From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Kees Cook <kees@kernel.org>
Cc: "Linus Torvalds" <torvalds@linux-foundation.org>,
"Nathan Chancellor" <nathan@kernel.org>,
"Nicolas Schier" <nsc@kernel.org>,
"Nick Desaulniers" <ndesaulniers@google.com>,
"Bill Wendling" <morbo@google.com>,
"Justin Stitt" <justinstitt@google.com>,
"Masahiro Yamada" <masahiroy@kernel.org>,
"Alexey Gladkov" <legion@kernel.org>,
"Thomas Gleixner" <tglx@kernel.org>,
"Ingo Molnar" <mingo@redhat.com>,
"Borislav Petkov" <bp@alien8.de>,
"Dave Hansen" <dave.hansen@linux.intel.com>,
x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
"Paul Walmsley" <pjw@kernel.org>,
"Palmer Dabbelt" <palmer@dabbelt.com>,
"Albert Ou" <aou@eecs.berkeley.edu>,
"Alexandre Ghiti" <alex@ghiti.fr>,
"Arnd Bergmann" <arnd@arndb.de>,
"Catalin Marinas" <catalin.marinas@arm.com>,
"Will Deacon" <will@kernel.org>,
"Mark Rutland" <mark.rutland@arm.com>,
"Ard Biesheuvel" <ardb@kernel.org>,
"Ilias Apalodimas" <ilias.apalodimas@linaro.org>,
"Josh Poimboeuf" <jpoimboe@kernel.org>,
"Peter Zijlstra" <peterz@infradead.org>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
"Tamir Duberstein" <tamird@kernel.org>,
"Alexandre Courbot" <acourbot@nvidia.com>,
"Onur Özkan" <work@onurozkan.dev>,
"Jonathan Corbet" <corbet@lwn.net>,
"Randy Dunlap" <rdunlap@infradead.org>,
"Gustavo A. R. Silva" <gustavoars@kernel.org>,
linux-kbuild@vger.kernel.org, linux-kernel@vger.kernel.org,
llvm@lists.linux.dev, linux-riscv@lists.infradead.org,
linux-arch@vger.kernel.org, linux-arm-kernel@lists.infradead.org,
linux-efi@vger.kernel.org, rust-for-linux@vger.kernel.org,
linux-doc@vger.kernel.org, "Jens Axboe" <axboe@kernel.dk>,
linux-hardening@vger.kernel.org
Subject: Re: [PATCH v2 21/21] kbuild: use pigz for gzip compression if available
Date: Tue, 15 Sep 2026 15:30:43 +0100 [thread overview]
Message-ID: <aqk9gakQhxToLnDI@gremlin> (raw)
In-Reply-To: <202609140844.FA7E848A@keescook>
On Mon, Sep 14, 2026 at 09:39:07AM -0700, Kees Cook wrote:
> On Mon, Sep 14, 2026 at 10:22:20AM +0100, Lorenzo Stoakes (ARM) wrote:
> > On a 128-core Threadripper, gzip -9 of a 36 MiB x86-64 vmlinux.bin takes
> > 1.6s, and with pigz it takes 0.09s, so the performance increase is
> > significant.
>
> Neat! I wanna go learn how pigz accomplishes this -- I thought the
> problem with gzip was a common lookup table. Anyway...
Yeah not sure on the details :)
>
> > --- a/Documentation/kbuild/reproducible-builds.rst
> > +++ b/Documentation/kbuild/reproducible-builds.rst
> > @@ -76,6 +76,22 @@ include generated files. You should ensure the source tree is
> > pristine by running ``make mrproper`` or ``git clean -d -f -x`` before
> > building a source package.
> >
> > +Compression tools
> > +-----------------
> > +
> > +The compressed kernel image, compressed modules and packages are produced
> > +using the program named by the make variable ``KGZIP`` (described in
> > +Documentation/kbuild/kbuild.rst).
> > +
> > +It defaults to ``pigz`` if installed (a parallel implementation of gzip),
> > +or ``gzip`` otherwise.
