From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj2-f40.google.com (mail-pj2-f40.google.com [74.125.227.168]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 00B354052AA for ; Wed, 30 Sep 2026 14:08:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.168 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790777316; cv=none; b=Z/XfonoolxVoJIsroDQ6M+x3cSkEywgHgPOlFxfQahS2F7BxfCig9Hwm3R4JnwuCNFfOGH303AMe97aTcDsnnvixeeWj9c+vVAdV3bC+XjQYYcuTthbsJ8BmqhF1HA6JOhldwzIBFFB+byRF9pmCxc9phmrYUpCX7yc0safx7Ys= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790777316; c=relaxed/simple; bh=1AyjrPgQx/nxKqq6UcTsTHWPWznPqAjy5hY1ijksJUw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=BCSHUiKRPar2q/GQYdaOsKQn7wCGWzFhMBtZaMwNVNEa23V0M3vFN/yHKuj5nqROwRqgrMEYTCLv+fNzvm0LIipD/sRjDItUbvticfdDRh1uDX7AR1o+/oQNx7tZcuMLW9a55ab3CBxfhpqZsHCEqeaFLlCRFkOGSKPxRhr2McM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=B3A8VACv; arc=none smtp.client-ip=74.125.227.168 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="B3A8VACv" Received: by mail-pj2-f40.google.com with SMTP id 98e67ed59e1d1-3a2adb9bc3cso2054973a91.2 for ; Wed, 30 Sep 2026 07:08:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bytedance.com; s=google; t=1790777296; x=1791382096; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=mwIkzvmvri0jNuEZQ8eiZ6f7IsoamN6cu2j85HlYjLQ=; b=B3A8VACvJy6bN+3JoFkK+lshIX+L0O7QeIYS+lRrG+9eU9zEh7qOON6dTcS/F4mTE5 kVvqq8dV9jmFCUWC8p0a8vMfN0f0MivflyVA25t0G7PYkYGDx5pBhzPqNEFJIuYzjck+ GLJjMJCyDjDHScg32cpS5nZgDiGlHf6gh/Ts9utfgZHcBP9lAcA5iM/K2f5lgndMT+Rf S7Drr+FOG83UvVbMUVBDCjfdoIjeu3SzRPycl++rLy4J/EVTGC4LKeBel7SKeQ3e8sAY M+tRWoSUgJjSAA5DiBDzFOg20U3CJHyZ0FVq/qybP7KMS+JkuvBQtQhFz8UAQZd3EHi1 Cb+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790777296; x=1791382096; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=mwIkzvmvri0jNuEZQ8eiZ6f7IsoamN6cu2j85HlYjLQ=; b=RO+KoDZu4rwNcYyN+l5gewf0oKQuCGGcxHZXRxiPeDxFg0tv8k/zP8q19XYgE33K1n NL0MR1RWaKzUkjAMa/qojUrZTFrjPodz4TV7siH9u/9GEgD/KZ+deERBcugtTANOXzqh r8K01YQACZf2M+lmC/LZBvY1Pb5o7nIB/dKpggrNJtQlPS10z8jvTrdO+282qv80Pldf aZytOJmXY3fgBBvZOhNXGvwlpljFFqmfYxBU4C8+/VvbvuPTXsX/Kcw8GPyCImhzuKTF mRG85h063X7l1JTAmB1vTVkalLSfZbPA79rvb1lpghDtx/P+F+HlO44Z/i4KTJUj1V5O 7qnQ== X-Forwarded-Encrypted: i=1; AKwUvBwAJh+aZ8h9Mm8ctEF+FWpC04rivrGn0LW61+4Kj712JjBVHkw6g03vOeJVzXuQDyj3YTdTiYNpfPCmuzo=@vger.kernel.org X-Gm-Message-State: AFq9FYIiQ7u8djevjnY4UQRS+tA4l+AS9gwg/kw2K4MPHK/ix9D7hq8F 2pajRtzrooy/bgE3/k/omDAQCsttyXEGrBjCtKKblhJvEw02qmVTFy7EnVr7NbikJTg= X-Gm-Gg: AYBFou0n/65SeQ6/STPvLIrYuMjl7QzTmDxP9pSb0b87AeLS3JaqIHdFrrQaTAXxcZu rLAR6lc9C259edfd5Re2lhNv0Rhg9c76WZvx1mJbrYJTXYM+7P/CC8XmcAq1QCr7ghdPwXj+/FY fYEU1lr67dmQ++xRYV+SIsGlORbTpl4uZjBaemYWaehqPUH0i1goVM2GCcUyYvt50iLqIlayJnD BdSd3zoz7H7LHC931rXpEceAQhTyiVvHaHqvXINT+Pmvb0yYRRgLkZjkkdigAaoIW8N5w7/gT9O fBgzcpKE9ERyPgPBAJFU7CYQ2sZwFOimPkJuGxW1tYMwViMopUcPdC8xKqNjjGnpyUkM3OX3444 GFaFSU205a6Soioog4qSQahMjbZgqn0lyQLn9PktzvxwFHsfylKAew0e/suCrIFBovrpwXEt0qn Vw9cEA1PFwc/LxcsKoL5HE/cQYkGLpIjz3LCPaV4pWHGghR2b5JRbkaSDz8/my5aATkInLpKe3Z aAyadvOaDp2jQ== X-Received: by 2002:a17:90b:4b11:b0:3a0:d79d:b6bf with SMTP id 98e67ed59e1d1-3a4d14de36bmr642331a91.20.1790777295537; Wed, 30 Sep 2026 07:08:15 -0700 (PDT) Received: from G6L4RL2QG9 ([139.177.225.238]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a4e60ea12csm639509a91.1.2026.09.30.07.08.07 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 30 Sep 2026 07:08:14 -0700 (PDT) From: Muchun Song To: Andrew Morton , David Hildenbrand , Oscar Salvador , Madhavan Srinivasan , Michael Ellerman , Jonathan Corbet Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-doc@vger.kernel.org, Muchun Song , Lorenzo Stoakes , Mike Rapoport , Qi Zheng , Nicholas Piggin , Christophe Leroy , Ritesh Harjani , Shrikanth Hegde , Randy Dunlap , Muchun Song , Lance Yang Subject: [PATCH v6 07/12] mm/sparse-vmemmap: switch device DAX to shared tail vmemmap pages Date: Wed, 30 Sep 2026 22:06:22 +0800 Message-ID: <20260930140627.57431-8-songmuchun@bytedance.