Re: [PATCH 2/3] mm/madvise: skip device-private PMDs in cold and pageout walks

From: Zi Yan

Date: Tue Jul 07 2026 - 16:42:13 EST


On Tue Jul 7, 2026 at 9:45 AM EDT, Usama Arif wrote:
> madvise_cold_or_pageout_pte_range() takes pmd_trans_huge_lock(), whose
> pmd_is_huge() check returns true for a device-private PMD. The subsequent
> !pmd_present() branch has a VM_BUG_ON() asserting migration is the only
> allowed non-present case; a device-private PMD trips it.
>
> Potential trigger: an HMM-based GPU driver races with
> madvise(MADV_COLD)/MADV_PAGEOUT: pmd_trans_huge(*pmd) reads true, then
> migrate_vma_pages() flips the PMD to a device-private entry before the
> PMD lock is acquired.
>
> Skip device-private PMDs after taking the lock, before the !pmd_present()
> check.
>
> Reported-by: sashiko-bot <sashiko-bot@xxxxxxxxxx>
> Link: https://sashiko.dev/#/patchset/20260703173903.3789516-1-usama.arif%40linux.dev?part=6
> Fixes: 368076f52ebe ("mm/huge_memory: add device-private THP support to PMD operations")
> Signed-off-by: Usama Arif <usama.arif@xxxxxxxxx>
> ---
> mm/madvise.c | 3 +++
> 1 file changed, 3 insertions(+)
>

LGTM.

Reviewed-by: Zi Yan <ziy@xxxxxxxxxx>

Since it could trigger VM_BUG_ON(), probably cc stable?


--
Best Regards,
Yan, Zi