Re: [PATCH v5 14/19] mm, swap: cleanup swap entry management workflow
From: Kairui Song
Date: Wed Jan 14 2026 - 11:19:04 EST
On Wed, Jan 14, 2026 at 8:17 PM Chris Mason <clm@xxxxxxxx> wrote:
>
> On Sat, 20 Dec 2025 03:43:43 +0800 Kairui Song <ryncsn@xxxxxxxxx> wrote:
>
> Hi everyone,
>
> I ran mm-new through the AI review prompts, and this one was flagged:
>
> > diff --git a/kernel/power/swap.c b/kernel/power/swap.c
> > index 8050e51828351..036489d3b01a9 100644
> > --- a/kernel/power/swap.c
> > +++ b/kernel/power/swap.c
>
> [ ... ]
>
> > @@ -186,6 +186,7 @@ sector_t alloc_swapdev_block(int swap)
> >
> > void free_all_swap_pages(int swap)
> > {
> > + unsigned long offset;
> > struct rb_node *node;
> >
> > /*
> > @@ -197,8 +198,9 @@ void free_all_swap_pages(int swap)
> >
> > ext = rb_entry(node, struct swsusp_extent, node);
> > rb_erase(node, &swsusp_extents);
> > - swap_free_nr(swp_entry(swap, ext->start),
> > - ext->end - ext->start + 1);
> > +
> > + for (offset = ext->start; offset < ext->end; offset++)
> > + swap_free_hibernation_slot(swp_entry(swap, offset));
> ^^^^^^^^^^^
>
> Is this loop missing the final slot at ext->end?
>
> The old code freed (ext->end - ext->start + 1) entries, which is the
> inclusive range [ext->start, ext->end]. Looking at swsusp_extents_insert(),
> when a single slot is inserted it sets ext->start = ext->end = offset, and
> merging extends the range by incrementing ext->end or decrementing
> ext->start. This means ext->end is inclusive.
>
> The new loop uses "offset < ext->end" which iterates [ext->start, ext->end),
> missing the slot at ext->end. Should this be "offset <= ext->end" instead?
Wow, nice catch. Indeed that would be one swap leak for each
hibernation snapshot release I think. I only tested normal
hibernations, didn't realize there is issue with the "release before
use" path. `offset <= ext->end` is the right one here.