[PATCH] mm/memfd_luo: report error when restoring a folio fails mid-loop
From: David Carlier
Date: Wed Apr 15 2026 - 01:23:44 EST
memfd_luo_retrieve_folios() initialises err to -EIO, but the per-iteration
calls to mem_cgroup_charge(), shmem_add_to_page_cache() and
shmem_inode_acct_blocks() reuse and overwrite err. Once any iteration
completes successfully, err becomes zero.
If a later iteration's kho_restore_folio() returns NULL, the failure path
jumps to put_folios without resetting err, so the function returns 0.
The caller memfd_luo_retrieve() then takes the success path, sets
args->file and reports the restore as successful, leaving userspace with
a partially populated memfd and no indication that anything went wrong.
Set err to -EIO in the kho_restore_folio() failure branch so the error
is propagated to the caller.
Signed-off-by: David Carlier <devnexen@xxxxxxxxx>
---
mm/memfd_luo.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/mm/memfd_luo.c b/mm/memfd_luo.c
index b02b503c750d..35d1247281e0 100644
--- a/mm/memfd_luo.c
+++ b/mm/memfd_luo.c
@@ -427,6 +427,7 @@ static int memfd_luo_retrieve_folios(struct file *file,
if (!folio) {
pr_err("Unable to restore folio at physical address: %llx\n",
phys);
+ err = -EIO;
goto put_folios;
}
index = pfolio->index;
--
2.53.0