From: Yeoreum Yun <yeoreum.yun@arm.com>
To: Russell King <linux@armlinux.org.uk>,
Huacai Chen <chenhuacai@kernel.org>,
WANG Xuerui <kernel@xen0n.name>,
Thomas Bogendoerfer <tsbogend@alpha.franken.de>,
Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>, Arnd Bergmann <arnd@arndb.de>,
Andrew Morton <akpm@linux-foundation.org>,
Kairui Song <kasong@tencent.com>, Qi Zheng <qi.zheng@linux.dev>,
Shakeel Butt <shakeel.butt@linux.dev>,
Barry Song <baohua@kernel.org>,
Axel Rasmussen <axelrasmussen@google.com>,
Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
Johannes Weiner <hannes@cmpxchg.org>,
David Hildenbrand <david@kernel.org>,
Michal Hocko <mhocko@kernel.org>,
Lorenzo Stoakes <ljs@kernel.org>,
Tianrui Zhao <zhaotianrui@loongson.cn>,
Bibo Mao <maobibo@loongson.cn>, Anup Patel <anup@brainfault.org>,
Atish Patra <atish.patra@linux.dev>,
Paul Walmsley <pjw@kernel.org>,
Palmer Dabbelt <palmer@dabbelt.com>,
Albert Ou <aou@eecs.berkeley.edu>,
Alexandre Ghiti <alex@ghiti.fr>,
Dave Hansen <dave.hansen@linux.intel.com>,
Andy Lutomirski <luto@kernel.org>,
Peter Zijlstra <peterz@infradead.org>,
Thomas Gleixner <tglx@kernel.org>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
"Liam R. Howlett" <liam@infradead.org>,
Vlastimil Babka <vbabka@kernel.org>,
Mike Rapoport <rppt@kernel.org>,
Suren Baghdasaryan <surenb@google.com>,
Michal Hocko <mhocko@suse.com>, Jonas Bonn <jonas@southpole.se>,
Stefan Kristiansson <stefan.kristiansson@saunalahti.fi>,
Stafford Horne <shorne@gmail.com>
Cc: linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, loongarch@lists.linux.dev,
linux-mips@vger.kernel.org, linux-arch@vger.kernel.org,
linux-mm@kvack.org, kvm@vger.kernel.org,
kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org,
linux-openrisc@vger.kernel.org
Subject: [PATCH RFC v3 17/21] mm/pgtable: optimize pmdp_get() and friends for folded pagetable levels
Date: Wed, 02 Sep 2026 12:56:19 +0100 [thread overview]
Message-ID: <20260902-dummy_ptxp3-v3-17-5d8f5b17c25c@arm.com> (raw)
In-Reply-To: <20260902-dummy_ptxp3-v3-0-5d8f5b17c25c@arm.com>
From: "David Hildenbrand (Arm)" <david@kernel.org>
Using pmdp_get() and friends in common code on a kernel config with
folded page tables is suboptimal: they default to a READ_ONCE(), forcing
the compiler to actually read that value even though it will not actually
be used afterwards.
This was recently reported by Christophe Leroy [1] and block conversion
of more common code to pmdp_get() and friends.
(using pgdp_get() as one example)
Most of the code ignores the result from pgdp_get() on configs with
folded page tables entirely, as it's hardcoded:
pgd_present()==1 && pgd_leaf()==false
Common code will just treat it as a "this is a page table" and call
p4d_offset() or p4d_offset_lockless() for the next lower level, where
the obtained pgdp_get() result is ignored entirely.
So, return a dummy value and avoid any memory reads.
There is a catch, though:
1) If code calls pgd_val() and somehow relies on the data, it would now
see dummy values. The code really must be aware of folded page table
levels. Fortunately, code usually ignores pgd_val() completely for
page tables (with ptdump being one exception when calculating
effective permissions). it's checked + fixed the x86 ptdump mechanism.
2) If code passes the pgd_t to a function that would work on the result,
it would now see dummy values. The only concern is really passing
the pgd_t on the stack as a pointer to p4d_offset(). Most code that
would do that, should actually use p4d_offset_lockless(), which
handles this properly. it's checked + fixed problematic instances.
3) Calling set_pgd() / pgd_page() / pgd_page_vaddr() with a pgd_t obtained through
pgdp_get(). There was once such case in riscv code with set_pgd(), which
is fixed.
As an example, this is the generated code for perf_get_page_size() with
PGTABLE_LEVELS=3 on arm64:
Before:
00000000000052a0 <perf_get_page_size>:
...
