[PATCH 0/3] mm: handle device-private PMDs in walk callbacks

From: Usama Arif

Date: Tue Jul 07 2026 - 10:00:11 EST


Since commit 368076f52ebe ("mm/huge_memory: add device-private THP support
to PMD operations") a PMD may hold a device-private swap entry whenever
an HMM-based GPU driver migrates an anonymous THP folio to device memory
via migrate_vma_pages().

pmd_trans_huge_lock() succeeds for such PMDs (pmd_is_huge() returns true
for any non-present, non-none huge PMD), so several MM walk callbacks
that used to assume present THP or migration entry are now reachable with
a device-private PMD. The results range from a VM_BUG_ON() firing on debug
kernels, to an oops on a bogus vmemmap dereference, to silently isolating
an unrelated live folio from LRU in the aliasing case.

The first 2 fixes were reported as pre-existing issues by sashiko in my
PMD swap entry series [1]. Hopefully sashiko won't point these out
in the next PMD swap entry series :)

[1] https://sashiko.dev/#/patchset/20260703173903.3789516-1-usama.arif%40linux.dev?part=6

Usama Arif (3):
mm/mempolicy: skip device-private PMDs when queueing folios
mm/madvise: skip device-private PMDs in cold and pageout walks
mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd

mm/huge_memory.c | 3 +++
mm/madvise.c | 3 +++
mm/mempolicy.c | 2 ++
3 files changed, 8 insertions(+)

--
2.53.0-Meta