mm: do not call do_fault_around for non-linear fault

Ingo Korb reported that "repeated mapping of the same file on tmpfs
using remap_file_pages sometimes triggers a BUG at mm/filemap.c:202 when
the process exits".

He bisected the bug to d7c1755179b8 ("mm: implement ->map_pages for
shmem/tmpfs"), although the bug was actually added by commit
8c6e50b0290c ("mm: introduce vm_ops->map_pages()").

The problem is caused by calling do_fault_around for a _non-linear_
fault.  In this case pgoff is shifted and might become negative during

Faulting around non-linear page-fault makes no sense and breaks the
logic in do_fault_around because pgoff is shifted.

Signed-off-by: Konstantin Khlebnikov <>
Reported-by: Ingo Korb <>
Tested-by: Ingo Korb <>
Cc: Hugh Dickins <>
Cc: Sasha Levin <>
Cc: Dave Jones <>
Cc: Ning Qu <>
Cc: "Kirill A. Shutemov" <>
Cc: <>	[3.15.x]
Signed-off-by: Andrew Morton <>
Signed-off-by: Linus Torvalds <>
1 file changed