52dc: d53b4234 mrs x20, DAIF
52e0: d50343df msr DAIFSet, #0x3
...
52fc: d35e9a69 ubfx x9, x19, #30, #9 /* pud_offset_lockless() */
5300: f9403508 ldr x8, [x8, #0x68]
5304: f869790a ldr x10, [x8, x9, lsl #3] /* pudp_get() */
5308: f90007ea str x10, [sp, #0x8]
530c: f8697908 ldr x8, [x8, x9, lsl #3] /* pudp_get() */
...
5360: 90000009 adrp x9, 0x5000 <perf_prepare_sample+0x548>
5364: 92746908 and x8, x8, #0x7ffffff000
5368: d3557675 ubfx x21, x19, #21, #9 /* pmd_offset_lockless() */
...
5394: f8757ac8 ldr x8, [x22, x21, lsl #3] /* pmdp_get() */
After:
0000000000052a0 <perf_get_page_size>:
...
52dc: d53b4234 mrs x20, DAIF
52e0: d50343df msr DAIFSet, #0x3
... /* no pud_offset_lockless() and pudp_get() */
5318: 90000009 adrp x9, 0x5000 <perf_prepare_sample+0x548>
531c: 92746908 and x8, x8, #0x7ffffff000
5320: d3557675 ubfx x21, x19, #21, #9 /* pmd_offset_lockless() */
...
5334: f8757ac8 ldr x8, [x22, x21, lsl #3] /* pmdp_get() */
[1] https://lore.kernel.org/all/0019d675-ce3d-4a5c-89ed-f126c45145c9@kernel.org/
Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
---
include/asm-generic/pgtable-nop4d.h | 8 ++++++++
include/asm-generic/pgtable-nopmd.h | 8 ++++++++
include/asm-generic/pgtable-nopud.h | 8 ++++++++
3 files changed, 24 insertions(+)
diff --git a/include/asm-generic/pgtable-nop4d.h b/include/asm-generic/pgtable-nop4d.h
index 019c3f074b77..acd62ee23353 100644
--- a/include/asm-generic/pgtable-nop4d.h
+++ b/include/asm-generic/pgtable-nop4d.h
@@ -34,6 +34,14 @@ static inline bool pgd_leaf(pgd_t pgd) { return false; }
*/
#define set_pgd(pgdptr, pgdval) set_p4d((p4d_t *)(pgdptr), (p4d_t) { pgdval })
+static inline pgd_t pgdp_get(pgd_t *pgdp)
+{
+ pgd_t dummy = { 0 };
+
+ return dummy;
+}
+#define pgdp_get pgdp_get
+
static inline p4d_t *p4d_offset(pgd_t *pgd, unsigned long address)
{
return (p4d_t *)pgd;
diff --git a/include/asm-generic/pgtable-nopmd.h b/include/asm-generic/pgtable-nopmd.h
index 1dd5b165234b..9322f07ddf1e 100644
--- a/include/asm-generic/pgtable-nopmd.h
+++ b/include/asm-generic/pgtable-nopmd.h
@@ -43,6 +43,14 @@ static inline void pud_clear(pud_t *pud) { }
*/
#define set_pud(pudptr, pudval) set_pmd((pmd_t *)(pudptr), (pmd_t) { pudval })
+static inline pud_t pudp_get(pud_t *pudp)
+{
+ pud_t dummy = { 0 };
+
+ return dummy;
+}
+#define pudp_get pudp_get
+
static inline pmd_t * pmd_offset(pud_t * pud, unsigned long address)
{
return (pmd_t *)pud;
diff --git a/include/asm-generic/pgtable-nopud.h b/include/asm-generic/pgtable-nopud.h
index 5a2b0a81ae19..8f01abbb0050 100644
--- a/include/asm-generic/pgtable-nopud.h
+++ b/include/asm-generic/pgtable-nopud.h
@@ -41,6 +41,14 @@ static inline bool p4d_leaf(p4d_t p4d) { return false; }
*/
#define set_p4d(p4dptr, p4dval) set_pud((pud_t *)(p4dptr), (pud_t) { p4dval })
+static inline p4d_t p4dp_get(p4d_t *p4dp)
+{
+ p4d_t dummy = { 0 };
+
+ return dummy;
+}
+#define p4dp_get p4dp_get
+
static inline pud_t *pud_offset(p4d_t *p4d, unsigned long address)
{
return (pud_t *)p4d;
--
2.43.0
next prev parent reply other threads:[~2026-09-02 11:58 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 11:56 [PATCH RFC v3 00/21] mm: change behavior of pXdp_get()/pXd_page() in compile-time folded pgtable Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 01/21] ARM: mm: make nommu pgd_t a scalar Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 02/21] ARM: mm: make 2-level " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 03/21] ARM: mm: remove custom pgdp_get() Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 04/21] LoongArch: mm: define pud_leaf() only when PUD exists Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 05/21] MIPS: " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 06/21] mm/pgtable: define (pgd|p4d|pud)_leaf() for folded page tables Yeoreum Yun
