mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/4] mm: Fix page-table teardown during memory hot-remove
@ 2026-10-08  7:30 Muchun Song
  2026-10-08  7:30 ` [PATCH 1/4] x86/mm: fix missing pgtable destructor for vmemmap tables Muchun Song
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: Muchun Song @ 2026-10-08  7:30 UTC (permalink / raw)
  To: akpm
  Cc: linux-mm, stable, david, osalvador, dave.hansen, luto, peterz,
	tglx, mingo, bp, x86, hpa, catalin.marinas, will, mark.rutland,
	linux-arm-kernel, pjw, palmer, aou, alex, linux-riscv, agordeev,
	kevin.brodsky, bjorn, apopple, linux-kernel, muchun.song

Memory hot-remove can free page tables allocated through different
paths. Some of these paths run page-table constructors, while others,
including generic sparse-vmemmap population, do not. The teardown
paths on x86, RISC-V and arm64 do not consistently handle this
distinction, leaving constructors and destructors unbalanced and
corrupting NR_PAGETABLE accounting.

On x86, the destructor is missing for vmemmap PTE tables allocated by
HugeTLB vmemmap optimization. RISC-V also misses the destructor for
constructed PUD tables. Conversely, arm64 and RISC-V can run
destructors on vmemmap tables that were never constructed.

This series uses PageTable() to determine whether a destructor is
needed before freeing a page-table page. The RISC-V fixes share a
common freeing helper across PTE, PMD and PUD teardown.

This series is limited to bug fixes for the existing teardown paths.
A follow-up series will convert runtime vmemmap page-table allocation
to the generic page-table allocation helpers, ensuring that these
tables run the corresponding constructors. Once these tables follow
the normal constructor and destructor lifecycle, the PageTable()
checks in the arm64 and RISC-V teardown paths can be removed.

Muchun Song (4):
  x86/mm: fix missing pgtable destructor for vmemmap tables
  riscv/mm: fix hotplug page-table destructor handling
  riscv/mm: fix missing destructor for hotplug PUD tables
  arm64/mm: fix destructor for unconstructed hotplug page tables

 arch/arm64/mm/mmu.c   |  3 ++-
 arch/riscv/mm/init.c  | 34 +++++++++++++++-------------------
 arch/x86/mm/init_64.c |  2 ++
 3 files changed, 19 insertions(+), 20 deletions(-)


base-commit: a92f009ac1c21986ff1ea0706419e545a4739513
-- 
2.54.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 1/4] x86/mm: fix missing pgtable destructor for vmemmap tables
  2026-10-08  7:30 [PATCH 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
@ 2026-10-08  7:30 ` Muchun Song
  2026-10-08  8:32   ` Muchun Song
  2026-10-08  7:30 ` [PATCH 2/4] riscv/mm: fix hotplug page-table destructor handling Muchun Song
                   ` (2 subsequent siblings)
  3 siblings, 1 reply; 6+ messages in thread
From: Muchun Song @ 2026-10-08  7:30 UTC (permalink / raw)
  To: akpm
  Cc: linux-mm, stable, david, osalvador, dave.hansen, luto, peterz,
	tglx, mingo, bp, x86, hpa, catalin.marinas, will, mark.rutland,
	linux-arm-kernel, pjw, palmer, aou, alex, linux-riscv, agordeev,
	kevin.brodsky, bjorn, apopple, linux-kernel, muchun.song

Since commit 49f599666420 ("mm: call ctor/dtor for kernel PTEs"),
pte_alloc_one_kernel() runs the page-table constructor for kernel PTE
tables.

HugeTLB vmemmap optimization uses pte_alloc_one_kernel() when splitting
a PMD. Restoring the vmemmap backing pages does not collapse the PTE
table, so a later memory hot-remove eventually frees that table through
free_pagetable(). That path currently calls pagetable_free() directly
without decrementing NR_PAGETABLE.

Use PageTable() to identify constructor-backed tables and run the
matching destructor before freeing them. Keep reserved and
constructor-free tables on their existing paths. This also prepares
vmemmap teardown for generic runtime allocations through the normal
pgalloc helpers.

