From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f65.google.com (mail-wr1-f65.google.com [209.85.221.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A69A236B042 for ; Thu, 29 Jan 2026 22:49:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.65 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769726971; cv=none; b=SwlAof+B36Kh9NvF0G4esZD++S4LtO/8mQijAkEKtA0f7hfq28opDVzLDl8y+c9TPNrFMSuOWNpyXTuO7mpU5mjY1yu3wm24frYzGkQunR+D6Ylb090KIkTts3Y+2ZC6+FBuaRBrbu8P50CUPa9pR1rLiPx7Zu3aF25s/B27bkk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769726971; c=relaxed/simple; bh=0vN9vE+Xxz2aoRvKyShdy8kl+S0ypCq/XVsfcQDkNSY=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=cp4wmzFh12G6y8orfYi/DInY/vOvwSk3cxP4sjS3uOLXAxyf4OpPrucFmaQvFTV47AZSbouObCubDyRh1Mgp1GRmEUkfhQYxbfOa4UciB3kKYN6Cx2YjSl+A2l7p/3TFWGFFY4an3GvioylbLd2hwO0zYaY6iFHr+OiTgBT+hFQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=LKDYP9I+; arc=none smtp.client-ip=209.85.221.65 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="LKDYP9I+" Received: by mail-wr1-f65.google.com with SMTP id ffacd0b85a97d-430f2ee2f00so922183f8f.3 for ; Thu, 29 Jan 2026 14:49:29 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769726968; x=1770331768; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=MHnhQSU7iuKe1wvcKkKvWgrmHsO0QtdxT1/2Mr9iW+U=; b=LKDYP9I+sm065m/MPfN4jfp2GCp2N2AcAqK3AAgOlktJcYhztb6sYV+g/DejNUGXSb pI0tU8ZELGtl2vDqooj2Lr4oh6u38yuJkNVM6vwy7I6H2gwdVgVfr5LjdZy1crMuYqDt /QZPofQJiHf1ZupnnSYsLASWoRLsNzXUdi5tIbgoobsYQOlAcWgP7hWx3Gv9kTClnMgd xkwZxmwFSEcnb1SeB31ceCHkzStbdlk1RhQpvSAucb9pHE6hfK5w5Q5LimAXlA977jDn U7UnYoHYBwHA1QC7zwPFCRsYooffXW/2UtxutGf10yJxCHoDMQumYuJYhJE4ypK9o28G hIxg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769726968; x=1770331768; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=MHnhQSU7iuKe1wvcKkKvWgrmHsO0QtdxT1/2Mr9iW+U=; b=I8TBWqXEJBTUmblo7QhMZaRl80a1/VZrvw0LbcTuQ5/ddLBWKh0wuXzH8ktZeVtzH6 HVZRTyfnPK4WNN3gpDp73t+YE6nHvu/3aZPMIXl1wrZWpq5qMsYVdi2Rywz+xIt0iv43 OdYxgfT8Fqw065oWo+4Z8r03tSlly1SZUZTQ6IH4wkVLWlXRUbvhmvNRF/Xff3GbdzLZ ZdUuqcBQDsav2+MlM5BursNsnmPM+ywdWFiM18vUuSSeZkU0rIvz0IVN7QD+7COwTI8Q /jwsD0TdLT+1PLnXcaUX4x47tkRSZbePO1y0jq+IZceismg61J3HkiSFgi01+ify9cDN QwDg== X-Forwarded-Encrypted: i=1; AJvYcCVNuf+45W82CknwoSAod7cIm9MQNjw7AyKic3Zkpb5LR6cdY7YgnJAgxb29bxX4xhwmcmuFOeDKQUIkzRE=@vger.kernel.org X-Gm-Message-State: AOJu0YxXmlc4yrpYp3wHYMyecZBSTYQctAUBdToArmO/FyzR3ofzwpzB t75vBIst5EUpGP0sj7fU5Lm2qVfBdOrWEMaCav0uX+uYOoAHDbFFewpW X-Gm-Gg: AZuq6aJ567b1OHG0aR/ExkM05g2JRmvUxaHeiSb35EYlbVuT/j+JF7J/vpLGg3lUsMN w7Dr0jr2hOPp+dOsKGVdxTQQjwC7tUCxvTlcpROuTZ6s0bEaTgqwURt1taV9K+qK9s0Xf6xR+or Ju82uvK0/LPaJSSLmki/NyURJpGaL+wB2PcKrWvZccAkkW5sUdddF7GLdF3nGs2/yk7sJ2iCEWT kSQ3ozXEHupF6FLC0CBGs82xNMOSPIxvyspPD4dvVL9eH/OHstqVW6H3iPmgALh03oAvd+DUGQ0 7nrp7Zakhe2qn0RdqBRLcX0WBtKBL2Sllf/b0dBQXdXpXlC34PaPGSWZhpgtrfFLWLZln2ZgZUw AXqovl4lUk4wC8uh5Ycgrqqk5fRTaAfwVkCibketK4TagyobzmlQ09jP/REFTzGQpESnVBzMTRs +OhoamvEzd4gY3Vrfg5IsOD36yANXewirc687gIK8GoXByuccGsgQXoHaQD66x9HQ9e3aot+S6q zZ9HiytmkEcB8w= X-Received: by 2002:a05:6000:26c9:b0:435:9756:d4c4 with SMTP id ffacd0b85a97d-435f3a7bcd0mr1743299f8f.17.1769726967582; Thu, 29 Jan 2026 14:49:27 -0800 (PST) Received: from ?IPV6:2a02:6b6f:e752:5600:1cf6:3834:b349:c738? ([2a02:6b6f:e752:5600:1cf6:3834:b349:c738]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-435e1353ac2sm19060165f8f.38.2026.01.29.14.49.