[to-be-updated] mm-memory-failure-fix-refcount-leak-on-soft-offline-lbs-folio.patch removed from -mm tree
Andrew Morton <[email protected]>
| Newsgroups | org.kernel.vger.mm-commits |
|---|---|
| Message-ID | <[email protected]> |
The quilt patch titled
Subject: mm/memory-failure: fix refcount leak on soft-offline LBS folio
has been removed from the -mm tree. Its filename was
mm-memory-failure-fix-refcount-leak-on-soft-offline-lbs-folio.patch
This patch was dropped because an updated version will be issued
------------------------------------------------------
From: liyouhong <[email protected]>
Subject: mm/memory-failure: fix refcount leak on soft-offline LBS folio
Date: Tue, 4 Aug 2026 11:53:56 +0800
soft_offline_in_use_page() runs with a folio reference taken by
get_hwpoison_page().
Soft-offline skips splitting when min_order_for_split() is non-zero, so
large folios stay intact. That early return -EBUSY path never drops the
reference.
The other failure path is fine: try_to_split_thp_page(..., release=true)
puts the page when the split itself fails. memory_failure() also puts
explicitly on its analogous unsplit path.
Handle the new_order != 0 case separately and call folio_put() before
returning.
Link: https://lore.kernel.org/[email protected]
Fixes: 689b8986776c ("mm/memory-failure: improve large block size folio handling")
Signed-off-by: liyouhong <[email protected]>
Cc: Miaohe Lin <[email protected]>
Cc: Naoya Horiguchi <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---
mm/memory-failure.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
--- a/mm/memory-failure.c~mm-memory-failure-fix-refcount-leak-on-soft-offline-lbs-folio
+++ a/mm/memory-failure.c
@@ -2845,6 +2845,9 @@ EXPORT_SYMBOL(unpoison_memory);
* soft_offline_in_use_page handles hugetlb-pages and non-hugetlb pages.
* If the page is a non-dirty unmapped page-cache page, it simply invalidates.
* If the page is mapped, it migrates the contents over.
+ *
+ * The folio refcount has been incremented before entering this function.
+ * This folio reference must be released before the function returns on all paths.
*/
static int soft_offline_in_use_page(struct page *page)
{
@@ -2870,9 +2873,19 @@ static int soft_offline_in_use_page(stru
* NOTE: if minimizing the number of soft offline pages is
* preferred, split it to non-zero new_order like it is done in
* memory_failure().
+ *
+ * Drop the reference obtained upon entry;
+ * try_to_split_thp_page(..., release=true) handles refcounting itself
+ * when the split fails.
*/
- if (new_order || try_to_split_thp_page(page, /* new_order= */ 0,
- /* release= */ true)) {
+ if (new_order) {
+ pr_info("%#lx: order-%d folio cannot soft offline\n",
+ pfn, new_order);
+ folio_put(folio);
+ return -EBUSY;
+ }
+ if (try_to_split_thp_page(page, /* new_order= */ 0,
+ /* release= */ true)) {
pr_info("%#lx: thp split failed\n", pfn);
return -EBUSY;
}
_
Patches currently in -mm which might be from [email protected] are