Linux-mm Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
       [not found] <al4jGBGNG_QACaNL@sirena.org.uk>
@ 2026-07-20 14:41 ` Christoph Hellwig
  2026-07-20 14:46   ` Matthew Wilcox
  2026-07-20 21:58   ` Matthew Brost
  0 siblings, 2 replies; 9+ messages in thread
From: Christoph Hellwig @ 2026-07-20 14:41 UTC (permalink / raw)
  To: Mark Brown
  Cc: Andrew Morton, Christoph Hellwig, Linux Kernel Mailing List,
	Linux Next Mailing List, Matthew Brost, Hugh Dickins, Baolin Wang,
	linux-mm

On Mon, Jul 20, 2026 at 02:31:04PM +0100, Mark Brown wrote:
> Hi all,
> 
> Today's linux-next merge of the mm-unstable tree got a conflict in:
> 
>   drivers/gpu/drm/ttm/ttm_backup.c
> 
> between commit:
> 
>   a3fdf74ffa596 ("drm/ttm/pool: back up at native page order")
> 
> from the drm-misc-fixes tree and commit:
> 
>   c6bfdcf16f131 ("shmem: provide a shmem_write_folio wrapper")
> 
> from the mm-unstable tree.
> 
> I fixed it up (see below) and can carry the fix as necessary. This
> is now fixed as far as linux-next is concerned, but any non trivial
> conflicts should be mentioned to your upstream maintainer when your tree
> is submitted for merging.  You may also want to consider cooperating
> with the maintainer of the conflicting tree to minimise any particularly
> complex conflicts.

Much of the code here really should sit in shmem.c instead of having
random drivers/subsystems poke into the internals of shmem mappings
and folios.  But I feel like a broken record for saying that again
and again without any action :(

> 
> diff --combined drivers/gpu/drm/ttm/ttm_backup.c
> index 3c067aadc52de,c5b813a563e7f..0000000000000
> --- a/drivers/gpu/drm/ttm/ttm_backup.c
> +++ b/drivers/gpu/drm/ttm/ttm_backup.c
> @@@ -6,10 -6,9 +6,10 @@@
>   #include <drm/ttm/ttm_backup.h>
>   
>   #include <linux/export.h>
>  -#include <linux/page-flags.h>
>   #include <linux/swap.h>
>   
>  +#include "ttm_pool_internal.h"
>  +
>   /*
>    * Need to map shmem indices to handle since a handle value
>    * of 0 means error, following the swp_entry_t convention.
> @@@ -69,23 -68,17 +69,23 @@@ int ttm_backup_copy_page(struct file *b
>   }
>   
>   /**
>  - * ttm_backup_backup_page() - Backup a page
>  + * ttm_backup_backup_folio() - Backup a folio
>    * @backup: The struct backup pointer to use.
>  - * @page: The page to back up.
>  - * @writeback: Whether to perform immediate writeback of the page.
>  + * @folio: The folio to back up.
>  + * @order: The allocation order of @folio.  Since TTM allocates higher-order
>  + *         pages without __GFP_COMP, folio_nr_pages(@folio) would always
>  + *         return 1; the caller must pass the true order explicitly.
>  + * @writeback: Whether to perform immediate writeback of the folio's pages.
>    * This may have performance implications.
>  - * @idx: A unique integer for each page and each struct backup.
>  + * @idx: A unique integer for the first page of the folio and each struct backup.
>    * This allows the backup implementation to avoid managing
>    * its address space separately.
>  - * @page_gfp: The gfp value used when the page was allocated.
>  - * This is used for accounting purposes.
>  + * @folio_gfp: The gfp value used when the folio was allocated.
>  + * Currently unused.
>    * @alloc_gfp: The gfp to be used when allocating memory.
>  + * @nr_pages_backed: Output. On a successful return, set to the number of
>  + * pages actually backed up, which may be less than (1 << @order)
>  + * if an -ENOMEM was encountered mid-folio.
>    *
>    * Context: If called from reclaim context, the caller needs to
>    * assert that the shrinker gfp has __GFP_FS set, to avoid
> @@@ -94,87 -87,53 +94,87 @@@
>    * that the shrinker gfp has __GFP_IO set, since without it,
>    * we're not allowed to start backup IO.
>    *
>  - * Return: A handle on success. Negative error code on failure.
>  - *
>  - * Note: This function could be extended to back up a folio and
>  - * implementations would then split the folio internally if needed.
>  - * Drawback is that the caller would then have to keep track of
>  - * the folio size- and usage.
>  + * Return: A handle for the first backed-up page on success (handles for
>  + * subsequent pages follow sequentially). -ENOMEM if no pages could be backed
>  + * up. Any other negative error code if a non-ENOMEM failure occurred; in that
>  + * case any pages backed up so far are truncated before returning.
>    */
>   s64
>  -ttm_backup_backup_page(struct file *backup, struct page *page,
>  -		       bool writeback, pgoff_t idx, gfp_t page_gfp,
>  -		       gfp_t alloc_gfp)
>  +ttm_backup_backup_folio(struct file *backup, struct folio *folio,
>  +			unsigned int order, bool writeback, pgoff_t idx,
>  +			gfp_t folio_gfp, gfp_t alloc_gfp,
>  +			pgoff_t *nr_pages_backed)
>   {
>   	struct address_space *mapping = backup->f_mapping;
>  -	unsigned long handle = 0;
>  +	int nr_pages = 1 << order;
>   	struct folio *to_folio;
>  -	int ret;
>  +	int ret, i;
>   
>  -	to_folio = shmem_read_folio_gfp(mapping, idx, alloc_gfp);
>  -	if (IS_ERR(to_folio))
>  -		return PTR_ERR(to_folio);
>  +	*nr_pages_backed = 0;
>   
>  -	folio_mark_accessed(to_folio);
>  -	folio_lock(to_folio);
>  -	folio_mark_dirty(to_folio);
>  -	copy_highpage(folio_file_page(to_folio, idx), page);
>  -	handle = ttm_backup_shmem_idx_to_handle(idx);
>  +	for (i = 0; i < nr_pages; ) {
>  +		int to_nr, j;
>   
>  -	if (writeback && !folio_mapped(to_folio) &&
>  -	    folio_clear_dirty_for_io(to_folio)) {
>  -		folio_set_reclaim(to_folio);
>  -		ret = shmem_write_folio(to_folio);
>  -		if (!folio_test_writeback(to_folio))
>  -			folio_clear_reclaim(to_folio);
>   		/*
>  -		 * If writeout succeeds, it unlocks the folio.	errors
>  -		 * are otherwise dropped, since writeout is only best
>  -		 * effort here.
>  +		 * Only inject past the first subpage so *nr_pages_backed is
>  +		 * always > 0 here, matching a genuine mid-compound -ENOMEM
>  +		 * and driving the caller's reactive split fallback instead
>  +		 * of an early, no-progress failure.
>   		 */
>  -		if (ret)
>  +		if (IS_ENABLED(CONFIG_FAULT_INJECTION) && i &&
>  +		    ttm_backup_fault_inject_folio())
>  +			to_folio = ERR_PTR(-ENOMEM);
>  +		else
>  +			to_folio = shmem_read_folio_gfp(mapping, idx + i, alloc_gfp);
>  +		if (IS_ERR(to_folio)) {
>  +			int err = PTR_ERR(to_folio);
>  +
>  +			if (err == -ENOMEM && *nr_pages_backed)
>  +				return ttm_backup_shmem_idx_to_handle(idx);
>  +
>  +			if (*nr_pages_backed) {
>  +				shmem_truncate_range(file_inode(backup),
>  +						     (loff_t)idx << PAGE_SHIFT,
>  +						     ((loff_t)(idx + i) << PAGE_SHIFT) - 1);
>  +				/*
>  +				 * The pages just truncated are no longer
>  +				 * backed up; don't let the caller mistake
>  +				 * them for valid handles.
>  +				 */
>  +				*nr_pages_backed = 0;
>  +			}
>  +			return err;
>  +		}
>  +
>  +		to_nr = min_t(int, nr_pages - i,
>  +			      folio_next_index(to_folio) - (idx + i));
>  +
>  +		folio_mark_accessed(to_folio);
>  +		folio_lock(to_folio);
>  +		folio_mark_dirty(to_folio);
>  +
>  +		for (j = 0; j < to_nr; j++)
>  +			copy_highpage(folio_file_page(to_folio, idx + i + j),
>  +				      folio_page(folio, i + j));
>  +
>  +		if (writeback && !folio_mapped(to_folio) &&
>  +		    folio_clear_dirty_for_io(to_folio)) {
>  +			folio_set_reclaim(to_folio);
> ++			ret = shmem_write_folio(to_folio);
>  +			if (!folio_test_writeback(to_folio))
>  +				folio_clear_reclaim(to_folio);
>  +			if (ret == AOP_WRITEPAGE_ACTIVATE)
>  +				folio_unlock(to_folio);
>  +		} else {
>   			folio_unlock(to_folio);
>  -	} else {
>  -		folio_unlock(to_folio);
>  +		}
>  +
>  +		folio_put(to_folio);
>  +		i += to_nr;
>  +		*nr_pages_backed = i;
>   	}
>   
>  -	folio_put(to_folio);
>  -
>  -	return handle;
>  +	return ttm_backup_shmem_idx_to_handle(idx);
>   }
>   
>   /**


