From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 17C3D24A076 for ; Thu, 25 Jun 2026 15:51:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782402717; cv=none; b=og4BbVG7amxnEAe40GjdkFOMFCj668K895H+lmjpJxGNJ1fpuwauWrwSXM30jm9qd1M43sLeSsMJ5mYZ/aa0HvDa4NUjwj1PW7qanaArZ87dVKJ9XxEjze+M8S9qfL6iVdIgwotj5YQgEIA08T41n/vS8pi6FQbsUmynQh2RRg0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782402717; c=relaxed/simple; bh=Khk+EgWMgrd/fcIfSlawiG1GabII3LIvD1WbEgg6eN8=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=OzZXeZJtl7bDqmlv66inOCnuPnjAU0B2QuTKYp3FJMD+MIXZP0Rf+ALlriV3EghKu7RdzlpoUZr8tL9yQZjMsve5Xd3bDtEC/TaajOQHYkxzymXTRUDDb4SlLMk9w3cCFiH2xehBBhBuzjuaMXyIVhbyBbB/PhQRiuqpBWpB2Rk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=bgA0McvA; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=ieTXTgWV; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="bgA0McvA"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="ieTXTgWV" Received: from pps.filterd (m0279870.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 65PFe9fr2801479 for ; Thu, 25 Jun 2026 15:51:55 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= XaN+L0rplw4GK7Sfc4WHtZLm/QYscT75GFb5hPkpKto=; b=bgA0McvAmFJLtIls L/buW7JAYI9PfSDopgUvteWZRgcR/N5FKzN6CPAn6aoklfg7vNbD2F+czjeGAs57 duWQR7LM7mcfYrf9JKD7zLe8tmWfxQ9VikSWevJw4AvvfH5mvk2THdpe0C69sYT0 Wl2gmeVXHjw9r3gfyGpxtj/pO0kPIeZoTOZYezeZD62kVgmtytVHnUiF+l42iYep +LRMNrJbJJjw5iUu+qyCDDDg3PbqF/1ielieE3RZJmZhPZiD9WltuWyumNhtYAT1 fHnupap2l1GOf3hIJb4U/Ru7rY2Wacqc9tEfnb7S45bi9ehRNBvJ11PMBz6+6thl GrPamQ== Received: from mail-dl1-f69.google.com (mail-dl1-f69.google.com [74.125.82.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4f0uhmjyxr-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Thu, 25 Jun 2026 15:51:54 +0000 (GMT) Received: by mail-dl1-f69.google.com with SMTP id a92af1059eb24-138156c0492so42386c88.1 for ; Thu, 25 Jun 2026 08:51:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1782402714; x=1783007514; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=XaN+L0rplw4GK7Sfc4WHtZLm/QYscT75GFb5hPkpKto=; b=ieTXTgWVWfzmWyyeBCVwNyYDdS6zQF3Vi5+R4axRPG6CF2tJ41q62JndBcVDxgOEZC mcSjTpNYbqNs/D/5mLcPIKl+kqhDduWJg2Q4UG4CpVLbSLil2hJv433TnREOjepdSt3+ M8Y+Mr9+JgSScHu8Pmig/f+AilKGxPpQDq0BUtLGPFW0mBNZ8W4R6yYH/PtOdT10RWBk 2GPW8mLjwmA4YphryRPhPoX2Sk/dmG0CLncRl1PLaKF8TGXnkSWcnRnvq1+E2N330zWy cRHpo9EPJlQtc3oCrORwnWvAtyWS0FQFsYapr+wlwGo/RGwLZzIhhFejg0objAA+leF9 YTSA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782402714; x=1783007514; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=XaN+L0rplw4GK7Sfc4WHtZLm/QYscT75GFb5hPkpKto=; b=BRcRQYevA2nANh8QimbZ8gBBj2I2RvcMb5nkNhFMDKdnmYZSPJk+F2EuvWzPO2yprV ulWUlXnpzcu7JpDgv9vR5yTj4FTQ4HkQ5BYSm7YmaIPd4EzNTi9JQn2lx7XSBnQ76e1h felPxfNLbFPM1sR5RSC3DOKjAUNLm1OvVbbGvR/9xFUxHQUwR7Ezx0XBVV/VFRBojFnz Jy9ctDJjdsnb+6tmaQ7+mE522n8xH7HiG5i36HqN9jhlAxYjL5P2Tl+tTtCwSOn05RyJ Sotdrt66DhBTVcWfSSCw43dYqKICa4/+i6r7qzu9nQcrEztAauzaFQHjYf8c70+yA6AE ZSrw== X-Gm-Message-State: AOJu0YxpglmgTX/eeusSWUDIMFk+eOo3C7sQd3oDHXCUWB2UbLCBO0oT 91GveJIOaJVI4Ny5iGkESaSYjWSYfWePYrc7Rr5YZaphsqq8MoC4erjQUTG0/ikEiuRCqDmdYMI