While fiddling with pagemap, I discovered a bug in add_to_pagemap. When it is copying an entry that is not at the end of the buffer, it uses put_user to copy a u64 into a char* buffer. The problem is that put_user determines how much to copy based on the size of the *destination*, not the source, so it only copied one byte. To fix this, I replaced the call to put_user with a call to copy_to_user, as is used when copying the last (possibly partial) PFN into the buffer.