From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1934E40D59D for ; Fri, 19 Jun 2026 02:39:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781836754; cv=none; b=EaNwtRGyG+PUdGx2jzSop9+W7JN7Mtt38zuWJCnq6sfBtwKKf1buMeBKxqp7nngRwNdwC1wQgId4MB9/pPA7V4upRvGxul+/dso+hwXGKdmrmZS5/qMqnF+Dog/LGv0qboK2BMhyGJsi7ejcBD4LEqH9UOdrIMkj+rmXOB+2ETM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781836754; c=relaxed/simple; bh=6bUrOsk5ly2vIjkT004RQcaS8Ec2GUhz93x20eYD2UY=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=NuOXSuWT+ueIUeRp2wu+N/Irigqzp8+ETul4aZguTuPh0S+kuaXmGXoSAHm1jbtgPTY2nbIj+YJypOpBCgVeDLkgWSJrN2+eEDwOp1liThIoio3P2BwjaA/6fynPBtePV0+7yOhkA2LvLpdZLW2Gx98G2fDQeVeMA1VNbWhGkEQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=H+/x9NC1; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="H+/x9NC1" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1781836752; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=tuRRkjGz275Hq8qH3K7T2fHZ7i0zAjk57ruAUAt40+8=; b=H+/x9NC1nogNwcWMS+L35FZtKK23NPqRH2wB5z3J0EEy9hiHdf9uZQR8UcUI19i82kPE56 ICoGdoQZ16pNSoxGOQ7X/IMRsJgakwybJkqYx+RFVeHaFzLfkegRiLdPrJikzJauV8sqD5 /e4+oF1bKVudUK1xZeU9GsUwIVOWiM8= Received: from mail-qv1-f72.google.com (mail-qv1-f72.google.com [209.85.219.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-256-vZGoh9xpOWKB8htaVc_XBA-1; Thu, 18 Jun 2026 22:39:10 -0400 X-MC-Unique: vZGoh9xpOWKB8htaVc_XBA-1 X-Mimecast-MFC-AGG-ID: vZGoh9xpOWKB8htaVc_XBA_1781836750 Received: by mail-qv1-f72.google.com with SMTP id 6a1803df08f44-8cecb6dee57so50461706d6.1 for ; Thu, 18 Jun 2026 19:39:10 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781836750; x=1782441550; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=tuRRkjGz275Hq8qH3K7T2fHZ7i0zAjk57ruAUAt40+8=; b=LvmlRRFs5siCR66RI+SjTLmwhxHPaNZyJScR+IV4dhxsLwbTlLyL+7I1xwAWs4ckAF nnq2bpN5ime0ET0tr6pYm+B2wE7VWtBFduNWfVr9P0g9m7LUgzsYZ5cuX8CamLRvoCS2 8pPYN+v5G8Se8ShaYRk2XEggGTm7JwLQYGXhc6WuCDTxV344YuUly65e6poeWk5rvlW8 n9qkcYK6q9a7MYXRvBd4E5Y2xBeXBzxj6tAzRgEJvJpYfDRsvGNTNPxeuSC6XLR89A0x knUL10AaqccHgIMCcsBiDTlH1gQf7oKpvA/zx2luA4GV2ABdj+Dli5x848XH50pz2atl uAPQ== X-Forwarded-Encrypted: i=1; AFNElJ9yfZqOJQeX8tV5/oZM5JAMY+ztdLBLwJcbrfjrSiRP5KcdSqZ20xmZHqcHYvOISCRmxRNVXqaLTofKNg8=@vger.kernel.org X-Gm-Message-State: AOJu0Yw1N7zqGIH4KKE+mxDj4vxXW6lWzbu6twkpUijnnEgjyOzKfQy4 svJPRtC5juZqsH1lQ+W+gl6kR4jZBpPXcCDZHYNRSP3ajwBX6syjRwmXMU5DMGg6P8tyqX9BIcY 4eTr1B5RZJ55r8RCfCG3/e1U+BCEkDwL8mCkNSNtXXHJ36gw18F4kURdIZlNGaGYidA== X-Gm-Gg: AfdE7clsFT/e9IV1PjyOIeSr4KNqYWNCfhXuES3IiuCLLvmqN4TYUCXoy2tqnqKMztm mFNskKWN6t1mKeob5muvZcBosCOZYokzmg13S7sZgDGdMcpB+5hYOw3MSwrGs05NRQQr5TQ7xMV mCaMDIGYTwFVXQ9Aivs3W+Jk5brESqqn6fr3wdNYo1svzybb4maY1sbLrp+vvcew8HLxaTgScoD Eak1vjgKTcRJBvHJBvUlixewmvj6wx0B6MraUwx7ke18+jozMXXKMgKCpy0g3ty6hG8EfXkQCxm ylqTxNoO8r4NLlTVGdBlNPDBHyk7q0WnKn7OXWmRZjp9uocNwvVrAuvS+oHKZQLThVNyWHkRkN5 NjHmpCuo8K6ZPGw== X-Received: by 2002:ad4:5d41:0:b0:89c:867b:a9bb with SMTP id 6a1803df08f44-8de4c46d3abmr22002116d6.18.1781836749862; Thu, 18 Jun 2026 19:39:09 -0700 (PDT) X-Received: by 2002:ad4:5d41:0:b0:89c:867b:a9bb with SMTP id 6a1803df08f44-8de4c46d3abmr22001816d6.18.1781836749382; Thu, 18 Jun 2026 19:39:09 -0700 (PDT) Received: from [192.168.2.110] ([70.53.200.215]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8de632c5de0sm9206176d6.49.2026.06.18.19.39.08 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 18 Jun 2026 19:39:09 -0700 (PDT) Message-ID: <698e5cdc-8f1d-4984-bb54-a4b7979b4dc8@redhat.com> Date: Thu, 18 Jun 2026 22:38:58 -0400 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] mm: page_ext: validate section in for_each_page_ext iterator To: "David Hildenbrand (Arm)" , Ketan , Andrew Morton , Vlastimil Babka , Suren Baghdasaryan , Michal Hocko , Brendan Jackman , Johannes Weiner , Zi Yan Cc: kernel@oss.qualcomm.