* [PATCH v8 1/9] mm: fix stale ZONE_DEVICE refcount comment
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 12:34 ` [PATCH v8 2/9] mm: factor zone-device page init helpers out of __init_zone_device_page Li Zhe
` (8 subsequent siblings)
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
The comment in __init_zone_device_page() still uses the old
MEMORY_TYPE_* names and implies that FS_DAX pages regain a
refcount of 1 in the free path. That no longer matches the code.
Update the comment to describe the current policy correctly:
MEMORY_DEVICE_GENERIC pages regain a refcount of 1 in the free path,
while the remaining ZONE_DEVICE types start from 0 here and raise the
count again when the allocator or driver hands the page out.
No functional change intended.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
Reviewed-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Alistair Popple <apopple@nvidia.com>
Reviewed-by: Muchun Song <muchun.song@linux.dev>
---
mm/mm_init.c | 10 +++-------
1 file changed, 3 insertions(+), 7 deletions(-)
diff --git a/mm/mm_init.c b/mm/mm_init.c
index 0f64909e8d20..95808ab5cfdb 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1030,13 +1030,9 @@ static void __ref __init_zone_device_page(struct page *page, unsigned long pfn,
page->zone_device_data = NULL;
/*
- * ZONE_DEVICE pages other than MEMORY_TYPE_GENERIC are released
- * directly to the driver page allocator which will set the page count
- * to 1 when allocating the page.
- *
- * MEMORY_TYPE_GENERIC and MEMORY_TYPE_FS_DAX pages automatically have
- * their refcount reset to one whenever they are freed (ie. after
- * their refcount drops to 0).
+ * MEMORY_DEVICE_GENERIC pages regain a refcount of 1 in the free
+ * path. The remaining ZONE_DEVICE types start from 0 here and raise
+ * the count again when the allocator or driver hands the page out.
*/
switch (pgmap->type) {
case MEMORY_DEVICE_FS_DAX:
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v8 2/9] mm: factor zone-device page init helpers out of __init_zone_device_page
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
2026-07-27 12:34 ` [PATCH v8 1/9] mm: fix stale ZONE_DEVICE refcount comment Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 12:34 ` [PATCH v8 3/9] mm: add a set_page_section_from_pfn() helper Li Zhe
` (7 subsequent siblings)
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
memmap_init_zone_device() currently mixes refcount policy and core
ZONE_DEVICE page setup in a single helper.
Factor the refcount-reset predicate into pagemap_requires_refcount_reset(),
move the common page initialization into __zone_device_page_init(), and
wrap the existing slow path in zone_device_page_init_slow().
This keeps the slow-path behaviour unchanged and gives later patches
reusable helper boundaries.
No functional change intended.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
Reviewed-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
---
mm/mm_init.c | 56 ++++++++++++++++++++++++++++++++++------------------
1 file changed, 37 insertions(+), 19 deletions(-)
diff --git a/mm/mm_init.c b/mm/mm_init.c
index 95808ab5cfdb..a70acb7431a6 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1005,11 +1005,37 @@ static void __init memmap_init(void)
}
#ifdef CONFIG_ZONE_DEVICE
-static void __ref __init_zone_device_page(struct page *page, unsigned long pfn,
+/*
+ * Return true when memmap_init_zone_device() must initialize the page
+ * refcount to 0. MEMORY_DEVICE_GENERIC pages regain a refcount of 1 in
+ * the free path, while the remaining ZONE_DEVICE types start from 0 here
+ * and raise the count again when the allocator or driver hands the page
+ * out.
+ */
+static inline bool pagemap_requires_refcount_reset(const struct dev_pagemap *pgmap)
+{
+ /*
+ * MEMORY_DEVICE_GENERIC pages regain a refcount of 1 in the free
+ * path. The remaining ZONE_DEVICE types start from 0 here and raise
+ * the count again when the allocator or driver hands the page out.
+ */
+ switch (pgmap->type) {
+ case MEMORY_DEVICE_FS_DAX:
+ case MEMORY_DEVICE_PRIVATE:
+ case MEMORY_DEVICE_COHERENT:
+ case MEMORY_DEVICE_PCI_P2PDMA:
+ return true;
+ case MEMORY_DEVICE_GENERIC:
+ return false;
+ }
+
+ return false;
+}
+
+static void __ref __zone_device_page_init(struct page *page, unsigned long pfn,
unsigned long zone_idx, int nid,
struct dev_pagemap *pgmap)
{
-
__init_single_page(page, pfn, zone_idx, nid);
/*
@@ -1028,23 +1054,15 @@ static void __ref __init_zone_device_page(struct page *page, unsigned long pfn,
*/
page_folio(page)->pgmap = pgmap;
page->zone_device_data = NULL;
+}
- /*
- * MEMORY_DEVICE_GENERIC pages regain a refcount of 1 in the free
- * path. The remaining ZONE_DEVICE types start from 0 here and raise
- * the count again when the allocator or driver hands the page out.
- */
- switch (pgmap->type) {
- case MEMORY_DEVICE_FS_DAX:
- case MEMORY_DEVICE_PRIVATE:
- case MEMORY_DEVICE_COHERENT:
- case MEMORY_DEVICE_PCI_P2PDMA:
+static void __ref zone_device_page_init_slow(struct page *page,
+ unsigned long pfn, unsigned long zone_idx, int nid,
+ struct dev_pagemap *pgmap)
+{
+ __zone_device_page_init(page, pfn, zone_idx, nid, pgmap);
+ if (pagemap_requires_refcount_reset(pgmap))
set_page_count(page, 0);
- break;
-
- case MEMORY_DEVICE_GENERIC:
- break;
- }
}
/*
@@ -1090,7 +1108,7 @@ static void __ref memmap_init_compound(struct page *head,
for (pfn = head_pfn + 1; pfn < end_pfn; pfn++) {
struct page *page = pfn_to_page(pfn);
- __init_zone_device_page(page, pfn, zone_idx, nid, pgmap);
+ zone_device_page_init_slow(page, pfn, zone_idx, nid, pgmap);
prep_compound_tail(page, head, order);
set_page_count(page, 0);
}
@@ -1126,7 +1144,7 @@ void __ref memmap_init_zone_device(struct zone *zone,
for (pfn = start_pfn; pfn < end_pfn; pfn += pfns_per_compound) {
struct page *page = pfn_to_page(pfn);
- __init_zone_device_page(page, pfn, zone_idx, nid, pgmap);
+ zone_device_page_init_slow(page, pfn, zone_idx, nid, pgmap);
if (IS_ALIGNED(pfn, PAGES_PER_SECTION))
cond_resched();
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v8 3/9] mm: add a set_page_section_from_pfn() helper
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
2026-07-27 12:34 ` [PATCH v8 1/9] mm: fix stale ZONE_DEVICE refcount comment Li Zhe
2026-07-27 12:34 ` [PATCH v8 2/9] mm: factor zone-device page init helpers out of __init_zone_device_page Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 12:34 ` [PATCH v8 4/9] mm: add a template-based fast path for zone-device page init Li Zhe
` (6 subsequent siblings)
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
Callers that want to update section bits from a PFN currently need to
open-code:
set_page_section(page, pfn_to_section_nr(pfn));
and guard that sequence with #ifdef SECTION_IN_PAGE_FLAGS.
