[merged mm-stable] mm-huge_memory-skip-device-private-pmds-in-madvise_free_huge_pmd.patch removed from -mm tree

Andrew Morton <[email protected]> Tue, 04 Aug 2026 19:26:42 -0700
Newsgroups org.kernel.vger.mm-commits,org.kernel.vger.stable
Message-ID <[email protected]>
The quilt patch titled
     Subject: mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd
has been removed from the -mm tree.  Its filename was
     mm-huge_memory-skip-device-private-pmds-in-madvise_free_huge_pmd.patch

This patch was dropped because it was merged into the mm-stable branch
of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm

------------------------------------------------------
From: Usama Arif <[email protected]>
Subject: mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd
Date: Fri, 10 Jul 2026 03:55:23 -0700

madvise_free_pte_range() checks pmd_trans_huge(*pmd) unlocked, then
madvise_free_huge_pmd() takes pmd_trans_huge_lock().  pmd_is_huge()
returns true for a device-private PMD, so orig_pmd can be device-private
and enter the !pmd_present() branch.

Skip device-private PMDs in that non-present branch and continue to out
before calling pmd_folio().  Downgrade the check to VM_WARN_ON_ONCE() so
an unexpected PMD softleaf logs a warning rather than panicking.  Drop the
thp_migration_supported() guard: it expands to
IS_ENABLED(CONFIG_ARCH_SUPPORTS_PMD_SOFTLEAF), and both
pmd_is_migration_entry() and pmd_is_device_private_entry() already return
false when that config is not selected, so the guard suppresses only the
case where the warning would already be silent.

Potential trigger: an HMM-based GPU driver races with madvise(MADV_FREE):
migrate_vma_pages() flips the PMD to a device-private entry between the
caller's pmd_trans_huge() check and the callee's pmd_trans_huge_lock().

Link: https://lore.kernel.org/[email protected]
Fixes: 368076f52ebe ("mm/huge_memory: add device-private THP support to PMD operations")
Signed-off-by: Usama Arif <[email protected]>
Reviewed-by: Joshua Hahn <[email protected]>
Reviewed-by: Zi Yan <[email protected]>
Reviewed-by: Balbir Singh <[email protected]>
Acked-by: David Hildenbrand (Arm) <[email protected]>
Reviewed-by: Gregory Price <[email protected]>
Cc: Alistair Popple <[email protected]>
Cc: Baolin Wang <[email protected]>
Cc: Barry Song <[email protected]>
Cc: Byungchul Park <[email protected]>
Cc: Dev Jain <[email protected]>
Cc: "Huang, Ying" <[email protected]>
Cc: Jann Horn <[email protected]>
Cc: Johannes Weiner <[email protected]>
Cc: Lance Yang <[email protected]>
Cc: Liam R. Howlett <[email protected]>
Cc: Lorenzo Stoakes <[email protected]>
Cc: Matthew Brost <[email protected]>
Cc: Nico Pache <[email protected]>
Cc: Rakie Kim <[email protected]>
Cc: Ryan Roberts <[email protected]>
Cc: sashiko-bot <[email protected]>
Cc: Shakeel Butt <[email protected]>
Cc: Vlastimil Babka <[email protected]>
Cc: <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---

 mm/huge_memory.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/mm/huge_memory.c~mm-huge_memory-skip-device-private-pmds-in-madvise_free_huge_pmd
+++ a/mm/huge_memory.c
@@ -2331,8 +2331,8 @@ bool madvise_free_huge_pmd(struct mmu_ga
 		goto out;
 
 	if (unlikely(!pmd_present(orig_pmd))) {
-		VM_BUG_ON(thp_migration_supported() &&
-				  !pmd_is_migration_entry(orig_pmd));
+		VM_WARN_ON_ONCE(!pmd_is_migration_entry(orig_pmd) &&
+				!pmd_is_device_private_entry(orig_pmd));
 		goto out;
 	}
 
_

Patches currently in -mm which might be from [email protected] are

mm-vmstat-mm-memcontrol-add-_monotonic-vmstat-readers.patch
mm-vmscan-add-pgrotate_anon-and-pgrotate_file-vmstat-counters.patch
mm-vmscan-reduce-lru_lock-contention-via-vmstat-derived-scan-balance-cost.patch