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 29 Jan 2026 14:49:26 -0800 (PST) Message-ID: Date: Thu, 29 Jan 2026 22:49:26 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] mm: khugepaged: fix NR_FILE_PAGES accounting in collapse_file() Content-Language: en-GB To: Shakeel Butt , Andrew Morton Cc: Johannes Weiner , Rik van Riel , Song Liu , Kiryl Shutsemau , David Hildenbrand , Lorenzo Stoakes , Zi Yan , Baolin Wang , "Liam R . Howlett" , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Lance Yang , Meta kernel team , linux-mm@kvack.org, cgroups@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260129184054.910897-1-shakeel.butt@linux.dev> From: Usama Arif In-Reply-To: <20260129184054.910897-1-shakeel.butt@linux.dev> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 29/01/2026 18:40, Shakeel Butt wrote: > In META's fleet, we are seeing high level cgroups with zero file memcg > stat but their descendants have non-zero file stat. This should not be > possible. On further inspection by looking at kernel data structures > though drgn, it was revealed that the high level cgroups have negative > file stat which was aggregated from their children. > > Another interesting point was that this specific issue start happening > more often as we started deploying thp-always more widely which > indicates some correlation between file memory and THPs and indeed it > was found that file memcg stat accounting is buggy in the collapse code > path from the start. > > When collapse_file() replaces small folios with a large THP, it fails to > properly update the NR_FILE_PAGES memcg stat for both the old folios > being freed and the new THP being added. It assumes the old and new > folios belong to the same cgroup. However this assumption breaks in > couple of scenarios: > > 1. Binary (executable) package downloader running in a different cgroup > than the actual job executing the downloaded package. > > 2. File shared and mapped by processes running in different cgroups. One > process read-in the file and the second process either through > madvise(COLLAPSE) or khugepaged on behalf of second process > collapsing the file. > > So, the current code has two bugs: > > 1. For non-shmem files, NR_FILE_PAGES is never incremented for the new > THP because nr_none is always 0 for non-shmem, and the stat update is > inside the "if (nr_none)" block. > > 2. When freeing old folios, NR_FILE_PAGES is never decremented because > folio->mapping is set to NULL directly without calling > filemap_unaccount_folio(). > > These bugs cause incorrect per-memcg accounting when the process > triggering the collapse (MADV_COLLAPSE or khugepaged) belongs to a > different memcg than the process that originally faulted in the pages: > > - Process A (memcg X) reads file, creating 512 small page cache folios > charged to memcg X (NR_FILE_PAGES += 512 for memcg X) > > - Process B (memcg Y) triggers collapse via MADV_COLLAPSE or khugepaged > scans B's mm. The new THP is charged to memcg Y. > > - Old folios freed: NR_FILE_PAGES not decremented (bug) > New THP added: NR_FILE_PAGES not incremented (bug) > > - Later, THP removed from page cache: NR_FILE_PAGES -= 512 for memcg Y > > Result: memcg X has +512 inflated pages, memcg Y has -512 (negative!) > > Fix this by: > 1. Always incrementing NR_FILE_PAGES by HPAGE_PMD_NR for the new THP > 2. Decrementing NR_FILE_PAGES for each old folio before clearing its > mapping pointer > > For shmem with holes (nr_none > 0), the net change is still +nr_none > since we decrement (HPAGE_PMD_NR - nr_none) old pages and increment > HPAGE_PMD_NR new pages. > > Fixes: 99cb0dbd47a1 ("mm,thp: add read-only THP support for (non-shmem) FS") > Signed-off-by: Shakeel Butt