Intel-GFX Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Matthias Goergens" <matthias.goergens@gmail.com>
Cc: dri-devel@lists.freedesktop.org, intel-gfx@lists.freedesktop.org
Subject: Re: [PATCH] drm/i915: look up shmem folios by index for writeback
Date: Fri, 02 Oct 2026 09:14:38 +0000	[thread overview]
Message-ID: <20261002091439.59C611F00899@smtp.kernel.org> (raw)
In-Reply-To: <20261002073107.2209644-1-matthias.goergens@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] i915: soft lockup in __shmem_writeback() on large sparse objects
--

commit 13d0555b9d9183775f7e6a194865fdfde399b137
Author: Matthias Goergens <matthias.goergens@gmail.com>

drm/i915: look up shmem folios by index for writeback

This commit reverts to walking the object by index using the folio API
instead of using writeback_iter(), because writeback_iter() misses
shmem folios that do not set PAGECACHE_TAG_DIRTY. It introduces a
manual loop in __shmem_writeback() to find folios by index.

> diff --git a/drivers/gpu/drm/i915/gem/i915_gem_shmem.c b/drivers/gpu/drm/i915/gem/i915_gem_shmem.c
> index ef94401662955..54424e434f3b3 100644
> --- a/drivers/gpu/drm/i915/gem/i915_gem_shmem.c
> +++ b/drivers/gpu/drm/i915/gem/i915_gem_shmem.c

[ ... ]

>  void __shmem_writeback(size_t size, struct address_space *mapping)
>  {
> -	struct writeback_control wbc = {
> -		.sync_mode = WB_SYNC_NONE,
> -		.nr_to_write = SWAP_CLUSTER_MAX,
> -		.range_start = 0,
> -		.range_end = LLONG_MAX,
> -	};
> -	struct folio *folio = NULL;
> -	int error = 0;
> +	pgoff_t nr_pages = size >> PAGE_SHIFT;
> +	pgoff_t index = 0;
>  
>  	/*
> +	 * shmem marks folios dirty with noop_dirty_folio(), which does not
> +	 * set PAGECACHE_TAG_DIRTY, so writeback_iter() would find none of
> +	 * them.  Look up each folio of the object by index and test its
> +	 * dirty flag.
> +	 *
>  	 * Leave mmapings intact (GTT will have been revoked on unbinding,
>  	 * leaving only CPU mmapings around) and add those folios to the LRU
>  	 * instead of invoking writeback so they are aged and paged out
>  	 * as normal.
>  	 */
> -	while ((folio = writeback_iter(mapping, &wbc, folio, &error))) {
> -		if (folio_mapped(folio))
> -			folio_redirty_for_writepage(&wbc, folio);
> +	while (index < nr_pages) {
> +		struct folio *folio;
> +
> +		/*
> +		 * Skip folios that are absent or locked: this runs from the
> +		 * shrinker and the OOM notifier, so do not wait for a lock.
> +		 */
> +		folio = __filemap_get_folio(mapping, index,
> +					    FGP_LOCK | FGP_NOWAIT, 0);
> +		if (IS_ERR(folio)) {
> +			index++;
> +			continue;
> +		}
                 ^^^^

[Severity: High]
Can this loop cause a soft lockup for large sparse objects?

If the object has a large hole, __filemap_get_folio() will return -ENOENT for
missing folios. The loop then handles this error by stepping forward only 1
page at a time.

For extremely large sparse objects under memory pressure, could this result in
an unbounded CPU stall without yielding, blocking kswapd or direct reclaim,
since there is no cond_resched() in the loop?

> +
> +		index = folio->index;
> +		if (!folio_mapped(folio) && folio_clear_dirty_for_io(folio))
> +			shmem_writeback_folio(folio);
>  		else
> -			error = shmem_write_folio(folio);
> +			folio_unlock(folio);
> +
> +		/* Writing may have split the folio, so read its size only now. */
> +		index += folio_nr_pages(folio);
> +		folio_put(folio);
>  	}
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002073107.2209644-1-matthias.goergens@gmail.com?part=1

  reply	other threads:[~2026-10-02  9:14 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02  7:31 [PATCH] drm/i915: look up shmem folios by index for writeback Matthias Goergens
2026-10-02  9:14 ` sashiko-bot [this message]
2026-10-04  9:49   ` Matthias Goergens
2026-10-02 21:37 ` ✗ LGCI.VerificationFailed: failure for " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002091439.59C611F00899@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=intel-gfx@lists.freedesktop.org \
    --cc=matthias.goergens@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox