From: Luigi Rizzo <lrizzo@google.com>
To: Luigi Rizzo <rizzo.unipi@gmail.com>,
Joerg Roedel <joro@8bytes.org>, Will Deacon <will@kernel.org>,
Robin Murphy <robin.murphy@arm.com>,
Christoph Hellwig <hch@lst.de>,
Marek Szyprowski <m.szyprowski@samsung.com>,
Andrew Morton <akpm@linux-foundation.org>,
Vlastimil Babka <vbabka@kernel.org>,
David Hildenbrand <david@kernel.org>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@kernel.org>,
Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
"Rafael J . Wysocki" <rafael@kernel.org>,
Danilo Krummrich <dakr@kernel.org>,
Jonathan Corbet <corbet@lwn.net>,
Jesper Dangaard Brouer <hawk@kernel.org>,
Ilias Apalodimas <ilias.apalodimas@linaro.org>,
Willem de Bruijn <willemb@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
Joshua Washington <joshwash@google.com>,
Harshitha Ramamurthy <hramamurthy@google.com>,
Saeed Mahameed <saeedm@nvidia.com>,
Tariq Toukan <tariqt@nvidia.com>,
Tony Nguyen <anthony.l.nguyen@intel.com>,
Przemek Kitszel <przemyslaw.kitszel@intel.com>,
Alexander Lobakin <aleksander.lobakin@intel.com>,
Michael Chan <michael.chan@broadcom.com>,
Pavan Chebbi <pavan.chebbi@broadcom.com>,
iommu@lists.linux.dev, netdev@vger.kernel.org,
linux-mm@kvack.org, driver-core@lists.linux.dev,
linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org,
Luigi Rizzo <lrizzo@google.com>
Subject: [RFC: DMA_PMD 03/22] mm: Add split_page_compound()
Date: Sat, 3 Oct 2026 21:22:22 +0000 [thread overview]
Message-ID: <20261003212241.3432303-4-lrizzo@google.com> (raw)
In-Reply-To: <20261003212241.3432303-1-lrizzo@google.com>
Add split_page_compound(), which splits an order-@old_order page into
independently refcounted order-@new_order compound pages (or order-0
pages when @new_order == 0). This is the high-order counterpart of
split_page(), used by DMA_PMD pools to carve PMD pages into smaller
compound blocks.
All resulting pieces are returned frozen (refcount 0) so the caller can
park them in a pool and publish each piece with page_ref_unfreeze(piece, 1)
when handed out.
Also add a KUnit test suite (CONFIG_SPLIT_PAGE_COMPOUND_KUNIT_TEST) in
mm/split_page_compound_kunit.c.
Signed-off-by: Luigi Rizzo <lrizzo@google.com>
---
include/linux/mm.h | 2 +
mm/Kconfig.debug | 11 ++++
mm/Makefile | 1 +
mm/page_alloc.c | 85 +++++++++++++++++++++++++
mm/split_page_compound_kunit.c | 113 +++++++++++++++++++++++++++++++++
5 files changed, 212 insertions(+)
create mode 100644 mm/split_page_compound_kunit.c
diff --git a/include/linux/mm.h b/include/linux/mm.h
index dd09c438fa23e..799a42005627f 100644
--- a/include/linux/mm.h
+++ b/include/linux/mm.h
@@ -1985,6 +1985,8 @@ static inline struct folio *virt_to_folio(const void *x)
void __folio_put(struct folio *folio);
void split_page(struct page *page, unsigned int order);
+int split_page_compound(struct page *page, unsigned int old_order,
+ unsigned int new_order);
void folio_copy(struct folio *dst, struct folio *src);
int folio_mc_copy(struct folio *dst, struct folio *src);
diff --git a/mm/Kconfig.debug b/mm/Kconfig.debug
index 15dca19dd07da..e1a04671c3b0d 100644
--- a/mm/Kconfig.debug
+++ b/mm/Kconfig.debug
@@ -347,3 +347,14 @@ config MEM_ALLOC_PROFILING_DEBUG
help
Adds warnings with helpful error messages for memory allocation
profiling.
+
+config SPLIT_PAGE_COMPOUND_KUNIT_TEST
+ bool "KUnit test for split_page_compound() (built-in)" if !KUNIT_ALL_TESTS
+ depends on KUNIT=y
+ default KUNIT_ALL_TESTS
+ help
+ Builds KUnit unit tests for split_page_compound() in mm/page_alloc.c,
+ verifying compound splitting, sub-block freezing, and speculative
+ reference handling.
