Re: [PATCH] mm/rmap: don't discard lazyfree THPs at PMD level
From: Lance Yang
Date: Fri Oct 09 2026 - 22:28:32 EST
On 2026/10/10 10:08, Zi Yan wrote:
__discard_anon_folio_pmd_locked() clears a lazyfree THP PMD before it knows
whether the folio can be discarded, and restores it if the folio was
redirtied or has extra references. A concurrent munmap() or
MREMAP_DONTUNMAP skips the temporary none PMD and unlinks the VMA from its
anon_vma, so the folio stays mapped after the anon_vma is freed and a later
rmap walk uses the freed anon_vma.
Using an invalidated PMD instead of a cleared one requires additional arch
code fixes. Instead, disable the PMD level discard of lazyfree THPs, as
before commit 735ecdfaf4e8 ("mm/vmscan: avoid split lazyfree THP during
shrink_folio_list()").
Fixes: 735ecdfaf4e8 ("mm/vmscan: avoid split lazyfree THP during shrink_folio_list()")
Reported-by: Kyle Zeng <kylebot@xxxxxxxxxx>
Closes: https://lore.kernel.org/r/20261009165214.40212-2-kylebot@xxxxxxxxxx
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Zi Yan <ziy@xxxxxxxxxx>
---
LGTM!
Reviewed-by: Lance Yang <lance.yang@xxxxxxxxx>