Add set_page_section_from_pfn() to wrap that update in one place. When
section bits are stored in page flags, the helper derives the section
number from the PFN and updates the page flags. Otherwise keep it as a
no-op so callers can use one helper without open-coding
SECTION_IN_PAGE_FLAGS.
Convert set_page_links() to use the new helper so later ZONE_DEVICE
fast-path patches can also update section bits without open-coding
SECTION_IN_PAGE_FLAGS at each callsite.
This keeps the PFN-to-section translation local to the configurations
that actually store section bits in struct page flags, and avoids
exposing that detail to generic callers.
No functional change intended.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
Reviewed-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Acked-by: Muchun Song <muchun.song@linux.dev>
Reviewed-by: Balbir Singh <balbirs@nvidia.com>
---
include/linux/mm.h | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/include/linux/mm.h b/include/linux/mm.h
index 485df9c2dbdd..43343bfce493 100644
--- a/include/linux/mm.h
+++ b/include/linux/mm.h
@@ -2541,11 +2541,22 @@ static inline void set_page_section(struct page *page, unsigned long section)
page->flags.f |= (section & SECTIONS_MASK) << SECTIONS_PGSHIFT;
}
+static inline void set_page_section_from_pfn(struct page *page,
+ unsigned long pfn)
+{
+ set_page_section(page, pfn_to_section_nr(pfn));
+}
+
static inline unsigned long memdesc_section(memdesc_flags_t mdf)
{
return (mdf.f >> SECTIONS_PGSHIFT) & SECTIONS_MASK;
}
#else /* !SECTION_IN_PAGE_FLAGS */
+static inline void set_page_section_from_pfn(struct page *page,
+ unsigned long pfn)
+{
+}
+
static inline unsigned long memdesc_section(memdesc_flags_t mdf)
{
return 0;
@@ -2768,9 +2779,7 @@ static inline void set_page_links(struct page *page, enum zone_type zone,
{
set_page_zone(page, zone);
set_page_node(page, node);
-#ifdef SECTION_IN_PAGE_FLAGS
- set_page_section(page, pfn_to_section_nr(pfn));
-#endif
+ set_page_section_from_pfn(page, pfn);
}
/**
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v8 4/9] mm: add a template-based fast path for zone-device page init
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
` (2 preceding siblings ...)
2026-07-27 12:34 ` [PATCH v8 3/9] mm: add a set_page_section_from_pfn() helper Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 12:34 ` [PATCH v8 5/9] mm: extend the template fast path to zone-device compound tails Li Zhe
` (5 subsequent siblings)
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
memmap_init_zone_device() repeats nearly identical head-page
initialization for each PFN. Prepare one reusable ZONE_DEVICE head-page
template through the existing slow path, refresh the PFN-dependent
fields in that template before each copy, and memcpy it into each
destination page.
The optimized path assigns _refcount through the copied template, so
keep it disabled when the page_ref_set tracepoint is enabled.
This patch accelerates head-page initialization. The pfns_per_compound
== 1 case gets the full benefit here, compound tails are handled in the
next patch.
Tested in a VM with a 100 GB fsdax namespace device configured with
map=dev on Intel Ice Lake server. This test exercises the nd_pmem rebind
path (pfns_per_compound == 1).
Test procedure:
Rebind the nd_pmem driver 30 times and collect the memmap initialization
time from the pr_debug() output of memmap_init_zone_device().
Base(v7.2-rc1):
First binding: 1456 ms
Average of subsequent rebinds: 244.28 ms
With this patch and its prerequisites applied:
First binding: 1440 ms
Average of subsequent rebinds: 217.19 ms
This reduces the average memmap initialization time measured during rebind
from 244.28 ms to 217.19 ms, or about 11%.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
---
mm/mm_init.c | 59 +++++++++++++++++++++++++++++++++++++++++++++++++++-
1 file changed, 58 insertions(+), 1 deletion(-)
diff --git a/mm/mm_init.c b/mm/mm_init.c
index a70acb7431a6..c2645b9bcef3 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1065,6 +1065,44 @@ static void __ref zone_device_page_init_slow(struct page *page,
set_page_count(page, 0);
}
+static inline bool zone_device_page_init_optimization_enabled(void)
+{
+ /*
+ * The template fast path copies a preinitialized struct page image.
+ * Skip it when the page_ref_set tracepoint is enabled.
+ */
+ return !page_ref_tracepoint_active(page_ref_set);
+}
+
+/*
+ * 'template' is a reusable page prototype rather than a strictly immutable
+ * object. Most ZONE_DEVICE fields stay constant across the pages covered by
+ * the current template, but section bits and page->virtual may still depend
+ * on the PFN. Refresh those PFN-dependent fields in the template before
+ * copying it into @page.
+ */
+static inline void zone_device_page_update_template(struct page *template,
+ unsigned long pfn)
+{
+ set_page_section_from_pfn(template, pfn);
+#ifdef WANT_PAGE_VIRTUAL
+ if (!is_highmem_idx(ZONE_DEVICE))
+ set_page_address(template, __va(pfn << PAGE_SHIFT));
+#endif
+}
+
+static void zone_device_page_init_from_template(struct page *page,
+ unsigned long pfn, struct page *template)
+{
+ /*
+ * 'template' carries the invariant portion of a ZONE_DEVICE struct
+ * page. Update the PFN-dependent fields in place before copying it
+ * to the destination page.
+ */
+ zone_device_page_update_template(template, pfn);
+ memcpy(page, template, sizeof(*page));
+}
+
/*
* With compound page geometry and when struct pages are stored in ram most
* tail pages are reused. Consequently, the amount of unique struct pages to
@@ -1120,6 +1158,7 @@ void __ref memmap_init_zone_device(struct zone *zone,
unsigned long nr_pages,
struct dev_pagemap *pgmap)
{
+ bool use_template = zone_device_page_init_optimization_enabled();
unsigned long pfn, end_pfn = start_pfn + nr_pages;
struct pglist_data *pgdat = zone->zone_pgdat;
struct vmem_altmap *altmap = pgmap_altmap(pgmap);
@@ -1127,6 +1166,7 @@ void __ref memmap_init_zone_device(struct zone *zone,
unsigned long zone_idx = zone_idx(zone);
unsigned long start = jiffies;
int nid = pgdat->node_id;
+ struct page template;
if (WARN_ON_ONCE(!pgmap || zone_idx != ZONE_DEVICE))
return;
@@ -1144,7 +1184,24 @@ void __ref memmap_init_zone_device(struct zone *zone,
for (pfn = start_pfn; pfn < end_pfn; pfn += pfns_per_compound) {
struct page *page = pfn_to_page(pfn);
- zone_device_page_init_slow(page, pfn, zone_idx, nid, pgmap);
+ if (!use_template) {
+ zone_device_page_init_slow(page, pfn, zone_idx,
+ nid, pgmap);
+ } else if (pfn == start_pfn) {
+ /*
+ * Seed the reusable head-page template from the
+ * first real struct page, because the existing
+ * page-init and pageblock helpers expect a real
+ * memmap entry rather than a stack object.
