From: Baoquan He <baoquan.he@linux.dev>
To: kasong@tencent.com
Cc: linux-mm@kvack.org, Andrew Morton <akpm@linux-foundation.org>,
Barry Song <baohua@kernel.org>,
Axel Rasmussen <axelrasmussen@google.com>,
Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
Shakeel Butt <shakeel.butt@linux.dev>,
Johannes Weiner <hannes@cmpxchg.org>,
Michal Hocko <mhocko@kernel.org>,
Roman Gushchin <roman.gushchin@linux.dev>,
Muchun Song <muchun.song@linux.dev>, Chris Li <chrisl@kernel.org>,
Baolin Wang <baolin.wang@linux.alibaba.com>,
David Hildenbrand <david@kernel.org>,
Lorenzo Stoakes <ljs@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
Vlastimil Babka <vbabka@kernel.org>, Yu Zhao <yuzhao@google.com>,
Zi Yan <ziy@nvidia.com>, Qi Zheng <qi.zheng@linux.dev>,
cgroups@vger.kernel.org, linux-kernel@vger.kernel.org,
Kairui Song <ryncsn@gmail.com>
Subject: Re: [PATCH 7/7] mm/mglru: improve code readability and harden folio_inc_gen
Date: Thu, 20 Aug 2026 08:53:35 +0800 [thread overview]
Message-ID: <aoZQD3b6q8s-pXU0@MiWiFi-R3L-srv> (raw)
In-Reply-To: <20260818-mglru-flags-cleanup-v1-7-8dbbdac0d28c@tencent.com>
On 08/18/26 at 01:38pm, Kairui Song via B4 Relay wrote:
> From: Kairui Song <kasong@tencent.com>
>
> The helper should never be called for an off-list folio, and it always
> expects the folio to be in the oldest generation before doing any
> cmpxchg. Add a sanity check for the off-list case: if it is ever
> violated, bail out and keep the folio flags untouched to minimize the
> damage, instead of silently treating the folio as if it were in the
> oldest generation and promoting it updating the flags to an unexpected
> status.
>
> Also rename the variables to clearly distinguish the folio's current
> gen from the oldest gen.
>
> Signed-off-by: Kairui Song <kasong@tencent.com>
> ---
> mm/vmscan.c | 14 +++++++++-----
> 1 file changed, 9 insertions(+), 5 deletions(-)
>
> diff --git a/mm/vmscan.c b/mm/vmscan.c
> index 7169cac60869..7e3ae0c6cba3 100644
> --- a/mm/vmscan.c
> +++ b/mm/vmscan.c
> @@ -3308,18 +3308,22 @@ static int folio_inc_gen(struct lruvec *lruvec, struct folio *folio)
> {
> int type = folio_is_file_lru(folio);
> struct lru_gen_folio *lrugen = &lruvec->lrugen;
> - int new_gen, old_gen = lru_gen_from_seq(lrugen->min_seq[type]);
> + int new_gen, old_gen, min_gen = lru_gen_from_seq(lrugen->min_seq[type]);
> unsigned long new_flags, old_flags = READ_ONCE(*folio_flags(folio, 0));
>
> do {
> - new_gen = lru_gen_from_flags(old_flags);
> + old_gen = lru_gen_from_flags(old_flags);
> + /* This helper should never be called for off-list folios */
> + VM_WARN_ON_ONCE(old_gen < 0);
> + if (old_gen < 0)
> + return min_gen;
As Barry doubted, I think this change is wrong. old_gen < 0 in folio_inc_gen()
could only happen inc_min_seq() call it. While inc_min_seq() call it
because inc_max_seq() need increase max_gen to max_gen + 1 and found
get_nr_gens(lruvec, type) == MAX_NR_GENS, it has to move the oldest gen to
2nd old oldest gen. Here returning min_gen for old_gen < 0 means it will
be put in the lastest max_gen. It may not be expected.