Fixes: 49f599666420 ("mm: call ctor/dtor for kernel PTEs")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
---
 arch/x86/mm/init_64.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/arch/x86/mm/init_64.c b/arch/x86/mm/init_64.c
index 70e682180291..a3ea627157ab 100644
--- a/arch/x86/mm/init_64.c
+++ b/arch/x86/mm/init_64.c
@@ -1003,6 +1003,8 @@ static void __meminit free_pagetable(struct page *page)
 {
 	if (PageReserved(page))
 		free_reserved_page(page);
+	else if (PageTable(page))
+		pagetable_dtor_free(page_ptdesc(page));
 	else
 		pagetable_free(page_ptdesc(page));
 }
-- 
2.54.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 2/4] riscv/mm: fix hotplug page-table destructor handling
  2026-10-08  7:30 [PATCH 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
  2026-10-08  7:30 ` [PATCH 1/4] x86/mm: fix missing pgtable destructor for vmemmap tables Muchun Song
@ 2026-10-08  7:30 ` Muchun Song
  2026-10-08  7:30 ` [PATCH 3/4] riscv/mm: fix missing destructor for hotplug PUD tables Muchun Song
  2026-10-08  7:30 ` [PATCH 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables Muchun Song
  3 siblings, 0 replies; 6+ messages in thread
From: Muchun Song @ 2026-10-08  7:30 UTC (permalink / raw)
  To: akpm
  Cc: linux-mm, stable, david, osalvador, dave.hansen, luto, peterz,
	tglx, mingo, bp, x86, hpa, catalin.marinas, will, mark.rutland,
	linux-arm-kernel, pjw, palmer, aou, alex, linux-riscv, agordeev,
	kevin.brodsky, bjorn, apopple, linux-kernel, muchun.song

RISC-V uses the same memory-hotplug teardown code for the linear map and
vmemmap, although their page-table pages are not always allocated in the
same way. Late linear-map allocations run page-table constructors, while
vmemmap and early allocations may provide constructor-free pages.

The PTE path unconditionally runs the destructor, which is wrong for
constructor-free vmemmap tables. The PMD path avoids that problem by
using is_vmemmap as a proxy for constructor state, but that assumption
will no longer hold once runtime vmemmap allocations use the normal
pgalloc helpers.

Page-table constructors record their state in PG_table. Centralize
page-table freeing and use PageTable() to decide whether the destructor
is required. Keep reserved and constructor-free pages on their existing
freeing paths.

Fixes: c75a74f4ba19 ("riscv: mm: Add memory hotplugging support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
---
 arch/riscv/mm/init.c | 29 ++++++++++++++---------------
 1 file changed, 14 insertions(+), 15 deletions(-)

diff --git a/arch/riscv/mm/init.c b/arch/riscv/mm/init.c
index 857f9a55039c..429a0b015ec1 100644
--- a/arch/riscv/mm/init.c
+++ b/arch/riscv/mm/init.c
@@ -1486,10 +1486,19 @@ struct execmem_info __init *execmem_arch_setup(void)
 #endif /* CONFIG_EXECMEM */
 
 #ifdef CONFIG_MEMORY_HOTPLUG
+static void __meminit free_pagetable(struct page *page)
+{
+	if (PageReserved(page))
+		free_reserved_page(page);
+	else if (PageTable(page))
+		pagetable_dtor_free(page_ptdesc(page));
+	else
+		pagetable_free(page_ptdesc(page));
+}
+
 static void __meminit free_pte_table(pte_t *pte_start, pmd_t *pmd)
 {
 	struct page *page = pmd_page(*pmd);
-	struct ptdesc *ptdesc = page_ptdesc(page);
 	pte_t *pte;
 	int i;
 
@@ -1499,18 +1508,13 @@ static void __meminit free_pte_table(pte_t *pte_start, pmd_t *pmd)
 			return;
 	}
 
-	pagetable_dtor(ptdesc);
-	if (PageReserved(page))
-		free_reserved_page(page);
-	else
-		pagetable_free(ptdesc);
+	free_pagetable(page);
 	pmd_clear(pmd);
 }
 
-static void __meminit free_pmd_table(pmd_t *pmd_start, pud_t *pud, bool is_vmemmap)
+static void __meminit free_pmd_table(pmd_t *pmd_start, pud_t *pud)
 {
 	struct page *page = pud_page(*pud);
-	struct ptdesc *ptdesc = page_ptdesc(page);
 	pmd_t *pmd;
 	int i;
 
@@ -1520,12 +1524,7 @@ static void __meminit free_pmd_table(pmd_t *pmd_start, pud_t *pud, bool is_vmemm
 			return;
 	}
 