2026-09-02 12:15 ` sashiko-bot
2026-09-02 11:56 ` [PATCH RFC v3 07/21] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 08/21] mm: vmscan: remove stack copy address of pud/pmd pass in walk_pud/pmd_range() Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 09/21] loongarch: kvm: remove stack copy address of pXd in pXd_offset() Yeoreum Yun
2026-09-02 12:19 ` sashiko-bot
2026-09-02 12:38 ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 10/21] riscv: " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 11/21] riscv: mm: use proper set_pXd() for generic compile-time folded patable in vmalloc_fault() Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 12/21] mm/pgtable: redefine PGTABLE_LEVEL enum with ascend order from PGD Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 13/21] x86: mm: use pgtable_level enum in effective_prot_pXd() Yeoreum Yun
2026-09-02 20:48 ` Dave Hansen
2026-09-02 11:56 ` [PATCH RFC v3 14/21] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() Yeoreum Yun
2026-09-02 20:46 ` Dave Hansen
2026-09-02 11:56 ` [PATCH RFC v3 15/21] x86: mm: skip collapse_pud_page() when CONFIG_X86_DIRECT_GBPAGES disabled Yeoreum Yun
2026-09-02 12:17 ` sashiko-bot
2026-09-02 12:29 ` Yeoreum Yun
2026-09-02 15:38 ` Dave Hansen
2026-09-02 16:48 ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 16/21] openrisc/pgtable: drop __pmd_offset() Yeoreum Yun
2026-09-02 11:56 ` Yeoreum Yun [this message]
2026-09-02 11:56 ` [PATCH RFC v3 18/21] mm/pgtable: catch abuse of folded dummy pgd_t/p4d_t/pud_t Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 19/21] mm/pgtable: disallow calling (pgd|p4d|pud)_page, pgd_page_vaddr() and (p4d|pud)_pgtable with dummy Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 20/21] mm/pgtable: disallow calling folded set_pgd/set_p4d/set_pud " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 21/21] Documentation: mm: clarify behaviour of compile-time folded page tables Yeoreum Yun
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902-dummy_ptxp3-v3-17-5d8f5b17c25c@arm.com \
--to=yeoreum.yun@arm.com \
--cc=akpm@linux-foundation.org \
--cc=alex@ghiti.fr \
--cc=anup@brainfault.org \
--cc=aou@eecs.berkeley.edu \
--cc=arnd@arndb.de \
--cc=atish.patra@linux.dev \
--cc=axelrasmussen@google.com \
--cc=baohua@kernel.org \
--cc=bp@alien8.de \
--cc=catalin.marinas@arm.com \
--cc=chenhuacai@kernel.org \
--cc=dave.hansen@linux.intel.com \
--cc=david@kernel.org \
--cc=hannes@cmpxchg.org \
--cc=hpa@zytor.com \
--cc=jonas@southpole.se \
--cc=kasong@tencent.com \
--cc=kernel@xen0n.name \
--cc=kvm-riscv@lists.infradead.org \
--cc=kvm@vger.kernel.org \
--cc=liam@infradead.org \
--cc=linux-arch@vger.kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mips@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-openrisc@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=linux@armlinux.org.uk \
--cc=ljs@kernel.org \
--cc=loongarch@lists.linux.dev \
--cc=luto@kernel.org \
--cc=maobibo@loongson.cn \
--cc=mhocko@kernel.org \
--cc=mhocko@suse.com \
--cc=mingo@redhat.com \
--cc=palmer@dabbelt.com \
--cc=peterz@infradead.org \
--cc=pjw@kernel.org \
--cc=qi.zheng@linux.dev \
--cc=rppt@kernel.org \
--cc=shakeel.butt@linux.dev \
--cc=shorne@gmail.com \
--cc=stefan.kristiansson@saunalahti.fi \
--cc=surenb@google.com \
--cc=tglx@kernel.org \
--cc=tsbogend@alpha.franken.de \
--cc=vbabka@kernel.org \
--cc=weixugc@google.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
--cc=yuanchu@google.com \
--cc=zhaotianrui@loongson.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox