From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mta0.migadu.com (out-55.mta0.migadu.com [91.218.175.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9EBAB1F94F for ; Sat, 10 Oct 2026 02:04:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.55 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791597871; cv=none; b=VG0VhqQOHPrrUUbg6/LiVO+ElGhCXl/NOdS7SZSsfhh2gAyU+D50EAEi3K6jye3tRZOTwh9oPlDmlOEkyakBPj7RO9Wf3d3Fjx2M9pJ1wQXLg++SxXyUbUHITKIHprE2UfwSEkXM0CYWMhj6kN+9SulwShi5VbC3dmYnAVsmSb4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791597871; c=relaxed/simple; bh=fbmxI+htNWm74+BKcQ7IgvVzWZQKZq0MmTX+riidlGQ=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=Vv059a1poSdelqZ71taENav/VgsnCZ93JdlrFGt7XODNMLKBIIPWNJwZG3XdiGDvRZLVx0B6FxC/ZVPkfKf9Z7PKT98xkFnbdhCnG0aZdLebqPDKlSie5pK9GNc9oKXSozO+bGxuBnZdaZ6+uTmY/LgV7UWE/aS5WN+XF4gAO4I= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=FKG/sy/l; arc=none smtp.client-ip=91.218.175.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="FKG/sy/l" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=fbmxI+htNWm74+BKcQ7IgvVzWZQKZq0MmTX+riidlGQ=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1791597866; v=1; x=1792202666; b=FKG/sy/lZB2dNFjWpqgvN5VwDtTKpSwOj/nsE1d6r01NeWdMc6w8rnJzau8xFdG/TGCoOII9 DQllyG/uRqaIj+wFyww4IJA4PfFs5r1VpUsSpSstZ1jqd32mSQHUYegl8gZTSRo3/70+ylrXmqw P07gDFF4Ig9MTVnDJrTQiGuc= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id 6dd7cb59ec794fa2; Sat, 10 Oct 2026 02:04:26 +0000 X-Mizu-Trace-ID: 6dd7cb59ec794fa2 X-Migadu-Flow: FLOW_OUT Message-ID: Date: Sat, 10 Oct 2026 10:04:12 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] mm/huge_memory: avoid transient none PMDs during lazyfree reclaim Content-Language: en-US To: Zi Yan , "David Hildenbrand (Arm)" Cc: Kyle Zeng , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrew Morton , Baolin Wang , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Usama Arif , Kiryl Shutsemau , stable@vger.kernel.org References: <20261009165214.40212-2-kylebot@openai.com> <8db35dc0-eb06-42e4-90f9-534522e810e1@kernel.org> <55765FF3-18D7-424C-984D-81C316F323E1@nvidia.com> <0ec81c65-fbf5-405f-948b-0fb1b2e083e8@linux.dev> From: Lance Yang In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 2026/10/10 09:56, Zi Yan wrote: > On Fri Oct 9, 2026 at 9:12 PM EDT, Lance Yang wrote: >> >> >> On 2026/10/10 04:44, David Hildenbrand (Arm) wrote: >>> On 10/9/26 22:27, Zi Yan wrote: >>>> On 9 Oct 2026, at 16:23, David Hildenbrand (Arm) wrote: >>>> >>>>> On 10/9/26 20:17, Zi Yan wrote: >>>>>> >>>>>> There are some gaps we need to close before getting this fix in: >>>>>> >>>>>> 1. GUP-fast cannot follow the invalidated PMD: riscv and LoongArch need >>>>>> pmd_access_permitted() that requires _PAGE_PRESENT; s390's >>>>>> pmdp_invalidate() needs a change. >>>>> >>>>> Ugh. We really need pmdp_invalidate() to have reasonable semantics. This whole >>>>> PMD locking is a mess :( >>>>> >>>>>> >>>>>> 2. sparc64's thp_pte_count can be imbalanced with this change (based on >>>>>> Lance's offlist feedback). >>>>> >>>>> Ack. >>>>> >>>>>> >>>>>> In addition, powerpc has a page table check issue similr to riscv, where riscv >>>>>> fixed it with commit 9f4a88b8d01a6. This is not related to this issue >>>>>> but discovered along with the investigation. >>>>> >>>>> Zi, do you have the capacity to take over this patch? >>>> >>>> Yes, I can take over it. My plan is to send a series including >>>> patches for 1 and this patch as is. powerpc fix can be a separate one. >>>> >>>> Best Regards, >>>> Yan, Zi >>> >>> If we need a quick stable fix we could temporarily disable the whole thing until >>> it is fixed, just a thought. >> >> +1 we could do that for now. A quick fix with minimal churn (correctness >> comes first). > > How about the patch below? unmap_huge_pmd_locked() and > __discard_anon_folio_pmd_locked() will be dead code to keep the patch > small. Later, with arch fixes, the function can be re-enabled. Looks good to me! Thanks for the quick fix! > > > From 2204b9d08530796847a586428b1f782b987d071c Mon Sep 17 00:00:00 2001 > From: Zi Yan > Date: Fri, 9 Oct 2026 21:28:10 -0400 > Subject: [PATCH] mm/rmap: don't discard lazyfree THPs at PMD level > > __discard_anon_folio_pmd_locked() clears a lazyfree THP PMD before it knows > whether the folio can be discarded, and restores it if the folio was > redirtied or has extra references. A concurrent munmap() or > MREMAP_DONTUNMAP skips the temporary none PMD and unlinks the VMA from its > anon_vma, so the folio stays mapped after the anon_vma is freed and a later > rmap walk uses the freed anon_vma. > > Using an invalidated PMD instead of a cleared one requires additional arch > code fixes. Instead, disable the PMD level discard of lazyfree THPs, as > before commit 735ecdfaf4e8 ("mm/vmscan: avoid split lazyfree THP during > shrink_folio_list()"). > > Fixes: 735ecdfaf4e8 ("mm/vmscan: avoid split lazyfree THP during shrink_folio_list()") > Reported-by: Kyle Zeng > Closes: https://lore.kernel.org/r/20261009165214.40212-2-kylebot@openai.com > Cc: stable@vger.kernel.org > Assisted-by: LLM > Signed-off-by: Zi Yan > --- Reviewed-by: Lance Yang > mm/rmap.c | 11 ----------- > 1 file changed, 11 deletions(-) > > diff --git a/mm/rmap.c b/mm/rmap.c > index 805db93fe0428..1131b76bbbc28 100644 > --- a/mm/rmap.c > +++ b/mm/rmap.c > @@ -2275,17 +2275,6 @@ static bool try_to_unmap_one(struct folio *folio, struct vm_area_struct *vma, > } > > if (!pvmw.pte) { > - if (folio_test_lazyfree(folio)) { > - if (unmap_huge_pmd_locked(vma, pvmw.address, pvmw.pmd, folio)) > - goto walk_done; > - /* > - * unmap_huge_pmd_locked has either already marked > - * the folio as swap-backed or decided to retain it > - * due to GUP or speculative references. > - */ > - goto walk_abort; > - } > - > if (flags & TTU_SPLIT_HUGE_PMD) { > /* > * We temporarily have to drop the PTL and