All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Kirill A. Shutemov" <kirill@shutemov.name>
To: Vlastimil Babka <vbabka@suse.cz>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>,
	Andrew Morton <akpm@linux-foundation.org>,
	Hugh Dickins <hughd@google.com>,
	Andrea Arcangeli <aarcange@redhat.com>,
	Dave Hansen <dave.hansen@intel.com>,
	Johannes Weiner <hannes@cmpxchg.org>,
	Michal Hocko <mhocko@suse.cz>,
	David Rientjes <rientjes@google.com>,
	"Aneesh Kumar K.V" <aneesh.kumar@linux.vnet.ibm.com>,
	linux-kernel@vger.kernel.org, linux-mm@kvack.org
Subject: Re: [PATCHv10 37/36, RFC] thp: allow mlocked THP again
Date: Mon, 14 Sep 2015 14:05:04 +0300	[thread overview]
Message-ID: <20150914110504.GB8293@node.dhcp.inet.fi> (raw)
In-Reply-To: <55F2D586.3040204@suse.cz>

On Fri, Sep 11, 2015 at 03:22:14PM +0200, Vlastimil Babka wrote:
> On 09/03/2015 05:16 PM, Kirill A. Shutemov wrote:
> >This patch brings back mlocked THP. Instead of forbidding mlocked pages
> >altogether, we just avoid mlocking PTE-mapped THPs and munlock THPs on
> >split_huge_pmd().
> >
> >This means PTE-mapped THPs will be on normal lru lists and will be
> >split under memory pressure by vmscan. After the split vmscan will
> >detect unevictable small pages and mlock them.
> 
> Yeah that sounds like a compromise that should work.
> 
> >This way we can void leaking mlocked pages into non-VM_LOCKED VMAs.
> 
>                  avoid
> 
> But mlocked page in non-mlocked VMA's is a normal thing for shared pages
> when only one of the sharing mm's did mlock(), right? So this description
> doesn't explain the whole issue. I admit I forgot the exact details already
> :(

Right. I'm as always bad on documentation.

Before THP refcounting rework, THP was not allowed to cross VMA boundary.
So, if we have THP and we split it, PG_mlocked can be safely transfered to
small pages.

With new THP refcounting and naive approach to mlocking we can end up with
this scenario:
 1. we have a mlocked THP, which belong to one VM_LOCKED VMA.
 2. the process does munlock() on the *part* of the THP:
      - the VMA is split into two, one of them VM_LOCKED;
      - huge PMD split into PTE table;
      - THP is still mlocked;
 3. split_huge_page():
      - it transfers PG_mlocked to *all* small pages regrardless if it
	blong to any VM_LOCKED VMA.

We probably could munlock() all small pages on split_huge_page(), but I
think we have accounting issue already on step two.