-	if (!is_vmemmap)
-		pagetable_dtor(ptdesc);
-	if (PageReserved(page))
-		free_reserved_page(page);
-	else
-		pagetable_free(ptdesc);
+	free_pagetable(page);
 	pud_clear(pud);
 }
 
@@ -1645,7 +1644,7 @@ static void __meminit remove_pud_mapping(pud_t *pud_base, unsigned long addr, un
 		remove_pmd_mapping(pmd_base, addr, next, is_vmemmap, altmap);
 
 		if (pgtable_l4_enabled)
-			free_pmd_table(pmd_base, pudp, is_vmemmap);
+			free_pmd_table(pmd_base, pudp);
 	}
 }
 
-- 
2.54.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 3/4] riscv/mm: fix missing destructor for hotplug PUD tables
  2026-10-08  7:30 [PATCH 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
  2026-10-08  7:30 ` [PATCH 1/4] x86/mm: fix missing pgtable destructor for vmemmap tables Muchun Song
  2026-10-08  7:30 ` [PATCH 2/4] riscv/mm: fix hotplug page-table destructor handling Muchun Song
@ 2026-10-08  7:30 ` Muchun Song
  2026-10-08  7:30 ` [PATCH 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables Muchun Song
  3 siblings, 0 replies; 6+ messages in thread
From: Muchun Song @ 2026-10-08  7:30 UTC (permalink / raw)
  To: akpm
  Cc: linux-mm, stable, david, osalvador, dave.hansen, luto, peterz,
	tglx, mingo, bp, x86, hpa, catalin.marinas, will, mark.rutland,
	linux-arm-kernel, pjw, palmer, aou, alex, linux-riscv, agordeev,
	kevin.brodsky, bjorn, apopple, linux-kernel, muchun.song

Commit 8472cc4503eb ("riscv: mm: call PUD/P4D ctor in special kernel
pgtable alloc") made alloc_pud_late() run the PUD page-table constructor.
However, free_pud_table() still frees non-reserved PUD tables directly
without decrementing NR_PAGETABLE.

Free PUD tables through the common free_pagetable() helper so that
constructor-backed tables run the matching destructor before being
freed.

Fixes: 8472cc4503eb ("riscv: mm: call PUD/P4D ctor in special kernel pgtable alloc")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
---
 arch/riscv/mm/init.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/arch/riscv/mm/init.c b/arch/riscv/mm/init.c
index 429a0b015ec1..62077539ee78 100644
--- a/arch/riscv/mm/init.c
+++ b/arch/riscv/mm/init.c
@@ -1540,10 +1540,7 @@ static void __meminit free_pud_table(pud_t *pud_start, p4d_t *p4d)
 			return;
 	}
 
-	if (PageReserved(page))
-		free_reserved_page(page);
-	else
-		__free_pages(page, 0);
+	free_pagetable(page);
 	p4d_clear(p4d);
 }
 
-- 
2.54.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables
  2026-10-08  7:30 [PATCH 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
                   ` (2 preceding siblings ...)
  2026-10-08  7:30 ` [PATCH 3/4] riscv/mm: fix missing destructor for hotplug PUD tables Muchun Song
@ 2026-10-08  7:30 ` Muchun Song
  3 siblings, 0 replies; 6+ messages in thread
From: Muchun Song @ 2026-10-08  7:30 UTC (permalink / raw)
  To: akpm
  Cc: linux-mm, stable, david, osalvador, dave.hansen, luto, peterz,
	tglx, mingo, bp, x86, hpa, catalin.marinas, will, mark.rutland,
	linux-arm-kernel, pjw, palmer, aou, alex, linux-riscv, agordeev,
	kevin.brodsky, bjorn, apopple, linux-kernel, muchun.song

Commit c594b83457cc ("arm64: mm: call pagetable dtor when freeing
hot-removed page tables") made free_hotplug_pgtable_page()
unconditionally run the page-table destructor. This matches page tables
allocated by the arm64 mapping code, which runs the corresponding
constructors.

However, arm64 also uses the generic sparse-vmemmap population code.
Runtime intermediate page tables allocated by that code do not run a
page-table constructor. Freeing one during memory hot-remove therefore
runs a destructor without a matching constructor and corrupts
NR_PAGETABLE accounting.

Use PageTable() to run the destructor only for page-table pages whose
constructor initialized them. This keeps the arm64-created page-table
lifecycle balanced while safely freeing constructor-free vmemmap tables.

