[RFC PATCH 0/4] mm/vmalloc: make the mapping functions undo their partial mappings

From: Hao Ge

Date: Fri Oct 09 2026 - 02:35:29 EST


__vmap_pages_range_noflush() and friends can install some PTEs before
failing and leave them mapped, and the kernel callers do not agree on
who cleans them up. pcpu_map_pages() and kmsan_ioremap_page_range()
roll back what they mapped before the failure, while
vm_module_tags_populate() and the __GFP_NOFAIL retry loop in
__vmalloc_area_node() rely on the mapping functions cleaning up and
do not call anything like vunmap_range() themselves. When the same
range is mapped again, the attempt hits the leftovers and fails, with
a BUG() in vmap_pte_range() for huge mappings and a warning on the
small-page path.

This moves the rollback into the mapping functions. A failed vmap
leaves nothing mapped, and the callers no longer clean up after it.

Patch 1 is the KMSAN part. The shadow and the origin of a range
are mapped by two separate calls, so the rollback there has to
cover both. Patch 2 adds it to __vmap_pages_range_noflush() and
vmap_page_range(). Patches 3 and 4 drop the powerpc and percpu
cleanups that are not needed anymore.

Hao Ge (4):
mm/kmsan: undo the shadow mapping when the origin mapping fails
mm/vmalloc: undo partial mappings inside the mapping functions
powerpc: drop redundant unmaps of failed vmap mappings
mm/percpu: stop unmapping the CPU that failed to map

arch/powerpc/kernel/isa-bridge.c | 5 ++--
arch/powerpc/kernel/pci_64.c | 4 +--
mm/kmsan/shadow.c | 4 +++
mm/percpu-vm.c | 5 ++--
mm/vmalloc.c | 44 +++++++++++++++++++++++---------
5 files changed, 42 insertions(+), 20 deletions(-)

--
2.25.1