Skip to content

Commit 40aed8b

Browse files
jchu314atgithubgregkh
authored andcommitted
mm/memory-failure: teach kill_accessing_process to accept hugetlb tail page pfn
commit 057a6f2 upstream. When a hugetlb folio is being poisoned again, try_memory_failure_hugetlb() passed head pfn to kill_accessing_process(), that is not right. The precise pfn of the poisoned page should be used in order to determine the precise vaddr as the SIGBUS payload. This issue has already been taken care of in the normal path, that is, hwpoison_user_mappings(), see [1][2]. Further more, for [3] to work correctly in the hugetlb repoisoning case, it's essential to inform VM the precise poisoned page, not the head page. [1] https://lkml.kernel.org/r/20231218135837.3310403-1-willy@infradead.org [2] https://lkml.kernel.org/r/20250224211445.2663312-1-jane.chu@oracle.com [3] https://lore.kernel.org/lkml/20251116013223.1557158-1-jiaqiyan@google.com/ Link: https://lkml.kernel.org/r/20260120232234.3462258-2-jane.chu@oracle.com Signed-off-by: Jane Chu <jane.chu@oracle.com> Reviewed-by: Liam R. Howlett <Liam.Howlett@oracle.com> Acked-by: Miaohe Lin <linmiaohe@huawei.com> Cc: Chris Mason <clm@meta.com> Cc: David Hildenbrand <david@kernel.org> Cc: David Rientjes <rientjes@google.com> Cc: Jiaqi Yan <jiaqiyan@google.com> Cc: Lorenzo Stoakes <lorenzo.stoakes@oracle.com> Cc: Matthew Wilcox (Oracle) <willy@infradead.org> Cc: Michal Hocko <mhocko@suse.com> Cc: Mike Rapoport <rppt@kernel.org> Cc: Muchun Song <muchun.song@linux.dev> Cc: Naoya Horiguchi <nao.horiguchi@gmail.com> Cc: Oscar Salvador <osalvador@suse.de> Cc: Suren Baghdasaryan <surenb@google.com> Cc: William Roche <william.roche@oracle.com> Cc: <stable@vger.kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent b0020cb commit 40aed8b

1 file changed

Lines changed: 8 additions & 6 deletions

File tree

mm/memory-failure.c

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -684,6 +684,8 @@ static int check_hwpoisoned_entry(pte_t pte, unsigned long addr, short shift,
684684
unsigned long poisoned_pfn, struct to_kill *tk)
685685
{
686686
unsigned long pfn = 0;
687+
unsigned long hwpoison_vaddr;
688+
unsigned long mask;
687689

688690
if (pte_present(pte)) {
689691
pfn = pte_pfn(pte);
@@ -694,10 +696,12 @@ static int check_hwpoisoned_entry(pte_t pte, unsigned long addr, short shift,
694696
pfn = swp_offset_pfn(swp);
695697
}
696698

697-
if (!pfn || pfn != poisoned_pfn)
699+
mask = ~((1UL << (shift - PAGE_SHIFT)) - 1);
700+
if (!pfn || pfn != (poisoned_pfn & mask))
698701
return 0;
699702

700-
set_to_kill(tk, addr, shift);
703+
hwpoison_vaddr = addr + ((poisoned_pfn - pfn) << PAGE_SHIFT);
704+
set_to_kill(tk, hwpoison_vaddr, shift);
701705
return 1;
702706
}
703707

@@ -2042,10 +2046,8 @@ static int try_memory_failure_hugetlb(unsigned long pfn, int flags, int *hugetlb
20422046
case MF_HUGETLB_FOLIO_PRE_POISONED:
20432047
case MF_HUGETLB_PAGE_PRE_POISONED:
20442048
rv = -EHWPOISON;
2045-
if (flags & MF_ACTION_REQUIRED) {
2046-
folio = page_folio(p);
2047-
rv = kill_accessing_process(current, folio_pfn(folio), flags);
2048-
}
2049+
if (flags & MF_ACTION_REQUIRED)
2050+
rv = kill_accessing_process(current, pfn, flags);
20492051
if (res == MF_HUGETLB_PAGE_PRE_POISONED)
20502052
action_result(pfn, MF_MSG_ALREADY_POISONED, MF_FAILED);
20512053
else

0 commit comments

Comments
 (0)