[PATCH 0/4] mm: reject zone device folios in more folio walkers

Gregory Price <[email protected]> Tue, 28 Jul 2026 15:47:10 -0400
Newsgroups dev.linux.lists.damon,org.kernel.vger.linux-kernel,org.kvack.linux-mm
Message-ID <[email protected]>
Several LRU-oriented mm walkers resolve the folio backing a PMD/hugetlb
entry (or a physical pfn) and then reclaim, age, migrate, or lazyfree it
without ever checking for ZONE_DEVICE memory.

This series adds missing folio_is_zone_device() rejections, matching
the checks that comparable walkers already perform.

The changes fall into two groups:

1) Genuine gaps:

 - mm/huge_memory, mm/madvise: the !pmd_present branch above these sites
   only filters device-private entries (which are non-present).

   A present zone device PMD (e.g. device-coherent) would still reach the
   folio and be lazyfreed / aged / paged out. Add an explicit check.

 - mm/mempolicy: queue_folios_pmd() can see a present zone device PMD
   (e.g. device-coherent) and queue it for migration.


2) Defensive / consistency:

 - mm/damon: damon_get_folio() already excludes zone device memory
   implicitly (pfn_to_online_page(), lru checks).  The explicit check
   is added in the single damon_get_folio() chokepoint so every DAMON
   caller is covered uniformly and the guarantee is stated explicitly.

 - mm/mempolicy: queue_folios_hugetlb() cannot see zone device memory
   (hugetlb folios are never ZONE_DEVICE).  We add the check to keep
   all three mempolicy walkers consistent.

No crash reproducer - this is a correctness/hardening cleanup found by
inspection. All checks are placed after the folio is resolved and before
it is acted upon, on paths that already hold the relevant page-table lock,
so no locking or refcount changes are involved.

Gregory Price (4):
  mm/damon: defensively skip zone device folios in damon_get_folio()
  mm/huge_memory: skip zone device folios in madvise_free_huge_pmd()
  mm/madvise: skip zone device folios in cold/pageout PMD range
  mm/mempolicy: skip zone device folios when queueing folios

 mm/damon/ops-common.c | 3 ++-
 mm/huge_memory.c      | 4 ++++
 mm/madvise.c          | 3 +++
 mm/mempolicy.c        | 4 ++++
 4 files changed, 13 insertions(+), 1 deletion(-)

-- 
2.55.0