[PATCH v2 0/3] mm: reject zone device folios in more folio walkers
From: Gregory Price
Date: Mon Aug 17 2026 - 18:08:26 EST
Several LRU-oriented mm walkers resolve the folio backing a PMD entry
(or a physical pfn) and then reclaim, age, migrate, or lazyfree it
without ever checking for ZONE_DEVICE memory.
This series adds missing folio_is_zone_device() rejections, matching
the checks that comparable walkers already perform.
- mm/huge_memory, mm/madvise: the !pmd_present branch above these sites
only filters device-private entries (which are non-present).
A present zone device PMD (e.g. device-coherent) would still reach the
folio and be lazyfreed / aged / paged out. Add an explicit check.
- mm/mempolicy: queue_folios_pmd() can see a present zone device PMD
(e.g. device-coherent) and queue it for migration.
No crash reproducer - this is a correctness/hardening cleanup found by
inspection. All checks are placed after the folio is resolved and before
it is acted upon, on paths that already hold the relevant page-table lock,
so no locking or refcount changes are involved.
Gregory Price (3):
mm/huge_memory: skip zone device folios in madvise_free_huge_pmd()
mm/madvise: skip zone device folios in cold/pageout PMD range
mm/mempolicy: skip zone device folios when queueing folios
mm/huge_memory.c | 4 ++++
mm/madvise.c | 3 +++
mm/mempolicy.c | 2 ++
3 files changed, 9 insertions(+)
---
v2 - drop hugetlb, move checks earlier in queue migration route
- fixes tags for all 3
--
2.53.0-Meta