+ */
+ zone_device_page_init_slow(page, pfn, zone_idx,
+ nid, pgmap);
+ /* init template page */
+ memcpy(&template, page, sizeof(*page));
+ } else {
+ zone_device_page_init_from_template(page, pfn,
+ &template);
+ }
if (IS_ALIGNED(pfn, PAGES_PER_SECTION))
cond_resched();
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v8 5/9] mm: extend the template fast path to zone-device compound tails
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
` (3 preceding siblings ...)
2026-07-27 12:34 ` [PATCH v8 4/9] mm: add a template-based fast path for zone-device page init Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 12:34 ` [PATCH v8 6/9] string: introduce memcpy_nontemporal() Li Zhe
` (4 subsequent siblings)
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
The template fast path from the previous patch only accelerates head
pages. Compound tails in memmap_init_compound() still go through the
zone_device_page_init_slow() one by one.
Build separate head and tail templates and reuse one prepared tail
template across the tail pages in a compound range. Head pages preserve
the existing refcount policy, while compound tails always start with a
refcount of 0 after prep_compound_tail().
This extends the template-copy fast path to pfns_per_compound > 1
without changing the existing zone_device_page_init_slow() helper.
Tail-page PFN-dependent fields are refreshed in the reusable tail
template before each copy.
Tested in a VM with a 100 GB devdax namespace (align=2097152) on Intel
Ice Lake server. This test exercises the dax_pmem rebind path and
measures memmap initialization latency.
Test procedure:
Unbind and rebind the dax_pmem driver 30 times, collect memmap
initialization time from the pr_debug() output of memmap_init_zone_device().
Base(v7.2-rc1):
First binding: 1462 ms
Average of subsequent rebinds: 273.31 ms
With this patch and its prerequisites applied:
First binding: 1403 ms
Average of subsequent rebinds: 244.37 ms
This reduces the average memmap initialization time measured during rebind
from 273.31 ms to 244.37 ms, or about 10.6%.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
---
mm/mm_init.c | 40 +++++++++++++++++++++++++++++++++++-----
1 file changed, 35 insertions(+), 5 deletions(-)
diff --git a/mm/mm_init.c b/mm/mm_init.c
index c2645b9bcef3..2668acef4fe6 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1074,6 +1074,16 @@ static inline bool zone_device_page_init_optimization_enabled(void)
return !page_ref_tracepoint_active(page_ref_set);
}
+static inline void zone_device_tail_page_init(struct page *page,
+ unsigned long pfn, unsigned long zone_idx, int nid,
+ struct dev_pagemap *pgmap, const struct page *head,
+ unsigned int order)
+{
+ zone_device_page_init_slow(page, pfn, zone_idx, nid, pgmap);
+ prep_compound_tail(page, head, order);
+ set_page_count(page, 0);
+}
+
/*
* 'template' is a reusable page prototype rather than a strictly immutable
* object. Most ZONE_DEVICE fields stay constant across the pages covered by
@@ -1131,10 +1141,12 @@ static void __ref memmap_init_compound(struct page *head,
unsigned long head_pfn,
unsigned long zone_idx, int nid,
struct dev_pagemap *pgmap,
- unsigned long nr_pages)
+ unsigned long nr_pages,
+ bool use_template)
{
unsigned long pfn, end_pfn = head_pfn + nr_pages;
unsigned int order = pgmap->vmemmap_shift;
+ struct page template;
/*
* We have to initialize the pages, including setting up page links.
@@ -1143,12 +1155,29 @@ static void __ref memmap_init_compound(struct page *head,
* the pages in the same go.
*/
__SetPageHead(head);
+
for (pfn = head_pfn + 1; pfn < end_pfn; pfn++) {
struct page *page = pfn_to_page(pfn);
- zone_device_page_init_slow(page, pfn, zone_idx, nid, pgmap);
- prep_compound_tail(page, head, order);
- set_page_count(page, 0);
+ if (!use_template) {
+ zone_device_tail_page_init(page, pfn, zone_idx, nid,
+ pgmap, head, order);
+ } else if (pfn == head_pfn + 1) {
+ /*
+ * All tails of the same compound page share the
+ * state established by prep_compound_tail(). Reuse
+ * one tail template for the whole range and
+ * refresh only the PFN-dependent fields in that
+ * template before each copy.
+ */
+ zone_device_tail_page_init(page, pfn, zone_idx, nid,
+ pgmap, head, order);
+ /* init template page */
+ memcpy(&template, page, sizeof(*page));
+ } else {
+ zone_device_page_init_from_template(page, pfn,
+ &template);
+ }
}
prep_compound_head(head, order);
}
@@ -1210,7 +1239,8 @@ void __ref memmap_init_zone_device(struct zone *zone,
continue;
memmap_init_compound(page, pfn, zone_idx, nid, pgmap,
- compound_nr_pages(pfn, altmap, pgmap));
+ compound_nr_pages(pfn, altmap, pgmap),
+ use_template);
}
pageblock_migratetype_init_range(start_pfn, nr_pages, MIGRATE_MOVABLE);
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v8 6/9] string: introduce memcpy_nontemporal()
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
` (4 preceding siblings ...)
2026-07-27 12:34 ` [PATCH v8 5/9] mm: extend the template fast path to zone-device compound tails Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 12:34 ` [PATCH v8 7/9] x86/string: extend memcpy_flushcache() fixed-size fastpaths Li Zhe
` (3 subsequent siblings)
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
Introduce memcpy_nontemporal() for write-once copy sites that want a
named non-temporal copy primitive.
On x86_64, override the helper in arch/x86/include/asm/string_64.h using
the usual self-macro pattern, next to the existing memcpy_flushcache()
backend that memcpy_nontemporal() wraps.
include/linux/string.h provides the generic memcpy_nontemporal()
fallback as
#define memcpy_nontemporal(dst, src, len) \
((void)memcpy(dst, src, len))
instead of an inline wrapper, so architectures without a specialized
backend keep the usual memcpy() FORTIFY coverage when the compiler can
still see object sizes at the original call site. It also makes the
memcpy_nontemporal() API uniformly void, matching memcpy_flushcache()
and the x86 backend, so callers cannot accidentally depend on a return
value on fallback architectures.
memcpy_nontemporal() is only a copy primitive. It does not imply a drain
or a publication barrier. Callers that use it before a producer-consumer
or device-visible handoff must provide the required ordering at that
handoff point.
