[PATCH stable/linux-6.6.y] mm/memory-failure: fix missing ->mf_stats count when hugetlb folio already poisoned

From: Qi Xi

Date: Mon Jul 06 2026 - 05:49:24 EST


When a new subpage is poisoned on a hugetlb folio that has already been
marked hwpoison (MF_HUGETLB_FOLIO_PRE_POISONED), hugetlb_update_hwpoison()
increments num_poisoned_pages directly, but the per-node ->mf_stats is
not updated because this path bypasses action_result(). This leaves the
two accounting counters inconsistent within the hardware memory-failure
path: a new poison event is counted in num_poisoned_pages but not reflected
in the per-node mf_stats.

In mainline, commit a148a2040191 ("mm/memory-failure: fix missing
->mf_stats count in hugetlb poison") fixed this by removing the direct
num_poisoned_pages_inc() from the helper and adding action_result() calls
in try_memory_failure_hugetlb() for the already-poisoned cases. The
backport to linux-6.6.y as commit 252bb328b36f ("mm/memory-failure: fix
missing ->mf_stats count in hugetlb poison") applied the refactoring
(naming, constants, switch-case) but omitted the core counting fix,
leaving the inconsistency in place.

Fix this by adding a matching update_per_node_mf_stats() call alongside
the existing num_poisoned_pages_inc() in the same block, so both counters
stay consistent without restructuring the error path.

Fixes: 252bb328b36f ("mm/memory-failure: fix missing ->mf_stats count in hugetlb poison")
Signed-off-by: Qi Xi <xiqi2@xxxxxxxxxx>
---
mm/memory-failure.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/mm/memory-failure.c b/mm/memory-failure.c
index 86cdf36ee3bb..5f9203bf8ec1 100644
--- a/mm/memory-failure.c
+++ b/mm/memory-failure.c
@@ -1947,8 +1947,10 @@ static int hugetlb_update_hwpoison(struct folio *folio, struct page *page)
raw_hwp->page = page;
llist_add(&raw_hwp->node, head);
/* the first error event will be counted in action_result(). */
- if (ret)
+ if (ret) {
num_poisoned_pages_inc(page_to_pfn(page));
+ update_per_node_mf_stats(page_to_pfn(page), MF_FAILED);
+ }
} else {
/*
* Failed to save raw error info. We no longer trace all
--
2.33.0