Re: [PATCH v2] mm/khugepaged: flush deferred unmaps before dropping a failed folio
From: David Hildenbrand (Arm)
Date: Wed Oct 07 2026 - 07:05:00 EST
On 10/7/26 06:10, Kyle Zeng wrote:
> collapse_file() can fail its reference-count or dirty-folio check after
> unmapping with TTU_BATCH_FLUSH. Both paths put back the isolated folio,
> then unlock it and drop the lookup reference before reaching the common
> try_to_unmap_flush().
>
> The page-cache reference does not keep the folio stable once the lock is
> released. Another collapse can replace and free it. With its PTEs
> already gone, that collapse cannot flush the first task's per-task TLB
> batch, and retract_page_tables() skips short or unaligned VMAs. A CPU
> can therefore retain a user translation to the freed folio. This has
> been reproduced with unprivileged MADV_COLLAPSE on a memfd.
>
> Flush at out_unlock while the lookup reference and folio lock are still
> held. The common flush continues to cover the accumulated pagelist on
> both success and rollback, preserving batching on successful collapses.
>
> Fixes: 6d9df8a5889c ("mm/thp: collapse_file() do try_to_unmap(TTU_BATCH_FLUSH)")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Kyle Zeng <kylebot@xxxxxxxxxx>
> ---
LGTM
Acked-by: David Hildenbrand (Arm) <david@xxxxxxxxxx>
--
Cheers,
David