+
+ If unsure, say N.
diff --git a/mm/Makefile b/mm/Makefile
index e7245cb88c665..448c0f5f783f3 100644
--- a/mm/Makefile
+++ b/mm/Makefile
@@ -148,3 +148,4 @@ obj-$(CONFIG_EXECMEM) += execmem.o
obj-$(CONFIG_TMPFS_QUOTA) += shmem_quota.o
obj-$(CONFIG_LAZY_MMU_MODE_KUNIT_TEST) += tests/lazy_mmu_mode_kunit.o
obj-$(CONFIG_MEM_ALLOC_PROFILING) += alloc_tag.o
+obj-$(CONFIG_SPLIT_PAGE_COMPOUND_KUNIT_TEST) += split_page_compound_kunit.o
diff --git a/mm/page_alloc.c b/mm/page_alloc.c
index e8e9905cdea5b..a663ec81a588b 100644
--- a/mm/page_alloc.c
+++ b/mm/page_alloc.c
@@ -3133,6 +3133,91 @@ void split_page(struct page *page, unsigned int order)
}
EXPORT_SYMBOL_GPL(split_page);
+/*
+ * split_page_compound() - split an order-@old_order page into compound pages
+ * of order @new_order
+ * @page: the page to split
+ * @old_order: the current order of @page
+ * @new_order: the order of the resulting pages
+ *
+ * Unlike split_page(), which produces order-0 pages, this produces
+ * 1 << (@old_order - @new_order) compound pages, each with its own head.
+ * @page must not be compound, and the caller must hold the only reference to
+ * it: the block is frozen while the new heads are built.
+ *
+ * All pieces (including @page at index 0) are returned frozen, with a zero
+ * refcount. Publish each piece with
+ * page_ref_unfreeze(piece, 1) before handing it out: its release store orders
+ * the compound layout built here against anyone who then observes the
+ * refcount. A relaxed set_page_count() would not, and on a weakly ordered
+ * machine a PFN walker could see a live refcount on a head whose layout is
+ * not visible yet.
+ *
+ * Memcg-charged pages are rejected: the accounting helpers assume a split
+ * produces order-0 pages and would mis-attribute the new compound heads.
+ *
+ * Return: 0 on success, -EINVAL if @page cannot be split or if @new_order is
+ * larger than @old_order, -EBUSY if anyone but the caller holds a reference
+ * to it.
+ */
+int split_page_compound(struct page *page, unsigned int old_order,
+ unsigned int new_order)
+{
+ unsigned int i, step = 1U << new_order, nr = 1U << old_order;
+
+ if (WARN_ON_ONCE(PageCompound(page) || !page_count(page)))
+ return -EINVAL;
+
+ if (WARN_ON_ONCE(new_order > old_order))
+ return -EINVAL;
+
+ if (WARN_ON_ONCE(memcg_kmem_online() && PageMemcgKmem(page)))
+ return -EINVAL;
+
+ /*
+ * Shape the new compound pages while the block is frozen, which is
+ * the order __alloc_pages_noprof() itself uses: prep_new_page()
+ * builds the page with a zero refcount and the set_page_refcounted()
+ * that follows is what makes it visible.
+ *
+ * Freezing stops a speculative PFN walker from resolving a compound
+ * page that is only half built: get_page_unless_zero() fails for as
+ * long as the layout below is being written. It does not order
+ * against memory_failure(), which sets PG_hwpoison before taking any
+ * reference, so the non-atomic __SetPageHead() below can still lose a
+ * concurrent poison bit - exactly as it can for every other
+ * prep_compound_page() caller, the page allocator included.
+ *
+ * A failed freeze is not a bug, it means someone holds a speculative
+ * reference. Every PFN walker in the tree gates
+ * get_page_unless_zero() on PageLRU, which a freshly allocated block
+ * is not, so in practice only the hwpoison machinery gets here. Let
+ * the caller fall back rather than warn: a machine running
+ * panic_on_warn should not die of a condition the caller handles.
+ */
+ if (!page_ref_freeze(page, 1))
+ return -EBUSY;
+
+ if (!new_order) {
+ /*
+ * The subpages of a non-compound block are already
+ * independent frozen pages, so only the bookkeeping applies.
