]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
mm/memfd_luo: report error when restoring a folio fails mid-loop
authorDavid Carlier <devnexen@gmail.com>
Wed, 15 Apr 2026 05:23:00 +0000 (06:23 +0100)
committerMike Rapoport (Microsoft) <rppt@kernel.org>
Tue, 28 Apr 2026 13:16:16 +0000 (16:16 +0300)
memfd_luo_retrieve_folios() initialises err to -EIO, but the per-iteration
calls to mem_cgroup_charge(), shmem_add_to_page_cache() and
shmem_inode_acct_blocks() reuse and overwrite err.  Once any iteration
completes successfully, err becomes zero.

If a later iteration's kho_restore_folio() returns NULL, the failure path
jumps to put_folios without resetting err, so the function returns 0.
The caller memfd_luo_retrieve() then takes the success path, sets
args->file and reports the restore as successful, leaving userspace with
a partially populated memfd and no indication that anything went wrong.

Set err to -EIO in the kho_restore_folio() failure branch so the error
is propagated to the caller.

Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Pratyush Yadav <pratyush@kernel.org>
Fixes: b3749f174d68 ("mm: memfd_luo: allow preserving memfd")
Link: https://patch.msgid.link/20260415052300.362539-1-devnexen@gmail.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
mm/memfd_luo.c

index b02b503c750df0d353bd85c84e6468b6ab41771f..35d1247281e0473de81e2fbb6f7a85f415b6ab44 100644 (file)
@@ -427,6 +427,7 @@ static int memfd_luo_retrieve_folios(struct file *file,
                if (!folio) {
                        pr_err("Unable to restore folio at physical address: %llx\n",
                               phys);
+                       err = -EIO;
                        goto put_folios;
                }
                index = pfolio->index;