From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 028273D5C31; Wed, 9 Sep 2026 09:24:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788945888; cv=none; b=K/TMX03kCktBr2qNCMfroKY9saf+aKIFNOoU4vH4S670bAXEZY674WqTmtmH2Z/4X0Rt7XKVb0HaXCVynNs63hCxFGGqsrUB++LZuN5h4vGgn8wbd4DZzV+5T018+65y4Mjz6uLDPVMYOG+Co1b27ZyIk+rOM++baeZ3G0sik7s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788945888; c=relaxed/simple; bh=9+bm5oEDo0srrI28L4tLmxJZ+mPiWBRVfLLAJe1RaA4=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Qr/MgyFTm9djIDUMjP4P2Mn2PjDuckG1OYA8GHp3x+0Fj+/XhnBxr3mx2LiHhY4hLPiZDY5Ch0LyVqiot+I8cFcmRQRWbetEfM3+6vwxh1XZ2Yq+y0bxXsnxMK6Xpy1Qr4eFJQRocQ43WbnkXtCtnTPbFTIFY2BDFKJ61NNTbYk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=WPCpNNRd; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="WPCpNNRd" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4B3641F00A3D; Wed, 9 Sep 2026 09:24:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1788945886; bh=nfrCF2g2kP9K2twlNtCkjBDUEX8FE2jfXjcc77olkz4=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=WPCpNNRdqmAOzJKeAhJyM/qgdzFD5BDME+mzm/D0LYvQ35AZoE4IRpxt25A1WsWHU sdtDrJ2SzE2rLe+38qA+kIZiPHpWx7DG5zabqjD8m1sFFCGh28tbh/24A8lpUJIFJA 90PNWxQUDtx1JhX6wZlw2KH++f/ocL2mGqqXk69QhjvNpTik/9nRjZtzYlg1RJ/Zvl 2+czxp/V1dBm2oQ0APDu3O2qm08FKwHORszxVq5qWcLy82Dh04OpvMPiPUpaNhJR8+ k+H4+6SF+XD0j+iaWt0h1ot8PSJlBtASdm2va8Gh1AI1D+S801KAs3R2kItf6C9Obz Kas5gMq8eNKdQ== Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfauth.ams.internal (Postfix) with ESMTP id 068B4198003A; Wed, 9 Sep 2026 05:24:24 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-05.internal (MEProxy); Wed, 09 Sep 2026 05:24:39 -0400 X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTFezydZ8FO8du2voecZC8AJNWBjGdsMbkEpRuZb1pJQCW8oQ/07jIMET6eEJr7fJk jK9b6/RVqplj/hwhlVFzNnuocUhGgqg++Dch+Fm39jov+euRCynPx3rDxn0l47uIcRTbRe l+xEzXbGBcRtTkTfbYEXOMv4wH/lwQzt9buwKydCbN0FMAoNRBVHjKw/0cNgJBZE1BhGh1 JIXdKXcVftccaMtpxVBgo74J6jWGt3VGDg3iw3wOFkhLBvYixt8JDYpFgoMYQzIsuuDFfO TmxjKB4+9FqzGw50TIvRfIkKnb0q9Uf+9J1G9dVByYDZGVfHLSHUlaveJL4gG3BOiwlNKu W94uMmoQw8nCimvgXUVlZxRFenvsExaDrMIxjkEpClNVWT8tTK0cUg3hfPedKUKzNTSxyw PQo3wSULgn+sr5Li/cuB2N6JbBdIRHieJsLH5DmSrr71RvsAofAw1M8uaPgyS5jmndiHxA zgS7f4oYsB34Klb9A5GIOP450BEQMbKt+S+wq27jxTPVFVkAOI0leIfTeRPDSAMJ/S5Cvj F+Dp6/7hHUv6nzA8YtErGhpxUI3elZWjTSI/dwCeUc77iE929sk0qwionLasDve2qpQnkr zdh7bJtqaOjuGUMpQqo0lzAFv6JNtn6CdttnT8jAZQyBSC+9JMBThNfmCvrw X-ME-Proxy: Feedback-ID: i10464835:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 9 Sep 2026 05:24:22 -0400 (EDT) Date: Wed, 9 Sep 2026 10:24:21 +0100 From: Kiryl Shutsemau To: "Lorenzo Stoakes (ARM)" Cc: Andrew Morton , David Hildenbrand , Zi Yan , Baolin Wang , "Liam R. Howlett" , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Lance Yang , Usama Arif , Guo Ren , Brian Cain , Geert Uytterhoeven , Dinh Nguyen , Simon Schuster , Jonas Bonn , Stefan Kristiansson , Stafford Horne , Yoshinori Sato , Rich Felker , John Paul Adrian Glaubitz , Paul Walmsley , Palmer Dabbelt , Albert Ou , Alexandre Ghiti , Russell King , Vineet Gupta , Michal Simek , Chris Zankel , Max Filippov , Will Deacon , "Aneesh Kumar K.V" , Nick Piggin , Peter Zijlstra , "David S. Miller" , Andreas Larsson , Richard Henderson , Matt Turner , Magnus Lindholm , Catalin Marinas , Mark Rutland , Huacai Chen , WANG Xuerui , Thomas Bogendoerfer , "James E.J. Bottomley" , Helge Deller , Madhavan Srinivasan , Michael Ellerman , "Christophe Leroy (CS GROUP)" , Heiko Carstens , Vasily Gorbik , Alexander Gordeev , Christian Borntraeger , Sven Schnelle , Richard Weinberger , Anton Ivanov , Johannes Berg , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Arnd Bergmann , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Jason Gunthorpe , John Hubbard , Peter Xu , linux-mm@kvack.org, linux-kernel@vger.kernel.org, linux-csky@vger.kernel.org, linux-hexagon@vger.kernel.org, linux-m68k@lists.linux-m68k.org, linux-openrisc@vger.kernel.org, linux-sh@vger.kernel.org, linux-riscv@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-snps-arc@lists.infradead.org, linux-arch@vger.kernel.org, sparclinux@vger.kernel.org, linux-alpha@vger.kernel.org, loongarch@lists.linux.dev, linux-mips@vger.kernel.org, linux-parisc@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-s390@vger.kernel.org, linux-um@lists.infradead.org, Hugh