The immediate user is the ZONE_DEVICE template-copy path. It populates
struct page descriptors in a write-once pattern, so a regular cached
memcpy() can incur avoidable write-allocate traffic and cache pollution
for data with little near-term reuse.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
---
arch/x86/include/asm/string_64.h | 12 ++++++++++++
include/linux/string.h | 13 +++++++++++++
2 files changed, 25 insertions(+)
diff --git a/arch/x86/include/asm/string_64.h b/arch/x86/include/asm/string_64.h
index 4635616863f5..21ae515ae35a 100644
--- a/arch/x86/include/asm/string_64.h
+++ b/arch/x86/include/asm/string_64.h
@@ -100,6 +100,18 @@ static __always_inline void memcpy_flushcache(void *dst, const void *src, size_t
}
__memcpy_flushcache(dst, src, cnt);
}
+
+#define memcpy_nontemporal memcpy_nontemporal
+/*
+ * Reuse the existing x86 flushcache backend as the non-temporal copy
+ * primitive.
+ */
+static __always_inline void memcpy_nontemporal(void *dst, const void *src,
+ size_t cnt)
+{
+ memcpy_flushcache(dst, src, cnt);
+}
+
#endif
#endif /* __KERNEL__ */
diff --git a/include/linux/string.h b/include/linux/string.h
index 5702daca4326..6cb5cdd01158 100644
--- a/include/linux/string.h
+++ b/include/linux/string.h
@@ -278,6 +278,19 @@ static inline void memcpy_flushcache(void *dst, const void *src, size_t cnt)
}
#endif
+#ifndef memcpy_nontemporal
+/*
+ * memcpy_nontemporal() requests a non-temporal copy when the
+ * architecture has a suitable backend. Architectures without a
+ * specialized backend fall back to memcpy(). Keep this as a
+ * function-like macro so the compiler can still see the original
+ * memcpy() call site and preserve the usual FORTIFY coverage when
+ * object sizes remain visible there, while keeping the API void.
+ */
+#define memcpy_nontemporal(dst, src, len) \
+ ((void)memcpy(dst, src, len))
+#endif
+
void *memchr_inv(const void *s, int c, size_t n);
char *strreplace(char *str, char old, char new);
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v8 7/9] x86/string: extend memcpy_flushcache() fixed-size fastpaths
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
` (5 preceding siblings ...)
2026-07-27 12:34 ` [PATCH v8 6/9] string: introduce memcpy_nontemporal() Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-29 23:48 ` Borislav Petkov
2026-07-27 12:34 ` [PATCH v8 8/9] mm: use memcpy_nontemporal() in zone-device template copies Li Zhe
` (2 subsequent siblings)
9 siblings, 1 reply; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
The new x86 memcpy_nontemporal() helper in this series maps to
memcpy_flushcache(), and the ZONE_DEVICE fast path uses that primitive
for constant-sized struct page template copies.
The immediately relevant x86_64 sizeof(struct page) values here are 64,
80, and 96 bytes. memcpy_flushcache() currently inlines only the 4, 8,
and 16-byte cases, so even those constant-sized struct page copies fall
through to __memcpy_flushcache().
Add 32, 48, 64, 80, and 96-byte MOVNTI sequences to the main fixed-size
switch so those constant-sized copies can stay on the inline path.
Factor the larger sequences into movnti_8()/16()/32()/64() helpers so
the switch can reuse them without duplicating the inline assembly.
While the ZONE_DEVICE template-copy path only needs 64/80/96-byte
copies, keep 32-byte and 48-byte copies inline as well rather than
sending those nearby fixed-size cases back to __memcpy_flushcache().
These new fixed-size cases follow the existing memcpy_flushcache()
fixed-size MOVNTI cases. The existing 4/8/16-byte cases already use
MOVNTI without a separate destination alignment check.
The movnti_8()/16()/32()/64() helpers keep the "memory" clobber
intentionally. The destination memory operand describes the MOVNTI
destination, but it does not express the broader compiler-scheduling
constraint that this path wants: keep the fixed-size copy as a compact
sequence of streaming stores and avoid moving unrelated memory accesses
into the middle of that sequence.
A microbenchmark compared two memcpy_flushcache()-style helpers that
shared the same generic body and differed only in whether
32/48/64/80/96-byte copies stayed in the fixed-size switch or were
redirected to __memcpy_flushcache() when the destination was not 8-byte
aligned. The timed interval covered the copy loop only; wmb() was used
only to separate rounds.
In pseudo-code, the two variants were:
variant A:
switch (len) {
case 32:
case 48:
case 64:
case 80:
case 96:
do fixed-size MOVNTI stores;
return;
default:
generic __memcpy_flushcache()-style body;
}
variant B:
switch (len) {
case 32:
case 48:
case 64:
case 80:
case 96:
if (!IS_ALIGNED(dst, 8))
goto generic_path;
do fixed-size MOVNTI stores;
return;
default:
generic_path:
generic __memcpy_flushcache()-style body;
}
For offsets 1..7 averaged, keeping those sizes in the fixed-size
switch took about 0.410/0.411/0.426/0.426/0.428 us per
32/48/64/80/96-byte copy, while redirecting the same cases to
__memcpy_flushcache() took about 0.962/0.956/0.923/0.998/1.001 us.
The correctness rationale for not adding a separate destination
alignment check is that these cases follow the existing 4/8/16-byte
memcpy_flushcache() MOVNTI cases, and I did not find Intel SDM text
requiring an 8-byte aligned destination for MOVNTI.
The microbenchmark is only the performance motivation for keeping
these small constant-size copies in the inline path.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
---
arch/x86/include/asm/string_64.h | 56 +++++++++++++++++++++++++++++++-
1 file changed, 55 insertions(+), 1 deletion(-)
diff --git a/arch/x86/include/asm/string_64.h b/arch/x86/include/asm/string_64.h
index 21ae515ae35a..bc6a9f34b346 100644
--- a/arch/x86/include/asm/string_64.h
+++ b/arch/x86/include/asm/string_64.h
@@ -82,7 +82,35 @@ int strcmp(const char *cs, const char *ct);
#ifdef CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE
#define __HAVE_ARCH_MEMCPY_FLUSHCACHE 1
void __memcpy_flushcache(void *dst, const void *src, size_t cnt);
-static __always_inline void memcpy_flushcache(void *dst, const void *src, size_t cnt)
+
+static __always_inline void movnti_8(void *dst, const void *src)
+{
+ asm volatile("movntiq %1, %0"
+ : "=m"(*(u64 *)dst)
+ : "r"(*(const u64 *)src)
+ : "memory");
+}
+
+static __always_inline void movnti_16(void *dst, const void *src)
+{
+ movnti_8(dst, src);
+ movnti_8(dst + 8, src + 8);
+}
+
+static __always_inline void movnti_32(void *dst, const void *src)
+{
+ movnti_16(dst, src);
+ movnti_16(dst + 16, src + 16);
+}
+
+static __always_inline void movnti_64(void *dst, const void *src)
+{
+ movnti_32(dst, src);
+ movnti_32(dst + 32, src + 32);
+}
+
+static __always_inline void memcpy_flushcache(void *dst, const void *src,
+ size_t cnt)
{
if (__builtin_constant_p(cnt)) {
switch (cnt) {
@@ -96,8 +124,34 @@ static __always_inline void memcpy_flushcache(void *dst, const void *src, size_t
asm ("movntiq %1, %0" : "=m"(*(u64 *)dst) : "r"(*(u64 *)src));
asm ("movntiq %1, %0" : "=m"(*(u64 *)(dst + 8)) : "r"(*(u64 *)(src + 8)));
return;
+ /*
+ * The relevant fixed-size copies here are the
+ * x86_64 struct page sizes: 64, 80, and 96 bytes.
