Folio-related bug in __iov_iter_get_pages_alloc()?
From: David Howells
Date: Tue Sep 29 2026 - 08:53:33 EST
Hi Willy,
I'm looking at __iov_iter_get_pages_alloc() and when it's extracting from an
ITER_BVEC, I see:
for (int k = 0; k < n; k++) {
struct folio *folio = page_folio(page + k);
p[k] = page + k;
if (!folio_test_slab(folio))
folio_get(folio);
}
Isn't this wrong? You can't assume the page you're looking at is a folio, and
so you shouldn't use page_folio() on it until you've checked what it is.
Granted, it's quite likely to be a folio, but not only could it be a slab
page, it could also be a randomly allocated page used as a buffer, a network
receive buffer or something allocated with a fragment allocator.
Can we actually safely use folio_get() with all of those, or do we need to use
get_page()? (I know, at moment, get_page() is a wrapper around folio_get(),
but that's likely not to remain the case).
David