From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mta0.migadu.com (out-230.mta0.migadu.com [91.218.175.230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D2D840F759 for ; Mon, 24 Aug 2026 12:25:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.230 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787574348; cv=none; b=m9dDf80JZ9kteArsu0lpuGSTesvgkYd9ogagQRClHBtf6rXqz/ptZIbt8w9Opvl/zNN0gxjTOssurQ09bBuWF4Kci/HfHbws+wCXPfiqvSl4hJpCfljQEkPh/g8SPz+0vbi08+RgLBbbYGNeG+PCHUDqO2zntsO5N+vTIS3XTbQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787574348; c=relaxed/simple; bh=bByriFdYljnZ/ThpugvNwdIhIddEfJ2Jmu46aFYPFbo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mGVx64b44JfXxjjZLdYHedco5uZf0/WR3LIynKIpyokzUkPpVce0fgw1BWDcWT/7Bu6hi3/dp+KYS0s3Ed0wfmkMdSNfaR/VJP/h1nPDU2/9BFirHzfxm6lfcom0kYxqTP4luFgiZX0GRQZk/Tnn6T94LjOlorruwiJrzhQlfWo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=Bz1CRkA1; arc=none smtp.client-ip=91.218.175.230 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="Bz1CRkA1" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=bByriFdYljnZ/ThpugvNwdIhIddEfJ2Jmu46aFYPFbo=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787574342; v=1; x=1788179142; b=Bz1CRkA1jDNaiXfnDlocv3luqDArdg2Si3EgjfUTlLxUeaw7maAmFXS2Lk1UUtX7XjuJfWWW GSH1PD+A5LithIRLBwMyUxMV1U60QSsWBjSZRRbcQqmFdlZQkEBPV+0/72xKLOC0dIjCFwQGbKR v2qXeUWvVcOWG12hRSUcvHR4= X-Envelope-To: linux-kernel@vger.kernel.org Received: from fedora (117.129.78.49) by smtp.migadu.com with ESMTPS id 47db1fdcc048b7db; Mon, 24 Aug 2026 12:25:42 +0000 X-Mizu-Trace-ID: 47db1fdcc048b7db X-Migadu-Flow: FLOW_OUT From: Hao Li To: vbabka@kernel.org, harry@kernel.org, akpm@linux-foundation.org Cc: cl@gentwo.org, rientjes@google.com, roman.gushchin@linux.dev, linux-mm@kvack.org, linux-kernel@vger.kernel.org, Hao Li Subject: [RFC PATCH 1/2] mm/slub: make the case handling in __slab_free() easier to follow Date: Mon, 24 Aug 2026 20:25:09 +0800 Message-ID: <20260824122513.3829-1-hao.li@linux.dev> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260824122004.3652-1-hao.li@linux.dev> References: <20260824122004.3652-1-hao.li@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit There are 7 possible transitions in __slab_free(): a. partial->partial b. partial->empty, offlist c. partial->empty, onlist, exceeding min_partial d. partial->empty, onlist, not exceeding min_partial e. full->empty, exceeding min_partial f. full->empty, not exceeding min_partial g. full->partial (There is no offlist variant of e, f and g as a full slab is on no list.) Clarify which case each branch handles, and replace the goto with a return at the end of the skipped block so that every branch explicitly states its coverage. Case 'a' is the only path that needs neither list_lock nor list handling. Give it an early continue: handling it upfront is much clearer than forcing every other case into a nested block. Also, read SL_partial once after the loop right where it is used, rather than re-reading it on every iteration. No functional change. Signed-off-by: Hao Li --- mm/slub.c | 95 ++++++++++++++++++++++++++++--------------------------- 1 file changed, 49 insertions(+), 46 deletions(-) diff --git a/mm/slub.c b/mm/slub.c index b0cd0572e2f2..e20375307770 100644 --- a/mm/slub.c +++ b/mm/slub.c @@ -5748,76 +5748,79 @@ static void __slab_free(struct kmem_cache *s, struct slab *slab, new.inuse -= cnt; /* - * Might need to be taken off (due to becoming empty) or added - * to (due to not being full anymore) the partial list. - * Unless it's frozen. + * partial->partial: the slab was on the node partial list and + * stays there, so we need no list handling and no list_lock. + * + * Note that continue in a do-while goes on to evaluate the + * condition below, so we do perform the freelist update. */ - if (!new.inuse || was_full) { - - n = get_node(s, slab_nid(slab)); - /* - * Speculatively acquire the list_lock. - * If the cmpxchg does not succeed then we may - * drop the list_lock without any processing. - * - * Otherwise the list_lock will synchronize with - * other processors updating the list of slabs. - */ - spin_lock_irqsave(&n->list_lock, flags); + if (!was_full && new.inuse) + continue; - on_node_partial = slab_test_node_partial(slab); - } + /* + * The slab might need to be taken off (due to becoming empty) + * or added to (due to not being full anymore) the partial + * list. + * + * Speculatively acquire list_lock before calling cmpxchg(), as + * performing cmpxchg() prior to lock acquisition races with + * concurrent paths, such as the shrinker. + * + * If the cmpxchg does not succeed then we will drop the + * list_lock and retry. + */ + n = get_node(s, slab_nid(slab)); + spin_lock_irqsave(&n->list_lock, flags); } while (!slab_update_freelist(s, slab, &old, &new, "__slab_free")); if (likely(!n)) { + /* partial->partial: we didn't take the list_lock */ + return; + } + + on_node_partial = slab_test_node_partial(slab); + + if (!was_full && !on_node_partial) { /* - * We didn't take the list_lock because the slab was already on - * the partial list and will remain there. + * partial->empty, offlist: a bulk refill has taken the slab + * off the partial list and will put it back, so its list + * handling is not ours to do. */ + spin_unlock_irqrestore(&n->list_lock, flags); return; } - /* - * This slab was partially empty but not on the per-node partial list, - * in which case we shouldn't manipulate its list, just return. - */ - if (!was_full && !on_node_partial) { + /* full/partial->empty, exceed: we have enough partial slabs already */ + if (unlikely(!new.inuse && n->nr_partial >= s->min_partial)) { + /* partial->empty, onlist, exceed */ + if (likely(!was_full)) { + remove_partial(n, slab); + stat(s, FREE_REMOVE_PARTIAL); + } + /* full->empty, exceed: it is on no list to remove from */ + spin_unlock_irqrestore(&n->list_lock, flags); + stat(s, FREE_SLAB); + discard_slab(s, slab); return; } /* - * If slab became empty, should we add/keep it on the partial list or we - * have enough? + * At this point, only three cases remain: + * full->partial + * full->empty, not exceed + * partial->empty, onlist, not exceed */ - if (unlikely(!new.inuse && n->nr_partial >= s->min_partial)) - goto slab_empty; - /* - * Objects left in the slab. If it was not on the partial list before - * then add it. - */ + /* full->partial; full->empty, not exceed */ if (unlikely(was_full)) { add_partial(n, slab, ADD_TO_TAIL); stat(s, FREE_ADD_PARTIAL); } - spin_unlock_irqrestore(&n->list_lock, flags); - return; - -slab_empty: - /* - * The slab could have a single object and thus go from full to empty in - * a single free, but more likely it was on the partial list. Remove it. - */ - if (likely(!was_full)) { - remove_partial(n, slab); - stat(s, FREE_REMOVE_PARTIAL); - } + /* partial->empty, onlist, not exceed: it stays where it is */ spin_unlock_irqrestore(&n->list_lock, flags); - stat(s, FREE_SLAB); - discard_slab(s, slab); } /* -- 2.55.0