From nobody Mon Feb 9 16:33:41 2026 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 02E3D266B57 for ; Thu, 1 May 2025 22:55:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1746140114; cv=none; b=RxNO3Jo3fdBZb8BX7Ux4SPCSXHSCWGxW0E7F/h3s2o4/QF9U50MBiAH3Za6RqmfPZrDTbsAkEINzeOMzisSKu9qiIF+Z2eGyJiI1b7k3nh60U0jxM5hDeoHYlwWasQd2Lkk/VsR0JySyqgo9lK9dewcewD1ypY2FxnTLWrzyZx0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1746140114; c=relaxed/simple; bh=EpbLx9LzIZ6EMGyQqnrBQeqco0/lB5MLg2sfA/nK0Jg=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=nJ5n/gxygl7XKQfTA7bSAZlBEZ0lEaAtF6FviSAF31LBdgtV998FjwNhzZoOnE9zFrFgsmCtHhbfMj+MdvWjz73fwMzYL8DiHM08lLBxNv0Vs6F8XH0U2LQ+CUanmEDku/YI7OqvLRQ+pY8YjOxIdbl8PzQFfWjmEIdFImtOQ0M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--changyuanl.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=h8f3Vn3u; arc=none smtp.client-ip=209.85.214.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--changyuanl.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="h8f3Vn3u" Received: by mail-pl1-f201.google.com with SMTP id d9443c01a7336-2242ce15cc3so16197905ad.1 for ; Thu, 01 May 2025 15:55:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1746140112; x=1746744912; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=KsrtYfKvpGG224Vuugu7gIhtwe4eY04G0mgo4ynGz+o=; b=h8f3Vn3uhJwMBXGeuAy90XdczzaPSwWnk3K9a3Q6LpWJozN2xcVsoJoZWTlkXCV1yp sQ97350Y5QamOMwRHMQwfH6IaadBqZERgOtvIEGA8p5kBk8jzn1xnXr7yr/amTU5j0wA RMuaGCSapglvYrnBQr1vkzQg6OeUfAHPwYJb72GsX6DDbOpRYtn4a5+5sOW2E51JVGQo THHGOf93cj5R48MqkCXY1wgecfg0qqq1/zpT5RgKaZ0Ye2LzBEdn+6Tpbex9tfEgn5Ha 0U10ts5oxOhihb4H9Et6bpXh3LKwq57CvfSCszCBZnKI40HKCwOGjeC6BuuLL3h4unai erWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1746140112; x=1746744912; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=KsrtYfKvpGG224Vuugu7gIhtwe4eY04G0mgo4ynGz+o=; b=hNb5ch09tyt8mK2Ia18RoOG56FFGRjYDW9qU/ORveolsS4JH6Yrr7ftzJ1ITy/coDK MuWMwXiYYfbRjOtlouR8UMW+vpnTLru4dEL3EKAM4VWEu509cbBDX+GVn3L0f6zCoV2M NsNTUNAQmekoPiubp8F/xQ8X4rq8C0JJtp6M47bt+ZE7qOOpo53rynEtnmAI3Qo2r80u 0BOdAWyB0LqoXlWX56SBc7JdVl8bCxDpWRNtgOokXJnQi3HTvozFXrLyTUVIisqsGKnP /U+zKpw7SMlHGhKg72BzU/Dj11/zmZ7yv+T236HKlgthzrrVlufKqrrWPnhrYv/MRb2/ sGSg== X-Gm-Message-State: AOJu0YxNS8V6m3RJKDV/VxzF1S6vEy0awyJ8kIu3kpttAD+PZvathplk Mn5666CA73evEBtQegh1xQZmHgHtCFekfy07Exk1dd8TNrM15yTQUEskWHslzlJJzJqerezeHDh rRk//kOus3hLc1fpJNqm3cISODtBIonbOEd2UPEwHxWtG6YOv6dJPfMQhhYSEn7K/zRtgGC60sS F7RkOMlB5Qzc6bvYJIBMGnwww+awgq6Zr1pItVf1SVWHMwKF6RMsEtpid3V7gePQ== X-Google-Smtp-Source: AGHT+IFLb0PSdHgpE7Ok3NaDj2F1I/2reklfUyriSmie18M/0zt3atLCcdPUxCKomSzRS6uR7s3ME4uvfN3pXcz1 X-Received: from pgac15.prod.google.com ([2002:a05:6a02:294f:b0:b16:4869:6621]) (user=changyuanl job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:dacf:b0:220:df73:b639 with SMTP id d9443c01a7336-22e10393d3dmr10129945ad.36.1746140112204; Thu, 01 May 2025 15:55:12 -0700 (PDT) Date: Thu, 1 May 2025 15:54:09 -0700 In-Reply-To: <20250501225425.635167-1-changyuanl@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20250501225425.635167-1-changyuanl@google.com> X-Mailer: git-send-email 