---end quoted text---


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-07-20 14:41 ` linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree Christoph Hellwig
@ 2026-07-20 14:46   ` Matthew Wilcox
  2026-07-20 22:08     ` Matthew Brost
  2026-07-20 21:58   ` Matthew Brost
  1 sibling, 1 reply; 9+ messages in thread
From: Matthew Wilcox @ 2026-07-20 14:46 UTC (permalink / raw)
  To: Christoph Hellwig
  Cc: Mark Brown, Andrew Morton, Linux Kernel Mailing List,
	Linux Next Mailing List, Matthew Brost, Hugh Dickins, Baolin Wang,
	linux-mm, Christian Koenig, Huang Rui, dri-devel

On Mon, Jul 20, 2026 at 04:41:41PM +0200, Christoph Hellwig wrote:
> >   /**
> >  - * ttm_backup_backup_page() - Backup a page
> >  + * ttm_backup_backup_folio() - Backup a folio
> >    * @backup: The struct backup pointer to use.
> >  - * @page: The page to back up.
> >  - * @writeback: Whether to perform immediate writeback of the page.
> >  + * @folio: The folio to back up.
> >  + * @order: The allocation order of @folio.  Since TTM allocates higher-order
> >  + *         pages without __GFP_COMP, folio_nr_pages(@folio) would always
> >  + *         return 1; the caller must pass the true order explicitly.

Wait, what?  This is just broken.  TTM should change to allocate using
GFP_COMP.  Why can't graphics people ask questions before writing stupid
patches?



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-07-20 14:41 ` linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree Christoph Hellwig
  2026-07-20 14:46   ` Matthew Wilcox
@ 2026-07-20 21:58   ` Matthew Brost
  2026-07-21  4:54     ` Christoph Hellwig
  1 sibling, 1 reply; 9+ messages in thread
From: Matthew Brost @ 2026-07-20 21:58 UTC (permalink / raw)
  To: Christoph Hellwig
  Cc: Mark Brown, Andrew Morton, Linux Kernel Mailing List,
	Linux Next Mailing List, Hugh Dickins, Baolin Wang, linux-mm

On Mon, Jul 20, 2026 at 04:41:41PM +0200, Christoph Hellwig wrote:
> On Mon, Jul 20, 2026 at 02:31:04PM +0100, Mark Brown wrote:
> > Hi all,
> > 
> > Today's linux-next merge of the mm-unstable tree got a conflict in:
> > 
> >   drivers/gpu/drm/ttm/ttm_backup.c
> > 
> > between commit:
> > 
> >   a3fdf74ffa596 ("drm/ttm/pool: back up at native page order")
> > 
> > from the drm-misc-fixes tree and commit:
> > 
> >   c6bfdcf16f131 ("shmem: provide a shmem_write_folio wrapper")
> > 
> > from the mm-unstable tree.
> > 
> > I fixed it up (see below) and can carry the fix as necessary. This
> > is now fixed as far as linux-next is concerned, but any non trivial
> > conflicts should be mentioned to your upstream maintainer when your tree
> > is submitted for merging.  You may also want to consider cooperating
> > with the maintainer of the conflicting tree to minimise any particularly
> > complex conflicts.
> 
> Much of the code here really should sit in shmem.c instead of having
> random drivers/subsystems poke into the internals of shmem mappings
> and folios.  But I feel like a broken record for saying that again
> and again without any action :(
> 

Do you have a suggestion of what parts to move over to shmem.c?

Pretty much all of this? I can take a look at this in a follow up?