+ * Keep 32-byte and 48-byte copies inline as well
+ * instead of sending those nearby fixed-size
+ * cases back to __memcpy_flushcache().
+ */
+ case 32:
+ movnti_32(dst, src);
+ return;
+ case 48:
+ movnti_32(dst, src);
+ movnti_16(dst + 32, src + 32);
+ return;
+ case 64:
+ movnti_64(dst, src);
+ return;
+ case 80:
+ movnti_64(dst, src);
+ movnti_16(dst + 64, src + 64);
+ return;
+ case 96:
+ movnti_64(dst, src);
+ movnti_32(dst + 64, src + 64);
+ return;
}
}
+
__memcpy_flushcache(dst, src, cnt);
}
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [PATCH v8 7/9] x86/string: extend memcpy_flushcache() fixed-size fastpaths
2026-07-27 12:34 ` [PATCH v8 7/9] x86/string: extend memcpy_flushcache() fixed-size fastpaths Li Zhe
@ 2026-07-29 23:48 ` Borislav Petkov
2026-07-30 8:05 ` Li Zhe
2026-07-30 8:14 ` David Laight
0 siblings, 2 replies; 15+ messages in thread
From: Borislav Petkov @ 2026-07-29 23:48 UTC (permalink / raw)
To: Li Zhe
Cc: akpm, apopple, arnd, balbirs, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx, linux-arch, linux-hardening,
linux-kernel, linux-mm, x86
On Mon, Jul 27, 2026 at 08:34:27PM +0800, Li Zhe wrote:
> The new x86 memcpy_nontemporal() helper in this series maps to
s/in this series//
That's implicit.
> memcpy_flushcache(), and the ZONE_DEVICE fast path uses that primitive
> for constant-sized struct page template copies.
>
> The immediately relevant x86_64 sizeof(struct page) values here are 64,
> 80, and 96 bytes. memcpy_flushcache() currently inlines only the 4, 8,
> and 16-byte cases, so even those constant-sized struct page copies fall
> through to __memcpy_flushcache().
>
> Add 32, 48, 64, 80, and 96-byte MOVNTI sequences to the main fixed-size
> switch so those constant-sized copies can stay on the inline path.
> Factor the larger sequences into movnti_8()/16()/32()/64() helpers so
> the switch can reuse them without duplicating the inline assembly.
> While the ZONE_DEVICE template-copy path only needs 64/80/96-byte
> copies, keep 32-byte and 48-byte copies inline as well rather than
> sending those nearby fixed-size cases back to __memcpy_flushcache().
Do not explain the code - explain *why* those sizes. I already asked a bunch
of times.
>
> These new fixed-size cases follow the existing memcpy_flushcache()
> fixed-size MOVNTI cases. The existing 4/8/16-byte cases already use
> MOVNTI without a separate destination alignment check.
>
> The movnti_8()/16()/32()/64() helpers keep the "memory" clobber
> intentionally. The destination memory operand describes the MOVNTI
> destination, but it does not express the broader compiler-scheduling
> constraint that this path wants: keep the fixed-size copy as a compact
> sequence of streaming stores and avoid moving unrelated memory accesses
> into the middle of that sequence.
A lot of bla for its own sake.
> A microbenchmark compared two memcpy_flushcache()-style helpers that
> shared the same generic body and differed only in whether
> 32/48/64/80/96-byte copies stayed in the fixed-size switch or were
> redirected to __memcpy_flushcache() when the destination was not 8-byte
> aligned. The timed interval covered the copy loop only; wmb() was used
> only to separate rounds.
So we're doing this only for a microbenchmark's sake?
> In pseudo-code, the two variants were:
>
> variant A:
> switch (len) {
> case 32:
> case 48:
> case 64:
> case 80:
> case 96:
> do fixed-size MOVNTI stores;
> return;
> default:
> generic __memcpy_flushcache()-style body;
> }
>
> variant B:
> switch (len) {
> case 32:
> case 48:
> case 64:
> case 80:
> case 96:
> if (!IS_ALIGNED(dst, 8))
> goto generic_path;
> do fixed-size MOVNTI stores;
> return;
> default:
> generic_path:
> generic __memcpy_flushcache()-style body;
> }
>
> For offsets 1..7 averaged, keeping those sizes in the fixed-size
> switch took about 0.410/0.411/0.426/0.426/0.428 us per
> 32/48/64/80/96-byte copy, while redirecting the same cases to
> __memcpy_flushcache() took about 0.962/0.956/0.923/0.998/1.001 us.
>
> The correctness rationale for not adding a separate destination
> alignment check is that these cases follow the existing 4/8/16-byte
> memcpy_flushcache() MOVNTI cases, and I did not find Intel SDM text
> requiring an 8-byte aligned destination for MOVNTI.
>
> The microbenchmark is only the performance motivation for keeping
> these small constant-size copies in the inline path.
So in the end of the commit message, I still don't know why we need this code.
I mean, it should be pretty trivial to explain: I'm adding those additional
sizes because it brings this and that. Srsly.
If you cannot justify that, why are you even doing it?
So from going over this again, the reason why you're adding those other sizes
are because struct page can be that big. Yes?
How do you know? What's the proof?
I'd expect a justification along the lines of: in a somewhat normal Linux
installation, struct size can be of size <bla>. Adding MOVNTI helpers of size
<bla> brings so and so performance uplift.
How hard it is to write it this way?
> Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
> ---
> arch/x86/include/asm/string_64.h | 56 +++++++++++++++++++++++++++++++-
> 1 file changed, 55 insertions(+), 1 deletion(-)
...
at least the code is making a lot more sense now.
The fact that you had to axe off so much cruft off of it tells me that you
haven't really measured it right.
So why do I really want your patch?
Thx.