> >Not-Yet-Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
> >---
> >
> >I'm not yet 100% certain that this approch is correct. Review would be appriciated.
> >More testing is required.
> >
> >---
> >  mm/gup.c         |  6 ++++--
> >  mm/huge_memory.c | 33 +++++++++++++++++++++++-------
> >  mm/memory.c      |  3 +--
> >  mm/mlock.c       | 61 +++++++++++++++++++++++++++++++++++++-------------------
> >  4 files changed, 71 insertions(+), 32 deletions(-)
> >
> >diff --git a/mm/gup.c b/mm/gup.c
> >index 70d65e4015a4..e95b0cb6ed81 100644
> >--- a/mm/gup.c
> >+++ b/mm/gup.c
> >@@ -143,6 +143,10 @@ retry:
> >  		mark_page_accessed(page);
> >  	}
> >  	if ((flags & FOLL_MLOCK) && (vma->vm_flags & VM_LOCKED)) {
> >+		/* Do not mlock pte-mapped THP */
> >+		if (PageTransCompound(page))
> >+			goto out;
> >+
> >  		/*
> >  		 * The preliminary mapping check is mainly to avoid the
> >  		 * pointless overhead of lock_page on the ZERO_PAGE
> >@@ -920,8 +924,6 @@ long populate_vma_page_range(struct vm_area_struct *vma,
> >  	gup_flags = FOLL_TOUCH | FOLL_POPULATE | FOLL_MLOCK;
> >  	if (vma->vm_flags & VM_LOCKONFAULT)
> >  		gup_flags &= ~FOLL_POPULATE;
> >-	if (vma->vm_flags & VM_LOCKED)
> >-		gup_flags |= FOLL_SPLIT;
> >  	/*
> >  	 * We want to touch writable mappings with a write fault in order
> >  	 * to break COW, except for shared mappings because these don't COW
> >diff --git a/mm/huge_memory.c b/mm/huge_memory.c
> >index 2cc99f9096a8..d714de02473b 100644
> >--- a/mm/huge_memory.c
> >+++ b/mm/huge_memory.c
> >@@ -846,8 +846,6 @@ int do_huge_pmd_anonymous_page(struct mm_struct *mm, struct vm_area_struct *vma,
> >
> >  	if (haddr < vma->vm_start || haddr + HPAGE_PMD_SIZE > vma->vm_end)
> >  		return VM_FAULT_FALLBACK;
> >-	if (vma->vm_flags & VM_LOCKED)
> >-		return VM_FAULT_FALLBACK;
> >  	if (unlikely(anon_vma_prepare(vma)))
> >  		return VM_FAULT_OOM;
> >  	if (unlikely(khugepaged_enter(vma, vma->vm_flags)))
> >@@ -1316,7 +1314,16 @@ struct page *follow_trans_huge_pmd(struct vm_area_struct *vma,
> >  			update_mmu_cache_pmd(vma, addr, pmd);
> >  	}
> >  	if ((flags & FOLL_MLOCK) && (vma->vm_flags & VM_LOCKED)) {
> >-		if (page->mapping && trylock_page(page)) {
> >+		/*
> >+		 * We don't mlock() pte-mapped THPs. This way we can avoid
> >+		 * leaking mlocked pages into non-VM_LOCKED VMAs.
> >+		 * In most cases the pmd is the only mapping of the page: we
> >+		 * break COW for the mlock(). The only scenario when we have
> 
> I don't understand what's meant by "we break COW for the mlock()"?

mm/gup.c:

 880 long populate_vma_page_range(struct vm_area_struct *vma,                   
 881                 unsigned long start, unsigned long end, int *nonblocking)  
.....
 894         /*                                                                 
 895          * We want to touch writable mappings with a write fault in order  
 896          * to break COW, except for shared mappings because these don't COW
 897          * and we would not want to dirty them for nothing.                
 898          */                                                                
 899         if ((vma->vm_flags & (VM_WRITE | VM_SHARED)) == VM_WRITE)          
 900                 gup_flags |= FOLL_WRITE;                                   


> >+		 * the page shared here is if we mlocking read-only mapping
> >+		 * shared over fork(). We skip mlocking such pages.
> 
> Why do we skip them? There's no PTE mapping involved, just multiple PMD
> mappings? Why are those a problem?

We don't have a way to protect against parallel split_huge_pmd(). :(

-- 
 Kirill A. Shutemov

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>

WARNING: multiple messages have this Message-ID (diff)
From: "Kirill A. Shutemov" <kirill@shutemov.name>
To: Vlastimil Babka <vbabka@suse.cz>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>,
	Andrew Morton <akpm@linux-foundation.org>,
	Hugh Dickins <hughd@google.com>,
	Andrea Arcangeli <aarcange@redhat.com>,
	Dave Hansen <dave.hansen@intel.com>,
	Johannes Weiner <hannes@cmpxchg.org>,
	Michal Hocko <mhocko@suse.cz>,
	David Rientjes <rientjes@google.com>,
	"Aneesh Kumar K.V" <aneesh.kumar@linux.vnet.ibm.com>,
	linux-kernel@vger.kernel.org, linux-mm@kvack.org
Subject: Re: [PATCHv10 37/36, RFC] thp: allow mlocked THP again
Date: Mon, 14 Sep 2015 14:05:04 +0300	[thread overview]
Message-ID: <20150914110504.GB8293@node.dhcp.inet.fi> (raw)
In-Reply-To: <55F2D586.3040204@suse.cz>

On Fri, Sep 11, 2015 at 03:22:14PM +0200, Vlastimil Babka wrote:
> On 09/03/2015 05:16 PM, Kirill A. Shutemov wrote:
> >This patch brings back mlocked THP. Instead of forbidding mlocked pages
> >altogether, we just avoid mlocking PTE-mapped THPs and munlock THPs on
> >split_huge_pmd().
> >
> >This means PTE-mapped THPs will be on normal lru lists and will be
> >split under memory pressure by vmscan. After the split vmscan will
> >detect unevictable small pages and mlock them.
> 
> Yeah that sounds like a compromise that should work.
> 
> >This way we can void leaking mlocked pages into non-VM_LOCKED VMAs.
> 
>                  avoid
> 
> But mlocked page in non-mlocked VMA's is a normal thing for shared pages
> when only one of the sharing mm's did mlock(), right? So this description
> doesn't explain the whole issue. I admit I forgot the exact details already
> :(

Right. I'm as always bad on documentation.

