[PATCH v2 19/20 DO-NOT-MERGE] hugetlb_vmemmap: Add fault injection for in-place vmemmap PMD splits
From: James Houghton
Date: Fri Oct 02 2026 - 20:23:15 EST
Like try_update_vmemmap_pte(), try_populate_vmemmap_pmd() may fail,
e.g. on arm64 when replacing the block mapping keeps racing with
hardware access flag updates. HVO handles such failures by not
optimizing the folio.
Add a fault-injection capability, fail_hugetlb_vmemmap_pmd, alongside
fail_hugetlb_vmemmap_pte. When a fault is injected, the PMD split fails
with -EAGAIN without touching the page tables.
It can be configured through debugfs or through the
fail_hugetlb_vmemmap_pmd= boot option. Since vmemmap PMDs are only split
once, the boot option is the most effective way to exercise this path.
Assisted-by: LLM
Signed-off-by: James Houghton <jthoughton@xxxxxxxxxx>
---
.../fault-injection/fault-injection.rst | 8 +++++---
lib/Kconfig.debug | 4 ++--
mm/hugetlb_vmemmap.c | 20 ++++++++++++++++++-
3 files changed, 26 insertions(+), 6 deletions(-)
diff --git a/Documentation/fault-injection/fault-injection.rst b/Documentation/fault-injection/fault-injection.rst
index 403206645fa4..5cfabea811da 100644
--- a/Documentation/fault-injection/fault-injection.rst
+++ b/Documentation/fault-injection/fault-injection.rst
@@ -16,10 +16,11 @@ Available fault injection capabilities
injects page allocation failures. (alloc_pages(), get_free_pages(), ...)
-- fail_hugetlb_vmemmap_pte
+- fail_hugetlb_vmemmap_pte, fail_hugetlb_vmemmap_pmd
- injects failures of the in-place vmemmap PTE remaps done by HugeTLB vmemmap
- optimization. (try_update_vmemmap_pte())
+ injects failures of the in-place vmemmap PTE remaps and PMD splits done by
+ HugeTLB vmemmap optimization. (try_update_vmemmap_pte(),
+ try_populate_vmemmap_pmd())
- fail_usercopy
@@ -269,6 +270,7 @@ use the boot option::
failslab=
fail_page_alloc=
fail_hugetlb_vmemmap_pte=
+ fail_hugetlb_vmemmap_pmd=
fail_usercopy=
fail_make_request=
fail_futex=
diff --git a/lib/Kconfig.debug b/lib/Kconfig.debug
index 96cd1f1da94a..7abda377c737 100644
--- a/lib/Kconfig.debug
+++ b/lib/Kconfig.debug
@@ -2072,8 +2072,8 @@ config FAIL_HUGETLB_VMEMMAP
help
Provide fault-injection capability for the in-place vmemmap page
table updates done by HugeTLB vmemmap optimization (HVO), i.e.
- try_update_vmemmap_pte(). This exercises the rollback and
- partially-optimized folio paths.
+ try_update_vmemmap_pte() and try_populate_vmemmap_pmd(). This
+ exercises the rollback and partially-optimized folio paths.
config FAULT_INJECTION_USERCOPY
bool "Fault injection capability for usercopy functions"
diff --git a/mm/hugetlb_vmemmap.c b/mm/hugetlb_vmemmap.c
index 9e0f52474bdb..f50880dd79a2 100644
--- a/mm/hugetlb_vmemmap.c
+++ b/mm/hugetlb_vmemmap.c
@@ -53,6 +53,7 @@ struct vmemmap_remap_walk {
#ifdef CONFIG_FAIL_HUGETLB_VMEMMAP
static DECLARE_FAULT_ATTR(fail_hugetlb_vmemmap_pte);
+static DECLARE_FAULT_ATTR(fail_hugetlb_vmemmap_pmd);
static int __init setup_fail_hugetlb_vmemmap_pte(char *str)
{
@@ -60,11 +61,19 @@ static int __init setup_fail_hugetlb_vmemmap_pte(char *str)
}
__setup("fail_hugetlb_vmemmap_pte=", setup_fail_hugetlb_vmemmap_pte);
+static int __init setup_fail_hugetlb_vmemmap_pmd(char *str)
+{
+ return setup_fault_attr(&fail_hugetlb_vmemmap_pmd, str);
+}
+__setup("fail_hugetlb_vmemmap_pmd=", setup_fail_hugetlb_vmemmap_pmd);
+
#ifdef CONFIG_FAULT_INJECTION_DEBUG_FS
static int __init fail_hugetlb_vmemmap_debugfs(void)
{
fault_create_debugfs_attr("fail_hugetlb_vmemmap_pte", NULL,
&fail_hugetlb_vmemmap_pte);
+ fault_create_debugfs_attr("fail_hugetlb_vmemmap_pmd", NULL,
+ &fail_hugetlb_vmemmap_pmd);
return 0;
}
late_initcall(fail_hugetlb_vmemmap_debugfs);
@@ -80,8 +89,17 @@ static int hvo_update_vmemmap_pte(unsigned long addr, pte_t *ptep, pte_t pte)
return -EAGAIN;
return try_update_vmemmap_pte(addr, ptep, pte);
}
+
+static int hvo_populate_vmemmap_pmd(unsigned long addr, pmd_t *pmdp,
+ pte_t *pgtable)
+{
+ if (should_fail(&fail_hugetlb_vmemmap_pmd, PMD_SIZE))
+ return -EAGAIN;
+ return try_populate_vmemmap_pmd(addr, pmdp, pgtable);
+}
#else
#define hvo_update_vmemmap_pte try_update_vmemmap_pte
+#define hvo_populate_vmemmap_pmd try_populate_vmemmap_pmd
#endif /* CONFIG_FAIL_HUGETLB_VMEMMAP */
static int vmemmap_split_pmd(pmd_t *pmd, struct page *head, unsigned long start,
@@ -113,7 +131,7 @@ static int vmemmap_split_pmd(pmd_t *pmd, struct page *head, unsigned long start,
if (likely(pmd_leaf(*pmd))) {
/* Make pte visible before pmd. See comment in pmd_install(). */
smp_wmb();
- ret = try_populate_vmemmap_pmd(start, pmd, pgtable);
+ ret = hvo_populate_vmemmap_pmd(start, pmd, pgtable);
if (ret)
goto free;
--
2.56.0.rc1.315.gc6ed9934b7-goog