move_ptes() directly dereferences new_ptep when checking that the
destination slot is empty. new_ptep now points to hw_pte_t table storage,
while pte_none() consumes a logical pte_t value.

Read the destination entry through the standard ptep_get() accessor before
passing the logical value to pte_none().

Signed-off-by: Muhammad Usama Anjum <[email protected]>
---
 mm/mremap.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/mm/mremap.c b/mm/mremap.c
index d966ee8248b6b..ecb90ccee6fdd 100644
--- a/mm/mremap.c
+++ b/mm/mremap.c
@@ -264,7 +264,7 @@ static int move_ptes(struct pagetable_move_control *pmc,
 
        for (; old_addr < old_end; old_ptep += nr_ptes, old_addr += nr_ptes * 
PAGE_SIZE,
                new_ptep += nr_ptes, new_addr += nr_ptes * PAGE_SIZE) {
-               VM_WARN_ON_ONCE(!pte_none(*new_ptep));
+               VM_WARN_ON_ONCE(!pte_none(ptep_get(new_ptep)));
 
                nr_ptes = 1;
                max_nr_ptes = (old_end - old_addr) >> PAGE_SHIFT;
-- 
2.47.3


Reply via email to