From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3C6EBC531DE for ; Fri, 16 Aug 2024 18:11:32 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id CB6B28D00AA; Fri, 16 Aug 2024 14:11:31 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id C66D28D00A2; Fri, 16 Aug 2024 14:11:31 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id B2F508D00AA; Fri, 16 Aug 2024 14:11:31 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id 8EA8D8D00A2 for ; Fri, 16 Aug 2024 14:11:31 -0400 (EDT) Received: from smtpin06.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay06.hostedemail.com (Postfix) with ESMTP id 3B3A0A4E01 for ; Fri, 16 Aug 2024 18:11:31 +0000 (UTC) X-FDA: 82458901182.06.8B2AB04 Received: from mail-lj1-f171.google.com (mail-lj1-f171.google.com [209.85.208.171]) by imf08.hostedemail.com (Postfix) with ESMTP id 43C1F160025 for ; Fri, 16 Aug 2024 18:11:28 +0000 (UTC) Authentication-Results: imf08.hostedemail.com; dkim=pass header.d=gmail.com header.s=20230601 header.b="ZH/qnSUL"; spf=pass (imf08.hostedemail.com: domain of ryncsn@gmail.com designates 209.85.208.171 as permitted sender) smtp.mailfrom=ryncsn@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1723831875; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=XYiRVeFf0+5cqJUAvUWrQbRs5eoo0Qo6oQyij7v1Aw4=; b=7g4hQBLml936htvc1QBonaa3vK5CRMXGbV4GhrHoulrfWgCiyrXXhb1QU4YWQhp5P5SYic mSS0mF9PWY0SZNbncevy1fdBcoF986iv3swpKN0WJdCNjqMPML4t4MAqaE1BehoI6oH+v8 9Cu4rxPqBORGNujPJb9c38Cq7n6jo0g= ARC-Authentication-Results: i=1; imf08.hostedemail.com; dkim=pass header.d=gmail.com header.s=20230601 header.b="ZH/qnSUL"; spf=pass (imf08.hostedemail.com: domain of ryncsn@gmail.com designates 209.85.208.171 as permitted sender) smtp.mailfrom=ryncsn@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1723831875; a=rsa-sha256; cv=none; b=xIuCRJ/0L3/MdDW1Qt8gzsb1T9sv/lgDLmujXtfYp7aXEboh8CKKODDE6eJ9NK3EK8oulU sWQQj0HtpTCRsXnemXoLE874SonULOod95zjLJNnSA5FMjYM9T0EmikgAJRMVAJFN9vAbg DHCSZ5bMSQNro+RaUWwtF/LvwpcqO8c= Received: by mail-lj1-f171.google.com with SMTP id 38308e7fff4ca-2eeb1ba0468so32082221fa.0 for ; Fri, 16 Aug 2024 11:11:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1723831888; x=1724436688; darn=kvack.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=XYiRVeFf0+5cqJUAvUWrQbRs5eoo0Qo6oQyij7v1Aw4=; b=ZH/qnSULd+/vDJ3nRHt1illWWw32zjnEza6G0BLGMgQRhOYpqs8fjFBipBgDZDrGpL ANEuvpwfUHB8ZttPYsSnLfZ+9QhCsFOxYQEK0ZnXe9hweJIqginliJfr8//hutNlfj2n +MztZRSM3yaM92sNmV6kjbLEGm+HWM6oiOpVBOVVDDYjBJcLuGCw+9Grg+t/Shm2LpL7 EgJRdWrWLADtqS6A9moYhhHmDG5cxIJ2kWKckdsZelaF/lgH8AMfVX3vyhM3D2gkiF7W 7G69Xuun7LAcct3XhH/ePnrBr5CjGwQg5LNJBcJHZPyI2osGAOv7KBob5AOWAQ+UYZD4 LY/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1723831888; x=1724436688; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=XYiRVeFf0+5cqJUAvUWrQbRs5eoo0Qo6oQyij7v1Aw4=; b=V3O5qjCsbRQ0sP8pFY97k+k3IK6zQ9DShNbJqcb776pxOWf+56IRi6IAme/rQo1szm