+ */
+ split_page_owner(page, old_order, 0);
+ pgalloc_tag_split(page_folio(page), old_order, 0);
+ split_page_memcg(page, old_order);
+ return 0;
+ }
+
+ split_page_owner(page, old_order, new_order);
+ pgalloc_tag_split(page_folio(page), old_order, new_order);
+
+ for (i = 0; i < nr; i += step)
+ prep_compound_page(page + i, new_order);
+
+ return 0;
+}
+
int __isolate_free_page(struct page *page, unsigned int order)
{
struct zone *zone = page_zone(page);
diff --git a/mm/split_page_compound_kunit.c b/mm/split_page_compound_kunit.c
new file mode 100644
index 0000000000000..bb0ac908bbc1e
--- /dev/null
+++ b/mm/split_page_compound_kunit.c
@@ -0,0 +1,113 @@
+// SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
+/*
+ * KUnit tests for split_page_compound().
+ */
+#include <kunit/test.h>
+#include <linux/gfp.h>
+#include <linux/mm.h>
+
+static void test_split_compound_pieces(struct kunit *test)
+{
+ const unsigned int old_order = 5, new_order = 2;
+ const unsigned int step = 1U << new_order;
+ const unsigned int nr = 1U << old_order;
+ struct page *page;
+ unsigned int i, j;
+ int ret;
+
+ page = alloc_pages(GFP_KERNEL, old_order);
+ KUNIT_ASSERT_NOT_NULL(test, page);
+ KUNIT_EXPECT_FALSE(test, PageCompound(page));
+
+ ret = split_page_compound(page, old_order, new_order);
+ if (ret)
+ __free_pages(page, old_order);
+ KUNIT_ASSERT_EQ(test, ret, 0);
+
+ for (i = 0; i < nr; i += step) {
+ struct page *sub = page + i;
+
+ /* All heads 0..N-1 are returned frozen (refcount 0). */
+ KUNIT_EXPECT_EQ(test, page_count(sub), 0);
+ KUNIT_EXPECT_TRUE(test, PageHead(sub));
+ KUNIT_EXPECT_EQ(test, compound_order(sub), new_order);
+
+ for (j = 1; j < step; j++) {
+ KUNIT_EXPECT_TRUE(test, PageTail(sub + j));
+ KUNIT_EXPECT_PTR_EQ(test, compound_head(sub + j), sub);
+ }
+
+ page_ref_unfreeze(sub, 1);
+
+ /* Tail get_page()/put_page() must operate on this piece's head. */
+ get_page(sub + 1);
+ KUNIT_EXPECT_EQ(test, page_count(sub), 2);
+ put_page(sub + 1);
+ KUNIT_EXPECT_EQ(test, page_count(sub), 1);
+ }
+
+ /* Each compound piece frees independently at new_order. */
+ for (i = 0; i < nr; i += step)
+ __free_pages(page + i, new_order);
+}
+
+static void test_split_order0_pieces(struct kunit *test)
+{
+ const unsigned int old_order = 3, nr = 1U << old_order;
+ struct page *page;
+ unsigned int i;
+ int ret;
+
+ page = alloc_pages(GFP_KERNEL, old_order);
+ KUNIT_ASSERT_NOT_NULL(test, page);
+
+ ret = split_page_compound(page, old_order, 0);
+ if (ret)
+ __free_pages(page, old_order);
+ KUNIT_ASSERT_EQ(test, ret, 0);
+
+ for (i = 0; i < nr; i++) {
+ struct page *sub = page + i;
+
+ KUNIT_EXPECT_FALSE(test, PageCompound(sub));
+ KUNIT_EXPECT_EQ(test, page_count(sub), 0);
+ page_ref_unfreeze(sub, 1);
+ __free_pages(sub, 0);
+ }
+}
+
+static void test_split_ebusy_extra_ref(struct kunit *test)
+{
+ const unsigned int old_order = 4;
+ const unsigned int new_order = 2;
+ struct page *page;
+ int ret;
+
+ page = alloc_pages(GFP_KERNEL, old_order);
+ KUNIT_ASSERT_NOT_NULL(test, page);
+
+ /* Simulate a concurrent speculative reference. */
+ get_page(page);
+ ret = split_page_compound(page, old_order, new_order);
+ KUNIT_EXPECT_EQ(test, ret, -EBUSY);
+ KUNIT_EXPECT_FALSE(test, PageCompound(page));
+
+ put_page(page);
+ __free_pages(page, old_order);
+}
+
+static struct kunit_case split_page_compound_test_cases[] = {
+ KUNIT_CASE(test_split_compound_pieces),
+ KUNIT_CASE(test_split_order0_pieces),
+ KUNIT_CASE(test_split_ebusy_extra_ref),
+ {}
+};
+
+static struct kunit_suite split_page_compound_test_suite = {
+ .name = "split_page_compound",
+ .test_cases = split_page_compound_test_cases,
+};
+
+kunit_test_suite(split_page_compound_test_suite);
