[RFC PATCH 1/4] mm/kmsan: undo the shadow mapping when the origin mapping fails

From: Hao Ge

Date: Fri Oct 09 2026 - 02:37:25 EST


kmsan_vmap_pages_range_noflush() first maps the shadow pages and then
the origin pages. If the second mapping fails, the first one is left
mapped, and the callers do not roll it back. The next vmap of the
same metadata range hits the stale PTEs again and BUG()s on the huge
mapping path, or gets -EBUSY with a WARN_ON() on the small page one.

Undo the shadow mapping on that error path, the same way
kmsan_ioremap_page_range() cleans up after a partial failure.
__vunmap_range_noflush() only clears the PTEs; nothing has touched
the shadow mapping, so no TLB flush is needed.

Fixes: 47ebd0310e89 ("mm: kmsan: handle alloc failures in kmsan_vmap_pages_range_noflush()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Hao Ge <hao.ge@xxxxxxxxx>
---
mm/kmsan/shadow.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/mm/kmsan/shadow.c b/mm/kmsan/shadow.c
index 0c88d89bf0d6..2166086d3dc3 100644
--- a/mm/kmsan/shadow.c
+++ b/mm/kmsan/shadow.c
@@ -258,6 +258,10 @@ int kmsan_vmap_pages_range_noflush(unsigned long start, unsigned long end,
o_pages, page_shift);
kmsan_leave_runtime();
if (mapped) {
+ /* Undo the shadow mapping set up above. */
+ kmsan_enter_runtime();
+ __vunmap_range_noflush(shadow_start, shadow_end);
+ kmsan_leave_runtime();
err = mapped;
goto ret;
}
--
2.25.1