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260930140627.57431-1-songmuchun@bytedance.com> References: <20260930140627.57431-1-songmuchun@bytedance.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit HugeTLB vmemmap optimization now uses per-zone shared tail vmemmap pages. Device DAX has not been switched to that mechanism yet. Switch device DAX to vmemmap_shared_tail_page() as well. This aligns DAX with HugeTLB by using the common per-zone shared tail vmemmap page. The optimization is enabled only for DEV-DAX through pgmap->vmemmap_shift, which supplies the compound page order recorded in section metadata before vmemmap population. Unlike FS-DAX, DEV-DAX does not modify tail struct pages, so sharing them is safe. Since the shared tail page can now back ZONE_DEVICE vmemmap mappings, initialize its entries with PG_reserved for device zones. Also skip poisoning vmemmap-optimizable sections while their struct pages may be shared. Each PTE mapping the shared device DAX tail page takes a page reference. A sufficiently large range could therefore cycle the reference count back to zero if population were allowed to continue after it became non-positive. Use try_get_page() so further mappings fail at that point. The section population error path tears down mappings created for the failed section, while the warning makes this currently impractical limit visible. Signed-off-by: Muchun Song Acked-by: Qi Zheng --- v6: - Prevent shared DAX tail-page refcount overflow with try_get_page() (suggested by Andrew Morton) - Make order const and move it to the top of the function (suggested by David Hildenbrand) - Clarify why optimized tail pages must not be poisoned (suggested by David Hildenbrand) v3: - Move device_zone() after the definition of NODE_DATA() to fix non-NUMA builds. - Update the commit message to describe the compound page order stored in section metadata - Collect Acked-by from Qi Zheng v2: - Explain why sharing tail vmemmap pages is safe for DEV-DAX (suggested by Qi Zheng) --- include/linux/mmzone.h | 10 +++++++ mm/memory_hotplug.c | 6 ++-- mm/sparse-vmemmap.c | 63 +++++++++++++++++------------------------- 3 files changed, 40 insertions(+), 39 deletions(-) diff --git a/include/linux/mmzone.h b/include/linux/mmzone.h index ee9cbaaa63f4..cd68c1904c91 100644 --- a/include/linux/mmzone.h +++ b/include/linux/mmzone.h @@ -2143,11 +2143,21 @@ static inline int online_device_section(const struct mem_section *section) return section && ((section->section_mem_map & flags) == flags); } + +static inline struct zone *device_zone(int nid) +{ + return &NODE_DATA(nid)->node_zones[ZONE_DEVICE]; +} #else static inline int online_device_section(const struct mem_section *section) { return 0; } + +static inline struct zone *device_zone(int nid) +{ + return NULL; +} #endif static inline int online_section_nr(unsigned long nr) diff --git a/mm/memory_hotplug.c b/mm/memory_hotplug.c index b428da66d279..d7a59167bec4 100644 --- a/mm/memory_hotplug.c +++ b/mm/memory_hotplug.c @@ -43,6 +43,7 @@ #include "mm_init.h" #include "page_alloc.h" #include "shuffle.h" +#include "sparse.h" enum { MEMMAP_ON_MEMORY_DISABLE = 0, @@ -554,8 +555,9 @@ void remove_pfn_range_from_zone(struct zone *zone, /* Select all remaining pages up to the next section boundary */ cur_nr_pages = min(end_pfn - pfn, SECTION_ALIGN_UP(pfn + 1) - pfn); - page_init_poison(pfn_to_page(pfn), - sizeof(struct page) * cur_nr_pages); + if (!section_vmemmap_optimizable(__pfn_to_section(pfn))) + page_init_poison(pfn_to_page(pfn), + sizeof(struct page) * cur_nr_pages); } /* diff --git a/mm/sparse-vmemmap.c b/mm/sparse-vmemmap.c index 26be355aaa37..d40a2f5b5fca 100644 --- a/mm/sparse-vmemmap.c +++ b/mm/sparse-vmemmap.c @@ -225,6 +225,8 @@ struct