+MODULE_DESCRIPTION("KUnit tests for split_page_compound()");
+MODULE_LICENSE("Dual BSD/GPL");
--
2.56.0.rc1.315.gc6ed9934b7-goog
next prev parent reply other threads:[~2026-10-03 21:22 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 21:22 [RFC: DMA_PMD 00/22] DMA_PMD: PMD_SIZE-backed IO buffer pools Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 01/22] iommu/dma: introduce CONFIG_DMA_PMD and metadata table Luigi Rizzo
2026-10-03 21:44 ` Randy Dunlap
2026-10-04 9:14 ` Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 02/22] iommu/dma: add DMA_PMD pool lifecycle and page recycle hook Luigi Rizzo
2026-10-03 21:22 ` Luigi Rizzo [this message]
2026-10-03 21:22 ` [RFC: DMA_PMD 04/22] iommu/dma: add DMA_PMD pool block allocation Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 05/22] iommu/dma: Global cap and shrinker for DMA_PMD pool memory Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 06/22] iommu/dma: reserve a per-domain IOVA window for DMA_PMD pages Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 07/22] iommu/dma: release DMA_PMD domain mappings on domain teardown Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 08/22] iommu/dma: use per-domain IOVA window to map DMA_PMD memory Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 09/22] iommu/dma: Add DMA_PMD arena allocator Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 10/22] driver core: Add per-device dma_pmd_* sysfs attributes Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 11/22] dma-mapping: Use DMA_PMD arena for dma_alloc_attrs() Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 12/22] net/core: Use per-CPU DMA_PMD pools for skb_page_frag_refill() Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 13/22] net/core: Use DMA_PMD for page_pool memory Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 14/22] iommu/dma: Support decrypted and pinned DMA_PMD pages Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 15/22] iommu/dma: Add background page scrubber for DMA_PMD pools Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 16/22] iommu/dma: Add per-NUMA-node PMD page reservoir Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 17/22] net/gve: Use DMA_PMD memory for RX buffers Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 18/22] net/gve: Use DMA_PMD memory for tx header bounce buffers Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 19/22] net/mlx5e: " Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 20/22] net/idpf: " Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 21/22] net/bnxt: " Luigi Rizzo
2026-10-03 21:22 ` [RFC: DMA_PMD 22/22] iommu/dma: Add DMA_PMD statistics and debugfs Luigi Rizzo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003212241.3432303-4-lrizzo@google.com \
--to=lrizzo@google.com \
--cc=akpm@linux-foundation.org \
--cc=aleksander.lobakin@intel.com \
--cc=anthony.l.nguyen@intel.com \
--cc=corbet@lwn.net \
--cc=dakr@kernel.org \
--cc=davem@davemloft.net \
--cc=david@kernel.org \
--cc=driver-core@lists.linux.dev \
--cc=edumazet@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=hawk@kernel.org \
--cc=hch@lst.de \
--cc=hramamurthy@google.com \
--cc=ilias.apalodimas@linaro.org \
--cc=iommu@lists.linux.dev \
--cc=joro@8bytes.org \
--cc=joshwash@google.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=m.szyprowski@samsung.com \
--cc=michael.chan@broadcom.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pavan.chebbi@broadcom.com \
--cc=przemyslaw.kitszel@intel.com \
--cc=rafael@kernel.org \
--cc=rizzo.unipi@gmail.com \
--cc=robin.murphy@arm.com \
--cc=saeedm@nvidia.com \
--cc=tariqt@nvidia.com \
--cc=vbabka@kernel.org \
--cc=will@kernel.org \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox