From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CBCF33D34B3 for ; Tue, 9 Jun 2026 10:12:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780999980; cv=none; b=PuHBHcNHndG1Np99Z6lIe4q9qUzZuu/9DTshFCfx4+6lzhB/LOFFggJcoek2cBQyygCsJmliOs6iBMeq0J6Y8STWp2p1lB2qAe+zeeHpJa+t0Rg9L3K4vT/5mtOziQjPi+y6HwQ/edGOJM5QRBejmPUn73TYTQQFBDBUGq5vkD0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780999980; c=relaxed/simple; bh=j2WAVOhcptz6OyUHo47zZkLVi+TN8pUJ+4T2CAdtlag=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=DjC4NVRTb/rW+fpb8zLJuc07fnvNVah27M9G6Ripxz9JUX4rcU9TVqSbnuNSAkAogxicrXqWuYhnAMo8rcyM6ICS2tAiZXXD95Fvo2F8cYhD7Emt+g+M2vCCeO+v6necA6VN/zfz1z5UbN+rNHBauxDJ80E6f7OsLINHglTLSZA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=cNLvVRC/; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=q6vAWqlB; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="cNLvVRC/"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="q6vAWqlB" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780999977; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type; bh=eG5xXsnRbSzhdk92bHjLO+lAL03tD8JhyLJB5wX13vg=; b=cNLvVRC/hfrv1avN8yAbOIEPfFBEDra0WieFb9ciXU/rDv1IAHDxcfDGRtme+0R2EkY5jd P+yrxwntFDJUAiYKRwyoFC21/MqvoGdrQDDtPMzJiALVxmqKXOim4jkMjhhsAumGQmfSgq 46ueuaTR67qni/nsGR0Gb9SDhi11WgM= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-473-YOceQSXwOVKoAtIPnFCtdw-1; Tue, 09 Jun 2026 06:12:56 -0400 X-MC-Unique: YOceQSXwOVKoAtIPnFCtdw-1 X-Mimecast-MFC-AGG-ID: YOceQSXwOVKoAtIPnFCtdw_1780999975 Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-490bae3a39bso50581985e9.1 for ; Tue, 09 Jun 2026 03:12:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1780999975; x=1781604775; darn=vger.kernel.org; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=eG5xXsnRbSzhdk92bHjLO+lAL03tD8JhyLJB5wX13vg=; b=q6vAWqlBqevw0ExObqgQ0g3ZxRx+Favu+CJTV6KaWfxHxINIYazXQZ+4gh2h3fWuDL QNVWBAmNBuo9TTRpJZNr84/Tab1aDRsQTQV00f04Fq4O77IlPxgcDW2aYwY0Kj51Hejy xRBKHNsD+HuoyC5/2obe4+d09uZPnjuUuamluqE8yQ9279MYL+VSpKsskjW3MgM0+Mx5 qvaZcYL5Y2Q1v/XGWLeSdH/F5d/9ytL4dM9eV5saOuFMsdqV/dhvW/wTbLkgWDVisdCo jl1WV5yIsUFWMQHgLT04Mv6817BzPhLgjPPXJS9u7/cghbC8qkXA+9hjlNQ59p6i86O2 kbKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780999975; x=1781604775; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=eG5xXsnRbSzhdk92bHjLO+lAL03tD8JhyLJB5wX13vg=; b=lJbSErPluKL2mcpU9+1BSmA6mgtb5+X5egM7GzXrlIRwauFUhi1CDw86cAS09tIMr/ iVgZeZbBOHID800cUmljaVwIAt3JfNUtFiA0jRntx8LnJ+brcB1NNRpets7W5bjIrE37 p8omCOsKywSTBDyTl4MfU+mFHKkHe94jZnTF34IGzgN2yXq2HSWxvOLw31uTmR+5VUxe yXJhyiL41vsjSW78HaQuRryBM+SdjdwmeGiHP+wXTXc6lg+ZnF4Vrzrpp1ZCKT3roCCy RN0tqO5Jg2UdkzQisHyp0KeijSsDJKksDfmZfE49mgJeUu8qPuj+Di9Z2CDkyFgiRqAW 1aJQ== X-Gm-Message-State: AOJu0YwMQ6Jw+kNLJtZTcyKdIxT11c2umJzrjTVVVAZdLaJ25m5AaB9z RjXyHaLcjJ+royToWV7bb/0QuPpPh25deBXo+/F2kGZUbpLJjUM3GVGlTKdPd3qEonDAk0xRooC uxmYvREJs2bmJLI8iCuaBFkevkPbI0blqs4X57yNmUIAz0uVY/miE9/JqmS87nNaUd3YhfvbGfy ENws43NjvPkWNh9RDyhZe5KSgkqsVsApV3CHS9if3MdbsjEQ== X-Gm-Gg: Acq92OHYjC9Q/E/fYT9XrTwzt56jMzydZdmyXJh9nxE/jokAV6YkoVkEQMFE6fcRH+u ekFKR64Hi+NWVJlIjXqtIsCd1B1UGl+wEd0WuowFOmPliQUzgUpUiTzUKYIp8Vq7VaDTNgbn1G7 xCtni63wy36psGdo3ITG46ZlCq3gNf80I1uQ7DE3PYSnQRZFfQpjsRnW7iA/y9WwUNuz4e16eC+ dShYctrNGlXJdlrNxEK4KMm/0UV07hWhkNqo/29IEztvalVYE/CW4C4EzNGMLAJLBycJxb3bnEf s/SI9dU/VVsfxe94qBw5XWi9LvfXiEMVT7Egh6obEYVPIkmry5SzrVYkhdHGqW4sLYZ/AuBwUlL sv3jgXw+VXfTAeuJK+kEGeL88o0pixal6oGk6QHjivNXTSmTaIrwvnA== X-Received: by 2002:a05:600c:3107:b0:490:9588:bdb6 with SMTP id 5b1f17b1804b1-490c264cc2emr328880195e9.33.1780999975382; Tue, 09 Jun 2026 03:12:55 -0700 (PDT) X-Received: by 2002:a05:600c:3107:b0:490:9588:bdb6 with SMTP id 5b1f17b1804b1-490c264cc2emr328879275e9.33.1780999974756; Tue, 09 Jun 2026 03:12:54 -0700 (PDT) Received: from redhat.com (IGLD-80-230-85-71.inter.net.il. [80.230.85.71]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-490bc3c15cesm460773715e9.5.2026.06.09.03.12.