2.49.0.906.g1f30a19c02-goog Message-ID: <20250501225425.635167-3-changyuanl@google.com> Subject: [PATCH v7 02/18] memblock: Add support for scratch memory From: Changyuan Lyu To: linux-kernel@vger.kernel.org Cc: changyuanl@google.com, akpm@linux-foundation.org, anthony.yznaga@oracle.com, arnd@arndb.de, ashish.kalra@amd.com, benh@kernel.crashing.org, bp@alien8.de, catalin.marinas@arm.com, corbet@lwn.net, dave.hansen@linux.intel.com, devicetree@vger.kernel.org, dwmw2@infradead.org, ebiederm@xmission.com, graf@amazon.com, hpa@zytor.com, jgowans@amazon.com, kexec@lists.infradead.org, krzk@kernel.org, linux-arm-kernel@lists.infradead.org, linux-doc@vger.kernel.org, linux-mm@kvack.org, luto@kernel.org, mark.rutland@arm.com, mingo@redhat.com, pasha.tatashin@soleen.com, pbonzini@redhat.com, peterz@infradead.org, ptyadav@amazon.de, robh@kernel.org, rostedt@goodmis.org, rppt@kernel.org, saravanak@google.com, skinsburskii@linux.microsoft.com, tglx@linutronix.de, thomas.lendacky@amd.com, will@kernel.org, x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Alexander Graf With KHO (Kexec HandOver), we need a way to ensure that the new kernel does not allocate memory on top of any memory regions that the previous kernel was handing over. But to know where those are, we need to include them in the memblock.reserved array which may not be big enough to hold all ranges that need to be persisted across kexec. To resize the array, we need to allocate memory. That brings us into a catch 22 situation. The solution to that is limit memblock allocations to the scratch regions: safe regions to operate in the case when there is memory that should remain intact across kexec. KHO provides several "scratch regions" as part of its metadata. These scratch regions are contiguous memory blocks that known not to contain any memory that should be persisted across kexec. These regions should be large enough to accommodate all memblock allocations done by the kexeced kernel. We introduce a new memblock_set_scratch_only() function that allows KHO to indicate that any memblock allocation must happen from the scratch regions. Later, we may want to perform another KHO kexec. For that, we reuse the same scratch regions. To ensure that no eventually handed over data gets allocated inside a scratch region, we flip the semantics of the scratch region with memblock_clear_scratch_only(): After that call, no allocations may happen from scratch memblock regions. We will lift that restriction in the next patch. Signed-off-by: Alexander Graf Co-developed-by: Mike Rapoport (Microsoft) Signed-off-by: Mike Rapoport (Microsoft) Signed-off-by: Changyuan Lyu --- include/linux/memblock.h | 20 +++++++++++++ mm/Kconfig | 4 +++ mm/memblock.c | 61 ++++++++++++++++++++++++++++++++++++++++ 3 files changed, 85 insertions(+) diff --git a/include/linux/memblock.h b/include/linux/memblock.h index 6c00fbc085132..993937a6b9620 100644 --- a/include/linux/memblock.h +++ b/include/linux/memblock.h @@ -45,6 +45,11 @@ extern unsigned long long max_possible_pfn; * @MEMBLOCK_RSRV_KERN: memory region that is reserved