Re: [PATCH v2 3/3] mm: fail the fault on a malformed swap entry instead of retrying it
From: Barry Song
Date: Mon Aug 17 2026 - 06:30:21 EST
On Thu, Aug 13, 2026 at 6:02 PM Breno Leitao <leitao@xxxxxxxxxx> wrote:
>
> do_swap_page() returns 0 when get_swap_device() fails, which the fault
> handler reads as "handled". For an entry that can never become valid
> the retry takes the same fault again, so the thread spins forever,
> retrying on the same fault.
>
> Return VM_FAULT_SIGBUS (Bad access) for a malformed entry (pr_err() was
> called at get_swap_device()).
>
> Signed-off-by: Breno Leitao <leitao@xxxxxxxxxx>
With a few minor nits below,
Reviewed-by: Barry Song <baohua@xxxxxxxxxx>
> ---
> mm/memory.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/mm/memory.c b/mm/memory.c
> index 7201e848129a7..fa2b3d2ad3202 100644
> --- a/mm/memory.c
> +++ b/mm/memory.c
> @@ -4957,6 +4957,9 @@ vm_fault_t do_swap_page(struct vm_fault *vmf)
> /* Prevent swapoff from happening to us, and reject a bad entry. */
> si = get_swap_device(entry);
> if (IS_ERR_OR_NULL(si)) {
> + /* A malformed entry never becomes valid, so don't retry it. */
> + if (IS_ERR(si))
> + ret = VM_FAULT_SIGBUS;
> si = NULL;
Rather than resetting si to NULL, a more natural approach might be:
index efdf82b3c418..0286b7635bcd 100644
--- a/mm/memory.c
+++ b/mm/memory.c
@@ -5272,7 +5272,7 @@ vm_fault_t do_swap_page(struct vm_fault *vmf)
if (vmf->pte)
pte_unmap_unlock(vmf->pte, vmf->ptl);
out:
- if (si)
+ if (!IS_ERR_OR_NULL(si))
put_swap_device(si);
return ret;
out_nomap:
Thanks
Barry