migrate_vma_split_unmapped_folio() propagates MIGRATE_PFN_MIGRATE from
the head entry to all HPAGE_PMD_NR entries of src_pfns[]. The two
bailouts below it in __migrate_device_pages() only cleared the head, and
the "next" label then advances by @nr, so the tails keep the flag and a
valid destination without ever going through folio_migrate_mapping().
migrate_vma_finalize() then maps unpopulated destination folios into
userspace.

Clear the flag across the whole @nr range at both bailouts.

Reported-by: Sashiko <[email protected]>
Fixes: 4265d67e405a ("mm/migrate_device: add THP splitting during migration")
Cc: Andrew Morton <[email protected]>
Cc: David Hildenbrand <[email protected]>
Cc: Lorenzo Stoakes <[email protected]>
Cc: Zi Yan <[email protected]>
Cc: Baolin Wang <[email protected]>
Cc: Liam R. Howlett <[email protected]>
Cc: Nico Pache <[email protected]>
Cc: Ryan Roberts <[email protected]>
Cc: Dev Jain <[email protected]>
Cc: Barry Song <[email protected]>
Cc: Lance Yang <[email protected]>
Cc: Usama Arif <[email protected]>
Cc: Joshua Hahn <[email protected]>
Cc: Rakie Kim <[email protected]>
Cc: Byungchul Park <[email protected]>
Cc: Gregory Price <[email protected]>
Cc: Ying Huang <[email protected]>
Cc: Alistair Popple <[email protected]>
Cc: Balbir Singh <[email protected]>
Cc: Maarten Lankhorst <[email protected]>
Cc: Maxime Ripard <[email protected]>
Cc: Thomas Zimmermann <[email protected]>
Cc: David Airlie <[email protected]>
Cc: Simona Vetter <[email protected]>
Cc: Thomas Hellström <[email protected]>
Cc: Francois Dugast <[email protected]>
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Assisted-by: GitHub_Copilot:claude-opus-5
Signed-off-by: Matthew Brost <[email protected]>
---
 mm/migrate_device.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/mm/migrate_device.c b/mm/migrate_device.c
index 908d2d4ec43a..d37a96cc6335 100644
--- a/mm/migrate_device.c
+++ b/mm/migrate_device.c
@@ -1199,10 +1199,14 @@ static void __migrate_device_pages(unsigned long 
*src_pfns,
                                 * device private or coherent memory.
                                 *
                                 * Try to get rid of swap cache if possible.
+                                *
+                                * @folio may have been split into @nr folios
+                                * above, so clear all of them.
                                 */
                                if (!folio_test_anon(folio) ||
                                    !folio_free_swap(folio)) {
-                                       src_pfns[i] &= ~MIGRATE_PFN_MIGRATE;
+                                       for (j = 0; j < nr && i + j < npages; 
j++)
+                                               src_pfns[i+j] &= 
~MIGRATE_PFN_MIGRATE;
                                        goto next;
                                }
                        }
@@ -1210,7 +1214,8 @@ static void __migrate_device_pages(unsigned long 
*src_pfns,
                        /*
                         * Other types of ZONE_DEVICE page are not supported.
                         */
-                       src_pfns[i] &= ~MIGRATE_PFN_MIGRATE;
+                       for (j = 0; j < nr && i + j < npages; j++)
+                               src_pfns[i+j] &= ~MIGRATE_PFN_MIGRATE;
                        goto next;
                }
 
-- 
2.34.1

Reply via email to