for kernel use, * either explictitly with memblock_reserve_kern() or via memblock * allocation APIs. All memblock allocations set this flag. + * @MEMBLOCK_KHO_SCRATCH: memory region that kexec can pass to the next + * kernel in handover mode. During early boot, we do not know about all + * memory reservations yet, so we get scratch memory from the previous + * kernel that we know is good to use. It is the only memory that + * allocations may happen from in this phase. */ enum memblock_flags { MEMBLOCK_NONE =3D 0x0, /* No special request */ @@ -54,6 +59,7 @@ enum memblock_flags { MEMBLOCK_DRIVER_MANAGED =3D 0x8, /* always detected via a driver */ MEMBLOCK_RSRV_NOINIT =3D 0x10, /* don't initialize struct pages */ MEMBLOCK_RSRV_KERN =3D 0x20, /* memory reserved for kernel use */ + MEMBLOCK_KHO_SCRATCH =3D 0x40, /* scratch memory for kexec handover */ }; =20 /** @@ -148,6 +154,8 @@ int memblock_mark_mirror(phys_addr_t base, phys_addr_t = size); int memblock_mark_nomap(phys_addr_t base, phys_addr_t size); int memblock_clear_nomap(phys_addr_t base, phys_addr_t size); int memblock_reserved_mark_noinit(phys_addr_t base, phys_addr_t size); +int memblock_mark_kho_scratch(phys_addr_t base, phys_addr_t size); +int memblock_clear_kho_scratch(phys_addr_t base, phys_addr_t size); =20 void memblock_free(void *ptr, size_t size); void reset_all_zones_managed_pages(void); @@ -291,6 +299,11 @@ static inline bool memblock_is_driver_managed(struct m= emblock_region *m) return m->flags & MEMBLOCK_DRIVER_MANAGED; } =20 +static inline bool memblock_is_kho_scratch(struct memblock_region *m) +{ + return m->flags & MEMBLOCK_KHO_SCRATCH; +} + int memblock_search_pfn_nid(unsigned long pfn, unsigned long *start_pfn, unsigned long *end_pfn); void __next_mem_pfn_range(int *idx, int nid, unsigned long *out_start_pfn, @@ -619,5 +632,12 @@ static inline void early_memtest(phys_addr_t start, ph= ys_addr_t end) { } static inline void memtest_report_meminfo(struct seq_file *m) { } #endif =20 +#ifdef CONFIG_MEMBLOCK_KHO_SCRATCH +void memblock_set_kho_scratch_only(void); +void memblock_clear_kho_scratch_only(void); +#else +static inline void memblock_set_kho_scratch_only(void) { } +static inline void memblock_clear_kho_scratch_only(void) { } +#endif =20 #endif /* _LINUX_MEMBLOCK_H */ diff --git a/mm/Kconfig b/mm/Kconfig index e113f713b4938..60ea9eba48140 100644 --- a/mm/Kconfig +++ b/mm/Kconfig @@ -469,6 +469,10 @@ config HAVE_GUP_FAST depends on MMU bool =20 +# Enable memblock support for scratch memory which is needed for kexec han= dover +config MEMBLOCK_KHO_SCRATCH + bool + # Don't discard allocated memory used to track "memory" and "reserved" mem= blocks # after early boot, so it can still be used to test for validity of memory. # Also, memblocks are updated with memory hot(un)plug. diff --git a/mm/memblock.c b/mm/memblock.c index 2dc95ecdee5ce..6eba0dfe87155 100644 --- a/mm/memblock.c +++ b/mm/memblock.c @@ -107,6 +107,13 @@ unsigned long min_low_pfn; unsigned long max_pfn; unsigned long long max_possible_pfn; =20 +#ifdef CONFIG_MEMBLOCK_KHO_SCRATCH +/* When set to true, only