From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mta1.migadu.com (out-136.mta1.migadu.com [95.215.58.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E6BCC449B21 for ; Fri, 9 Oct 2026 06:35:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.136 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791527759; cv=none; b=qj94JqwecXOTk8h/i6XrsfpVdeA0tWeRlnK/KHCohyzW0WseLhUp1rsCEo+Y8Xb6GjhEickV7zAOxsNsGM+dO2KkdTn5WnB3D0B6Yk6AAPPdEC6sRcg5dzhAj+8AD3Q3masqC4zQVrJGS7H4XfS/HE2KXVckwBv9N/j5weYxF1s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791527759; c=relaxed/simple; bh=Kt3m90GxEd2pntG610a36JDfeeYmcBGJyCrnR//SRJc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=GksUUCbng0Tt5o6SgwzeUEWimskcP4iq5cqeEuuI7BWFq+g/mmgaUWgNj/rB0Gf02A1leJMKrzF0LU+hdvpfyQolB4DBYDp0QAL05IRtjnDou2Cg9HGbefSkysfha7q1oqwXlrfLwScFJ7vxS1g7OzMA4ME4EW0KmE/LIPfGneA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=wkWSnT7a; arc=none smtp.client-ip=95.215.58.136 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="wkWSnT7a" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=Kt3m90GxEd2pntG610a36JDfeeYmcBGJyCrnR//SRJc=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1791527754; v=1; x=1792132554; b=wkWSnT7ahSyReEbXS0EDzEyhlllyNbMacSosLJzdp12xqpjeVbG9xmgSyfTPdw6K26GNv4Jg NUY4YTMQcaA2ibzU+Limastt/AQ0w32w6vQeoNJ3NGyJeBQaN/MYlIrWTCgaTRME2DwqRKWiA7j qefiYxtdWDjCgfGxH6A1i8Mc= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id b474d1347a814fa6; Fri, 09 Oct 2026 06:35:22 +0000 X-Mizu-Trace-ID: b474d1347a814fa6 X-Migadu-Flow: FLOW_OUT From: Hao Ge To: Suren Baghdasaryan , Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , "Ritesh Harjani (IBM)" , Shrikanth Hegde , Alexander Potapenko , Marco Elver , Dmitry Vyukov , Andrew Morton , Dennis Zhou , Tejun Heo , Christoph Lameter , Uladzislau Rezki Cc: Hao Ge , linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, kasan-dev@googlegroups.com, linux-mm@kvack.org, stable@vger.kernel.org Subject: [RFC PATCH 1/4] mm/kmsan: undo the shadow mapping when the origin mapping fails Date: Fri, 9 Oct 2026 14:36:16 +0800 Message-Id: <20261009063619.112313-2-hao.ge@linux.dev> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20261009063619.112313-1-hao.ge@linux.dev> References: <20261009063619.112313-1-hao.ge@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit kmsan_vmap_pages_range_noflush() first maps the shadow pages and then the origin pages. If the second mapping fails, the first one is left mapped, and the callers do not roll it back. The next vmap of the same metadata range hits the stale PTEs again and BUG()s on the huge mapping path, or gets -EBUSY with a WARN_ON() on the small page one. Undo the shadow mapping on that error path, the same way kmsan_ioremap_page_range() cleans up after a partial failure. __vunmap_range_noflush() only clears the PTEs; nothing has touched the shadow mapping, so no TLB flush is needed. Fixes: 47ebd0310e89 ("mm: kmsan: handle alloc failures in kmsan_vmap_pages_range_noflush()") Cc: stable@vger.kernel.org Signed-off-by: Hao Ge --- mm/kmsan/shadow.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/mm/kmsan/shadow.c b/mm/kmsan/shadow.c index 0c88d89bf0d6..2166086d3dc3 100644 --- a/mm/kmsan/shadow.c +++ b/mm/kmsan/shadow.c @@ -258,6 +258,10 @@ int kmsan_vmap_pages_range_noflush(unsigned long start, unsigned long end, o_pages, page_shift); kmsan_leave_runtime(); if (mapped) { + /* Undo the shadow mapping set up above. */ + kmsan_enter_runtime(); + __vunmap_range_noflush(shadow_start, shadow_end); + kmsan_leave_runtime(); err = mapped; goto ret; } -- 2.25.1