Date: Tue, 21 Apr 2026 15:47:06 +0000 From: Mark Johnston <markj@FreeBSD.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org Subject: git: 6c9dd7528350 - releng/13.5 - vm_fault: Reset m_needs_zeroing properly Message-ID: <69e79bfa.345bb.10fb0c33@gitrepo.freebsd.org>
index | next in thread | raw e-mail
The branch releng/13.5 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=6c9dd75283503091c202cda1606a539f65bda85f commit 6c9dd75283503091c202cda1606a539f65bda85f Author: Mark Johnston <markj@FreeBSD.org> AuthorDate: 2026-04-08 04:21:09 +0000 Commit: Mark Johnston <markj@FreeBSD.org> CommitDate: 2026-04-21 15:46:57 +0000 vm_fault: Reset m_needs_zeroing properly - When allocating a page, we should only consider the PG_ZERO flag when handling the top-level page. - Unconditionally reset the flag when restarting the fault handler. Previously, vm_fault_busy_sleep() would fail to reset it. Approved by: so Security: FreeBSD-EN-26:05.vm PR: 294039 Reviewed by: kib Tested by: Peter Much <pmc@citylink.dinoex.sub.org> MFC after: 3 days Fixes: cff67bc43df1 ("vm_fault: only rely on PG_ZERO when the page was newly allocated") Differential Revision: https://reviews.freebsd.org/D56234 (cherry picked from commit 04132e01004316ddd0e0cde6ef15b100b7b1844d) (cherry picked from commit 50f7b62f0862f764215cee98547d5b8c0979ec26) --- sys/vm/vm_fault.c | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/sys/vm/vm_fault.c b/sys/vm/vm_fault.c index 605f677aecd5..614cba69002e 100644 --- a/sys/vm/vm_fault.c +++ b/sys/vm/vm_fault.c @@ -242,8 +242,6 @@ unlock_vp(struct faultstate *fs) static void fault_deallocate(struct faultstate *fs) { - - fs->m_needs_zeroing = true; fault_page_release(&fs->m_cow); fault_page_release(&fs->m); vm_object_pip_wakeup(fs->object); @@ -1202,7 +1200,8 @@ vm_fault_allocate(struct faultstate *fs) vm_waitpfault(dset, vm_pfault_oom_wait * hz); return (FAULT_RESTART); } - fs->m_needs_zeroing = (fs->m->flags & PG_ZERO) == 0; + if (fs->object == fs->first_object) + fs->m_needs_zeroing = (fs->m->flags & PG_ZERO) == 0; fs->oom_started = false; return (FAULT_CONTINUE); @@ -1462,7 +1461,6 @@ vm_fault(vm_map_t map, vm_offset_t vaddr, vm_prot_t fault_type, fs.fault_flags = fault_flags; fs.map = map; fs.lookup_still_valid = false; - fs.m_needs_zeroing = true; fs.oom_started = false; fs.nera = -1; faultcount = 0; @@ -1470,6 +1468,7 @@ vm_fault(vm_map_t map, vm_offset_t vaddr, vm_prot_t fault_type, RetryFault: fs.fault_type = fault_type; + fs.m_needs_zeroing = true; /* * Find the backing store object and offset into it to begin thehome | help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?69e79bfa.345bb.10fb0c33>
