Re: [BUG] shmem: FALLOC_FL_PUNCH_HOLE vs fault-around race corrupts page cache / rss counters
From: Ayush Ranjan
Date: Fri Sep 25 2026 - 01:33:26 EST
On Thu, Sep 24, 2026 at 09:15 +0000, Jan Kara wrote:
> Can this be perhaps somehow related to the fixes in partial large folio
> truncation Zhang Yi is working on, possibly even the tmpfs bug in handling
> of folio split I've found [1]? It seems large folios are used here so that
> matches, I just don't immediately see how those bugs would lead to the
> errors reported here...
That would fit what I see, for what it's worth:
- the rss-counter imbalance from the reproducer is always exactly
one PMD-order folio (+/-512), which looks more like large-folio
split/accounting going wrong than lost or extra PTEs;
- the reproducer's punching thread deliberately mixes unaligned
sub-PMD ranges, so partial truncation of large folios is exercised
constantly, and the production "still mapped when deleted" splat
is reported from truncate_inode_partial_folio() (full stack in my
reply to Pedro).
Thanks,
Ayush