--
Regards/Gruss,
Boris.
https://people.kernel.org/tglx/notes-about-netiquette
^ permalink raw reply [flat|nested] 15+ messages in thread* Re: [PATCH v8 7/9] x86/string: extend memcpy_flushcache() fixed-size fastpaths
2026-07-29 23:48 ` Borislav Petkov
@ 2026-07-30 8:05 ` Li Zhe
2026-07-30 8:14 ` David Laight
1 sibling, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-30 8:05 UTC (permalink / raw)
To: Borislav Petkov
Cc: akpm, apopple, arnd, balbirs, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx, linux-arch, linux-hardening,
linux-kernel, linux-mm, x86
On 7/30/26 7:48 AM, Borislav Petkov wrote:
> On Mon, Jul 27, 2026 at 08:34:27PM +0800, Li Zhe wrote:
>> The new x86 memcpy_nontemporal() helper in this series maps to
> s/in this series//
>
> That's implicit.
>
>> memcpy_flushcache(), and the ZONE_DEVICE fast path uses that primitive
>> for constant-sized struct page template copies.
>>
>> The immediately relevant x86_64 sizeof(struct page) values here are 64,
>> 80, and 96 bytes. memcpy_flushcache() currently inlines only the 4, 8,
>> and 16-byte cases, so even those constant-sized struct page copies fall
>> through to __memcpy_flushcache().
>>
>> Add 32, 48, 64, 80, and 96-byte MOVNTI sequences to the main fixed-size
>> switch so those constant-sized copies can stay on the inline path.
>> Factor the larger sequences into movnti_8()/16()/32()/64() helpers so
>> the switch can reuse them without duplicating the inline assembly.
>> While the ZONE_DEVICE template-copy path only needs 64/80/96-byte
>> copies, keep 32-byte and 48-byte copies inline as well rather than
>> sending those nearby fixed-size cases back to __memcpy_flushcache().
> Do not explain the code - explain *why* those sizes. I already asked a bunch
> of times.
>
>> These new fixed-size cases follow the existing memcpy_flushcache()
>> fixed-size MOVNTI cases. The existing 4/8/16-byte cases already use
>> MOVNTI without a separate destination alignment check.
>>
>> The movnti_8()/16()/32()/64() helpers keep the "memory" clobber
>> intentionally. The destination memory operand describes the MOVNTI
>> destination, but it does not express the broader compiler-scheduling
>> constraint that this path wants: keep the fixed-size copy as a compact
>> sequence of streaming stores and avoid moving unrelated memory accesses
>> into the middle of that sequence.
> A lot of bla for its own sake.
>
>> A microbenchmark compared two memcpy_flushcache()-style helpers that
>> shared the same generic body and differed only in whether
>> 32/48/64/80/96-byte copies stayed in the fixed-size switch or were
>> redirected to __memcpy_flushcache() when the destination was not 8-byte
>> aligned. The timed interval covered the copy loop only; wmb() was used
>> only to separate rounds.
> So we're doing this only for a microbenchmark's sake?
>
>> In pseudo-code, the two variants were:
>>
>> variant A:
>> switch (len) {
>> case 32:
>> case 48:
>> case 64:
>> case 80:
>> case 96:
>> do fixed-size MOVNTI stores;
>> return;
>> default:
>> generic __memcpy_flushcache()-style body;
>> }
>>
>> variant B:
>> switch (len) {
>> case 32:
>> case 48:
>> case 64:
>> case 80:
>> case 96:
>> if (!IS_ALIGNED(dst, 8))
>> goto generic_path;
>> do fixed-size MOVNTI stores;
>> return;
>> default:
>> generic_path:
>> generic __memcpy_flushcache()-style body;
>> }
>>
>> For offsets 1..7 averaged, keeping those sizes in the fixed-size
>> switch took about 0.410/0.411/0.426/0.426/0.428 us per
>> 32/48/64/80/96-byte copy, while redirecting the same cases to
>> __memcpy_flushcache() took about 0.962/0.956/0.923/0.998/1.001 us.
>>
>> The correctness rationale for not adding a separate destination
>> alignment check is that these cases follow the existing 4/8/16-byte
>> memcpy_flushcache() MOVNTI cases, and I did not find Intel SDM text
>> requiring an 8-byte aligned destination for MOVNTI.
>>
>> The microbenchmark is only the performance motivation for keeping
>> these small constant-size copies in the inline path.
> So in the end of the commit message, I still don't know why we need this code.
>
> I mean, it should be pretty trivial to explain: I'm adding those additional
> sizes because it brings this and that. Srsly.
>
> If you cannot justify that, why are you even doing it?
>
> So from going over this again, the reason why you're adding those other sizes
> are because struct page can be that big. Yes?
>
> How do you know? What's the proof?
>
> I'd expect a justification along the lines of: in a somewhat normal Linux
> installation, struct size can be of size <bla>. Adding MOVNTI helpers of size
> <bla> brings so and so performance uplift.
Yes, the real motivation is the ZONE_DEVICE struct page template copy.
The second paragraph of the commit message was intended to explain the
main sizes: the immediately relevant x86_64 sizeof(struct page) values
are 64, 80 and 96 bytes. But I agree that the commit message did not
connect those sizes to the real ZONE_DEVICE benefit clearly enough.
This patch was added because I had measured a benefit from keeping those
struct page sized memcpy_flushcache() copies in the fixed-size MOVNTI
path. The current patch order and commit message did not make that clear
enough, because the ZONE_DEVICE memcpy_nontemporal() user came after the
x86 extension.
I will fix that in v9 by reordering the patches so the ZONE_DEVICE
memcpy_nontemporal() user comes first, and then rewriting the x86 commit
message around that caller and the measured benefit. I will also remove
"in this series" and trim the commit message so it focuses on why the
patch is useful rather than explaining the implementation details.
Thanks,
Zhe
>
> How hard it is to write it this way?
>
>> Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
>> ---
>> arch/x86/include/asm/string_64.h | 56 +++++++++++++++++++++++++++++++-
>> 1 file changed, 55 insertions(+), 1 deletion(-)
> ...
>
> at least the code is making a lot more sense now.
>
> The fact that you had to axe off so much cruft off of it tells me that you
> haven't really measured it right.
>
> So why do I really want your patch?
>
> Thx.
^ permalink raw reply [flat|nested] 15+ messages in thread* Re: [PATCH v8 7/9] x86/string: extend memcpy_flushcache() fixed-size fastpaths
2026-07-29 23:48 ` Borislav Petkov
2026-07-30 8:05 ` Li Zhe
@ 2026-07-30 8:14 ` David Laight
1 sibling, 0 replies; 15+ messages in thread
From: David Laight @ 2026-07-30 8:14 UTC (permalink / raw)
To: Borislav Petkov
Cc: Li Zhe, akpm, apopple, arnd, balbirs, dave.hansen, david, kees,
mingo, muchun.song, rppt, tglx, linux-arch, linux-hardening,
linux-kernel, linux-mm, x86
On Wed, 29 Jul 2026 16:48:42 -0700
Borislav Petkov <bp@alien8.de> wrote:
...