Matt

> > 
> > diff --combined drivers/gpu/drm/ttm/ttm_backup.c
> > index 3c067aadc52de,c5b813a563e7f..0000000000000
> > --- a/drivers/gpu/drm/ttm/ttm_backup.c
> > +++ b/drivers/gpu/drm/ttm/ttm_backup.c
> > @@@ -6,10 -6,9 +6,10 @@@
> >   #include <drm/ttm/ttm_backup.h>
> >   
> >   #include <linux/export.h>
> >  -#include <linux/page-flags.h>
> >   #include <linux/swap.h>
> >   
> >  +#include "ttm_pool_internal.h"
> >  +
> >   /*
> >    * Need to map shmem indices to handle since a handle value
> >    * of 0 means error, following the swp_entry_t convention.
> > @@@ -69,23 -68,17 +69,23 @@@ int ttm_backup_copy_page(struct file *b
> >   }
> >   
> >   /**
> >  - * ttm_backup_backup_page() - Backup a page
> >  + * ttm_backup_backup_folio() - Backup a folio
> >    * @backup: The struct backup pointer to use.
> >  - * @page: The page to back up.
> >  - * @writeback: Whether to perform immediate writeback of the page.
> >  + * @folio: The folio to back up.
> >  + * @order: The allocation order of @folio.  Since TTM allocates higher-order
> >  + *         pages without __GFP_COMP, folio_nr_pages(@folio) would always
> >  + *         return 1; the caller must pass the true order explicitly.
> >  + * @writeback: Whether to perform immediate writeback of the folio's pages.
> >    * This may have performance implications.
> >  - * @idx: A unique integer for each page and each struct backup.
> >  + * @idx: A unique integer for the first page of the folio and each struct backup.
> >    * This allows the backup implementation to avoid managing
> >    * its address space separately.
> >  - * @page_gfp: The gfp value used when the page was allocated.
> >  - * This is used for accounting purposes.
> >  + * @folio_gfp: The gfp value used when the folio was allocated.
> >  + * Currently unused.
> >    * @alloc_gfp: The gfp to be used when allocating memory.
> >  + * @nr_pages_backed: Output. On a successful return, set to the number of
> >  + * pages actually backed up, which may be less than (1 << @order)
> >  + * if an -ENOMEM was encountered mid-folio.
> >    *
> >    * Context: If called from reclaim context, the caller needs to
> >    * assert that the shrinker gfp has __GFP_FS set, to avoid
> > @@@ -94,87 -87,53 +94,87 @@@
> >    * that the shrinker gfp has __GFP_IO set, since without it,
> >    * we're not allowed to start backup IO.
> >    *
> >  - * Return: A handle on success. Negative error code on failure.
> >  - *
> >  - * Note: This function could be extended to back up a folio and
> >  - * implementations would then split the folio internally if needed.
> >  - * Drawback is that the caller would then have to keep track of
> >  - * the folio size- and usage.
> >  + * Return: A handle for the first backed-up page on success (handles for
> >  + * subsequent pages follow sequentially). -ENOMEM if no pages could be backed
> >  + * up. Any other negative error code if a non-ENOMEM failure occurred; in that
> >  + * case any pages backed up so far are truncated before returning.
> >    */
> >   s64
> >  -ttm_backup_backup_page(struct file *backup, struct page *page,
> >  -		       bool writeback, pgoff_t idx, gfp_t page_gfp,
> >  -		       gfp_t alloc_gfp)
> >  +ttm_backup_backup_folio(struct file *backup, struct folio *folio,
> >  +			unsigned int order, bool writeback, pgoff_t idx,
> >  +			gfp_t folio_gfp, gfp_t alloc_gfp,
> >  +			pgoff_t *nr_pages_backed)
> >   {
> >   	struct address_space *mapping = backup->f_mapping;
> >  -	unsigned long handle = 0;
> >  +	int nr_pages = 1 << order;
> >   	struct folio *to_folio;
> >  -	int ret;
> >  +	int ret, i;
> >   
> >  -	to_folio = shmem_read_folio_gfp(mapping, idx, alloc_gfp);
> >  -	if (IS_ERR(to_folio))
> >  -		return PTR_ERR(to_folio);
> >  +	*nr_pages_backed = 0;
> >   
> >  -	folio_mark_accessed(to_folio);
> >  -	folio_lock(to_folio);
> >  -	folio_mark_dirty(to_folio);
> >  -	copy_highpage(folio_file_page(to_folio, idx), page);
> >  -	handle = ttm_backup_shmem_idx_to_handle(idx);
> >  +	for (i = 0; i < nr_pages; ) {
> >  +		int to_nr, j;
> >   
> >  -	if (writeback && !folio_mapped(to_folio) &&
> >  -	    folio_clear_dirty_for_io(to_folio)) {
> >  -		folio_set_reclaim(to_folio);
> >  -		ret = shmem_write_folio(to_folio);
> >  -		if (!folio_test_writeback(to_folio))
> >  -			folio_clear_reclaim(to_folio);
> >   		/*
> >  -		 * If writeout succeeds, it unlocks the folio.	errors
> >  -		 * are otherwise dropped, since writeout is only best
> >  -		 * effort here.
> >  +		 * Only inject past the first subpage so *nr_pages_backed is
> >  +		 * always > 0 here, matching a genuine mid-compound -ENOMEM
> >  +		 * and driving the caller's reactive split fallback instead
> >  +		 * of an early, no-progress failure.
> >   		 */
> >  -		if (ret)
> >  +		if (IS_ENABLED(CONFIG_FAULT_INJECTION) && i &&
> >  +		    ttm_backup_fault_inject_folio())
> >  +			to_folio = ERR_PTR(-ENOMEM);
> >  +		else
> >  +			to_folio = shmem_read_folio_gfp(mapping, idx + i, alloc_gfp);
> >  +		if (IS_ERR(to_folio)) {
> >  +			int err = PTR_ERR(to_folio);
> >  +
> >  +			if (err == -ENOMEM && *nr_pages_backed)
> >  +				return ttm_backup_shmem_idx_to_handle(idx);
> >  +
> >  +			if (*nr_pages_backed) {
> >  +				shmem_truncate_range(file_inode(backup),
> >  +						     (loff_t)idx << PAGE_SHIFT,
> >  +						     ((loff_t)(idx + i) << PAGE_SHIFT) - 1);
> >  +				/*
> >  +				 * The pages just truncated are no longer
> >  +				 * backed up; don't let the caller mistake
> >  +				 * them for valid handles.
> >  +				 */
> >  +				*nr_pages_backed = 0;
> >  +			}
> >  +			return err;
> >  +		}
> >  +
> >  +		to_nr = min_t(int, nr_pages - i,
> >  +			      folio_next_index(to_folio) - (idx + i));
> >  +
> >  +		folio_mark_accessed(to_folio);
> >  +		folio_lock(to_folio);
> >  +		folio_mark_dirty(to_folio);
> >  +
> >  +		for (j = 0; j < to_nr; j++)
> >  +			copy_highpage(folio_file_page(to_folio, idx + i + j),
> >  +				      folio_page(folio, i + j));
> >  +
> >  +		if (writeback && !folio_mapped(to_folio) &&
> >  +		    folio_clear_dirty_for_io(to_folio)) {
> >  +			folio_set_reclaim(to_folio);
> > ++			ret = shmem_write_folio(to_folio);
> >  +			if (!folio_test_writeback(to_folio))
> >  +				folio_clear_reclaim(to_folio);
> >  +			if (ret == AOP_WRITEPAGE_ACTIVATE)
> >  +				folio_unlock(to_folio);
> >  +		} else {
> >   			folio_unlock(to_folio);
> >  -	} else {
> >  -		folio_unlock(to_folio);
> >  +		}
> >  +
> >  +		folio_put(to_folio);
> >  +		i += to_nr;
> >  +		*nr_pages_backed = i;
> >   	}
> >   
> >  -	folio_put(to_folio);
> >  -
> >  -	return handle;
> >  +	return ttm_backup_shmem_idx_to_handle(idx);
> >   }
> >   
> >   /**
> 
> 
> ---end quoted text---