Before THP refcounting rework, THP was not allowed to cross VMA boundary.
So, if we have THP and we split it, PG_mlocked can be safely transfered to
small pages.

With new THP refcounting and naive approach to mlocking we can end up with
this scenario:
 1. we have a mlocked THP, which belong to one VM_LOCKED VMA.
 2. the process does munlock() on the *part* of the THP:
      - the VMA is split into two, one of them VM_LOCKED;
      - huge PMD split into PTE table;
      - THP is still mlocked;
 3. split_huge_page():
      - it transfers PG_mlocked to *all* small pages regrardless if it
	blong to any VM_LOCKED VMA.

We probably could munlock() all small pages on split_huge_page(), but I
think we have accounting issue already on step two.

> >Not-Yet-Signed-off-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
> >---
> >
> >I'm not yet 100% certain that this approch is correct. Review would be appriciated.
> >More testing is required.
> >
> >---
> >  mm/gup.c         |  6 ++++--
> >  mm/huge_memory.c | 33 +++++++++++++++++++++++-------
> >  mm/memory.c      |  3 +--
> >  mm/mlock.c       | 61 +++++++++++++++++++++++++++++++++++++-------------------
> >  4 files changed, 71 insertions(+), 32 deletions(-)
> >
> >diff --git a/mm/gup.c b/mm/gup.c
> >index 70d65e4015a4..e95b0cb6ed81 100644
> >--- a/mm/gup.c
> >+++ b/mm/gup.c
> >@@ -143,6 +143,10 @@ retry:
> >  		mark_page_accessed(page);
> >  	}
> >  	if ((flags & FOLL_MLOCK) && (vma->vm_flags & VM_LOCKED)) {
> >+		/* Do not mlock pte-mapped THP */
> >+		if (PageTransCompound(page))
> >+			goto out;
> >+
> >  		/*
> >  		 * The preliminary mapping check is mainly to avoid the
> >  		 * pointless overhead of lock_page on the ZERO_PAGE
> >@@ -920,8 +924,6 @@ long populate_vma_page_range(struct vm_area_struct *vma,
> >  	gup_flags = FOLL_TOUCH | FOLL_POPULATE | FOLL_MLOCK;
> >  	if (vma->vm_flags & VM_LOCKONFAULT)
> >  		gup_flags &= ~FOLL_POPULATE;
> >-	if (vma->vm_flags & VM_LOCKED)
> >-		gup_flags |= FOLL_SPLIT;
> >  	/*
> >  	 * We want to touch writable mappings with a write fault in order
> >  	 * to break COW, except for shared mappings because these don't COW
> >diff --git a/mm/huge_memory.c b/mm/huge_memory.c
> >index 2cc99f9096a8..d714de02473b 100644
> >--- a/mm/huge_memory.c
> >+++ b/mm/huge_memory.c
> >@@ -846,8 +846,6 @@ int do_huge_pmd_anonymous_page(struct mm_struct *mm, struct vm_area_struct *vma,
> >
> >  	if (haddr < vma->vm_start || haddr + HPAGE_PMD_SIZE > vma->vm_end)
> >  		return VM_FAULT_FALLBACK;
> >-	if (vma->vm_flags & VM_LOCKED)
> >-		return VM_FAULT_FALLBACK;
> >  	if (unlikely(anon_vma_prepare(vma)))
> >  		return VM_FAULT_OOM;
> >  	if (unlikely(khugepaged_enter(vma, vma->vm_flags)))
> >@@ -1316,7 +1314,16 @@ struct page *follow_trans_huge_pmd(struct vm_area_struct *vma,
> >  			update_mmu_cache_pmd(vma, addr, pmd);
> >  	}
> >  	if ((flags & FOLL_MLOCK) && (vma->vm_flags & VM_LOCKED)) {
> >-		if (page->mapping && trylock_page(page)) {
> >+		/*
> >+		 * We don't mlock() pte-mapped THPs. This way we can avoid
> >+		 * leaking mlocked pages into non-VM_LOCKED VMAs.
> >+		 * In most cases the pmd is the only mapping of the page: we
> >+		 * break COW for the mlock(). The only scenario when we have
> 
> I don't understand what's meant by "we break COW for the mlock()"?

