Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1497019 > unrolled thread

[PATCH 2/4] mm: prevent double decrease of nr_reserved_highatomic

Started byMinchan Kim <minchan@kernel.org>
First post2016-10-07 07:50 +0200
Last post2016-10-12 09:00 +0200
Articles 4 — 3 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 2/4] mm: prevent double decrease of nr_reserved_highatomic Minchan Kim <minchan@kernel.org> - 2016-10-07 07:50 +0200
    Re: [PATCH 2/4] mm: prevent double decrease of nr_reserved_highatomic Vlastimil Babka <vbabka@suse.cz> - 2016-10-07 14:50 +0200
      Re: [PATCH 2/4] mm: prevent double decrease of nr_reserved_highatomic Minchan Kim <minchan@kernel.org> - 2016-10-07 16:50 +0200
    Re: [PATCH 2/4] mm: prevent double decrease of nr_reserved_highatomic Mel Gorman <mgorman@techsingularity.net> - 2016-10-12 09:00 +0200

#1497019 — [PATCH 2/4] mm: prevent double decrease of nr_reserved_highatomic

FromMinchan Kim <minchan@kernel.org>
Date2016-10-07 07:50 +0200
Subject[PATCH 2/4] mm: prevent double decrease of nr_reserved_highatomic
Message-ID<spwcF-3WG-1@gated-at.bofh.it>
There is race between page freeing and unreserved highatomic.

 CPU 0				    CPU 1

    free_hot_cold_page
      mt = get_pfnblock_migratetype
      set_pcppage_migratetype(page, mt)
    				    unreserve_highatomic_pageblock
    				    spin_lock_irqsave(&zone->lock)
    				    move_freepages_block
    				    set_pageblock_migratetype(page)
    				    spin_unlock_irqrestore(&zone->lock)
      free_pcppages_bulk
        __free_one_page(mt) <- mt is stale

By above race, a page on CPU 0 could go non-highorderatomic free list
since the pageblock's type is changed. By that, unreserve logic of
highorderatomic can decrease reserved count on a same pageblock
several times and then it will make mismatch between
nr_reserved_highatomic and the number of reserved pageblock.

So, this patch verifies whether the pageblock is highatomic or not
and decrease the count only if the pageblock is highatomic.

Signed-off-by: Minchan Kim <minchan@kernel.org>
---
 mm/page_alloc.c | 24 ++++++++++++++++++------
 1 file changed, 18 insertions(+), 6 deletions(-)

diff --git a/mm/page_alloc.c b/mm/page_alloc.c
index e7cbb3cc22fa..d110cd640264 100644
--- a/mm/page_alloc.c
+++ b/mm/page_alloc.c
@@ -2133,13 +2133,25 @@ static void unreserve_highatomic_pageblock(const struct alloc_context *ac)
 				continue;
 
 			/*
-			 * It should never happen but changes to locking could
-			 * inadvertently allow a per-cpu drain to add pages
-			 * to MIGRATE_HIGHATOMIC while unreserving so be safe
-			 * and watch for underflows.
+			 * In page freeing path, migratetype change is racy so
+			 * we can counter several free pages in a pageblock
+			 * in this loop althoug we changed the pageblock type
+			 * from highatomic to ac->migratetype. So we should
+			 * adjust the count once.
 			 */
-			zone->nr_reserved_highatomic -= min(pageblock_nr_pages,
-				zone->nr_reserved_highatomic);
+			if (get_pageblock_migratetype(page) ==
+							MIGRATE_HIGHATOMIC) {
+				/*
+				 * It should never happen but changes to
+				 * locking could inadvertently allow a per-cpu
+				 * drain to add pages to MIGRATE_HIGHATOMIC
+				 * while unreserving so be safe and watch for
+				 * underflows.
+				 */
+				zone->nr_reserved_highatomic -= min(
+						pageblock_nr_pages,
+						zone->nr_reserved_highatomic);
+			}
 
 			/*
 			 * Convert to ac->migratetype and avoid the normal
-- 
2.7.4

[toc] | [next] | [standalone]


#1497140

FromVlastimil Babka <vbabka@suse.cz>
Date2016-10-07 14:50 +0200
Message-ID<spCL8-tX-11@gated-at.bofh.it>
In reply to#1497019
On 10/07/2016 07:45 AM, Minchan Kim wrote:
> There is race between page freeing and unreserved highatomic.
>
>  CPU 0				    CPU 1
>
>     free_hot_cold_page
>       mt = get_pfnblock_migratetype

so here mt == MIGRATE_HIGHATOMIC?

>       set_pcppage_migratetype(page, mt)
>     				    unreserve_highatomic_pageblock
>     				    spin_lock_irqsave(&zone->lock)
>     				    move_freepages_block
>     				    set_pageblock_migratetype(page)
>     				    spin_unlock_irqrestore(&zone->lock)
>       free_pcppages_bulk
>         __free_one_page(mt) <- mt is stale
>
> By above race, a page on CPU 0 could go non-highorderatomic free list
> since the pageblock's type is changed.
> By that, unreserve logic of
> highorderatomic can decrease reserved count on a same pageblock
> several times and then it will make mismatch between
> nr_reserved_highatomic and the number of reserved pageblock.

Hmm I see.

> So, this patch verifies whether the pageblock is highatomic or not
> and decrease the count only if the pageblock is highatomic.

