Re: [PATCH v2 1/2] userfaultfd: clear the inherited uffd bit in move_swap_pte()
From: Andrew Morton
Date: Fri Sep 25 2026 - 00:48:35 EST
On Fri, 25 Sep 2026 13:29:06 +0900 Donggeun Yoo <donggeunyoo.kernel@xxxxxxxxx> wrote:
> UFFDIO_MOVE on a swapped-out page installs the source PTE at the
> destination unchanged, so a uffd bit set on the source lands in a
> destination VMA that was never registered for write protection. It
> can't be unset there, and THP collapse can't happen either, because a
> swap entry with the uffd bit set makes the scan bail.
>
> I don't think it's intentional because for an unswapped page the bit
> doesn't come along, and I don't see why being swapped out should change
> that.
>
> Clear the uffd bit on the moved swap entry unless the destination is
> RWP-registered.
Thanks, but...
When fixing a bug, please always fully describe the userspace-visible
effects of that bug.
> Fixes: adef440691ba ("userfaultfd: UFFDIO_MOVE uABI")
> Cc: <stable@xxxxxxxxxxxxxxx>
Especially when proposing a backport.
Please review the first half-page of
Documentation/process/stable-kernel-rules.rst
I don't mean "be reluctant to backport". I mean "when proposing a
backport, explain *why*".
> Assisted-by: LLM
Great! Please add a prompt to LLM's .md ensuring that future
changelogs always provide this information. Please also share that
update with the rest of your organization.