>
> /* folio_update_gen() has promoted this page? */
> - if (new_gen >= 0 && new_gen != old_gen)
> - return new_gen;
> + if (old_gen != min_gen)
> + return old_gen;
>
> new_flags = old_flags;
> - new_gen = (old_gen + 1) % MAX_NR_GENS;
> + new_gen = (min_gen + 1) % MAX_NR_GENS;
> lru_gen_set_flags(&new_flags, new_gen);
> lru_refs_set_flags(&new_flags, 0);
> } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags));
>
> --
> 2.55.0
>
>
next prev parent reply other threads:[~2026-08-20 0:53 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-18 5:38 [PATCH 0/7] mm/mglru: clean up folio counters and flag usage Kairui Song via B4 Relay
2026-08-18 5:38 ` [PATCH 1/7] mm/memcontrol: make lru_zone_size atomic and simplify sanity check Kairui Song via B4 Relay
2026-08-19 2:05 ` Ridong Chen
2026-08-18 5:38 ` [PATCH 2/7] mm/mglru: introduce helpers for manipulating gen and refs flags Kairui Song via B4 Relay
2026-08-19 9:03 ` Baolin Wang
2026-08-19 9:37 ` Kairui Song
2026-08-19 9:46 ` Baolin Wang
2026-08-19 9:49 ` Kairui Song
2026-08-20 1:43 ` Ridong Chen
2026-08-20 2:04 ` Ridong Chen
2026-08-20 2:05 ` Ridong Chen
2026-08-18 5:38 ` [PATCH 3/7] mm/migrate: copy the referenced state via folio_migrate_refs() Kairui Song via B4 Relay
2026-08-19 10:12 ` Baoquan He
2026-08-18 5:38 ` [PATCH 4/7] mm/mglru: move max_seq read into walk_update_folio Kairui Song via B4 Relay
2026-08-19 9:18 ` Baolin Wang
2026-08-20 2:13 ` Ridong Chen
2026-08-18 5:38 ` [PATCH 5/7] mm/mglru: use explicit tier range in read_ctrl_pos() Kairui Song via B4 Relay
2026-08-19 9:25 ` Baolin Wang
2026-08-19 10:16 ` Baoquan He
2026-08-19 21:24 ` Barry Song
2026-08-20 2:33 ` Ridong Chen
2026-08-20 3:22 ` Kairui Song
2026-08-18 5:38 ` [PATCH 6/7] mm/mglru: fix potential generation folio number leak Kairui Song via B4 Relay
2026-08-20 1:52 ` Baolin Wang
2026-08-20 3:45 ` Kairui Song
2026-08-20 8:53 ` Baolin Wang
2026-08-18 5:38 ` [PATCH 7/7] mm/mglru: improve code readability and harden folio_inc_gen Kairui Song via B4 Relay
2026-08-19 21:30 ` Barry Song
2026-08-20 0:53 ` Baoquan He [this message]
2026-08-20 0:57 ` Baoquan He
2026-08-20 1:02 ` Baolin Wang
2026-08-20 2:11 ` Kairui Song
2026-08-20 2:27 ` Baoquan He
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aoZQD3b6q8s-pXU0@MiWiFi-R3L-srv \
--to=baoquan.he@linux.dev \
--cc=akpm@linux-foundation.org \
--cc=axelrasmussen@google.com \
--cc=baohua@kernel.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=cgroups@vger.kernel.org \
--cc=chrisl@kernel.org \
--cc=david@kernel.org \
--cc=hannes@cmpxchg.org \
--cc=kasong@tencent.com \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=mhocko@kernel.org \
--cc=muchun.song@linux.dev \
--cc=qi.zheng@linux.dev \
--cc=roman.gushchin@linux.dev \
--cc=ryncsn@gmail.com \
--cc=shakeel.butt@linux.dev \
--cc=vbabka@kernel.org \
--cc=weixugc@google.com \
--cc=yuanchu@google.com \
--cc=yuzhao@google.com \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox