Re: [PATCH v2 2/4] mm, swap: only allow swapped-out slots into the swap cache

From: Kairui Song

Date: Mon Aug 10 2026 - 14:24:07 EST


On Sun, Aug 09, 2026 at 11:45:57PM +0800, Youngjun Park wrote:
> __swap_cache_add_check() turns away folio entries and slots with no count
> and lets everything else in. That is safe only when the caller owns the
> slot. Cluster readahead owns nothing, it walks a raw page_cluster sized
> window of offsets around the faulting entry, so it can land on any slot.
>
> A bad slot gets in. The check reads the count with __swp_tb_get_count(),
> which shifts the count bits out without looking at the type, and
> SWP_TB_BAD has all of them set, so the slot reads as SWP_TB_COUNT_MAX.
> Readahead then allocates a folio and reads the offset off the device for a
> slot nothing will ever swap in, and the folio entry that replaces it drops
> the bad marker.
>
> Readahead used to be guarded by swap_entry_swapped(), which goes through
> swp_tb_get_count() and gets -EINVAL for a bad slot. That call went away
> when the swap cache checks moved into __swap_cache_add_check(), and the
> raw accessor there does not do the same type test.
>
> Require a shadow entry instead. A slot dropped from the swap cache always
> gets one, empty if there is no workingset value. The type test runs first,
> so the count is only read off a countable entry, and the check as a whole
> runs before the folio allocation in __swap_cache_alloc().
>
> Reproduced with a badpages list written into the swap header by hand.
> Readahead took over four bad slots before this patch and none after. It
> needs a crafted header, so a normal setup will not hit it.
>
> Fixes: e1e6750df3b4 ("mm, swap: add support for stable large allocation in swap cache directly")
> Signed-off-by: Youngjun Park <youngjun.park@xxxxxxx>
> ---
> mm/swap_state.c | 9 +++++++--
> 1 file changed, 7 insertions(+), 2 deletions(-)

Thanks!

Acked-by: Kairui Song <kasong@xxxxxxxxxxx>

We need this fix for 7.2 I think.