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-07-20 14:46   ` Matthew Wilcox
@ 2026-07-20 22:08     ` Matthew Brost
  2026-07-21 16:55       ` Matthew Brost
  0 siblings, 1 reply; 9+ messages in thread
From: Matthew Brost @ 2026-07-20 22:08 UTC (permalink / raw)
  To: Matthew Wilcox
  Cc: Christoph Hellwig, Mark Brown, Andrew Morton,
	Linux Kernel Mailing List, Linux Next Mailing List, Hugh Dickins,
	Baolin Wang, linux-mm, Christian Koenig, Huang Rui, dri-devel

On Mon, Jul 20, 2026 at 03:46:00PM +0100, Matthew Wilcox wrote:
> On Mon, Jul 20, 2026 at 04:41:41PM +0200, Christoph Hellwig wrote:
> > >   /**
> > >  - * ttm_backup_backup_page() - Backup a page
> > >  + * ttm_backup_backup_folio() - Backup a folio
> > >    * @backup: The struct backup pointer to use.
> > >  - * @page: The page to back up.
> > >  - * @writeback: Whether to perform immediate writeback of the page.
> > >  + * @folio: The folio to back up.
> > >  + * @order: The allocation order of @folio.  Since TTM allocates higher-order
> > >  + *         pages without __GFP_COMP, folio_nr_pages(@folio) would always
> > >  + *         return 1; the caller must pass the true order explicitly.
> 
> Wait, what?  This is just broken.  TTM should change to allocate using
> GFP_COMP.  Why can't graphics people ask questions before writing stupid
> patches?
> 

To be honest, I have no idea why TTM doesn't set GFP_COMP. This
predates my work in graphics by nearly a decade.