> > +
> > +The generated output between two invocations of identical builds with
> > +either of the default tools will be byte-for-byte equivalent.
> > +
> > +However, for reproducible builds, ensure the same tool is used on all build
> > +hosts, as different tools may generate different output from one another.
> > +
> > Module signing
> > --------------
> >
>
> This doc update seems totally unneeded? Having the same build tools for RB
> is already a known requirement. I don't think anything new is added here?
Ack that's fair enough, will drop the doc update.
>
> > diff --git a/Makefile b/Makefile
> > index 790ef23c5e8a..38c0cdc9f591 100644
> > --- a/Makefile
> > +++ b/Makefile
> > @@ -561,7 +561,7 @@ PERL = perl
> > PYTHON3 = python3
> > CHECK = sparse
> > BASH = bash
> > -KGZIP = gzip
> > +KGZIP := $(if $(shell command -v pigz 2>/dev/null),pigz,gzip)
>
> I think the more idiomatic way to do this is:
>
> KGZIP := $(call try-run,command -v pigz,pigz,gzip)
try-run is defined in scripts/Makefile.compiler which is only included ~200
lines after KGZIP is set.
That'll also set up and tear down a temp dir for a probe that doesn't need
that, so I think it's fine as it is.
>
> However, parallelism needs to be set. We can't let it eat all CPUs: it
> needs to respect the -j make option (and make its CPU reservation known
> to "make"), which we already have a solution for in
> scripts/jobserver-exec.
The only place where it's invoked is vmlinux.bin at the end of the serial
tail, where all the tokens would be free anyway.
So I don't think it really buys anything at all?
Using jobserver-exec would also put python3 and two wrapper scripts in
front of every gzip in the build including tar -I "$(KGZIP)" when packaging
and some arm and m68k scripts too.
(For the module zips it's already constrained to a single process.)
Overall I think it's less complexity and really no delta to just invoke it
as normal.
It's designed as drop-in so it makes sense to use it as that.
>
> However, I would actually argue that given such an improvement we should just
> make pigz explicitly required and not optional. It is packaged everywhere:
>
> │ Debian / Ubuntu │ ✅ │ pigz (main)
> │ Fedora │ ✅ │ pigz 2.8 (current)
> │ RHEL / CentOS / Rocky / Alma │ ✅ via EPEL │ pigz — not in base/AppStream
> │ openSUSE / SLE │ ✅ │ pigz
> │ Arch Linux │ ✅ │ pigz (extra)
> │ Alpine │ ✅ │ pigz
> │ Gentoo │ ✅ │ app-arch/pigz 2.8
>
> Only RHEL appears a little glitchy, but likely they would trivially move
> it to base since it's already packaged, but off in EPEL.
Definitely not something for this series, the fallback is one invocation of
command -v and I don't really want to break RHEL either :)
If, once this has landed, we want to go that way then it's simple enough
for us to change it.
>
> So, I would say that pigz would be best run as something like:
>
> KGZIP := $(PYTHON3) $(abs_srctree)/scripts/jobserver-exec $(abs_srctree)/scripts/parallel-pigz
>
> with scripts/parallel-pigz being something like:
>
> #!/bin/sh
> exec pigz -p ${PARALLELISM:-1} "$@"
>
> > --- a/scripts/Makefile.modinst
> > +++ b/scripts/Makefile.modinst
> > @@ -145,8 +145,10 @@ endif
> > #
> > # Compression
> > #
> > +# Modules are compressed in parallel by make itself, so keep the compressor
> > +# single-threaded when it is pigz.
> > quiet_cmd_gzip = GZIP $@
> > - cmd_gzip = $(KGZIP) -n -f $<
> > + cmd_gzip = $(KGZIP) $(if $(filter pigz,$(notdir $(firstword $(KGZIP)))),-p 1) -n -f $<
> > quiet_cmd_xz = XZ $@
>
> Then this could be:
>
> cmd_gzip = SINGLE_THREADED=1 $(KGZIP) -n -f $<
This is already achieved for the modinst case with a one-liner in any case.
>
> and we patch scripts/jobserver-exec:
>
> diff --git a/scripts/jobserver-exec b/scripts/jobserver-exec
> index 21b319e6c9a5..8b953148ee9f 100755
> --- a/scripts/jobserver-exec
> +++ b/scripts/jobserver-exec
> @@ -5,6 +5,7 @@
> Determines how many parallel tasks "make" is expecting, as it is
> not exposed via any special variables, reserves them all, runs a subprocess
> with PARALLELISM environment variable set, and releases the jobs back again.
> +If SINGLE_THREADED is set, nothing is reserved and PARALLELISM is 1.
>
> See:
> https://www.gnu.org/software/make/manual/html_node/POSIX-Jobserver.html#POSIX-Jobserver
> diff --git a/tools/lib/python/jobserver.py b/tools/lib/python/jobserver.py
> index 0b1ffdf9f7a3..fc38c5020b22 100755
> --- a/tools/lib/python/jobserver.py
> +++ b/tools/lib/python/jobserver.py
> @@ -29,6 +29,11 @@ $claim child to do the actual work.
> The end goal here is to keep the total number of build tasks under the
> limit established by the initial ``make -j$n_proc`` call.
>
> +Setting the ``SINGLE_THREADED`` environment variable skips the reservation
> +entirely and runs the command with ``PARALLELISM=1``. This is meant for callers
> +that run many short commands in parallel themselves, where each one should use
> +only the job slot it already holds.
> +
> See:
> https://www.gnu.org/software/make/manual/html_node/POSIX-Jobserver.html#POSIX-Jobserver
> """
> @@ -68,6 +73,13 @@ class JobserverExec:
> self.is_open = True # We only try once
> self.claim = None
> #
> + # SINGLE_THREADED asks for no reservation at all: the command runs
> + # with PARALLELISM=1, using only the slot its caller already holds.
> + #
> + if os.environ.get('SINGLE_THREADED'):
> + self.claim = 1
> + return
> + #
> # Check the make flags for "--jobserver=R,W"
> # Note that GNU Make has used --jobserver-fds and --jobserver-auth
> # so this handles all of them.
>
> --
> Kees Cook
--
Cheers, Lorenzo
next prev parent reply other threads:[~2026-09-15 14:30 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 9:21 [PATCH v2 00/21] kbuild: significantly speed up kernel builds Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 01/21] kbuild: do not allocate .modinfo in vmlinux Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 02/21] kallsyms: index symbols by token to speed up table compression Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 03/21] kallsyms: output binary data to speed output and kallsyms assembly Lorenzo Stoakes (ARM)
2026-09-14 20:16 ` Markus Elfring
2026-09-14 21:44 ` David Laight
2026-09-15 7:10 ` [v2 " Markus Elfring
2026-09-14 9:22 ` [PATCH v2 04/21] kbuild: do not sort nm output where the order is irrelevant Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 05/21] kbuild: only emit vmlinux relocations when required Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 06/21] elf-parse: add section flags, symbol binding and a read-only mapping Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 07/21] kallsyms: reimplement mksysmap in C Lorenzo Stoakes (ARM)
2026-09-14 16:33 ` Markus Elfring
2026-09-14 16:54 ` Markus Elfring
2026-09-14 17:01 ` Markus Elfring
2026-09-14 9:22 ` [PATCH v2 08/21] kbuild: cache list, composite object state per object Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 09/21] kbuild: implement and use depcheck to check dependency timestamps Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 10/21] kbuild: move the toolchain checks into init/Kconfig.toolchain Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 11/21] kbuild: avoid re-running compiler and linker probes Lorenzo Stoakes (ARM)
2026-09-14 15:02 ` John Stoffel
2026-09-14 15:24 ` Lorenzo Stoakes (ARM)
