Re: [PATCH] mm/userfaultfd: clear uffd-wp PTE state when re-registering without WP

Mike Rapoport <[email protected]>
Newsgroups gmane.linux.kernel,gmane.linux.kernel.mm
Message-ID <[email protected]>
On Mon, Jun 01, 2026 at 04:26:09PM +0800, Jianhui Zhou wrote:
> UFFDIO_REGISTER can be issued on a range that is already registered in
> the same userfaultfd context, replacing the VMA's userfaultfd tracking
> mode.  For example, a range can be registered with
> UFFDIO_REGISTER_MODE_WP and later re-registered with
> UFFDIO_REGISTER_MODE_MISSING.
> 
> When the second registration removes VM_UFFD_WP, the VMA flags are
> updated but existing uffd-wp state in page-table entries is left behind.
> That stale state can survive in swap PTEs.  On swapin, do_swap_page()
> restores _PAGE_UFFD_WP from the swap PTE and can then install a writable
> PTE, triggering page_table_check:
> 
>   pte_uffd_wp(pte) && pte_write(pte)
> 
> Handle removal of WP mode through UFFDIO_REGISTER the same way as
> UFFDIO_UNREGISTER: resolve the per-PTE uffd-wp state before dropping
> VM_UFFD_WP from the VMA.
> 
> Also make the same-context fast path require an exact UFFD mode match.
> The old subset check treats MISSING|WP -> MISSING as a no-op, even though
> WP mode is being removed.

The recent RWP changes prevent re-registering to the same uffd with a mode
that clears VM_UFFD_WP or VM_UFFD_RWP. See commit 6eab8f2cc646
("userfaultfd: add UFFDIO_REGISTER_MODE_RWP and UFFDIO_RWPROTECT plumbing")
in the mm tree.

Andrew, can you please drop this patch from mm-unstable?
 
> Fixes: f45ec5ff16a7 ("userfaultfd: wp: support swap and page migration")
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=18d274a59b87cf80e86d
> Signed-off-by: Jianhui Zhou <[email protected]>
> ---
>  mm/userfaultfd.c | 10 +++++++++-
>  1 file changed, 9 insertions(+), 1 deletion(-)

-- 
Sincerely yours,
Mike.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.