On Sun, Aug 02, 2020 at 12:12:42PM -0700, Hugh Dickins wrote: > pmdp_collapse_flush() should be given the start address at which the huge > page is mapped, haddr: it was given addr, which at that point has been > used as a local variable, incremented to the end address of the extent. > > Found by source inspection while chasing a hugepage locking bug, which > I then could not explain by this. At first I thought this was very bad; > then saw that all of the page translations that were not flushed would > actually still point to the right pages afterwards, so harmless; then > realized that I know nothing of how different architectures and models > cache intermediate paging structures, so maybe it matters after all - > particularly since the page table concerned is immediately freed. > > Much easier to fix than to think about. > > Fixes: 27e1f8273113 ("khugepaged: enable collapse pmd for pte-mapped THP") > Signed-off-by: Hugh Dickins <hughd@xxxxxxxxxx> > Cc: stable@xxxxxxxxxxxxxxx # v5.4+ Acked-by: Kirill A. Shutemov <kirill.shutemov@xxxxxxxxxxxxxxx> -- Kirill A. Shutemov