Re: [PATCH v3] mm/khugepaged: avoid underflow in madvise_collapse for sub-PMD MADV_COLLAPSE
From: Lorenzo Stoakes
Date: Wed May 13 2026 - 05:24:16 EST
On Wed, May 13, 2026 at 01:54:28PM +0800, Wandun Chen wrote:
> From: Chen Wandun <chenwandun@xxxxxxxxxxx>
>
> madvise_collapse() computes the THP-aligned window:
>
> hstart = ALIGN(start, HPAGE_PMD_SIZE); /* round up */
> hend = ALIGN_DOWN(end, HPAGE_PMD_SIZE); /* round down */
>
> The following case will cause hstart > hend, and result in underflow
> in the return statement, avoid it by returning zero early when
> hstart > hend. The return value is due to input is valid to madvise(),
> and there is nothing to collapse.
>
> madvise(PMD-aligned + PAGE_SIZE, PAGE_SIZE, MADV_COLLAPSE);
>
> In addition, kmalloc_obj(), mmgrab() and lru_add_drain_all() are
> unnecessary when hstart == hend, so skip these operations by
> returning early too.
>
> Signed-off-by: Chen Wandun <chenwandun@xxxxxxxxxxx>
LGTM, so:
Reviewed-by: Lorenzo Stoakes <ljs@xxxxxxxxxx>
Cheers, Lorenzo
> ---
> v2 --> v3:
> - Return 0 when hstart > hend, suggested by David and Lorenzo.
>
> v1 --> v2:
> - Rebase and resolve code conflict.
> - Return -EINVAL when hstart > hend, suggested by Lorenzo.
> - Drop Fixes tag, suggested by David and Lorenzo.
> - Updated commit message to be more explicit, suggested by Lorenzo.
> ---
> mm/khugepaged.c | 9 ++++++---
> 1 file changed, 6 insertions(+), 3 deletions(-)
>
> diff --git a/mm/khugepaged.c b/mm/khugepaged.c
> index 28a843f30b32..fd7e893c998d 100644
> --- a/mm/khugepaged.c
> +++ b/mm/khugepaged.c
> @@ -2837,6 +2837,12 @@ int madvise_collapse(struct vm_area_struct *vma, unsigned long start,
> if (!thp_vma_allowable_order(vma, vma->vm_flags, TVA_FORCED_COLLAPSE, PMD_ORDER))
> return -EINVAL;
>
> + hstart = ALIGN(start, HPAGE_PMD_SIZE);
> + hend = ALIGN_DOWN(end, HPAGE_PMD_SIZE);
> +
> + if (hstart >= hend)
> + return 0;
> +
> cc = kmalloc_obj(*cc);
> if (!cc)
> return -ENOMEM;
> @@ -2846,9 +2852,6 @@ int madvise_collapse(struct vm_area_struct *vma, unsigned long start,
> mmgrab(mm);
> lru_add_drain_all();
>
> - hstart = ALIGN(start, HPAGE_PMD_SIZE);
> - hend = ALIGN_DOWN(end, HPAGE_PMD_SIZE);
> -
> for (addr = hstart; addr < hend; addr += HPAGE_PMD_SIZE) {
> enum scan_result result = SCAN_FAIL;
>
> --
> 2.43.0
>