allocate from MEMBLOCK_KHO_SCRATCH ranges */ +static bool kho_scratch_only; +#else +#define kho_scratch_only false +#endif + static struct memblock_region memblock_memory_init_regions[INIT_MEMBLOCK_M= EMORY_REGIONS] __initdata_memblock; static struct memblock_region memblock_reserved_init_regions[INIT_MEMBLOCK= _RESERVED_REGIONS] __initdata_memblock; #ifdef CONFIG_HAVE_MEMBLOCK_PHYS_MAP @@ -166,6 +173,10 @@ bool __init_memblock memblock_has_mirror(void) =20 static enum memblock_flags __init_memblock choose_memblock_flags(void) { + /* skip non-scratch memory for kho early boot allocations */ + if (kho_scratch_only) + return MEMBLOCK_KHO_SCRATCH; + return system_has_some_mirror ? MEMBLOCK_MIRROR : MEMBLOCK_NONE; } =20 @@ -925,6 +936,18 @@ int __init_memblock memblock_physmem_add(phys_addr_t b= ase, phys_addr_t size) } #endif =20 +#ifdef CONFIG_MEMBLOCK_KHO_SCRATCH +__init void memblock_set_kho_scratch_only(void) +{ + kho_scratch_only =3D true; +} + +__init void memblock_clear_kho_scratch_only(void) +{ + kho_scratch_only =3D false; +} +#endif + /** * memblock_setclr_flag - set or clear flag for a memory region * @type: memblock type to set/clear flag for @@ -1050,6 +1073,36 @@ int __init_memblock memblock_reserved_mark_noinit(ph= ys_addr_t base, phys_addr_t MEMBLOCK_RSRV_NOINIT); } =20 +/** + * memblock_mark_kho_scratch - Mark a memory region as MEMBLOCK_KHO_SCRATC= H. + * @base: the base phys addr of the region + * @size: the size of the region + * + * Only memory regions marked with %MEMBLOCK_KHO_SCRATCH will be considered + * for allocations during early boot with kexec handover. + * + * Return: 0 on success, -errno on failure. + */ +__init int memblock_mark_kho_scratch(phys_addr_t base, phys_addr_t size) +{ + return memblock_setclr_flag(&memblock.memory, base, size, 1, + MEMBLOCK_KHO_SCRATCH); +} + +/** + * memblock_clear_kho_scratch - Clear MEMBLOCK_KHO_SCRATCH flag for a + * specified region. + * @base: the base phys addr of the region + * @size: the size of the region + * + * Return: 0 on success, -errno on failure. + */ +__init int memblock_clear_kho_scratch(phys_addr_t base, phys_addr_t size) +{ + return memblock_setclr_flag(&memblock.memory, base, size, 0, + MEMBLOCK_KHO_SCRATCH); +} + static bool should_skip_region(struct memblock_type *type, struct memblock_region *m, int nid, int flags) @@ -1081,6 +1134,13 @@ static bool should_skip_region(struct memblock_type = *type, if (!(flags & MEMBLOCK_DRIVER_MANAGED) && memblock_is_driver_managed(m)) return true; =20 + /* + * In early alloc during kexec handover, we can only consider + * MEMBLOCK_KHO_SCRATCH regions for the allocations + */ + if ((flags & MEMBLOCK_KHO_SCRATCH) && !memblock_is_kho_scratch(m)) + return true; + return false; } =20 @@ -2465,6 +2525,7 @@ static const char * const flagname[] =3D { [ilog2(MEMBLOCK_DRIVER_MANAGED)] =3D "DRV_MNG", [ilog2(MEMBLOCK_RSRV_NOINIT)] =3D "RSV_NIT", [ilog2(MEMBLOCK_RSRV_KERN)] =3D "RSV_KERN", + [ilog2(MEMBLOCK_KHO_SCRATCH)] =3D "KHO_SCRATCH", }; =20 static int memblock_debug_show(struct seq_file *m, void *private) --=20 2.49.0.906.g1f30a19c02-goog