Re: [PATCH] mm/memfd: don't unreserve hugetlb pages on -EEXIST in error path
From: Hongfu Li
Date: Tue Sep 01 2026 - 05:02:26 EST
On 9/1/26 8:35 AM, Andrew Morton wrote:
On Mon, 31 Aug 2026 17:06:31 +0800 Hongfu Li <hongfu.li@xxxxxxxxx> wrote:
From: Hongfu Li <lihongfu@xxxxxxxxxx>Thanks.
If hugetlb_add_to_page_cache() fails with -EEXIST, a concurrent fault has
already instantiated the folio in the page cache, and the reservation now
belongs to that folio. Calling hugetlb_unreserve_pages() in that case
incorrectly removes the region backing the cached folio, and a later
truncate or inode eviction passes a negative (chg - freed) into
hugepage_subpool_put_pages(), corrupting subpool and resv_huge_pages
accounting.
Skip the unreserve on -EEXIST; failures other than -EEXIST leave the
reservation unconsumed and still unreserve it.
AI review might have found another bug and it suggests that your
proposal only partially fixes this bug:
https://sashiko.dev/#/patchset/20260831090631.29227-1-hongfu.li@xxxxxxxxx
Thank you for the reminder.
I have carefully gone through the Sashiko review report.
The issue it pointed out is valid. I will address this
remaining problem and send out a v2 patch shortly.
--
Best regards,
Hongfu