Re: [PATCH] mm/hugetlb: fix resv_huge_pages double decrement in memfd error path

From: Muchun Song

Date: Tue Aug 25 2026 - 01:43:15 EST




> On Aug 25, 2026, at 10:10, Hongfu Li <hongfu.li@xxxxxxxxx> wrote:
>
> From: Hongfu Li <lihongfu@xxxxxxxxxx>
>
> alloc_hugetlb_folio_reserve() decrements h->resv_huge_pages when
> dequeuing a folio, but unlike the use_global_reservation handling in
> hugetlb_alloc_folio(), it does not set HPageRestoreReserve on the folio.
>
> Its sole caller memfd_alloc_folio() pre-allocates a reservation via
> hugetlb_reserve_pages() before allocating. When hugetlb_add_to_page_cache()
> fails, folio_put() drops the folio without HPageRestoreReserve set, so
> free_huge_folio() does not restore the reservation. The subsequent
> hugetlb_unreserve_pages() on the err_unresv path decrements the counter
> a second time, leaving resv_huge_pages off by one for every failed
> allocation.
>
> Set HPageRestoreReserve when consuming the reservation in
> alloc_hugetlb_folio_reserve(). On the error path, free_huge_folio() then
> restores the reservation before hugetlb_unreserve_pages() releases it.
> The success path is unaffected, as hugetlb_add_to_page_cache() clears
> the flag once the folio is added to the page cache.
>
> Fixes: 26a8ea80929c ("mm/hugetlb: fix memfd_pin_folios resv_huge_pages leak")
> Signed-off-by: Hongfu Li <lihongfu@xxxxxxxxxx>

Reviewed-by: Muchun Song <muchun.song@xxxxxxxxx>

Thanks.