From: "Kiryl Shutsemau (Meta)" <[email protected]>

PAGEMAP_SCAN reports an unpopulated PTE in a uffd-wp VMA as written, but
a range with no page table at all -- a PMD hole -- is skipped:
pagemap_scan_pte_hole() tests p->cur_vma_category, which never carries
PAGE_IS_WRITTEN, so the hole is neither reported nor (under
PM_SCAN_WP_MATCHING) armed.

In a uffd-wp VMA, WP_UNPOPULATED installs uffd-wp markers when protecting
a range, allocating page tables as needed, so an unpopulated slot is
treated as written -- see the pte_none() handling in
pagemap_page_category(). A missing marker therefore means the range was
zapped, e.g. via MADV_DONTNEED. This applies to anon and shmem VMAs.

An anonymous THP is write-protected in place as a huge PMD, so a
full-PMD MADV_DONTNEED clears it to pmd_none -- a hole with no page table
-- and pagemap_scan_pte_hole() misses it. For a MAP_PRIVATE|MAP_ANON
mapping MADV_DONTNEED has fill-with-zeros semantics, so a write-tracking
checkpoint/migration tool (e.g. CRIU) treats the range as unchanged and
keeps its previous contents; after restore or live migration the process
reads stale data instead of zeroes -- data corruption.

Report a hole in a non-hugetlb uffd-wp VMA as written, matching the
pte_none handling in pagemap_page_category(); the existing
PM_SCAN_WP_MATCHING path then arms it via uffd_wp_range().

hugetlb is excluded: pagemap_hugetlb_category() reports an empty hugetlb
entry (huge_pte_none) as not-written, unlike pagemap_page_category(),
which reports pte_none as written. pagemap_scan_pte_hole() fires for a
hugetlb slot only when it has no page table; keeping that not-written
matches how an allocated-but-empty hugetlb entry reads, so the hole and
the empty-entry cases agree within the VMA.

Reported-by: Sashiko AI review <[email protected]>
Closes: 
https://sashiko.dev/#/patchset/[email protected]
Fixes: 2bad466cc9d9 ("mm/uffd: UFFD_FEATURE_WP_UNPOPULATED")
Cc: Muhammad Usama Anjum <[email protected]>
Cc: Peter Xu <[email protected]>
Cc: [email protected]
Signed-off-by: Kiryl Shutsemau <[email protected]>
Assisted-by: Claude:claude-fable-5
---
 fs/proc/task_mmu.c | 20 ++++++++++++++++++--
 1 file changed, 18 insertions(+), 2 deletions(-)

diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
index d45c729ab6bb..229d1fc3d7f1 100644
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -3049,12 +3049,28 @@ static int pagemap_scan_pte_hole(unsigned long addr, 
unsigned long end,
 {
        struct pagemap_scan_private *p = walk->private;
        struct vm_area_struct *vma = walk->vma;
+       unsigned long categories;
        int ret, err;
 
-       if (!vma || !pagemap_scan_is_interesting_page(p->cur_vma_category, p))
+       if (!vma)
                return 0;
 
-       ret = pagemap_scan_output(p->cur_vma_category, p, addr, &end);
+       /*
+        * In a uffd-wp VMA an unpopulated range is treated as written:
+        * uffd-wp registration populates page tables and installs markers
+        * with WP_UNPOPULATED, so a missing marker means the range was
+        * zapped. See the pte_none() handling in pagemap_page_category().
+        *
+        * hugetlb differs, see pagemap_hugetlb_category().
+        */
+       categories = p->cur_vma_category;
+       if (userfaultfd_wp(vma) && !is_vm_hugetlb_page(vma))
+               categories |= PAGE_IS_WRITTEN;
+
+       if (!pagemap_scan_is_interesting_page(categories, p))
+               return 0;
+
+       ret = pagemap_scan_output(categories, p, addr, &end);
        if (addr == end)
                return ret;
 
-- 
2.54.0


Reply via email to