Yeah I guess that's the easiest solution.

> Signed-off-by: Minchan Kim <minchan@kernel.org>

Acked-by: Vlastimil Babka <vbabka@suse.cz>

> ---
>  mm/page_alloc.c | 24 ++++++++++++++++++------
>  1 file changed, 18 insertions(+), 6 deletions(-)
>
> diff --git a/mm/page_alloc.c b/mm/page_alloc.c
> index e7cbb3cc22fa..d110cd640264 100644
> --- a/mm/page_alloc.c
> +++ b/mm/page_alloc.c
> @@ -2133,13 +2133,25 @@ static void unreserve_highatomic_pageblock(const struct alloc_context *ac)
>  				continue;
>
>  			/*
> -			 * It should never happen but changes to locking could
> -			 * inadvertently allow a per-cpu drain to add pages
> -			 * to MIGRATE_HIGHATOMIC while unreserving so be safe
> -			 * and watch for underflows.
> +			 * In page freeing path, migratetype change is racy so
> +			 * we can counter several free pages in a pageblock
> +			 * in this loop althoug we changed the pageblock type
> +			 * from highatomic to ac->migratetype. So we should
> +			 * adjust the count once.
>  			 */
> -			zone->nr_reserved_highatomic -= min(pageblock_nr_pages,
> -				zone->nr_reserved_highatomic);
> +			if (get_pageblock_migratetype(page) ==
> +							MIGRATE_HIGHATOMIC) {
> +				/*
> +				 * It should never happen but changes to
> +				 * locking could inadvertently allow a per-cpu
> +				 * drain to add pages to MIGRATE_HIGHATOMIC
> +				 * while unreserving so be safe and watch for
> +				 * underflows.
> +				 */
> +				zone->nr_reserved_highatomic -= min(
> +						pageblock_nr_pages,
> +						zone->nr_reserved_highatomic);
> +			}
>
>  			/*
>  			 * Convert to ac->migratetype and avoid the normal
>

[toc] | [prev] | [next] | [standalone]


#1497199

FromMinchan Kim <minchan@kernel.org>
Date2016-10-07 16:50 +0200
Message-ID<spEDg-1QU-49@gated-at.bofh.it>
In reply to#1497140
On Fri, Oct 07, 2016 at 02:44:15PM +0200, Vlastimil Babka wrote:
> On 10/07/2016 07:45 AM, Minchan Kim wrote:
> >There is race between page freeing and unreserved highatomic.
> >
> > CPU 0				    CPU 1
> >
> >    free_hot_cold_page
> >      mt = get_pfnblock_migratetype
> 
> so here mt == MIGRATE_HIGHATOMIC?

Yes.

> 
> >      set_pcppage_migratetype(page, mt)
> >    				    unreserve_highatomic_pageblock
> >    				    spin_lock_irqsave(&zone->lock)
> >    				    move_freepages_block
> >    				    set_pageblock_migratetype(page)
> >    				    spin_unlock_irqrestore(&zone->lock)
> >      free_pcppages_bulk
> >        __free_one_page(mt) <- mt is stale
> >
> >By above race, a page on CPU 0 could go non-highorderatomic free list
> >since the pageblock's type is changed.
> >By that, unreserve logic of
> >highorderatomic can decrease reserved count on a same pageblock
> >several times and then it will make mismatch between
> >nr_reserved_highatomic and the number of reserved pageblock.
> 
> Hmm I see.
> 
> >So, this patch verifies whether the pageblock is highatomic or not
> >and decrease the count only if the pageblock is highatomic.
> 
> Yeah I guess that's the easiest solution.
> 
> >Signed-off-by: Minchan Kim <minchan@kernel.org>
> 
> Acked-by: Vlastimil Babka <vbabka@suse.cz>

Thanks, Vlastimil.

[toc] | [prev] | [next] | [standalone]


#1499392

FromMel Gorman <mgorman@techsingularity.net>
Date2016-10-12 09:00 +0200
Message-ID<srlGa-Ku-35@gated-at.bofh.it>
In reply to#1497019
On Fri, Oct 07, 2016 at 02:45:34PM +0900, Minchan Kim wrote:
> There is race between page freeing and unreserved highatomic.
> 
>  CPU 0				    CPU 1
> 
>     free_hot_cold_page
>       mt = get_pfnblock_migratetype
>       set_pcppage_migratetype(page, mt)
>     				    unreserve_highatomic_pageblock
>     				    spin_lock_irqsave(&zone->lock)
>     				    move_freepages_block
>     				    set_pageblock_migratetype(page)
>     				    spin_unlock_irqrestore(&zone->lock)
>       free_pcppages_bulk
>         __free_one_page(mt) <- mt is stale
> 
> By above race, a page on CPU 0 could go non-highorderatomic free list
> since the pageblock's type is changed. By that, unreserve logic of
> highorderatomic can decrease reserved count on a same pageblock
> several times and then it will make mismatch between
> nr_reserved_highatomic and the number of reserved pageblock.
> 
> So, this patch verifies whether the pageblock is highatomic or not
> and decrease the count only if the pageblock is highatomic.
> 
> Signed-off-by: Minchan Kim <minchan@kernel.org>

Acked-by: Mel Gorman <mgorman@techsingularity.net>

-- 
Mel Gorman
SUSE Labs

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web