OE1K6AmZN3vT06aIm0f4QXA9cm2dk0YPe0+Te6npaYuaa/QRl0Y4UFgbycGyZvBOclCe yRsSk5Bj9Pd7klHnll//OwDo9Wf9FxY+Tykp1b2j9IBWa/ifqCG00QSBlpjoQDr1Ozz9 Os5zTSmdzOpEbneHNsW4lSDaHBnU76Y+sDTTkaRTxxcZgNviKFRkW0vsnNPtJhnWTrCw TELY3wsmMq3MnGp3ORZI9jgHFYNaFf6n/byQZSfpQ7IGdVDYllCFP4He4+/YuVEeZH2U zU0g== X-Forwarded-Encrypted: i=1; AJvYcCVkiwdHDuo9XEbs2e57LpPphBv6KGNSSSPbuPZXeGf2xqAnQ7Y8pPaKXzrh8YYKO8Pujz9iOrsZ6pFioO0ocjVOo6A= X-Gm-Message-State: AOJu0YwD+ViHGGweOqSJ17wyMB4uNwDZu1gJYBICc9ihoSp5uMEXcnnt 2RqiL/1vZI8e+3cLHyJDIez31wHmhOIsv6UwvWQAonrPcb2CTIBdeUcDGjvKsew3BNuYTK5h9Dr LDkKMEkBvDxZEXUXZnTKy2nnjcH8= X-Google-Smtp-Source: AGHT+IHvagy/jC4UfMJoAyZUldlTNcBtKV7+YnWUxpuC/1fJ84lKI1dCqwGI677whW9d6Dq+3j66FLsh3EaJ0bXebXw= X-Received: by 2002:a05:651c:114:b0:2f0:1a19:f3f3 with SMTP id 38308e7fff4ca-2f3be5ddea6mr24061851fa.33.1723831887063; Fri, 16 Aug 2024 11:11:27 -0700 (PDT) MIME-Version: 1.0 References: <20240813120328.1275952-1-usamaarif642@gmail.com> <20240813120328.1275952-2-usamaarif642@gmail.com> <403b7f3c-6e5b-4030-ab1c-3198f36e3f73@gmail.com> In-Reply-To: <403b7f3c-6e5b-4030-ab1c-3198f36e3f73@gmail.com> From: Kairui Song Date: Sat, 17 Aug 2024 02:11:10 +0800 Message-ID: Subject: Re: [PATCH v3 1/6] mm: free zapped tail pages when splitting isolated thp To: Usama Arif Cc: akpm@linux-foundation.org, linux-mm@kvack.org, hannes@cmpxchg.org, riel@surriel.com, shakeel.butt@linux.dev, roman.gushchin@linux.dev, yuzhao@google.com, david@redhat.com, baohua@kernel.org, ryan.roberts@arm.com, rppt@kernel.org, willy@infradead.org, cerasuolodomenico@gmail.com, corbet@lwn.net, linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, kernel-team@meta.com, Shuang Zhai Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspam-User: X-Stat-Signature: 7x9bingycpicu1hfidnn5sxbwj1a1pym X-Rspamd-Queue-Id: 43C1F160025 X-Rspamd-Server: rspam11 X-HE-Tag: 1723831888-22247 X-HE-Meta: U2FsdGVkX18QxKyq/6n/sFXeu9u/ykWQYPjZxzs0vSeqAqaBvr56fTo3dkkVszaQW5zD1qwLhWiK83DHlOC4YTYRqFhZX0ao8cl7vFsKfa/1qMQHf14MnfDZjRKuG4ETvkzvfS6K+pqHA7kOs/qitoraJl37T/6jeHmGlDJciS43wzveKiw7+HGr7yXvTYAKX6zsNQ8PhFy77giKqnIAJyQ/Ua7cx+gYjGgcqHE9lhZE1JK+SpIuE/euKgK6lzv5sPQn7cAHV4P3yhyJHLmU6Cdpw/4jUWEuOqjRW5kE4iSIZHQxU7SJ389cgshAcEdM50cHuEwXUnlOnLd6IYPfB9WsDezsrIU1ju2LdsgoK0t/zGmZdeqql4irpicqW69ZwH6Jb+lwFDQUK2kIcdCZ/7WzDRoWN6GhtRCQYDcFze992GMOaUnKIOKKt3qsFwO1AQQctBP+tWE4qhEr+KIS/J7b69R1z3owzCB0d/NMXQ4OS7K2sRUF4TC7fCsc4nfI5aDZWLA+/lr+1B6mGq492ahurwidtJETnWktl25aM/R78vrnhIzX+vDYsNqqZfWTnRoUJU75UxMSI4fwd2wtOl/Zw4HUiFcYI6Jvn8nlylTkWu34JcACiS7xyoqY2APnOpuI3Lox0quXjak8vxWzwMFEwAQZ8dJeDyFkWISPazETD+oCvI0Jd+ybDVCScojL61ceMZVaK/MCZWl+8rrB9UfjRDZKlK7f0Gnt97kv58jcmnNp0K44esqkwqE0kUFDrwfyZYS0VHBCcMDwfmTBYjxJqn54cd9WyqVsU2QQ0gRac/2KNuJzh7f6HqBYtBEjFiWfxBplpYdK8KAr9uku+Qtkhrad89slgC9dAKbpbWhpfrh/BblGnjc2LhSm/wYJzL71iAXuqwpqBL3W/duMTReA2bt2chqtPZMtqVm8leS4BJxUQLRD0un0wBSZLU9SFOzYcbfqQW+y+OnzJLe Qvxh8b+u Zlil+xdv6e8NE6OAsxF7CkWYgc2+MJ0UIsa46tHh63SurGe7cjWhWIxquk8rFcvWyESERffkZcTXrRwq20Czaip/cIF2uBm3DhKMSbsk1ZA/3Sh5Ungrmtne+pBbJvf4Ic0aE8bERJQ73FIpF9wzQuNCHOJHM+89PiqoVe4Vdgqi1l7CATA5F3azjWDp8dbkRPYCZeSmXKSW8NFu1rg56NNegFGY3RTk/ed7++hYQmgjE8sgmFLuXGZvuhdgZntMcxbxilXFho9Z15rHXSxeaKc+fgh25bNIdIc93O5hWRa6u+TW4jqQ5oWeJgZ/AYK1eU1S3sVApsrdRvtGwrDdI2565mgFtdp0GYJdfykcuqPf1FEQCOD7k/ESvmnP5Th/beGXcO0iu82kx/wbd1G2UA7/Alg== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Sat, Aug 17, 2024 at 1:03=E2=80=AFAM Usama Arif = wrote: > On 16/08/2024 17:55, Kairui Song wrote: > > On Fri, Aug 16, 2024 at 3:16=E2=80=AFAM Usama Arif wrote: > >> On 15/08/2024 19:47, Kairui Song wrote: > >>> On Tue, Aug 13, 2024 at 8:03=E2=80=AFPM Usama Arif wrote: > >>>> > >>>> From: Yu Zhao > >>>> > >>>> If a tail page has only two references left, one inherited from the > >>>> isolation of its head and the other from lru_add_page_tail() which w= e > >>>> are about to drop, it means this tail page was concurrently zapped. > >>>> Then we can safely free it and save page reclaim or migration the > >>>> trouble of trying it. > >>>> > >>>> Signed-off-by: Yu Zhao > >>>> Tested-by: Shuang Zhai > >>>> Signed-off-by: Usama Arif > >>>> Acked-by: Johannes Weiner > >>>> --- > >>>> mm/huge_memory.c | 27 +++++++++++++++++++++++++++ > >>>> 1 file changed, 27 insertions(+) > >>> > >>> Hi, Usama, Yu > >>> > >>> This commit is causing the kernel to panic very quickly with build > >>> kernel test on top of tmpfs with all mTHP enabled, the panic comes > >>> after: > >>> > >> > >> Hi, > >> > >> Thanks for pointing this out. It is a very silly bug I have introduced= going from v1 page version to the folio version of the patch in v3. > >> > >> Doing below over this patch will fix it: > >> > >> diff --git a/mm/huge_memory.c b/mm/huge_memory.c > >> index 907813102430..a6ca454e1168 100644 > >> --- a/mm/huge_memory.c > >> +++ b/mm/huge_memory.c > >> @@ -3183,7 +3183,7 @@ static void __split_huge_page(struct page *page,= struct list_head *list, > >> > >> folio_clear_active(new_folio); > >> folio_clear_unevictable(new_folio); > >> - if (!folio_batch_add(&free_folios, folio)) { > >> + if (!folio_batch_add(&free_folios, new_folio))= { > >> mem_cgroup_uncharge_folios(&free_folio= s); > >> free_unref_folios(&free_folios); > >> } > >> > >> > >> I will include it in the next revision. > >> > > > > Hi, > > > > After the fix, I'm still seeing below panic: > > [ 24.926629] list_del corruption. prev->next should be > > ffffea000491cf88, but was ffffea0006207708. (prev=3Dffffea000491cfc8) > > [ 24.930783] ------------[ cut here ]------------ > > [ 24.932519] kernel BUG at lib/list_debug.c:64! > > [ 24.934325] Oops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI > > [ 24.936339] CPU: 32 UID: 0 PID: 2112 Comm: gzip Not tainted > > 6.11.0-rc3.ptch+ #147 > > [ 24.938575] Hardware name: Red Hat KVM/RHEL-AV, BIOS 0.0.0 02/06/201= 5 > > [ 24.940680] RIP: 0010:__list_del_entry_valid_or_report+0xaa/0xc0 > > [ 24.942536] Code: 8c ff 0f 0b 48 89 fe 48 c7 c7 f8 9d 51 82 e8 9d > > 36 8c ff 0f 0b 48 89 d1 48 89 f2 48 89 fe 48 c7 c7 30 9e 51 82 e8 86 > > 36 8c ff <0f> 0b 48 c7 c7 80 9e 51 82 e8 78 36 8c ff 0f 0b 66 0f 1f 44 > > 00 00 > > [ 24.948418] RSP: 0018:ffffc90005c2b770 EFLAGS: 00010246 > > [ 24.949996] RAX: 000000000000006d RBX: ffffea000491cf88 RCX: 0000000= 000000000 > > [ 24.952293] RDX: 0000000000000000 RSI: ffff889ffee1c180 RDI: ffff889= ffee1c180 > > [ 24.954616] RBP: ffffea000491cf80 R08: 0000000000000000 R09: c000000= 0ffff7fff > > [ 24.956908] R10: 0000000000000001 R11: ffffc90005c2b5a8 R12: ffffc90= 005c2b954 > > [ 24.959253] R13: ffffc90005c2bbc0 R14: ffffc90005c2b7c0 R15: ffffc90= 005c2b940 > > [ 24.961410] FS: 00007fe5a235e740(0000) GS:ffff889ffee00000(0000) > > knlGS:0000000000000000 > > [ 24.963587] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > > [ 24.965112] CR2: 00007fe5a24ddcd0 CR3: 000000010cb40001 CR4: 0000000= 000770eb0 > > [ 24.967037] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000= 000000000 > > [ 24.968933] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000= 000000400 > > [ 24.970802] PKRU: 55555554 > > [ 24.971559] Call Trace: > > [ 24.972241] > > [ 24.972805] ? __die_body+0x1e/0x60 > > [ 24.973756] ? die+0x3c/0x60 > > [ 24.974450] ? do_trap+0xe8/0x110 > > [ 24.975235] ? __list_del_entry_valid_or_report+0xaa/0xc0 > > [ 24.976543] ? do_error_trap+0x65/0x80 > > [ 24.977542] ? __list_del_entry_valid_or_report+0xaa/0xc0 > > [ 24.978891] ? exc_invalid_op+0x50/0x70 > > [ 24.979870] ? __list_del_entry_valid_or_report+0xaa/0xc0 > > [ 24.981295] ? asm_exc_invalid_op+0x1a/0x20 > > [ 24.982389] ? __list_del_entry_valid_or_report+0xaa/0xc0 > > [ 24.983781] shrink_folio_list+0x39a/0x1200 > > [ 24.984898] shrink_inactive_list+0x1c0/0x420 > > [ 24.986082] shrink_lruvec+0x5db/0x780 > > [ 24.987078] shrink_node+0x243/0xb00 > > [ 24.988063] ? get_pfnblock_flags_mask.constprop.117+0x1d/0x50 > > [ 24.989622] do_try_to_free_pages+0xbd/0x4e0 > > [ 24.990732] try_to_free_mem_cgroup_pages+0x107/0x230 > > [ 24.992034] try_charge_memcg+0x184/0x5d0 > > [ 24.993145] obj_cgroup_charge_pages+0x38/0x110 > > [ 24.994326] __memcg_kmem_charge_page+0x8d/0xf0 > > [ 24.995531] __alloc_pages_noprof+0x278/0x360 > > [ 24.996712] alloc_pages_mpol_noprof+0xf0/0x230 > > [ 24.997896] pipe_write+0x2ad/0x5f0 > > [ 24.998837] ? __pfx_tick_nohz_handler+0x10/0x10 > > [ 25.000234] ? update_process_times+0x8c/0xa0 > > [ 25.001377] ? timerqueue_add+0x77/0x90 > > [ 25.002257] vfs_write+0x39b/0x420 > > [ 25.003083] ksys_write+0xbd/0xd0 > > [ 25.003950] do_syscall_64+0x47/0x110 > > [ 25.004917] entry_SYSCALL_64_after_hwframe+0x76/0x7e > > [ 25.006210] RIP: 0033:0x7fe5a246f784 > > [ 25.007149] Code: c7 00 16 00 00 00 b8 ff ff ff ff c3 66 2e 0f 1f > > 84 00 00 00 00 00 f3 0f 1e fa 80 3d c5 08 0e 00 00 74 13 b8 01 00 00 > > 00 0f 05 <48> 3d 00 f0 ff ff 77 54 c3 0f 1f 00 