> at least the code is making a lot more sense now.
>
> The fact that you had to axe off so much cruft off of it tells me that you
> haven't really measured it right.
Especially since if you do actually measure the clock counts (non-trivial)
you'll find that loops are often completely free.
The out-of-order execution unit will (effectively) execute the loop control
instructions to generate a list of instructions that get executed at a
later time.
So provided the loop control doesn't use more clocks than the loop body
(and there are spare ALU units - usually true) loops really make little
difference.
This also means that unrolling loops often doesn't make things faster.
You do need to minimise the loop control instructions (and gcc doesn't
like the best loop that uses negative offsets from the end), and
intel cpu can't execute single clock loops (amd ones can).
Inlining also increases the code size, the I-cache reads are actually
likely to be significant.
You need to time a single 'cold-cache' call not just loops for long
enough that the result is also skewed by timer ticks (etc).
David
>
> So why do I really want your patch?
>
> Thx.
>
^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH v8 8/9] mm: use memcpy_nontemporal() in zone-device template copies
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
` (6 preceding siblings ...)
2026-07-27 12:34 ` [PATCH v8 7/9] x86/string: extend memcpy_flushcache() fixed-size fastpaths Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 12:34 ` [PATCH v8 9/9] mm: always use the zone-device template init path Li Zhe
2026-07-27 20:57 ` [PATCH v8 0/9] mm: optimize zone-device memmap initialization Andrew Morton
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
The template fast path currently uses memcpy() for the actual struct
page copy. Switch zone_device_page_init_from_template() to
memcpy_nontemporal().
ZONE_DEVICE memmap initialization is largely write-once: each struct
page is populated once, and most destination cachelines are not expected
to be reused immediately afterwards. On x86, a regular cached memcpy()
can therefore incur write-allocate traffic by pulling destination
cachelines into the cache before writeback, and can populate the cache
with data that has little near-term reuse. Using memcpy_nontemporal()
lets this path request nontemporal stores for that copy pattern, which
can reduce cache pollution and avoid part of the associated
write-allocate overhead, while architectures without a specialized
backend still fall back to memcpy().
No separate drain is added here. memcpy_nontemporal() is used only as
the copy primitive while memmap_init_zone_device() is still initializing
the struct page array. The ordinary stores that follow in this path,
such as compound-page setup, are part of the same CPU's initialization
sequence; they are not used as a publication store that tells another CPU
or device to consume data written by the non-temporal copy.
Therefore this call site does not need a helper-level drain for
correctness. Callers that use memcpy_nontemporal() as part of a
producer-consumer or device-visible handoff must add the required
ordering themselves.
At this point, sanitized builds still use the slow path so KASAN/KMSAN
retain their instrumented stores. The following cleanup removes that
local opt-out together with the remaining non-template fallback.
Tested in a VM with a 100 GB fsdax namespace device configured with
map=dev and a 100 GB devdax namespace (align=2097152) on Intel Ice Lake
server.
Test procedure:
Rebind the nd_pmem and dax_pmem driver 30 times and collect the memmap
initialization time from the pr_debug() output of
memmap_init_zone_device().
Base(v7.2-rc1):
First binding for nd_pmem driver: 1456 ms
Average of subsequent rebinds: 244.28 ms
First binding for dax_pmem driver: 1462 ms
Average of subsequent rebinds: 273.31 ms
With this series:
First binding for nd_pmem driver: 1272 ms
Average of subsequent rebinds: 96.79 ms
First binding for dax_pmem driver: 1354 ms
Average of subsequent rebinds: 119.04 ms
This reduces the average memmap initialization time measured during rebind
by about 60.4% for nd_pmem and 56.4% for dax_pmem.
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
---
mm/mm_init.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/mm/mm_init.c b/mm/mm_init.c
index 2668acef4fe6..2a723a518f41 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1067,11 +1067,21 @@ static void __ref zone_device_page_init_slow(struct page *page,
static inline bool zone_device_page_init_optimization_enabled(void)
{
+ /*
+ * Keep sanitized builds on the slow path so their stores stay
+ * instrumented.
+ */
+ if (IS_ENABLED(CONFIG_KASAN) || IS_ENABLED(CONFIG_KMSAN))
+ return false;
+
/*
* The template fast path copies a preinitialized struct page image.
* Skip it when the page_ref_set tracepoint is enabled.
*/
- return !page_ref_tracepoint_active(page_ref_set);
+ if (page_ref_tracepoint_active(page_ref_set))
+ return false;
+
+ return true;
}
static inline void zone_device_tail_page_init(struct page *page,
@@ -1110,7 +1120,7 @@ static void zone_device_page_init_from_template(struct page *page,
* to the destination page.
*/
zone_device_page_update_template(template, pfn);
- memcpy(page, template, sizeof(*page));
+ memcpy_nontemporal(page, template, sizeof(*page));
}
/*
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v8 9/9] mm: always use the zone-device template init path
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
` (7 preceding siblings ...)
2026-07-27 12:34 ` [PATCH v8 8/9] mm: use memcpy_nontemporal() in zone-device template copies Li Zhe
@ 2026-07-27 12:34 ` Li Zhe
2026-07-27 20:57 ` [PATCH v8 0/9] mm: optimize zone-device memmap initialization Andrew Morton
9 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-27 12:34 UTC (permalink / raw)
To: akpm, apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx
Cc: linux-arch, linux-hardening, linux-kernel, linux-mm, x86,
lizhe.67
The template path still has a local opt-out predicate for the
page_ref_set tracepoint and keeps a non-template fallback path. This
makes the code more complex without a strong reason to keep the
separate path.
Use the template path unconditionally after the corresponding seed page
has been initialized: the first head page seeds the head template, and
the first tail page in each compound range seeds the tail template.
This keeps the first-page seeding logic unchanged, but removes the extra
non-template fallback from the main loops.
This also means sanitized builds no longer force this path back to the
per-page initialization stores, and an enabled page_ref_set tracepoint
will no longer observe every ZONE_DEVICE initialization-time refcount
assignment. That tradeoff is intentional: this code is still initializing
struct pages before they are handed out, and keeping those local debug
special cases would preserve a separate initialization-only path while
making the common code more complex.
Suggested-by: Muchun Song <muchun.song@linux.dev>
Signed-off-by: Li Zhe <lizhe.67@bytedance.com>
---
mm/mm_init.c | 36 ++++--------------------------------
1 file changed, 4 insertions(+), 32 deletions(-)
diff --git a/mm/mm_init.c b/mm/mm_init.c
index 2a723a518f41..ae42a1311e1d 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1065,25 +1065,6 @@ static void __ref zone_device_page_init_slow(struct page *page,
set_page_count(page, 0);
}
-static inline bool zone_device_page_init_optimization_enabled(void)
-{
- /*
- * Keep sanitized builds on the slow path so their stores stay
- * instrumented.
