Re: [PATCH v2 1/2] userfaultfd: clear the inherited uffd bit in move_swap_pte()

From: Andrew Morton

Date: Fri Sep 25 2026 - 00:48:35 EST


On Fri, 25 Sep 2026 13:29:06 +0900 Donggeun Yoo <donggeunyoo.kernel@xxxxxxxxx> wrote:

> UFFDIO_MOVE on a swapped-out page installs the source PTE at the
> destination unchanged, so a uffd bit set on the source lands in a
> destination VMA that was never registered for write protection. It
> can't be unset there, and THP collapse can't happen either, because a
> swap entry with the uffd bit set makes the scan bail.
>
> I don't think it's intentional because for an unswapped page the bit
> doesn't come along, and I don't see why being swapped out should change
> that.
>
> Clear the uffd bit on the moved swap entry unless the destination is
> RWP-registered.

Thanks, but...

When fixing a bug, please always fully describe the userspace-visible
effects of that bug.

> Fixes: adef440691ba ("userfaultfd: UFFDIO_MOVE uABI")
> Cc: <stable@xxxxxxxxxxxxxxx>

Especially when proposing a backport.

Please review the first half-page of
Documentation/process/stable-kernel-rules.rst

I don't mean "be reluctant to backport". I mean "when proposing a
backport, explain *why*".

> Assisted-by: LLM

Great! Please add a prompt to LLM's .md ensuring that future
changelogs always provide this information. Please also share that
update with the rest of your organization.