Fixes: c594b83457cc ("arm64: mm: call pagetable dtor when freeing hot-removed page tables")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
---
 arch/arm64/mm/mmu.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c
index 7343ac9294f8..688b33095651 100644
--- a/arch/arm64/mm/mmu.c
+++ b/arch/arm64/mm/mmu.c
@@ -1495,7 +1495,8 @@ static void free_hotplug_page_range(struct page *page, size_t size,
 
 static void free_hotplug_pgtable_page(struct page *page)
 {
-	pagetable_dtor(page_ptdesc(page));
+	if (PageTable(page))
+		pagetable_dtor(page_ptdesc(page));
 	free_hotplug_page_range(page, PAGE_SIZE, NULL);
 }
 
-- 
2.54.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH 1/4] x86/mm: fix missing pgtable destructor for vmemmap tables
  2026-10-08  7:30 ` [PATCH 1/4] x86/mm: fix missing pgtable destructor for vmemmap tables Muchun Song
@ 2026-10-08  8:32   ` Muchun Song
  0 siblings, 0 replies; 6+ messages in thread
From: Muchun Song @ 2026-10-08  8:32 UTC (permalink / raw)
  To: Muchun Song
  Cc: akpm, linux-mm, stable, david, osalvador, dave.hansen, luto,
	peterz, tglx, mingo, bp, x86, hpa, catalin.marinas, will,
	mark.rutland, linux-arm-kernel, pjw, palmer, aou, alex,
	linux-riscv, agordeev, kevin.brodsky, bjorn, apopple,
	linux-kernel



> On Oct 8, 2026, at 09:30, Muchun Song <songmuchun@bytedance.com> wrote:
> 
> Since commit 49f599666420 ("mm: call ctor/dtor for kernel PTEs"),
> pte_alloc_one_kernel() runs the page-table constructor for kernel PTE
> tables.
> 
> HugeTLB vmemmap optimization uses pte_alloc_one_kernel() when splitting
> a PMD. Restoring the vmemmap backing pages does not collapse the PTE
> table, so a later memory hot-remove eventually frees that table through
> free_pagetable(). That path currently calls pagetable_free() directly
> without decrementing NR_PAGETABLE.
> 
> Use PageTable() to identify constructor-backed tables and run the
> matching destructor before freeing them. Keep reserved and
> constructor-free tables on their existing paths. This also prepares
> vmemmap teardown for generic runtime allocations through the normal
> pgalloc helpers.
> 
> Fixes: 49f599666420 ("mm: call ctor/dtor for kernel PTEs")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Muchun Song <songmuchun@bytedance.com>
> ---
> arch/x86/mm/init_64.c | 2 ++
> 1 file changed, 2 insertions(+)
> 
> diff --git a/arch/x86/mm/init_64.c b/arch/x86/mm/init_64.c
> index 70e682180291..a3ea627157ab 100644
> --- a/arch/x86/mm/init_64.c
> +++ b/arch/x86/mm/init_64.c
> @@ -1003,6 +1003,8 @@ static void __meminit free_pagetable(struct page *page)
> {
> 	if (PageReserved(page))
> 		free_reserved_page(page);
> + 	else if (PageTable(page))
> + 		pagetable_dtor_free(page_ptdesc(page));

Sashiko mentioned that kernel page table pages and vmemmap pages are
freed to the buddy allocator before their parent entries are cleared
and before the TLB is flushed, creating a dangling pointer window.

That's a a real but pre-existing issue, I will not fix that in this
series.

> 	else
> 		pagetable_free(page_ptdesc(page));
> }
> -- 
> 2.54.0
> 


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-08  8:33 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08  7:30 [PATCH 0/4] mm: Fix page-table teardown during memory hot-remove Muchun Song
2026-10-08  7:30 ` [PATCH 1/4] x86/mm: fix missing pgtable destructor for vmemmap tables Muchun Song
2026-10-08  8:32   ` Muchun Song
2026-10-08  7:30 ` [PATCH 2/4] riscv/mm: fix hotplug page-table destructor handling Muchun Song
2026-10-08  7:30 ` [PATCH 3/4] riscv/mm: fix missing destructor for hotplug PUD tables Muchun Song
2026-10-08  7:30 ` [PATCH 4/4] arm64/mm: fix destructor for unconstructed hotplug page tables Muchun Song

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®