- */
- if (IS_ENABLED(CONFIG_KASAN) || IS_ENABLED(CONFIG_KMSAN))
- return false;
-
- /*
- * The template fast path copies a preinitialized struct page image.
- * Skip it when the page_ref_set tracepoint is enabled.
- */
- if (page_ref_tracepoint_active(page_ref_set))
- return false;
-
- return true;
-}
-
static inline void zone_device_tail_page_init(struct page *page,
unsigned long pfn, unsigned long zone_idx, int nid,
struct dev_pagemap *pgmap, const struct page *head,
@@ -1151,8 +1132,7 @@ static void __ref memmap_init_compound(struct page *head,
unsigned long head_pfn,
unsigned long zone_idx, int nid,
struct dev_pagemap *pgmap,
- unsigned long nr_pages,
- bool use_template)
+ unsigned long nr_pages)
{
unsigned long pfn, end_pfn = head_pfn + nr_pages;
unsigned int order = pgmap->vmemmap_shift;
@@ -1169,10 +1149,7 @@ static void __ref memmap_init_compound(struct page *head,
for (pfn = head_pfn + 1; pfn < end_pfn; pfn++) {
struct page *page = pfn_to_page(pfn);
- if (!use_template) {
- zone_device_tail_page_init(page, pfn, zone_idx, nid,
- pgmap, head, order);
- } else if (pfn == head_pfn + 1) {
+ if (pfn == head_pfn + 1) {
/*
* All tails of the same compound page share the
* state established by prep_compound_tail(). Reuse
@@ -1197,7 +1174,6 @@ void __ref memmap_init_zone_device(struct zone *zone,
unsigned long nr_pages,
struct dev_pagemap *pgmap)
{
- bool use_template = zone_device_page_init_optimization_enabled();
unsigned long pfn, end_pfn = start_pfn + nr_pages;
struct pglist_data *pgdat = zone->zone_pgdat;
struct vmem_altmap *altmap = pgmap_altmap(pgmap);
@@ -1223,10 +1199,7 @@ void __ref memmap_init_zone_device(struct zone *zone,
for (pfn = start_pfn; pfn < end_pfn; pfn += pfns_per_compound) {
struct page *page = pfn_to_page(pfn);
- if (!use_template) {
- zone_device_page_init_slow(page, pfn, zone_idx,
- nid, pgmap);
- } else if (pfn == start_pfn) {
+ if (pfn == start_pfn) {
/*
* Seed the reusable head-page template from the
* first real struct page, because the existing
@@ -1249,8 +1222,7 @@ void __ref memmap_init_zone_device(struct zone *zone,
continue;
memmap_init_compound(page, pfn, zone_idx, nid, pgmap,
- compound_nr_pages(pfn, altmap, pgmap),
- use_template);
+ compound_nr_pages(pfn, altmap, pgmap));
}
pageblock_migratetype_init_range(start_pfn, nr_pages, MIGRATE_MOVABLE);
--
2.20.1
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [PATCH v8 0/9] mm: optimize zone-device memmap initialization
2026-07-27 12:34 [PATCH v8 0/9] mm: optimize zone-device memmap initialization Li Zhe
` (8 preceding siblings ...)
2026-07-27 12:34 ` [PATCH v8 9/9] mm: always use the zone-device template init path Li Zhe
@ 2026-07-27 20:57 ` Andrew Morton
2026-07-28 6:18 ` Li Zhe
9 siblings, 1 reply; 15+ messages in thread
From: Andrew Morton @ 2026-07-27 20:57 UTC (permalink / raw)
To: Li Zhe
Cc: apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx, linux-arch, linux-hardening,
linux-kernel, linux-mm, x86
On Mon, 27 Jul 2026 20:34:20 +0800 "Li Zhe" <lizhe.67@bytedance.com> wrote:
> memmap_init_zone_device() can take a noticeable amount of time when large
> pmem namespaces are bound or rebound, because it initializes nearly
> identical struct page descriptors one PFN at a time. This series reduces
> that ZONE_DEVICE memmap initialization overhead by reusing prepared
> struct page templates and, on x86, using memcpy_nontemporal() for the
> template copy path.
Thanks.
Human review started out strong but petered out later in the series.
This often happens. I'd prefer to wait until it fills out further.
AI review had things to say, as it often does:
https://sashiko.dev/#/patchset/20260727123429.5673-1-lizhe.67@bytedance.com
^ permalink raw reply [flat|nested] 15+ messages in thread* Re: [PATCH v8 0/9] mm: optimize zone-device memmap initialization
2026-07-27 20:57 ` [PATCH v8 0/9] mm: optimize zone-device memmap initialization Andrew Morton
@ 2026-07-28 6:18 ` Li Zhe
0 siblings, 0 replies; 15+ messages in thread
From: Li Zhe @ 2026-07-28 6:18 UTC (permalink / raw)
To: Andrew Morton
Cc: apopple, arnd, balbirs, bp, dave.hansen, david, kees, mingo,
muchun.song, rppt, tglx, linux-arch, linux-hardening,
linux-kernel, linux-mm, x86
On 7/28/26 4:57 AM, Andrew Morton wrote:
> On Mon, 27 Jul 2026 20:34:20 +0800 "Li Zhe" <lizhe.67@bytedance.com> wrote:
>
>> memmap_init_zone_device() can take a noticeable amount of time when large
>> pmem namespaces are bound or rebound, because it initializes nearly
>> identical struct page descriptors one PFN at a time. This series reduces
>> that ZONE_DEVICE memmap initialization overhead by reusing prepared
>> struct page templates and, on x86, using memcpy_nontemporal() for the
>> template copy path.
> Thanks.
>
> Human review started out strong but petered out later in the series.
> This often happens. I'd prefer to wait until it fills out further.
>
> AI review had things to say, as it often does:
> https://sashiko.dev/#/patchset/20260727123429.5673-1-lizhe.67@bytedance.com
Thanks for the review.
These comments seem to mostly cover the same memcpy_nontemporal(),
MOVNTI alignment, helper-level drain, and sanitizer/tracepoint tradeoff
topics that were discussed for v7.
The v8 changes keep the x86 non-temporal copy path unchanged, except for
making the generic memcpy_nontemporal() fallback a void function-like
macro. The remaining updates are clarifications in the cover letter and
commit messages.
So I do not plan further code changes for these comments at this point,
unless someone points out a problem in the previous discussion.
For the previous discussion, please see:
https://lore.kernel.org/all/20260722081800.90085-1-lizhe.67@bytedance.com/
Thanks,
Zhe
^ permalink raw reply [flat|nested] 15+ messages in thread