I found the following comment in TTM, which was added in this patch:
`git format-patch -1 bf9eee249ac20`

As far as I can tell, setting GFP_COMP would make things a lot easier in
a number of places.

Christian, who maintains TTM, is out for a couple of weeks, but this is
something we should probably take a closer look at.

Sorry for sending a stupid patch.

Matt


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-07-20 21:58   ` Matthew Brost
@ 2026-07-21  4:54     ` Christoph Hellwig
  2026-07-21  6:06       ` Matthew Brost
  0 siblings, 1 reply; 9+ messages in thread
From: Christoph Hellwig @ 2026-07-21  4:54 UTC (permalink / raw)
  To: Matthew Brost
  Cc: Christoph Hellwig, Mark Brown, Andrew Morton,
	Linux Kernel Mailing List, Linux Next Mailing List, Hugh Dickins,
	Baolin Wang, linux-mm

On Mon, Jul 20, 2026 at 02:58:34PM -0700, Matthew Brost wrote:
> Do you have a suggestion of what parts to move over to shmem.c?
> 
> Pretty much all of this?

That's my first guess.  Basically when using a shmem folio to store
data we should have the code dealing with it contained in the shmem
code except for well-defined APIs.

> I can take a look at this in a follow up?

That would be great.


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-07-21  4:54     ` Christoph Hellwig
@ 2026-07-21  6:06       ` Matthew Brost
  0 siblings, 0 replies; 9+ messages in thread
From: Matthew Brost @ 2026-07-21  6:06 UTC (permalink / raw)
  To: Christoph Hellwig
  Cc: Mark Brown, Andrew Morton, Linux Kernel Mailing List,
	Linux Next Mailing List, Hugh Dickins, Baolin Wang, linux-mm

On Tue, Jul 21, 2026 at 06:54:16AM +0200, Christoph Hellwig wrote:
> On Mon, Jul 20, 2026 at 02:58:34PM -0700, Matthew Brost wrote:
> > Do you have a suggestion of what parts to move over to shmem.c?
> > 
> > Pretty much all of this?
> 
> That's my first guess.  Basically when using a shmem folio to store
> data we should have the code dealing with it contained in the shmem
> code except for well-defined APIs.
>

After quickly typing something - I'm landing on basically everything in
shmem.c.

> > I can take a look at this in a follow up?
> 
> That would be great.

Will share something shortly.

Matt


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-07-20 22:08     ` Matthew Brost
@ 2026-07-21 16:55       ` Matthew Brost
  2026-08-03 12:55         ` Christian König
  0 siblings, 1 reply; 9+ messages in thread
From: Matthew Brost @ 2026-07-21 16:55 UTC (permalink / raw)
  To: Matthew Wilcox
  Cc: Christoph Hellwig, Mark Brown, Andrew Morton,
	Linux Kernel Mailing List, Linux Next Mailing List, Hugh Dickins,
	Baolin Wang, linux-mm, Christian Koenig, Huang Rui, dri-devel

On Mon, Jul 20, 2026 at 03:08:22PM -0700, Matthew Brost wrote:
> On Mon, Jul 20, 2026 at 03:46:00PM +0100, Matthew Wilcox wrote:
> > On Mon, Jul 20, 2026 at 04:41:41PM +0200, Christoph Hellwig wrote:
> > > >   /**
> > > >  - * ttm_backup_backup_page() - Backup a page
> > > >  + * ttm_backup_backup_folio() - Backup a folio
> > > >    * @backup: The struct backup pointer to use.
> > > >  - * @page: The page to back up.
> > > >  - * @writeback: Whether to perform immediate writeback of the page.
> > > >  + * @folio: The folio to back up.
> > > >  + * @order: The allocation order of @folio.  Since TTM allocates higher-order
> > > >  + *         pages without __GFP_COMP, folio_nr_pages(@folio) would always
> > > >  + *         return 1; the caller must pass the true order explicitly.
> > 
> > Wait, what?  This is just broken.  TTM should change to allocate using
> > GFP_COMP.  Why can't graphics people ask questions before writing stupid
> > patches?
> > 
> 
> To be honest, I have no idea why TTM doesn't set GFP_COMP. This
> predates my work in graphics by nearly a decade.
> 
> I found the following comment in TTM, which was added in this patch:
> `git format-patch -1 bf9eee249ac20`
> 
> As far as I can tell, setting GFP_COMP would make things a lot easier in
> a number of places.
> 
> Christian, who maintains TTM, is out for a couple of weeks, but this is
> something we should probably take a closer look at.
> 

I have looked into this a bit, changing TTM over to allocations with
GFP_COMP seems pretty straight forward. I have local patches that are
working with my driver (Xe), will post something shortly.