page __ref *vmemmap_shared_tail_page(unsigned int order, struct zone *zon set_page_node(page, zone_to_nid(zone)); set_page_zone(page, zone_idx(zone)); prep_compound_tail(page, NULL, order); + if (zone_is_zone_device(zone)) + __SetPageReserved(page); } page = virt_to_page(addr); @@ -288,14 +290,18 @@ static pte_t * __meminit vmemmap_pte_populate(pmd_t *pmd, unsigned long addr, in /* * When a PTE/PMD entry is freed from the init_mm * there's a free_pages() call to this page allocated - * above. Thus this get_page() is paired with the + * above. Thus this try_get_page() is paired with the * put_page_testzero() on the freeing path. * This can only called by certain ZONE_DEVICE path, * and through vmemmap_populate_compound_pages() when * slab is available. + * + * Use try_get_page() to prevent the shared page refcount + * from overflowing. */ - if (flags & VMEMMAP_POPULATE_DAX) - get_page(pfn_to_page(ptpfn)); + if ((flags & VMEMMAP_POPULATE_DAX) && + !try_get_page(pfn_to_page(ptpfn))) + return NULL; } entry = pfn_pte(ptpfn, PAGE_KERNEL); set_pte_at(&init_mm, addr, pte, entry); @@ -529,47 +535,27 @@ static bool __meminit reuse_compound_section(unsigned long start_pfn, return !IS_ALIGNED(offset, nr_pages) && nr_pages > PAGES_PER_SUBSECTION; } -static pte_t * __meminit compound_section_tail_page(unsigned long addr) -{ - pte_t *pte; - - addr -= PAGE_SIZE; - - /* - * Assuming sections are populated sequentially, the previous section's - * page data can be reused. - */ - pte = pte_offset_kernel(pmd_off_k(addr), addr); - if (!pte) - return NULL; - - return pte; -} - static int __meminit vmemmap_populate_compound_pages(unsigned long start_pfn, unsigned long start, unsigned long end, int node, struct dev_pagemap *pgmap) { const unsigned long flags = VMEMMAP_POPULATE_DAX; + const unsigned int order = pfn_to_section_compound_order(start_pfn); unsigned long size, addr; pte_t *pte; + struct page *page; int rc; - if (reuse_compound_section(start_pfn, pgmap)) { - pte = compound_section_tail_page(start); - if (!pte) - return -ENOMEM; + page = vmemmap_shared_tail_page(order, device_zone(node)); + if (!page) + return -ENOMEM; - /* - * Reuse the page that was populated in the prior iteration - * with just tail struct pages. - */ + if (reuse_compound_section(start_pfn, pgmap)) return vmemmap_populate_range(start, end, node, NULL, - pte_pfn(ptep_get(pte)), flags); - } + page_to_pfn(page), flags); - size = min(end - start, pgmap_vmemmap_nr(pgmap) * sizeof(struct page)); + size = min(end - start, (1UL << order) * sizeof(struct page)); for (addr = start; addr < end; addr += size) { unsigned long next, last = addr + size; @@ -585,12 +571,12 @@ static int __meminit vmemmap_populate_compound_pages(unsigned long start_pfn, return -ENOMEM; /* - * Reuse the previous page for the rest of tail pages + * Reuse the shared page for the rest of tail pages * See layout diagram in Documentation/mm/vmemmap_dedup.rst */ next += PAGE_SIZE; rc = vmemmap_populate_range(next, last, node, NULL, - pte_pfn(ptep_get(pte)), flags); + page_to_pfn(page), flags); if (rc) return -ENOMEM; } @@ -922,13 +908,16 @@ int __meminit sparse_add_section(int nid, unsigned long start_pfn, if (IS_ERR(memmap)) return PTR_ERR(memmap); + ms = __nr_to_section(section_nr); /* - * Poison uninitialized struct pages in order to catch invalid flags - * combinations. + * Poison uninitialized struct pages to catch invalid flag combinations. + * + * Tail struct pages in a vmemmap-optimized section are initialized and + * shared during vmemmap population, so they must not be overwritten here. */ - page_init_poison(memmap, sizeof(struct page) * nr_pages); + if (!section_vmemmap_optimizable(ms)) + page_init_poison(memmap, sizeof(struct page) * nr_pages); - ms = __nr_to_section(section_nr); __section_mark_present(ms, section_nr); /* Align memmap to section boundary in the subsection case */ -- 2.54.0