Re: [PATCH 1/6] alpha: add missing page_table_check_pte_clear() to ptep_get_and_clear()

From: Magnus Lindholm

Date: Wed Oct 07 2026 - 13:33:28 EST


Hi Matt,

On Tue, Oct 6, 2026 at 4:04 PM Matt Turner <mattst88@xxxxxxxxx> wrote:
>
> Alpha's CONFIG_COMPACTION-gated ptep_get_and_clear() overrides the
> generic version in include/linux/pgtable.h but omits its
> page_table_check_pte_clear() call. With CONFIG_PAGE_TABLE_CHECK=y the
> map count taken by set_ptes() is therefore never dropped when a PTE is
> cleared through this path.
>
> Add the missing call, and drop the now-duplicate one in
> ptep_clear_flush(), which already goes through ptep_get_and_clear().
>
> Signed-off-by: Matt Turner <mattst88@xxxxxxxxx>
> ---
> arch/alpha/include/asm/pgtable.h | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/arch/alpha/include/asm/pgtable.h b/arch/alpha/include/asm/pgtable.h
> index 6ebdd90f3035..8a175e0c2b42 100644
> --- a/arch/alpha/include/asm/pgtable.h
> +++ b/arch/alpha/include/asm/pgtable.h
> @@ -305,6 +305,7 @@ static inline pte_t ptep_get_and_clear(struct mm_struct *mm,
> pte_t pte = READ_ONCE(*ptep);
>
> pte_clear(mm, address, ptep);
> + page_table_check_pte_clear(mm, address, pte);
> return pte;
> }
>
> @@ -316,7 +317,6 @@ static inline pte_t ptep_clear_flush(struct vm_area_struct *vma,
> struct mm_struct *mm = vma->vm_mm;
> pte_t pte = ptep_get_and_clear(mm, addr, ptep);
>
> - page_table_check_pte_clear(mm, addr, pte);
> migrate_flush_tlb_page(vma, addr);
> return pte;
> }
>
> --
> 2.54.0
>

The misplaced call is mine (dd5712f3379c), but it only became reachable
once page table check is enabled for alpha.

The consequence is worth a line too: with page table check enabled, the
first page freed after zap_pte_range() hits the BUG_ON() in
__page_table_check_zero() (mm/page_table_check.c). My test kernels
have COMPACTION=y and PAGE_TABLE_CHECK_ENFORCED=y and run
clean with this applied.

Reviewed-by: Magnus Lindholm <linmag7@xxxxxxxxx>
Tested-by: Magnus Lindholm <linmag7@xxxxxxxxx>