From: "Yadav, Arvind" <arvind.yadav@intel.com>
To: Zi Yan <ziy@nvidia.com>
Cc: <linux-mm@kvack.org>, <linux-kernel@vger.kernel.org>,
<akpm@linux-foundation.org>, <david@kernel.org>,
<matthew.brost@intel.com>, <joshua.hahnjy@gmail.com>,
<rakie.kim@sk.com>, <byungchul@sk.com>, <gourry@gourry.net>,
<ying.huang@linux.alibaba.com>, <apopple@nvidia.com>
Subject: Re: [PATCH] mm/migrate_device: Clear stale mapping after freeing swapcache
Date: Fri, 24 Jul 2026 09:04:59 +0530 [thread overview]
Message-ID: <8275ff46-5b6a-4be2-8ba6-b7b3fae816e8@intel.com> (raw)
In-Reply-To: <70D21F4A-3BB9-45C7-B445-9414C0DC6FC9@nvidia.com>
On 24-07-2026 01:09, Zi Yan wrote:
> On 23 Jul 2026, at 6:08, Arvind Yadav wrote:
>
>> __migrate_device_pages() reads the folio mapping before calling
>> folio_free_swap(). When folio_free_swap() succeeds, the folio is removed
>> from the swap cache, but the saved mapping still points to swap_space.
>>
>> Passing the stale mapping to folio_migrate_mapping() makes it take the
>> mapped-folio path after the swapcache reference has been dropped. This can
>> cause an invalid swap_space lock access followed by a folio reference
>> count BUG.
>>
>> Clear the saved mapping so the source is migrated as a mappingless
>> anonymous folio.
> Why not use folio_mapping(folio) in the call to folio_migrate_mapping()?
> Or do mapping = folio_mapping(folio) instead of a hard-coded mapping = NULL?
Agree, Re-reading the mapping is clearer and avoids assuming it is
always NULL. I’ll update it to refresh mapping after folio_free_swap().
Thanks for the suggestion.
Regards,
Arvind
>
>> Fixes: df263d9a7dff ("mm/migrate_device: try to handle swapcache pages")
>> Cc: Andrew Morton <akpm@linux-foundation.org>
>> Cc: David Hildenbrand <david@kernel.org>
>> Cc: Matthew Brost <matthew.brost@intel.com>
>> Cc: Joshua Hahn <joshua.hahnjy@gmail.com>
>> Cc: Zi Yan <ziy@nvidia.com>
>> Cc: Rakie Kim <rakie.kim@sk.com>
>> Cc: Byungchul Park <byungchul@sk.com>
>> Cc: Gregory Price <gourry@gourry.net>
>> Cc: Ying Huang <ying.huang@linux.alibaba.com>
>> Cc: Alistair Popple <apopple@nvidia.com>
>> Signed-off-by: Arvind Yadav <arvind.yadav@intel.com>
>> ---
>> mm/migrate_device.c | 6 ++++++
>> 1 file changed, 6 insertions(+)
>>
>> diff --git a/mm/migrate_device.c b/mm/migrate_device.c
>> index 554754eb26ff..fa7fbacac514 100644
>> --- a/mm/migrate_device.c
>> +++ b/mm/migrate_device.c
>> @@ -1204,6 +1204,12 @@ static void __migrate_device_pages(unsigned long *src_pfns,
>> src_pfns[i] &= ~MIGRATE_PFN_MIGRATE;
>> goto next;
>> }
>> +
>> + /*
>> + * folio_free_swap() removed the folio from the swap
>> + * cache. Migrate it as a mappingless anonymous folio.
>> + */
>> + mapping = NULL;
>> }
>> } else if (folio_is_zone_device(newfolio)) {
>> /*
>> --
>> 2.43.0
>
> Best Regards,
> Yan, Zi
prev parent reply other threads:[~2026-07-24 3:35 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-23 10:08 Arvind Yadav
2026-07-23 19:39 ` Zi Yan
2026-07-24 3:34 ` Yadav, Arvind [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8275ff46-5b6a-4be2-8ba6-b7b3fae816e8@intel.com \
--to=arvind.yadav@intel.com \
--cc=akpm@linux-foundation.org \
--cc=apopple@nvidia.com \
--cc=byungchul@sk.com \
--cc=david@kernel.org \
--cc=gourry@gourry.net \
--cc=joshua.hahnjy@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=matthew.brost@intel.com \
--cc=rakie.kim@sk.com \
--cc=ying.huang@linux.alibaba.com \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®