Matt

> Sorry for sending a stupid patch.
> 
> Matt


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-07-21 16:55       ` Matthew Brost
@ 2026-08-03 12:55         ` Christian König
  2026-08-03 19:02           ` Matthew Brost
  0 siblings, 1 reply; 9+ messages in thread
From: Christian König @ 2026-08-03 12:55 UTC (permalink / raw)
  To: Matthew Brost, Matthew Wilcox
  Cc: Christoph Hellwig, Mark Brown, Andrew Morton,
	Linux Kernel Mailing List, Linux Next Mailing List, Hugh Dickins,
	Baolin Wang, linux-mm, Huang Rui, dri-devel

On 7/21/26 18:55, Matthew Brost wrote:
> On Mon, Jul 20, 2026 at 03:08:22PM -0700, Matthew Brost wrote:
>> On Mon, Jul 20, 2026 at 03:46:00PM +0100, Matthew Wilcox wrote:
>>> On Mon, Jul 20, 2026 at 04:41:41PM +0200, Christoph Hellwig wrote:
>>>>>   /**
>>>>>  - * ttm_backup_backup_page() - Backup a page
>>>>>  + * ttm_backup_backup_folio() - Backup a folio
>>>>>    * @backup: The struct backup pointer to use.
>>>>>  - * @page: The page to back up.
>>>>>  - * @writeback: Whether to perform immediate writeback of the page.
>>>>>  + * @folio: The folio to back up.
>>>>>  + * @order: The allocation order of @folio.  Since TTM allocates higher-order
>>>>>  + *         pages without __GFP_COMP, folio_nr_pages(@folio) would always
>>>>>  + *         return 1; the caller must pass the true order explicitly.
>>>
>>> Wait, what?  This is just broken.  TTM should change to allocate using
>>> GFP_COMP.  Why can't graphics people ask questions before writing stupid
>>> patches?
>>>
>>
>> To be honest, I have no idea why TTM doesn't set GFP_COMP. This
>> predates my work in graphics by nearly a decade.

Oh, that is a rather long (and sad) story.

TTM (or GFX HW in general) has the requirement that a page once allocated as huge page must stay a huge page as long as it exists, in other words a page split is not possible.

This is not a problem per see because in theory there should never be a page split required for such allocations because we map everything into userspace using VM_PFNMAP and vmf_insert_pfn_prot(), so the special bit is set we don't have any direct I/O, swapping.....

>>
>> I found the following comment in TTM, which was added in this patch:
>> `git format-patch -1 bf9eee249ac20`
>>
>> As far as I can tell, setting GFP_COMP would make things a lot easier in
>> a number of places.
>>
>> Christian, who maintains TTM, is out for a couple of weeks, but this is
>> something we should probably take a closer look at.
>>
> 
> I have looked into this a bit, changing TTM over to allocations with
> GFP_COMP seems pretty straight forward. I have local patches that are
> working with my driver (Xe), will post something shortly.

Well it should work in TTM. The issue was (is?) that we had multiple other components in the kernel who got that completely wrong.

Especially KVM tried to grab a page reference from walking the page tables, ignoring the special bit in the PTE and then just incrementing the page reference from 0->1 and then later doing a put_page() into the middle of a huge page allocation.

Long story short that already resulted in multiple CVEs.

So yeah in theory we could use GFP_COMP here, but we need to make sure that this doesn't break anywhere else.

Regards,
Christian.