2026-09-15 11:01 ` Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 12/21] modpost: cache section relocation mismatch state Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 13/21] modpost: emit module descriptors as assembly Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 14/21] kbuild: batch module finalisation Lorenzo Stoakes (ARM)
2026-09-14 18:00 ` Kees Cook
2026-09-15 10:44 ` Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 15/21] objtool: cache relocations, do less work Lorenzo Stoakes (ARM)
2026-09-14 19:44 ` Josh Poimboeuf
2026-09-14 20:06 ` Linus Torvalds
2026-09-14 22:23 ` Josh Poimboeuf
2026-09-14 22:30 ` Linus Torvalds
2026-09-15 12:24 ` Lorenzo Stoakes (ARM)
2026-09-15 12:19 ` Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 16/21] objtool: size the instruction hash to the text Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 17/21] objtool: decode instructions and resolve branch targets in parallel Lorenzo Stoakes (ARM)
2026-09-14 18:20 ` Kees Cook
2026-09-15 10:09 ` Lorenzo Stoakes (ARM)
2026-09-15 11:29 ` David Laight
2026-09-14 9:22 ` [PATCH v2 18/21] kbuild: rust: optionally parallelise rustc front end Lorenzo Stoakes (ARM)
2026-09-14 18:32 ` Kees Cook
2026-09-15 11:09 ` Lorenzo Stoakes (ARM)
2026-09-15 11:16 ` Lorenzo Stoakes (ARM)
2026-09-15 6:32 ` Miguel Ojeda
2026-09-15 11:15 ` Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 19/21] rust: make exports.o depend on the headers generated for it Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 20/21] kbuild: build rust crates in parallel with the rest of the build Lorenzo Stoakes (ARM)
2026-09-14 18:37 ` Kees Cook
2026-09-15 11:58 ` Lorenzo Stoakes (ARM)
2026-09-14 9:22 ` [PATCH v2 21/21] kbuild: use pigz for gzip compression if available Lorenzo Stoakes (ARM)
2026-09-14 16:39 ` Kees Cook
2026-09-14 16:49 ` H. Peter Anvin
2026-09-14 17:50 ` Kees Cook
2026-09-15 14:30 ` Lorenzo Stoakes (ARM) [this message]
2026-09-14 15:41 ` [PATCH v2 00/21] kbuild: significantly speed up kernel builds Kees Cook
2026-09-14 15:53 ` Linus Torvalds
2026-09-15 8:53 ` Arnd Bergmann
2026-09-15 11:35 ` Lorenzo Stoakes (ARM)
2026-09-14 18:25 ` Lorenzo Stoakes (ARM)
2026-09-14 18:43 ` Kees Cook
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqk9gakQhxToLnDI@gremlin \
--to=ljs@kernel.org \
--cc=a.hindborg@kernel.org \
--cc=acourbot@nvidia.com \
--cc=alex@ghiti.fr \
--cc=aliceryhl@google.com \
--cc=aou@eecs.berkeley.edu \
--cc=ardb@kernel.org \
--cc=arnd@arndb.de \
--cc=axboe@kernel.dk \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=bp@alien8.de \
--cc=catalin.marinas@arm.com \
--cc=corbet@lwn.net \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=dave.hansen@linux.intel.com \
--cc=gary@garyguo.net \
--cc=gustavoars@kernel.org \
--cc=hpa@zytor.com \
--cc=ilias.apalodimas@linaro.org \
--cc=jpoimboe@kernel.org \
--cc=justinstitt@google.com \
--cc=kees@kernel.org \
--cc=legion@kernel.org \
--cc=linux-arch@vger.kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-hardening@vger.kernel.org \
--cc=linux-kbuild@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=llvm@lists.linux.dev \
--cc=lossin@kernel.org \
--cc=mark.rutland@arm.com \
--cc=masahiroy@kernel.org \
--cc=mingo@redhat.com \
--cc=morbo@google.com \
--cc=nathan@kernel.org \
--cc=ndesaulniers@google.com \
--cc=nsc@kernel.org \
--cc=ojeda@kernel.org \
--cc=palmer@dabbelt.com \
--cc=peterz@infradead.org \
--cc=pjw@kernel.org \
--cc=rdunlap@infradead.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=tamird@kernel.org \
--cc=tglx@kernel.org \
--cc=tmgross@umich.edu \
--cc=torvalds@linux-foundation.org \
--cc=will@kernel.org \
--cc=work@onurozkan.dev \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®