mm/gup.c:

 880 long populate_vma_page_range(struct vm_area_struct *vma,                   
 881                 unsigned long start, unsigned long end, int *nonblocking)  
.....
 894         /*                                                                 
 895          * We want to touch writable mappings with a write fault in order  
 896          * to break COW, except for shared mappings because these don't COW
 897          * and we would not want to dirty them for nothing.                
 898          */                                                                
 899         if ((vma->vm_flags & (VM_WRITE | VM_SHARED)) == VM_WRITE)          
 900                 gup_flags |= FOLL_WRITE;                                   


> >+		 * the page shared here is if we mlocking read-only mapping
> >+		 * shared over fork(). We skip mlocking such pages.
> 
> Why do we skip them? There's no PTE mapping involved, just multiple PMD
> mappings? Why are those a problem?

We don't have a way to protect against parallel split_huge_pmd(). :(

-- 
 Kirill A. Shutemov

  reply	other threads:[~2015-09-14 11:05 UTC|newest]

Thread overview: 80+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-09-03 15:12 [PATCHv10 00/36] THP refcounting redesign Kirill A. Shutemov
2015-09-03 15:12 ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 01/36] mm, proc: adjust PSS calculation Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 02/36] rmap: add argument to charge compound page Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 03/36] memcg: adjust to support new THP refcounting Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 04/36] mm, thp: adjust conditions when we can reuse the page on WP fault Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 05/36] mm: adjust FOLL_SPLIT for new refcounting Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 06/36] mm: handle PTE-mapped tail pages in gerneric fast gup implementaiton Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 07/36] thp, mlock: do not allow huge pages in mlocked area Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 08/36] khugepaged: ignore pmd tables with THP mapped with ptes Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 09/36] thp: rename split_huge_page_pmd() to split_huge_pmd() Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 10/36] mm, vmstats: new THP splitting event Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 11/36] mm: temporally mark THP broken Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 12/36] thp: drop all split_huge_page()-related code Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:12 ` [PATCHv10 13/36] mm: drop tail page refcounting Kirill A. Shutemov
2015-09-03 15:12   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 14/36] futex, thp: remove special case for THP in get_futex_key Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 15/36] ksm: prepare to new THP semantics Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 16/36] mm, thp: remove compound_lock Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 17/36] arm64, thp: remove infrastructure for handling splitting PMDs Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 18/36] arm, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 19/36] mips, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 20/36] powerpc, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 21/36] s390, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 22/36] sparc, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 23/36] tile, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 24/36] x86, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 25/36] mm, " Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 26/36] mm: rework mapcount accounting to enable 4k mapping of THPs Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 27/36] mm: differentiate page_mapped() from page_mapcount() for compound pages Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 28/36] mm, numa: skip PTE-mapped THP on numa fault Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 29/36] thp: implement split_huge_pmd() Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 30/36] thp: add option to setup migration entries during PMD split Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 31/36] thp, mm: split_huge_page(): caller need to lock page Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 32/36] thp: reintroduce split_huge_page() Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 33/36] migrate_pages: try to split pages on qeueuing Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 34/36] thp: introduce deferred_split_huge_page() Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 35/36] mm: re-enable THP Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:13 ` [PATCHv10 36/36] thp: update documentation Kirill A. Shutemov
2015-09-03 15:13   ` Kirill A. Shutemov
2015-09-03 15:16 ` [PATCHv10 37/36, RFC] thp: allow mlocked THP again Kirill A. Shutemov
2015-09-03 15:16   ` Kirill A. Shutemov
2015-09-11 13:22   ` Vlastimil Babka
2015-09-11 13:22     ` Vlastimil Babka
2015-09-14 11:05     ` Kirill A. Shutemov [this message]
2015-09-14 11:05       ` Kirill A. Shutemov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20150914110504.GB8293@node.dhcp.inet.fi \
    --to=kirill@shutemov.name \
    --cc=aarcange@redhat.com \
    --cc=akpm@linux-foundation.org \
    --cc=aneesh.kumar@linux.vnet.ibm.com \
    --cc=dave.hansen@intel.com \
    --cc=hannes@cmpxchg.org \
    --cc=hughd@google.com \
    --cc=kirill.shutemov@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=mhocko@suse.cz \
    --cc=rientjes@google.com \
    --cc=vbabka@suse.cz \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.