Commit 21205bf8 authored by Mike Kravetz's avatar Mike Kravetz Committed by Linus Torvalds
Browse files

userfaultfd: hugetlbfs: reserve count on error in __mcopy_atomic_hugetlb

If __mcopy_atomic_hugetlb exits with an error, put_page will be called
if a huge page was allocated and needs to be freed.  If a reservation
was associated with the huge page, the PagePrivate flag will be set.
Clear PagePrivate before calling put_page/free_huge_page so that the
global reservation count is not incremented.


Signed-off-by: default avatarMike Kravetz <>
Signed-off-by: default avatarAndrea Arcangeli <>
Cc: "Dr. David Alan Gilbert" <>
Cc: Hillf Danton <>
Cc: Michael Rapoport <>
Cc: Mike Rapoport <>
Cc: Pavel Emelyanov <>
Signed-off-by: default avatarAndrew Morton <>
Signed-off-by: default avatarLinus Torvalds <>
parent 87ffc118
......@@ -301,8 +301,23 @@ static __always_inline ssize_t __mcopy_atomic_hugetlb(struct mm_struct *dst_mm,
if (page)
if (page) {
* We encountered an error and are about to free a newly
* allocated huge page. It is possible that there was a
* reservation associated with the page that has been
* consumed. See the routine restore_reserve_on_error
* for details. Unfortunately, we can not call
* restore_reserve_on_error now as it would require holding
* mmap_sem. Clear the PagePrivate flag so that the global
* reserve count will not be incremented in free_huge_page.
* The reservation map will still indicate the reservation
* was consumed and possibly prevent later page allocation.
* This is better than leaking a global reservation.
BUG_ON(copied < 0);
BUG_ON(err > 0);
BUG_ON(!copied && !err);
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment