From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 639BF4322E5 for ; Wed, 5 Aug 2026 11:33:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.21 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785929628; cv=none; b=DydW8LR/y+A5/+JPAdzzeMkKq/20P/S1A9xyQYJIGmAbV381tkkE7rWWcqTcNCCKLffRoxZLmP2fRtc8zP7/ghsDo0JYS3AEtpNVKy6nLhrHhl9NTQy6LetUKnhiwuGIGExK781lzprykerCQf2y5K996k0G8WU1ok//cTr8PYw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785929628; c=relaxed/simple; bh=XFroAvYH17C1kIbfMY9Te9f7dnenPbxnYxawMiiS4nk=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version:Content-Type; b=OLQ6oahhjF1mL35jG+gjBlMK6bPLwlOYJlcTHNh1MrfeKugc1yq0Rwhcw6rVnl89m7Uwvb0TUTCNXeXW9vKeIIAsezSwXnoA32NoN2kX92WDUwGJgWNeMTuBTIrWvVpD2EbwfQynrSsvgeqtIouPvRiDEat92KVXL4EmyMxl3L8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=XLSGcQfJ; arc=none smtp.client-ip=198.175.65.21 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="XLSGcQfJ" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785929626; x=1817465626; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=XFroAvYH17C1kIbfMY9Te9f7dnenPbxnYxawMiiS4nk=; b=XLSGcQfJdfK7RKRyYq8YLA2rkaICX9eFRyszMHsLu48u8Rhg6lFkZe93 /B2KLvKKWZiETDsAkDqLT6TYp6e5xTZHUUNpGRkG0cVr0X8CnNCRk5QBd U/HfcTkoo2eVZEe0B3W7/d4IAxbUltrCb1v3h7fyIciTKYscTF9Oqd1/x hKP4pOiFjhztH9HoRvQAgmMi6pRfb3n7ZhyVGwdeDCsaBVGwXxb8d1SVW tbLEqT22chMsw9+uxoAOuivm4JhA7lENhuo8j8YDue6yJf1LZTMBmMVbu keyQMc5qejswldn++na86vZQWgeQB/CwPArxCUmqFiIUZ4mBOVBCBHx/F g==; X-CSE-ConnectionGUID: aSbp6VnjSSmD6SG/RZAMfQ== X-CSE-MsgGUID: PNE3smEsQxyneWfotasRPA== X-IronPort-AV: E=McAfee;i="6800,10657,11865"; a="86358151" X-IronPort-AV: E=Sophos;i="6.25,206,1779174000"; d="scan'208";a="86358151" Received: from orviesa003.jf.intel.com ([10.64.159.143]) by orvoesa113.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 05 Aug 2026 04:33:44 -0700 X-CSE-ConnectionGUID: yffXgL7qQ8GKqJjwPIMxtg== X-CSE-MsgGUID: WKTCoPiMSbiE5AxVR+5rQA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,206,1779174000"; d="scan'208";a="265289741" Received: from gsse-cloud1.jf.intel.com ([10.54.39.91]) by ORVIESA003-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 05 Aug 2026 04:33:44 -0700 From: Matthew Brost To: intel-xe@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org Cc: Andrew Morton , David Hildenbrand , Lorenzo Stoakes , Zi Yan , Baolin Wang , "Liam R . Howlett" , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Lance Yang , Usama Arif , Joshua Hahn , Rakie Kim , Byungchul Park , Gregory Price , Ying Huang , Alistair Popple , Balbir Singh , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , =?UTF-8?q?Thomas=20Hellstr=C3=B6m?= , Francois Dugast Subject: [PATCH 0/4] Fix device page migration in low memory fallback Date: Wed, 5 Aug 2026 04:33:34 -0700 Message-Id: <20260805113338.3742178-1-matthew.brost@intel.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit LLMs made my breakfast, lunch, and dinner. Not really. They served as an assistive tool while I performed the debugging, testing, and analysis needed to isolate the root cause in core MM while fixing a known DRM SVM issue involving THP allocation failures in the CPU fault-to-device page migration path. When a CPU faults on a device private PMD and the driver cannot allocate a compound destination folio, the source THP has to be split. That path is broken: the CPU fault reference makes the split always fail, and it demotes the PMD only in the faulting VMA, leaving any other VMA mapping the folio pointing a huge PMD at an order-0 page. The latter is memory corruption, previously masked by the former. The DRM side had its own problems in the same fallback: there was no order-0 fallback at all despite a TODO saying one was needed, the error path computed folio_order() after put_page(), and once the destination is demoted to order-0 the source page array has to be populated per page rather than per folio head, or the copy stops after one page. Validation was performed using xe_exec_system_allocator. The issue was initially discovered on systems configured with an artificially constrained memory footprint (mem=8G), where failures occurred intermittently. Error injection was then introduced to reliably reproduce the failure condition, enabling thorough validation of the fix. Results were confirmed through pass/fail A/B testing. Matt Cc: Andrew Morton Cc: David Hildenbrand Cc: Lorenzo Stoakes Cc: Zi Yan Cc: Baolin Wang Cc: Liam R. Howlett Cc: Nico Pache Cc: Ryan Roberts Cc: Dev Jain Cc: Barry Song Cc: Lance Yang Cc: Usama Arif Cc: Joshua Hahn Cc: Rakie Kim Cc: Byungchul Park Cc: Gregory Price Cc: Ying Huang Cc: Alistair Popple Cc: Balbir Singh Cc: Maarten Lankhorst Cc: Maxime Ripard Cc: Thomas Zimmermann Cc: David Airlie Cc: Simona Vetter Cc: Thomas Hellström Cc: Francois Dugast Cc: dri-devel@lists.freedesktop.org Cc: linux-mm@kvack.org Cc: linux-kernel@vger.kernel.org Assisted-by: GitHub Copilot:claude-opus-5 Signed-off-by: Matthew Brost Matthew Brost (4): mm/migrate_device: Fix THP splitting of a CPU faulted device private folio mm/migrate_device: Apply the fault reference to the correct folio drm/pagemap: Fix folio allocation fallback and use-after-put drm/pagemap: Add fault injection for higher-order RAM folio allocation drivers/gpu/drm/drm_pagemap.c | 150 ++++++++++++++++++++++++++++------ mm/migrate_device.c | 120 +++++++++++++++++++++++---- 2 files changed, 230 insertions(+), 40 deletions(-) -- 2.34.1