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org References: <20260617-page_ext-v1-1-37ad802b1a38@oss.qualcomm.com> <1dbebf73-6c46-44e1-ac6a-f5ffa9849b37@kernel.org> Content-Language: en-US, en-CA From: Luiz Capitulino In-Reply-To: <1dbebf73-6c46-44e1-ac6a-f5ffa9849b37@kernel.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 2026-06-18 05:04, David Hildenbrand (Arm) wrote: > On 6/17/26 17:09, Ketan wrote: >> The page_ext iteration API do not validate if the PFN still >> belongs to a valid section while advancing the iterator. >> >> When dynamically adding memory in hotplug path, it can lead >> to a NULL pointer dereference during page_ext_lookup at the >> boundary of the last valid section. >> >> [ 14.555124][ T846] Call trace: >> [ 14.555125][ T846] lookup_page_ext+0x6c/0x108 (P) >> [ 14.555127][ T846] page_ext_lookup+0x30/0x3c >> [ 14.555129][ T846] +0x11c/0x260 >> [ 14.571201][ T846] __free_pages_ok+0x5e8/0x8e0 >> [ 14.571204][ T846] __free_pages_core+0x78/0xf0 >> [ 14.571206][ T846] generic_online_page+0x14/0x24 >> [ 14.597782][ T846] online_pages+0x178/0x30c >> [ 14.597784][ T846] memory_block_change_state+0x284/0x32c >> [ 14.597787][ T846] memory_subsys_online+0x4c/0x64 >> [ 14.597789][ T846] device_online+0x88/0xb0 >> [ 14.597791][ T846] online_memory_block+0x30/0x40 >> [ 14.597793][ T846] walk_memory_blocks+0xac/0xe8 >> [ 14.597794][ T846] add_memory_resource+0x280/0x298 >> [ 14.656161][ T846] add_memory+0x60/0x98 > > So, we do allocate the page_ext in memory_notify(MEM_GOING_ONLINE) -> ... > page_ext_callback() -> online_page_ext(). > > Which makes sure that all page_ext is actually allocated (for the full section). > > So when we later end up in generic_online_page(), the page_ext should be there > and the memory section should be valid. > > > How can online_pages(), which onlines memory part of present memory sections, > online (free) memory that suddenly does not belong to a present memory section? > > Something doesn't make sense here. Ketan, would you please share the full OOPs message and maybe tell us how you reproduce this issue? > >> >> Add a valid-section check before looking up the next page_ext >> so the iterator stops cleanly at section boundaries. >> >> Fixes: 9039b9096ea2 ("mm: page_owner: use new iteration API") > > If the problem is real, we'd want to CC stable. > >> Signed-off-by: Ketan Kishore >> --- >> mm/page_ext.c | 12 ++++++++++++ >> 1 file changed, 12 insertions(+) >> >> diff --git a/mm/page_ext.c b/mm/page_ext.c >> index e2e92bd27ebd..74067ea740fe 100644 >> --- a/mm/page_ext.c >> +++ b/mm/page_ext.c >> @@ -253,6 +253,18 @@ static struct page_ext *lookup_page_ext(const struct page *page) >> { >> unsigned long pfn = page_to_pfn(page); >> struct mem_section *section = __pfn_to_section(pfn); >> + >> + /* >> + * section can be NULL when the page_ext iterator's for-loop increment >> + * computes a PFN one step beyond the last registered section. This >> + * occurs because pfn_to_page() uses __nr_to_section() which succeeds >> + * for unregistered sections that share a root array with registered >> + * sections,while __pfn_to_section() returns NULL for them. >> + * >> + */ >> + if (!section) >> + return NULL; >> + >> struct page_ext *page_ext = READ_ONCE(section->page_ext); > > In addition to what Zi says, which will end up as: > > if (!section) > return NULL; > page_ext = READ_ONCE(section->page_ext); > > > drop that comment, not required. And likely best to just add a unlikely(), > because this doesn't usually happen. >