> 
> Matt
> 
>> Sorry for sending a stupid patch.
>>
>> Matt



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree
  2026-08-03 12:55         ` Christian König
@ 2026-08-03 19:02           ` Matthew Brost
  0 siblings, 0 replies; 9+ messages in thread
From: Matthew Brost @ 2026-08-03 19:02 UTC (permalink / raw)
  To: Christian König
  Cc: Matthew Wilcox, Christoph Hellwig, Mark Brown, Andrew Morton,
	Linux Kernel Mailing List, Linux Next Mailing List, Hugh Dickins,
	Baolin Wang, linux-mm, Huang Rui, dri-devel

On Mon, Aug 03, 2026 at 02:55:45PM +0200, Christian König wrote:
> On 7/21/26 18:55, Matthew Brost wrote:
> > On Mon, Jul 20, 2026 at 03:08:22PM -0700, Matthew Brost wrote:
> >> On Mon, Jul 20, 2026 at 03:46:00PM +0100, Matthew Wilcox wrote:
> >>> On Mon, Jul 20, 2026 at 04:41:41PM +0200, Christoph Hellwig wrote:
> >>>>>   /**
> >>>>>  - * ttm_backup_backup_page() - Backup a page
> >>>>>  + * ttm_backup_backup_folio() - Backup a folio
> >>>>>    * @backup: The struct backup pointer to use.
> >>>>>  - * @page: The page to back up.
> >>>>>  - * @writeback: Whether to perform immediate writeback of the page.
> >>>>>  + * @folio: The folio to back up.
> >>>>>  + * @order: The allocation order of @folio.  Since TTM allocates higher-order
> >>>>>  + *         pages without __GFP_COMP, folio_nr_pages(@folio) would always
> >>>>>  + *         return 1; the caller must pass the true order explicitly.
> >>>
> >>> Wait, what?  This is just broken.  TTM should change to allocate using
> >>> GFP_COMP.  Why can't graphics people ask questions before writing stupid
> >>> patches?
> >>>
> >>
> >> To be honest, I have no idea why TTM doesn't set GFP_COMP. This
> >> predates my work in graphics by nearly a decade.
> 
> Oh, that is a rather long (and sad) story.
> 
> TTM (or GFX HW in general) has the requirement that a page once allocated as huge page must stay a huge page as long as it exists, in other words a page split is not possible.
> 

Right, but I'd take it a step further: pages must remain resident (for
3D workloads) while DMA fences are attached to them (via the BO's
dma_resv).

That's why the pages are neither on the LRU nor rmappable. In other
words, everything is fully managed by TTM and the driver on the graphics
side.

> This is not a problem per see because in theory there should never be a page split required for such allocations because we map everything into userspace using VM_PFNMAP and vmf_insert_pfn_prot(), so the special bit is set we don't have any direct I/O, swapping.....
> 

Yes.

> >>
> >> I found the following comment in TTM, which was added in this patch:
> >> `git format-patch -1 bf9eee249ac20`
> >>
> >> As far as I can tell, setting GFP_COMP would make things a lot easier in
> >> a number of places.
> >>
> >> Christian, who maintains TTM, is out for a couple of weeks, but this is
> >> something we should probably take a closer look at.
> >>
> > 
> > I have looked into this a bit, changing TTM over to allocations with
> > GFP_COMP seems pretty straight forward. I have local patches that are
> > working with my driver (Xe), will post something shortly.
> 
> Well it should work in TTM. The issue was (is?) that we had multiple other components in the kernel who got that completely wrong.
> 

:(

> Especially KVM tried to grab a page reference from walking the page tables, ignoring the special bit in the PTE and then just incrementing the page reference from 0->1 and then later doing a put_page() into the middle of a huge page allocation.
> 

This does sound like a problem and a bit more clear than the comment in
the existing code.

> Long story short that already resulted in multiple CVEs.
> 
> So yeah in theory we could use GFP_COMP here, but we need to make sure that this doesn't break anywhere else.
> 

I haven't tested KVM or audited the entire kernel, so it's entirely
possible that my attempt to use GFP_COMP broke something. :(

It's probably worth investigating if this is still an issue. If it is,
we should at least update the comment in TTM to clearly explain what the
problem is.

Matt

> Regards,
> Christian.
> 
> > 
> > Matt
> > 
> >> Sorry for sending a stupid patch.
> >>
> >> Matt
> 


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-08-03 19:03 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <al4jGBGNG_QACaNL@sirena.org.uk>
2026-07-20 14:41 ` linux-next: manual merge of the mm-unstable tree with the drm-misc-fixes tree Christoph Hellwig
2026-07-20 14:46   ` Matthew Wilcox
2026-07-20 22:08     ` Matthew Brost
2026-07-21 16:55       ` Matthew Brost
2026-08-03 12:55         ` Christian König
2026-08-03 19:02           ` Matthew Brost
2026-07-20 21:58   ` Matthew Brost
2026-07-21  4:54     ` Christoph Hellwig
2026-07-21  6:06       ` Matthew Brost

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox