]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
mm/huge_memory: drop beyond-EOF folios with the right number of refs
authorZi Yan <ziy@nvidia.com>
Mon, 10 Mar 2025 15:57:27 +0000 (11:57 -0400)
committerAndrew Morton <akpm@linux-foundation.org>
Mon, 17 Mar 2025 00:40:25 +0000 (17:40 -0700)
When an after-split folio is large and needs to be dropped due to EOF,
folio_put_refs(folio, folio_nr_pages(folio)) should be used to drop all
page cache refs.  Otherwise, the folio will not be freed, causing memory
leak.

This leak would happen on a filesystem with blocksize > page_size and a
truncate is performed, where the blocksize makes folios split to >0 order
ones, causing truncated folios not being freed.

Link: https://lkml.kernel.org/r/20250310155727.472846-1-ziy@nvidia.com
Fixes: c010d47f107f ("mm: thp: split huge page to any lower order pages")
Signed-off-by: Zi Yan <ziy@nvidia.com>
Reported-by: Hugh Dickins <hughd@google.com>
Closes: https://lore.kernel.org/all/fcbadb7f-dd3e-21df-f9a7-2853b53183c4@google.com/
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: David Hildenbrand <david@redhat.com>
Cc: John Hubbard <jhubbard@nvidia.com>
Cc: Kefeng Wang <wangkefeng.wang@huawei.com>
Cc: Kirill A. Shuemov <kirill.shutemov@linux.intel.com>
Cc: Luis Chamberalin <mcgrof@kernel.org>
Cc: Matthew Wilcow (Oracle) <willy@infradead.org>
Cc: Miaohe Lin <linmiaohe@huawei.com>
Cc: Pankaj Raghav <p.raghav@samsung.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: Yu Zhao <yuzhao@google.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
mm/huge_memory.c

index 3d3ebdc002d59734755ddaf66489e93e12eee7df..373781b21e5ca5cb7eb7de6c0b3f7016ebb713ef 100644 (file)
@@ -3304,7 +3304,7 @@ static void __split_huge_page(struct page *page, struct list_head *list,
                                folio_account_cleaned(tail,
                                        inode_to_wb(folio->mapping->host));
                        __filemap_remove_folio(tail, NULL);
-                       folio_put(tail);
+                       folio_put_refs(tail, folio_nr_pages(tail));
                } else if (!folio_test_anon(folio)) {
                        __xa_store(&folio->mapping->i_pages, tail->index,
                                        tail, 0);