mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Shakeel Butt" <shakeel.butt@linux.dev>,
	"Muchun Song" <muchun.song@linux.dev>,
	"Liam R. Howlett" <liam@infradead.org>,
	"Matthew Wilcox (Oracle)" <willy@infradead.org>,
	"Suren Baghdasaryan" <surenb@google.com>,
	"Nico Pache" <nico.pache@linux.dev>,
	"Johannes Weiner" <hannes@cmpxchg.org>,
	"Gregory Price" <gourry@gourry.net>,
	"Kairui Song" <kasong@tencent.com>,
	"David Hildenbrand" <david@kernel.org>,
	"Michal Hocko" <mhocko@suse.com>,
	"Alistair Popple" <apopple@nvidia.com>,
	"Baolin Wang" <baolin.wang@linux.alibaba.com>,
	"Vlastimil Babka" <vbabka@kernel.org>, "Zi Yan" <ziy@nvidia.com>,
	"Lance Yang" <lance.yang@linux.dev>,
	"Lorenzo Stoakes" <ljs@kernel.org>,
	"Andrew Morton" <akpm@linux-foundation.org>,
	"Barry Song" <baohua@kernel.org>,
	"Ryan Roberts" <ryan.roberts@arm.com>,
	"Qi Zheng" <qi.zheng@linux.dev>, "Dev Jain" <dev.jain@arm.com>,
	"Ying Huang" <ying.huang@linux.alibaba.com>,
	"Usama Arif" <usama.arif@linux.dev>,
	"Mike Rapoport" <rppt@kernel.org>
Cc: "Jan Kara" <jack@suse.cz>, "Jonathan Corbet" <corbet@lwn.net>,
	"Pasha Tatashin" <pasha.tatashin@soleen.com>,
	linux-mm@kvack.org,
	"Mathieu Desnoyers" <mathieu.desnoyers@efficios.com>,
	kexec@lists.infradead.org,
	"Masami Hiramatsu" <mhiramat@kernel.org>,
	"Pratyush Yadav" <pratyush@kernel.org>,
	linux-doc@vger.kernel.org, linux-trace-kernel@vger.kernel.org,
	"Baoquan He" <baoquan.he@linux.dev>,
	linux-kernel@vger.kernel.org,
	"Dave Young" <ruirui.yang@linux.dev>,
	"Steven Rostedt" <rostedt@goodmis.org>,
	"Shuah Khan" <skhan@linuxfoundation.org>,
	linux-fsdevel@vger.kernel.org
Subject: Re: [PATCH v5 17/17] mm/page-flags: remove PG_private
Date: Mon, 21 Sep 2026 02:55:20 +0000	[thread overview]
Message-ID: <20260921025520.628971F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260920-remove-pg_private-v5-17-bb68b6a21869@nvidia.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] mm: silent memory leak masking due to PG_private removal
--

commit aee12ed3446e69cb6eee57384ca09e768dab36dd
Author: Zi Yan <ziy@nvidia.com>

mm/page-flags: remove PG_private

This commit removes the PG_private page flag and replaces its usage with
checking if folio->private != NULL. The space left by PG_private is
reserved as PG_folio for future use.

> diff --git a/include/linux/page-flags.h b/include/linux/page-flags.h
> index 7080a6a1a79e7..b0ddc652e76cc 100644
> --- a/include/linux/page-flags.h
> +++ b/include/linux/page-flags.h
[ ... ]
> @@ -1169,7 +1175,7 @@ static __always_inline void __ClearPageAnonExclusive(struct page *page)
>   */
>  #define PAGE_FLAGS_CHECK_AT_FREE				\
>  	(1UL << PG_lru		| 1UL << PG_locked	|	\
> -	 1UL << PG_private	| 1UL << PG_private_2	|	\
> +	 1UL << PG_private_2	|				\

[Severity: Medium]
Since PG_private is removed from PAGE_FLAGS_CHECK_AT_FREE, does this bypass
the safety check that ensures a page doesn't have uncleared private data?

Looking at __free_pages_prepare() in mm/page_alloc.c:

	page_cpupid_reset_last(page);
	page->flags.f &= ~PAGE_FLAGS_CHECK_AT_PREP;
	page->private = 0;
	reset_page_owner(page, order);

The head page's private field is silently zeroed here without any prior
verification that it was NULL. Previously, free_page_is_bad() would catch
and report leaked data via a bad_page() warning using
PAGE_FLAGS_CHECK_AT_FREE.

Now, if a buggy filesystem fails to detach and free folio->private data
before freeing the page, will this result in silent memory leaks?