Dickins , Qi Zheng Subject: Re: [PATCH v2 12/12] mm: change the contract for free_pgtables(), update docs Message-ID: References: <20260908-rcu-pagetable-freeing-v2-0-1f60b64e878e@kernel.org> <20260908-rcu-pagetable-freeing-v2-12-1f60b64e878e@kernel.org> Precedence: bulk X-Mailing-List: linux-arch@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260908-rcu-pagetable-freeing-v2-12-1f60b64e878e@kernel.org> On Tue, Sep 08, 2026 at 01:32:21PM +0100, Lorenzo Stoakes (ARM) wrote: > Now that page tables are freed after an RCU grace period, it is safe for > read-only page table walkers to walk page table ranges that are being > concurrently torn down, provided the mm is kept alive via mmgrab(). > > It is however unsafe for writers to do so, as they must obtain an > appropriate lock to do so safely. > > Update the pte_offset_map_lock()'s comment block to reflect this. > > Similarly update the process addresses documentation. > > Signed-off-by: Lorenzo Stoakes (ARM) > --- > Documentation/mm/process_addrs.rst | 6 ++++++ > mm/pgtable-generic.c | 15 +++++++++++---- > 2 files changed, 17 insertions(+), 4 deletions(-) > > diff --git a/Documentation/mm/process_addrs.rst b/Documentation/mm/process_addrs.rst > index a7296f251799..1e65b139f355 100644 > --- a/Documentation/mm/process_addrs.rst > +++ b/Documentation/mm/process_addrs.rst > @@ -537,6 +537,12 @@ We establish basic locking rules when interacting with page tables: > * When changing a page table entry the page table lock for that page table > **must** be held, except if you can safely assume nobody can access the page > tables concurrently (such as on invocation of :c:func:`!free_pgtables`). > +* Page tables may be *walked* under RCU alone, as page tables are freed only > + after an RCU grace period has elapsed. However, any entry found must be > + revalidated after the page table lock is taken (such as the > + :c:func:`!pmd_same` recheck performed by :c:func:`!pte_offset_map_lock`) > + before it is acted upon. Changing an entry always requires the page table > + lock. This says the PTL plus a recheck is enough to act on the entry. It is not: free_pte_range() clears the PMD without the PTL, so pmd_same() can pass and the table is torn down right after. That is the case we settled on for the pte_offset_map_lock() comment, and the two now disagree. Something like "Changing an entry requires the page table lock and one of the locks that excludes teardown (mmap or VMA lock)" would match the comment. > * Reads from and writes to page table entries must be *appropriately* > atomic. See the section on atomicity below for details. > * Populating previously empty entries requires that the mmap or VMA locks are > diff --git a/mm/pgtable-generic.c b/mm/pgtable-generic.c > index b91b1a98029c..a127e3e8f9b9 100644 > --- a/mm/pgtable-generic.c > +++ b/mm/pgtable-generic.c > @@ -385,10 +385,17 @@ pte_t *pte_offset_map_rw_nolock(struct mm_struct *mm, pmd_t *pmd, > * Note: "RO" / "RW" expresses the intended semantics, not that the *kmap* will > * be read-only/read-write protected. > * > - * Note that free_pgtables(), used after unmapping detached vmas, or when > - * exiting the whole mm, does not take page table lock before freeing a page > - * table, and may not use RCU at all: "outsiders" like khugepaged should avoid > - * pte_offset_map() and co once the vma is detached from mm or mm_users is zero. > + * Note that free_pgtables(), used after unmapping detached vmas or when exiting > + * the whole mm, does not take a page table lock before freeing a page table. > + * > + * As page table freeing itself is RCU-safe, page table readers can safely run > + * concurrently with page table teardown. > + * > + * However, writers CANNOT as, without a lock being held, nothing prevents > + * concurrent teardown. > + * > + * Also note that the PGD itself is freed at mmdrop() time, not under RCU - so > + * the walker must keep the mm alive either by pinning the mm or the VMA. > */ > pte_t *pte_offset_map_lock(struct mm_struct *mm, pmd_t *pmd, > unsigned long addr, spinlock_t **ptlp) > > -- > 2.55.0 > -- Kiryl Shutsemau / Kirill A. Shutemov