blob: e68f78e4bcd4e232ff61f73171ae02aa399d52c7 [file] [log] [blame]
From 52bb606039471608d802756fd2c84cf9569526e1 Mon Sep 17 00:00:00 2001
From: David Hildenbrand <>
Date: Fri, 18 Oct 2019 20:20:05 -0700
Subject: [PATCH] hugetlbfs: don't access uninitialized memmaps in
commit f231fe4235e22e18d847e05cbe705deaca56580a upstream.
Uninitialized memmaps contain garbage and in the worst case trigger
kernel BUGs, especially with CONFIG_PAGE_POISONING. They should not get
Let's make sure that we only consider online memory (managed by the
buddy) that has initialized memmaps. ZONE_DEVICE is not applicable.
page_zone() will call page_to_nid(), which will trigger
VM_BUG_ON_PGFLAGS(PagePoisoned(page), page) with CONFIG_PAGE_POISONING
and CONFIG_DEBUG_VM_PGFLAGS when called on uninitialized memmaps. This
can be the case when an offline memory block (e.g., never onlined) is
spanned by a zone.
Note: As explained by Michal in [1], alloc_contig_range() will verify
the range. So it boils down to the wrong access in this function.
Fixes: f1dd2cd13c4b ("mm, memory_hotplug: do not associate hotadded memory to zones until online") [visible after d0dc12e86b319]
Signed-off-by: David Hildenbrand <>
Reported-by: Michal Hocko <>
Acked-by: Michal Hocko <>
Reviewed-by: Mike Kravetz <>
Cc: Anshuman Khandual <>
Cc: <> [4.13+]
Signed-off-by: Andrew Morton <>
Signed-off-by: Linus Torvalds <>
Signed-off-by: Paul Gortmaker <>
diff --git a/mm/hugetlb.c b/mm/hugetlb.c
index ede7e7f5d1ab..4c842adf14e0 100644
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -1084,11 +1084,10 @@ static bool pfn_range_valid_gigantic(struct zone *z,
struct page *page;
for (i = start_pfn; i < end_pfn; i++) {
- if (!pfn_valid(i))
+ page = pfn_to_online_page(i);
+ if (!page)
return false;
- page = pfn_to_page(i);
if (page_zone(page) != z)
return false;