>  	 1UL << PG_writeback	| 1UL << PG_reserved	|	\
>  	 1UL << PG_active 	|				\
>  	 1UL << PG_unevictable	| __PG_MLOCKED | LRU_GEN_MASK)

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260920-remove-pg_private-v5-0-bb68b6a21869@nvidia.com?part=17

  reply	other threads:[~2026-09-21  2:55 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21  2:27 [PATCH v5 00/17] Remove PG_private by using page/folio->private checks instead Zi Yan
2026-09-21  2:27 ` [PATCH v5 01/17] mm/zsmalloc: replace PG_private with pointer comparison Zi Yan
2026-09-21  6:02   ` Lance Yang
2026-09-21  2:27 ` [PATCH v5 02/17] perf/ring_buffer: stop using PG_private as AUX page high-order marker Zi Yan
2026-09-21  6:19   ` Lance Yang
2026-09-21  2:27 ` [PATCH v5 03/17] xen/grant-table: stop setting PG_private on pages for grant mapping Zi Yan
2026-09-21  7:00   ` Lance Yang
2026-09-21  2:28 ` [PATCH v5 04/17] fscrypt: stop setting PG_private on bounce page Zi Yan
2026-09-21  7:03   ` Lance Yang
2026-09-21  2:28 ` [PATCH v5 05/17] mm/hugetlb: use direct assignment instead of folio_change_private() Zi Yan
2026-09-21  7:11   ` Lance Yang
2026-09-21  2:28 ` [PATCH v5 06/17] f2fs: stop using PG_private Zi Yan
2026-09-21  7:24   ` Lance Yang
2026-09-21  2:28 ` [PATCH v5 07/17] f2fs: convert the ->private flag helpers to folio-only Zi Yan
2026-09-21  7:39   ` Lance Yang
2026-09-21  2:28 ` [PATCH v5 08/17] erofs: mm/pagemap: add readahead_folio_last() to avoid folio->private Zi Yan
2026-09-21  8:20   ` Lance Yang
2026-09-21  2:28 ` [PATCH v5 09/17] erofs: use folio_attach/detach_private() instead of direct assignment Zi Yan
2026-09-21  8:45   ` Lance Yang
2026-09-21  2:28 ` [PATCH v5 10/17] mm/page-flags: check page/folio->private instead of PG_private Zi Yan
2026-09-21  9:22   ` David Hildenbrand (Arm)
2026-09-21  2:28 ` [PATCH v5 11/17] treewide: remove folio_set/clear_private() usage Zi Yan
2026-09-21  2:28 ` [PATCH v5 12/17] ceph: replace PagePrivate() with page_private() Zi Yan
2026-09-21  2:28 ` [PATCH v5 13/17] md: Use folio_alloc_buffers() Zi Yan
2026-09-21  9:23   ` David Hildenbrand (Arm)
2026-09-21  2:28 ` [PATCH v5 14/17] md: Use folio APIs in free_page() Zi Yan
2026-09-21  2:28 ` [PATCH v5 15/17] md: Remove the last use of page_buffers() Zi Yan
2026-09-21  2:28 ` [PATCH v5 16/17] treewide: remove PagePrivate() and PG_private from comments and docs Zi Yan
2026-09-21  2:28 ` [PATCH v5 17/17] mm/page-flags: remove PG_private Zi Yan
2026-09-21  2:55   ` sashiko-bot [this message]
2026-09-21 15:36     ` Zi Yan
2026-09-21  4:08 ` [PATCH v5 00/17] Remove PG_private by using page/folio->private checks instead Andrew Morton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921025520.628971F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=akpm@linux-foundation.org \
    --cc=apopple@nvidia.com \
    --cc=baohua@kernel.org \
    --cc=baolin.wang@linux.alibaba.com \
    --cc=baoquan.he@linux.dev \
    --cc=corbet@lwn.net \
    --cc=david@kernel.org \
    --cc=dev.jain@arm.com \
    --cc=gourry@gourry.net \
    --cc=hannes@cmpxchg.org \
    --cc=jack@suse.cz \
    --cc=kasong@tencent.com \
    --cc=kexec@lists.infradead.org \
    --cc=lance.yang@linux.dev \
    --cc=liam@infradead.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=ljs@kernel.org \
    --cc=mathieu.desnoyers@efficios.com \
    --cc=mhiramat@kernel.org \
    --cc=mhocko@suse.com \
    --cc=muchun.song@linux.dev \
    --cc=nico.pache@linux.dev \
    --cc=pasha.tatashin@soleen.com \
    --cc=pratyush@kernel.org \
    --cc=qi.zheng@linux.dev \
    --cc=rostedt@goodmis.org \
    --cc=rppt@kernel.org \
    --cc=ruirui.yang@linux.dev \
    --cc=ryan.roberts@arm.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=shakeel.butt@linux.dev \
    --cc=skhan@linuxfoundation.org \
    --cc=surenb@google.com \
    --cc=usama.arif@linux.dev \
    --cc=vbabka@kernel.org \
    --cc=willy@infradead.org \
    --cc=ying.huang@linux.alibaba.com \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®