From nobody Thu Oct 01 16:12:32 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hwcPr6CdRz6vC8R for ; Thu, 01 Oct 2026 16:12:32 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hwcPr4WHYz4Syx for ; Thu, 01 Oct 2026 16:12:32 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790871152; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=xcLhsxMqdjFpxIZvkkbGInd2z5fJ5kRdpy3PlODolYI=; b=yPVK/z8Km8QDFeF7bu2F72ICHLKohvDj6YLjgZG04k+ZqGWbDZrfY0f3emUvMahWOM7IGy s7/NyiZHJSsQCNYC7K7R4s84CKneyjLO7BFpYIRFLP5E/UGO5gXAl2py0BwNHsK79iR8jF c1wg1QNBmaVPafogTcxSIdFQIDRz80Sf1P37D43kk3ot1Mwrmnyc7pvW1onIdN55S6LjeG 0f1EpPzw+2nrydHco+M+aeB2gxx1vPzG3l0eIbj8ykv6KwxdDaQYxDeocbxIliFFt43w1E WyeSewlng1o7NlIztTfNlgigxQdTH8J8LUzFQuOJ/W6VDYEuBvAEp8mX/jeqWA== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790871152; b=XKpx//9x8s3WrF3LVkRXD1qdn8Kt5N4kQCC0CqVkFiRjj2BbNCfjdyAl6feGZpo6LWOVoU nfvFiBo9LPbVtGQ8/M66Ue4ImzGscFcBrnutHLUbS2ua+HCXSKqikEMHyIrQmtKCYuG+7b ucGUlj90vla9IoEneC2p2nxMVmOZNk9EWh5RnPg7xhrJk5NeoT1nEz6Z0kqoWF763HMGv7 Bj09OUBsfuZW6ZtjLG0AEIMqRJ+Gt7Mk0QrExDTDAPQgUBh+aFbfU6tjdQWBptSDx7pPQP 5HOLPPzAA0mvBim9eqRDAVC2EDm/6ssrTkMiSLM7Ccv4aoF/Dej5b0CzMjlpew== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790871152; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=xcLhsxMqdjFpxIZvkkbGInd2z5fJ5kRdpy3PlODolYI=; b=jDf7T4wJ7KyMYrYyVpGpxXtj0Dk0ljkr4aavq+CZXoB2bxKp9mNdySqVh3i+PfgBvK0tCH Sk9LTpVF9I2+h8g5gEcXNEJcvSoOg+8q3A59EyFcajkVL8BEqTfmNCUpTX7HZ2uzVBNnQK yD47K5cRKgqsIdV8pohMAalsucmTZNvv+TdweBT35/w7cYmshJSWrX77d9rfFZFQKWxIME XugO67cC0RVnbtPMp5yoWF/K3K/U+HlwDcAiyjPRIjAbsW1VCqSV2Uv+nXWVCceHZKIuq4 VneFM5r6HsbCHXZAblchdSPfZhnlwHm3NeoZW4ONmZQPAgfGt7zQ7zzfd+DSnw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hwcPr3ZX7zgcF for ; Thu, 01 Oct 2026 16:12:32 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3dfdf by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Thu, 01 Oct 2026 16:12:32 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: c3b8e0bb8b39 - stable/14 - vm_page: Fix the error path in vm_page_alloc_contig_domain() List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: c3b8e0bb8b3980c09204556f63a6fbdabe43a234 Auto-Submitted: auto-generated Date: Thu, 01 Oct 2026 16:12:32 +0000 Message-Id: <6abe8670.3dfdf.14cd263b@gitrepo.freebsd.org> The branch stable/14 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=c3b8e0bb8b3980c09204556f63a6fbdabe43a234 commit c3b8e0bb8b3980c09204556f63a6fbdabe43a234 Author: Mark Johnston AuthorDate: 2026-09-24 15:49:37 +0000 Commit: Mark Johnston CommitDate: 2026-10-01 13:42:38 +0000 vm_page: Fix the error path in vm_page_alloc_contig_domain() If we are inserting a run of pages into a VM object and fail at some point due to a memory allocation failure, we have to free all of the pages in the run. We do that by resetting some fields and calling vm_page_free_toq() on each page; this removes the page from the object and frees it back to the buddy allocator. If the page is supposed to be wired, we reset the reference count, but this was done incorrectly: the VPRC_OBJREF flag must be retained as the page still belongs to an object. Resetting it to zero will cause a panic in vm_page_free_prep(): vm_page_free_object_prep() will subtract VPRC_OBJREF from the refcount, causing underflow, and vm_page_free_prep() subsequently calls panic() if the refcount is non-zero. Reviewed by: alc, kib Fixes: fee2a2fa3983 ("Change synchonization rules for vm_page reference counting.") MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59908 (cherry picked from commit 742e58ddc989563f90a1d636cb29793641784ca1) --- sys/vm/vm_page.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sys/vm/vm_page.c b/sys/vm/vm_page.c index a3b929b19091..13f3a7157c40 100644 --- a/sys/vm/vm_page.c +++ b/sys/vm/vm_page.c @@ -2322,7 +2322,7 @@ vm_page_alloc_contig_domain(vm_object_t object, vm_pindex_t pindex, int domain, for (m = m_ret; m < &m_ret[npages]; m++) { if (m <= mpred && (req & VM_ALLOC_WIRED) != 0) - m->ref_count = 0; + m->ref_count = VPRC_OBJREF; m->oflags = VPO_UNMANAGED; m->busy_lock = VPB_UNBUSIED; /* Don't change PG_ZERO. */