From 47f3cecd720f8f8d94ad2f206e3bfe3bc2d3d4e5 Mon Sep 17 00:00:00 2001 From: Yichong Chen Date: Tue, 21 Jul 2026 11:52:07 +0800 Subject: [PATCH] hugetlb: evaluate subpool free state while locked unlock_or_release_subpool() drops spool->lock before calling subpool_is_free(). However, subpool_is_free() reads fields that are updated under spool->lock, including count, used_hpages and rsv_hpages. Keep the free-state evaluation under the same lock that protects those fields. The reservation accounting and kfree() calls still happen after dropping spool->lock. Link: https://lore.kernel.org/20260721035207.1437935-1-chenyichong@uniontech.com Signed-off-by: Yichong Chen Reviewed-by: Joshua Hahn Reviewed-by: Jane Chu Cc: David Hildenbrand Cc: Muchun Song Cc: Oscar Salvador Signed-off-by: Andrew Morton --- mm/hugetlb.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/mm/hugetlb.c b/mm/hugetlb.c index 6daf831b14c5..79e5c3b3e850 100644 --- a/mm/hugetlb.c +++ b/mm/hugetlb.c @@ -141,12 +141,14 @@ static inline bool subpool_is_free(struct hugepage_subpool *spool) static inline void unlock_or_release_subpool(struct hugepage_subpool *spool, unsigned long irq_flags) { - spin_unlock_irqrestore(&spool->lock, irq_flags); + bool free_subpool = subpool_is_free(spool); /* If no pages are used, and no other handles to the subpool * remain, give up any reservations based on minimum size and * free the subpool */ - if (subpool_is_free(spool)) { + spin_unlock_irqrestore(&spool->lock, irq_flags); + + if (free_subpool) { if (spool->min_hpages != -1) hugetlb_acct_memory(spool->hstate, -spool->min_hpages);