NbqQAxBYhPFH7WAyp1kzMNk3HSR4vyih4SXwKWHshrLm8p/vcQZzRyHxdbi8FxVVaaBo= X-Gm-Gg: AfdE7ckR2LBlc9vGJheitS/X/atUiP44BkETKeuHECB7x6D4lWzieezlB/+UnEgH2S0 ZpsSaBVar+gSxLj6RIjuOTQOrIC0Kqmuoz/X+VV6+49rREYeENJH8yFBdsCLqHKl/UJZsxkQOKW xHpP7O4lVRqqGDgbFIu3z+KoRqxtk7ApI95LRj+ivNvTPyc2sFL9EVZdwxg0jkKtxeBvQCTSZp1 A/oG7me7kg7cHCQm0sTZ5wNHm54XxgUJyQC00UtaT8mYy7fKcrzb24+3l26AsZILcD19grySYet ZujrGdY5ZSu64vad/dLXG+SuhymNCl7egODgZraoi0uWdMoyBuzWfxjfogVQs84RSDBa3XbnPsL /zrejEs5boEFUPiXHgScnXf1BnGhCToA+m7ew9dmqvqcknjDE0FcbsrLM/O2q X-Received: by 2002:a05:7022:160c:b0:137:fec9:8ffb with SMTP id a92af1059eb24-139dbb69b90mr2427653c88.25.1782402713723; Thu, 25 Jun 2026 08:51:53 -0700 (PDT) X-Received: by 2002:a05:7022:160c:b0:137:fec9:8ffb with SMTP id a92af1059eb24-139dbb69b90mr2427626c88.25.1782402713025; Thu, 25 Jun 2026 08:51:53 -0700 (PDT) Received: from hu-ashoraj-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-139d8f77602sm8736337c88.8.2026.06.25.08.51.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 25 Jun 2026 08:51:52 -0700 (PDT) Date: Thu, 25 Jun 2026 08:51:50 -0700 From: Ashok Raj To: Rik van Riel Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com, robin.murphy@arm.com, joro@8bytes.org, will@kernel.org, iommu@lists.linux.dev, jgg@ziepe.ca, kyle@mcmartin.ca, ashok.raj@oss.qualcomm.com Subject: Re: [PATCH 3/3] iova: defer maple tree erase on GFP_ATOMIC failure Message-ID: References: <20260624030853.2340880-1-riel@surriel.com> <20260624030853.2340880-4-riel@surriel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20260624030853.2340880-4-riel@surriel.com> X-Authority-Analysis: v=2.4 cv=cqerVV4i c=1 sm=1 tr=0 ts=6a3d4e9a cx=c_pps a=kVLUcbK0zfr7ocalXnG1qA==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=FelO9ux0wxsA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=gowsoOTTUOVcmtlkKump:22 a=mOSHGkzkEfEHChMdZykA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=vr4QvYf-bLy2KjpDp97w:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjI1MDEzNiBTYWx0ZWRfX46sjLTrZ0btc /KNhf3xlUnX/w8QPEqyj4ZRY4xr9n1OkAomIY88/cKc2eLEvFr+t+QI5GBrVw0Z/UgjTfObewHO /Vr3es8P58RzkhJ/BXmnv/uEVENPq+VznSP7isn+pVccPUQ6iUVUQ0STZJBqs+lKKFjBr3J8ZUi 1ZvUk+JUzT4bQBHGlKNoYnScQ1oaQtjWc11o4vHeJ5RAQXAZZryfomwM+oQQJkkgoC9mp0ZIJEt C+T/Ienj5hcwPfyCDd/7CfzLhkLT3t/fsJbjEcqJCWZgT/DXJds2X7+EgtW0h3pRf+KqFcf7pxD JDLYD/kKzwhmYSLYTyQ0AitGrYkYb3pOQtlri6BLmEeDmJMYyNNEZcd3yTlXCdiN5kqIjXixel9 PS3u8EmlA6hImQ5A7O+GMb649a9AyaDBAPHAHfvJ3tiLgwfF9v20PnJ5Hi+Mp+/6H3JVvGGSzfi 1NMzX1E8i5j+JE9dnrg== X-Proofpoint-Spam-Info: AW1haW4tMjYwNjI1MDEzNiBTYWx0ZWRfX3EszvgR4b1Gd rqC+aXq4xOXLYV4iMpWVQgQa2kUdKttaLuGNAD0yOkJS7wOGynM6DR2pDMhs9gY6APK6EGJXJm7 RXs1lfa+yf55YtAjDZDWPnrQRovrMMI= X-Proofpoint-GUID: S4s2o72EeY0zP4xRGMk-p8xfgljuuFUy X-Proofpoint-ORIG-GUID: S4s2o72EeY0zP4xRGMk-p8xfgljuuFUy X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-25_02,2026-06-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 clxscore=1015 bulkscore=0 phishscore=0 priorityscore=1501 malwarescore=0 suspectscore=0 impostorscore=0 spamscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2606250136 On Tue, Jun 23, 2026 at 11:07:36PM -0400, Rik van Riel wrote: Hi Rik, Thanks for the v4 redesign — the in-place marker approach is much cleaner than the delayed_work/llist scheme from v3, and it directly addresses the retry-forever concern I raised earlier. [snip] > +/* > + * Remove an IOVA entry from the maple tree and free it. > + * > + * This runs in atomic context (DMA map/unmap can be called from hardirq, > + * softirq, or with spinlocks held) and must not fail. Erasing an entry can > + * require a maple tree node for rebalancing, and mas_store_gfp(NULL, > + * GFP_ATOMIC) can fail under memory pressure. When it does, overwrite the slot > + * in place with IOVA_DEFERRED -- an in-place store needs no node allocation and > + * so cannot fail -- which keeps the address range reserved (the allocator's gap > + * search treats the non-NULL slot as occupied) and lets the struct iova be > + * freed now. The marker is erased later by iova_drain_deferred(). > + */ > static void remove_iova(struct iova_domain *iovad, struct iova *iova) > { > - MA_STATE(mas, &iovad->mtree, iova->pfn_lo, iova->pfn_hi); > + unsigned long pfn_lo = iova->pfn_lo, pfn_hi = iova->pfn_hi; > + > + MA_STATE(mas, &iovad->mtree, pfn_lo, pfn_hi); > > assert_spin_locked(&iovad->iova_lock); > > - if (iova->pfn_lo < iovad->dma_32bit_pfn) > + if (pfn_lo < iovad->dma_32bit_pfn) > iovad->max32_alloc_size = iovad->dma_32bit_pfn; > > - mas_store_gfp(&mas, NULL, GFP_ATOMIC); > + if (iova_kunit_defer_erase || mas_store_gfp(&mas, NULL, GFP_ATOMIC)) { > + /* Erase failed: mark the slot in place and defer removal. */ > + mas_set_range(&mas, pfn_lo, pfn_hi); > + if (WARN_ON_ONCE(mas_store_gfp(&mas, IOVA_DEFERRED, GFP_ATOMIC))) > + return; /* in-place store cannot fail; entry stays put */ /* * <-- deferred_lo/hi not updated and range stays * occupied for ever? */ > + if (pfn_lo < iovad->deferred_lo) > + iovad->deferred_lo = pfn_lo; > + if (pfn_hi > iovad->deferred_hi) > + iovad->deferred_hi = pfn_hi; > + free_iova_mem(iova); <--- only reached if second store succeeds? > + return; > + } > + > + free_iova_mem(iova); > + > + /* A successful erase means memory is available; clear any backlog. */ > + if (unlikely(iova_has_deferred(iovad))) > + iova_drain_deferred(iovad); > } > If the in-place marker store fails and WARN_ON_ONCE fires: - free_iova_mem(iova) is never reached — the struct iova leaks. - deferred_lo/hi is not updated — the address range stays permanently occupied with no way to reclaim it. - After the first occurrence, WARN_ON_ONCE suppresses the warning on all subsequent hits, so further failures on this path are completely silent. I understand the comment says this cannot happen, and if that guarantee holds then it's fine. But if it can, a BUG_ON might be a cleaner way to express that invariant — it makes the intent unambiguous rather than leaving the impression the failure is being gracefully handled when it isn't. Happy to be wrong if I'm missing something about the maple tree's in-place store guarantees. Cheers, Ashok