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 09 Jun 2026 03:12:54 -0700 (PDT) Date: Tue, 9 Jun 2026 06:12:49 -0400 From: "Michael S. Tsirkin" To: linux-kernel@vger.kernel.org Cc: Miaohe Lin , "David Hildenbrand (Arm)" , Jason Wang , Xuan Zhuo , Eugenio =?utf-8?B?UMOpcmV6?= , Muchun Song , Oscar Salvador , Andrew Morton , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Brendan Jackman , Johannes Weiner , Zi Yan , Baolin Wang , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Lance Yang , Hugh Dickins , Matthew Brost , Joshua Hahn , Rakie Kim , Byungchul Park , Gregory Price , Ying Huang , Alistair Popple , Christoph Lameter , David Rientjes , Roman Gushchin , Harry Yoo , Axel Rasmussen , Yuanchu Xie , Wei Xu , Chris Li , Kairui Song , Kemeng Shi , Nhat Pham , Baoquan He , virtualization@lists.linux.dev, linux-mm@kvack.org, Andrea Arcangeli , Naoya Horiguchi Subject: [PATCH splitout] mm: memory-failure: serialize TestSetPageHWPoison with zone->lock Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Mailer: git-send-email 2.51.2.2891.g4157995a80.dirty X-Mutt-Fcc: =sent TestSetPageHWPoison() is called without zone->lock, so its atomic update to page->flags can race with non-atomic flag operations that run under zone->lock in the buddy allocator. In particular, __free_pages_prepare() does: page->flags.f &= ~PAGE_FLAGS_CHECK_AT_PREP; This non-atomic read-modify-write, while correctly excluding __PG_HWPOISON from the mask, can still lose a concurrent TestSetPageHWPoison if the read happens before the poison bit is set and the write happens after. Will only get worse if/when we add more non-atomic flag operations. Fix by acquiring zone->lock around TestSetPageHWPoison and around ClearPageHWPoison in the retry path. This serializes with all buddy flag manipulation. The cost is negligible: one lock/unlock in an extremely rare path (hardware memory errors). Note: SetPageHWPoison and TestClearPageHWPoison calls elsewhere in this file operate on pages already removed from the buddy allocator or on non-buddy pages (DAX, hugetlb), so they do not need zone->lock protection. Fixes: 6a46079cf57a ("HWPOISON: The high level memory error handler in the VM v7") Acked-by: Miaohe Lin Signed-off-by: Michael S. Tsirkin Assisted-by: Claude:claude-opus-4-6 --- Sending separately as suggested by multiple people. I also added a Fixes tag. mm/memory-failure.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/mm/memory-failure.c b/mm/memory-failure.c index ee42d4361309..3880486028a1 100644 --- a/mm/memory-failure.c +++ b/mm/memory-failure.c @@ -2348,6 +2348,8 @@ int memory_failure(unsigned long pfn, int flags) unsigned long page_flags; bool retry = true; int hugetlb = 0; + struct zone *zone; + unsigned long mf_flags; if (!sysctl_memory_failure_recovery) panic("Memory failure on page %lx", pfn); @@ -2390,7 +2392,11 @@ int memory_failure(unsigned long pfn, int flags) if (hugetlb) goto unlock_mutex; + /* Serialize with non-atomic buddy flag operations */ + zone = page_zone(p); + spin_lock_irqsave(&zone->lock, mf_flags); if (TestSetPageHWPoison(p)) { + spin_unlock_irqrestore(&zone->lock, mf_flags); res = -EHWPOISON; if (flags & MF_ACTION_REQUIRED) res = kill_accessing_process(current, pfn, flags); @@ -2399,6 +2405,7 @@ int memory_failure(unsigned long pfn, int flags) action_result(pfn, MF_MSG_ALREADY_POISONED, MF_FAILED); goto unlock_mutex; } + spin_unlock_irqrestore(&zone->lock, mf_flags); /* * We need/can do nothing about count=0 pages. @@ -2420,7 +2427,10 @@ int memory_failure(unsigned long pfn, int flags) } else { /* We lost the race, try again */ if (retry) { + /* Serialize with non-atomic buddy flag operations */ + spin_lock_irqsave(&zone->lock, mf_flags); ClearPageHWPoison(p); + spin_unlock_irqrestore(&zone->lock, mf_flags); retry = false; goto try_again; } -- MST