 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chrisdown.name; s=google; t=1772115312; x=1772720112; darn=vger.kernel.org; h=user-agent:content-disposition:mime-version:message-id:subject:cc :to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=3FQ+7uigzhY0D9bUb7S9byYQ1qGUM2ULqVMWKZWoKSI=; b=auAcNGbaRQONiEC6YkgKXrnq3CztMh6ySQkFkyFX+OWTxejvLwqs3mbVo3xqNFobAo J9DzRRPIj3eUIoaM/et6uTQtrXsOSVKuw5A+/SPWQMEexfuMAC68FA64HlIIXp1BaskS 2unc/mgZTWtI1Oeh688KanCmY63y460M4OnJw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772115312; x=1772720112; h=user-agent:content-disposition:mime-version:message-id:subject:cc :to:from:date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=3FQ+7uigzhY0D9bUb7S9byYQ1qGUM2ULqVMWKZWoKSI=; b=RB04SOqJDy015foqpPzkoBI7ZOYC28C0fggwW25tgOKiCH8wT/MgspmTpKKvq66TRQ LFWMNeHOXSEsAD0VhVRodGQPUe05RPaYzdwemqx1TQV7fEeSQu+BPudb3EfloWxkzbtO /xOZQIHC7qoQDSqgrFAYqviw3u4u8XMOHb/x6h3mgZXcHRmrWvuEwiLz9lyXB+vqT4A2 U7rpITNnDIWNgOih4EXNaO42oBrcNAAjpVbKGD2Ejs+7Zg2d8VAoED4uUxMcL04ub87F KcC18whsrPyqbBXt6zCv0LX3fUfG7fAxA98G8MEIHXOQVceUghd5gDIuj4/nKlrGVZEP QgKQ== X-Forwarded-Encrypted: i=1; AJvYcCVQ8mqjDRLJ+CsI1ikOWGbp5a489CHt4b2V+A3OvT4tyOuD7of1LmAGRL7QsfB3GDQOxq9J62P5Q5/TK48=@vger.kernel.org X-Gm-Message-State: AOJu0Yw5F4GO4LGJoureMejvvSEqrFlbGxgo2/bWkB1CESx3WYk+SQYJ 5dSK4lzhje/iBuAJC4/dafuY3zF81kEIsDNwufjX2s5Xlu06uZj2W2oM4FZ3zq9ixNU= X-Gm-Gg: ATEYQzxZ2rYJKlNiZoszGKiOiDZFkWccilNQmFhlWTKu33mEgHxGYcktofNO+Ukkwo+ CgWwIY6RS6mdtjXXFBw6dN2365aXpEyZCeZrDc5AnH68sTCHgYl8a2Pjy+Jpq7ag8r7ams1hzk6 sV+R/x+JWs4jYsO6HIWEmy3S1ThAll3T5Pf2NEPC0StevLAKtYLEk6JG5qbo6hmpdnzRGYaFRP1 an87ZbnSNStza+V7T+OcmPZ7YbuycoXgY8o9u3i5stOM6JiP51aFa9WjpDa2Kz0vinuVxMndWAu jrZXS5yCoLtWwP4JI1rzuxs7zgjEPD4+kcnRzTI5sV8SrN2YbFFonL2RmhSawYAUv2/ni77CHQc CyXpaolKjAOJg9aD/jL/q7eZMhgfRcAKttndYgRVFpnyK5pHqiL/i0SsYVdbpFj8BYof9MmK+TI N6w7NUQhzM2ziiB9jPqw== X-Received: by 2002:a05:6a00:439b:b0:827:4526:50d with SMTP id d2e1a72fcca58-827452605cdmr1182006b3a.29.1772115311913; Thu, 26 Feb 2026 06:15:11 -0800 (PST) Received: from localhost ([154.47.23.70]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8273a05e831sm2569799b3a.58.2026.02.26.06.15.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 26 Feb 2026 06:15:11 -0800 (PST) Date: Thu, 26 Feb 2026 22:15:04 +0800 From: Chris Down To: Andrew Morton Cc: David Hildenbrand , Matthew Wilcox , kernel-team@fb.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v2 0/3] mm/huge_memory: Fix move_pages_huge_pmd() for huge zero pages Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/2.2.15 (2b349c5e) (2025-10-02) Changes since v1: - Reworked patch 2 per David's feedback to stop reconstructing the huge zero PMD and instead preserve PMD state from src_pmdval, then apply move_soft_dirty_pmd() and clear_uffd_wp_pmd(). - Added regression tests. - As a side note, I've kept the two mm fixes split intentionally for stable backports, even though patch one immediately gets superseded by patch two. The reason is they track back to different commits, so although patch 2 rewrites the same branch in newer trees, keeping the fixes separate preserves the correct Fixes: annotations and lets stable pick the applicable fix for a given tree. --- Two fixes for the huge zero page path in move_pages_huge_pmd() (UFFDIO_MOVE). Patch 1 fixes a use of NULL folio introduced by the folio_mk_pmd() conversion in commit e3981db444a0 ("mm: add folio_mk_pmd()"), which replaced mk_huge_pmd(src_page, ...) with folio_mk_pmd(src_folio, ...) in the huge zero page branch where src_folio is explicitly NULL. With SPARSEMEM_VMEMMAP this silently produces a PMD with a bogus PFN, on other memory models it is a NULL deref. Patch 2 fixes huge zeropage refcount corruption after commit d82d09e48219 ("mm/huge_memory: mark PMD mappings of the huge zero folio special") by preserving the moved huge zero PMD state instead of reconstructing the destination PMD from the folio. This keeps the PMD special bit intact on CONFIG_ARCH_HAS_PTE_SPECIAL architectures and avoids vm_normal_page_pmd() misclassifying the moved huge zeropage PMD as a normal page. Chris Down (3): mm/huge_memory: Fix use of NULL folio in move_pages_huge_pmd() mm/huge_memory: Prevent huge zeropage refcount corruption in PMD move selftests/mm: Add UFFDIO_MOVE huge zeropage PMD regression test mm/huge_memory.c | 3 +- tools/testing/selftests/mm/uffd-unit-tests.c | 176 +++++++++++++++++++ 2 files changed, 178 insertions(+), 1 deletion(-) -- 2.51.2