55 48 89 e5 48 83 ec 20 > > 48 89 > > [ 25.011961] RSP: 002b:00007ffdb0057b38 EFLAGS: 00000202 ORIG_RAX: > > 0000000000000001 > > [ 25.013946] RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007fe= 5a246f784 > > [ 25.015817] RDX: 0000000000008000 RSI: 0000558c0d311420 RDI: 0000000= 000000001 > > [ 25.017717] RBP: 00007ffdb0057b60 R08: 0000558c0d258c40 R09: 0000558= c0d311420 > > [ 25.019618] R10: 00007ffdb0057600 R11: 0000000000000202 R12: 0000000= 000008000 > > [ 25.021519] R13: 0000558c0d311420 R14: 0000000000000029 R15: 0000000= 000001f8d > > [ 25.023412] > > [ 25.023998] Modules linked in: > > [ 25.024900] ---[ end trace 0000000000000000 ]--- > > [ 25.026329] RIP: 0010:__list_del_entry_valid_or_report+0xaa/0xc0 > > [ 25.027885] Code: 8c ff 0f 0b 48 89 fe 48 c7 c7 f8 9d 51 82 e8 9d > > 36 8c ff 0f 0b 48 89 d1 48 89 f2 48 89 fe 48 c7 c7 30 9e 51 82 e8 86 > > 36 8c ff <0f> 0b 48 c7 c7 80 9e 51 82 e8 78 36 8c ff 0f 0b 66 0f 1f 44 > > 00 00 > > [ 25.032525] RSP: 0018:ffffc90005c2b770 EFLAGS: 00010246 > > [ 25.033892] RAX: 000000000000006d RBX: ffffea000491cf88 RCX: 0000000= 000000000 > > [ 25.035758] RDX: 0000000000000000 RSI: ffff889ffee1c180 RDI: ffff889= ffee1c180 > > [ 25.037661] RBP: ffffea000491cf80 R08: 0000000000000000 R09: c000000= 0ffff7fff > > [ 25.039543] R10: 0000000000000001 R11: ffffc90005c2b5a8 R12: ffffc90= 005c2b954 > > [ 25.041426] R13: ffffc90005c2bbc0 R14: ffffc90005c2b7c0 R15: ffffc90= 005c2b940 > > [ 25.043323] FS: 00007fe5a235e740(0000) GS:ffff889ffee00000(0000) > > knlGS:0000000000000000 > > [ 25.045478] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > > [ 25.047013] CR2: 00007fe5a24ddcd0 CR3: 000000010cb40001 CR4: 0000000= 000770eb0 > > [ 25.048935] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000= 000000000 > > [ 25.050858] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000= 000000400 > > [ 25.052881] PKRU: 55555554 > > [ 25.053634] Kernel panic - not syncing: Fatal exception > > [ 25.056902] Kernel Offset: disabled > > [ 25.057827] ---[ end Kernel panic - not syncing: Fatal exception ]--= - > > > > If I revert the fix and this patch, the panic is gone, let me know if > > I can help debug it. > > Yes, this is also needed to prevent race with shrink_folio: > > diff --git a/mm/huge_memory.c b/mm/huge_memory.c > index a6ca454e1168..75f5b059e804 100644 > --- a/mm/huge_memory.c > +++ b/mm/huge_memory.c > @@ -3183,6 +3183,7 @@ static void __split_huge_page(struct page *page, st= ruct list_head *list, > > folio_clear_active(new_folio); > folio_clear_unevictable(new_folio); > + list_del(&new_folio->lru); > if (!folio_batch_add(&free_folios, new_folio)) { > mem_cgroup_uncharge_folios(&free_folios); > free_unref_folios(&free_folios); > > > I have tested this so should be ok, but let me know otherwise. > > I will include this in the next revision I will send soon. > > Thanks. Thanks for the update, the panic problem is gone.