From: sashiko-bot@kernel.org
To: "Matthias Goergens" <matthias.goergens@gmail.com>
Cc: dri-devel@lists.freedesktop.org, intel-gfx@lists.freedesktop.org
Subject: Re: [PATCH] drm/i915: look up shmem folios by index for writeback
Date: Fri, 02 Oct 2026 09:14:38 +0000 [thread overview]
Message-ID: <20261002091439.59C611F00899@smtp.kernel.org> (raw)
In-Reply-To: <20261002073107.2209644-1-matthias.goergens@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] i915: soft lockup in __shmem_writeback() on large sparse objects
--
commit 13d0555b9d9183775f7e6a194865fdfde399b137
Author: Matthias Goergens <matthias.goergens@gmail.com>
drm/i915: look up shmem folios by index for writeback
This commit reverts to walking the object by index using the folio API
instead of using writeback_iter(), because writeback_iter() misses
shmem folios that do not set PAGECACHE_TAG_DIRTY. It introduces a
manual loop in __shmem_writeback() to find folios by index.
> diff --git a/drivers/gpu/drm/i915/gem/i915_gem_shmem.c b/drivers/gpu/drm/i915/gem/i915_gem_shmem.c
> index ef94401662955..54424e434f3b3 100644
> --- a/drivers/gpu/drm/i915/gem/i915_gem_shmem.c
> +++ b/drivers/gpu/drm/i915/gem/i915_gem_shmem.c
[ ... ]
> void __shmem_writeback(size_t size, struct address_space *mapping)
> {
> - struct writeback_control wbc = {
> - .sync_mode = WB_SYNC_NONE,
> - .nr_to_write = SWAP_CLUSTER_MAX,
> - .range_start = 0,
> - .range_end = LLONG_MAX,
> - };
> - struct folio *folio = NULL;
> - int error = 0;
> + pgoff_t nr_pages = size >> PAGE_SHIFT;
> + pgoff_t index = 0;
>
> /*
> + * shmem marks folios dirty with noop_dirty_folio(), which does not
> + * set PAGECACHE_TAG_DIRTY, so writeback_iter() would find none of
> + * them. Look up each folio of the object by index and test its
> + * dirty flag.
> + *
> * Leave mmapings intact (GTT will have been revoked on unbinding,
> * leaving only CPU mmapings around) and add those folios to the LRU
> * instead of invoking writeback so they are aged and paged out
> * as normal.
> */
> - while ((folio = writeback_iter(mapping, &wbc, folio, &error))) {
> - if (folio_mapped(folio))
> - folio_redirty_for_writepage(&wbc, folio);
> + while (index < nr_pages) {
> + struct folio *folio;
> +
> + /*
> + * Skip folios that are absent or locked: this runs from the
> + * shrinker and the OOM notifier, so do not wait for a lock.
> + */
> + folio = __filemap_get_folio(mapping, index,
> + FGP_LOCK | FGP_NOWAIT, 0);
> + if (IS_ERR(folio)) {
> + index++;
> + continue;
> + }
^^^^
[Severity: High]
Can this loop cause a soft lockup for large sparse objects?
If the object has a large hole, __filemap_get_folio() will return -ENOENT for
missing folios. The loop then handles this error by stepping forward only 1
page at a time.
For extremely large sparse objects under memory pressure, could this result in
an unbounded CPU stall without yielding, blocking kswapd or direct reclaim,
since there is no cond_resched() in the loop?
> +
> + index = folio->index;
> + if (!folio_mapped(folio) && folio_clear_dirty_for_io(folio))
> + shmem_writeback_folio(folio);
> else
> - error = shmem_write_folio(folio);
> + folio_unlock(folio);
> +
> + /* Writing may have split the folio, so read its size only now. */
> + index += folio_nr_pages(folio);
> + folio_put(folio);
> }
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002073107.2209644-1-matthias.goergens@gmail.com?part=1
next prev parent reply other threads:[~2026-10-02 9:14 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 7:31 [PATCH] drm/i915: look up shmem folios by index for writeback Matthias Goergens
2026-10-02 9:14 ` sashiko-bot [this message]
2026-10-04 9:49 ` Matthias Goergens
2026-10-02 21:37 ` ✗ LGCI.VerificationFailed: failure for " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002091439.59C611F00899@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=intel-gfx@lists.freedesktop.org \
--cc=matthias.goergens@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox