From nobody Mon Sep 28 20:05:41 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 907483290A6; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; cv=none; b=Ks0Utkr8otlcuNOhurqM4KDR/OXZQ3H4iRICm1bbkCB4ebKVg6+r+DZXMZvzOisN9KqjzANXog/ZwQsS4cJdvX0Im1dWmIs++oDixDEiGPTswsnRYz5lj0az3M8PzFoGX5rz7KSCVqGvOfIPgFTeCSuNZqA6Vb2ITbmXzaKXxBY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; c=relaxed/simple; bh=2gRxy25hnembdVhYLwRZncDSQOFGYsoukSzLF39j9ZU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=FUhdkEotoyAR8Ii8XNsJ/mYU65w5vxhJSNOkOAlR3MaKNrKVLBv+NJn9hkQj+0lv9VcFEyXJY1Qo4Fe3Kzk2JcphFM2Tozaf/owogg1G+eRdAvSEywuGXRTJoRmxqc006KFNUfG9UMuvfjFlN3z3dXQGOjVpRmgRmf73eUfsZxY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=YxaW6lZi; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="YxaW6lZi" Received: by smtp.kernel.org (Postfix) with ESMTPS id 1DAF8C2BCF7; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787031504; bh=2gRxy25hnembdVhYLwRZncDSQOFGYsoukSzLF39j9ZU=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=YxaW6lZinIMHZU5k8okndOkUM+44MLlwH4XKPA/n2SQtOh00509sra1motCX6yPLb v303PCaLott/IN8Y9Mxvoif0JOAC3NzgFkyFlFiMYPHTDFik/VKnjovSp6Mu9/AwzS SbIjaGWqpfmi6BZUIQQeBWtDMLHY+gQ0v21BBucNC/MhvtdCsBiPDtuO/c0BAe+28O syxICUizu05TX5YVNN3ynL03nKj3L/4Wwf5gzOuAYe0TOpe2Yx/eauSamHItpoiTZ/ ZdO5IasUTVc+eVfxWULRZUux8AjPrTMmv3JTxz+qUtCoDDHhOOFXJctygz/ei1BtG0 HK+Q81jqOTysQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EDD9EC5DF67; Tue, 18 Aug 2026 05:38:23 +0000 (UTC) From: Kairui Song via B4 Relay Date: Tue, 18 Aug 2026 13:38:03 +0800 Subject: [PATCH 1/7] mm/memcontrol: make lru_zone_size atomic and simplify sanity check Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-mglru-flags-cleanup-v1-1-8dbbdac0d28c@tencent.com> References: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> In-Reply-To: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787031500; l=3566; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=/T+OKeuJl3olH2b22zrXZqywkoz/djv44CIgkgQ7VaQ=; b=i+2Ei8YdqwDPFssEabm+WHT0ilQlC8IDHXtxYrZA1/QkexYde2gP0a8PvqjROPnzKpImG2i9Y ylZAtICzyIeApv5ta641aTQM6nqveZq6AQ9GZ+1AADs+c31OLcPr2CK X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song commit ca707239e8a7 ("mm: update_lru_size warn and reset bad lru_size") introduced a sanity check to catch memcg counter underflow, which was more of a workaround for another bug: lru_zone_size is unsigned, so underflow wraps it around and returns an enormously large number, then the memcg shrinker loops almost forever as the calculated number of folios to shrink is huge. That commit also checked if a zero value matches the empty LRU list, so we have to hold the LRU lock, and handle the positive and negative deltas separately. But later commit b4536f0c829c ("mm, memcg: fix the active list aging for lowmem requests when memcg is enabled") already removed the LRU emptiness check, so handling the deltas separately is no longer needed. And if we just turn it into an atomic long, underflow isn't a big issue either, and can be checked at the reader side, which is called much less frequently than the updater. So let's turn the counter into an atomic long and check at the reader side instead, which has a smaller overhead. The underflow correction is removed: a massive leak of the LRU size counter would indicate that something else has gone very wrong, and one should fix that leaking site instead. Besides, the updater-side sanity check is unlikely to catch the leaking site anyway: if a folio was removed without updating the counter while other folios remain on the LRU, the WARN only triggers much later, from a likely innocent callsite. Signed-off-by: Kairui Song Reviewed-by: Ridong Chen --- include/linux/memcontrol.h | 9 +++++++-- mm/memcontrol.c | 18 +----------------- 2 files changed, 8 insertions(+), 19 deletions(-) diff --git a/include/linux/memcontrol.h b/include/linux/memcontrol.h index e78bc98ab229..b13e3f056319 100644 --- a/include/linux/memcontrol.h +++ b/include/linux/memcontrol.h @@ -113,7 +113,7 @@ struct mem_cgroup_per_node { /* Fields which get updated often at the end. */ struct lruvec lruvec; CACHELINE_PADDING(_pad2_); - unsigned long lru_zone_size[MAX_NR_ZONES][NR_LRU_LISTS]; + atomic_long_t lru_zone_size[MAX_NR_ZONES][NR_LRU_LISTS]; struct mem_cgroup_reclaim_iter iter; =20 /* @@ -897,10 +897,15 @@ static inline unsigned long mem_cgroup_get_zone_lru_size(struct lruvec *lruvec, enum lru_list lru, int zone_idx) { + long val; struct mem_cgroup_per_node *mz; =20 mz =3D container_of(lruvec, struct mem_cgroup_per_node, lruvec); - return READ_ONCE(mz->lru_zone_size[zone_idx][lru]); + val =3D atomic_long_read(&mz->lru_zone_size[zone_idx][lru]); + if (WARN_ON_ONCE(val < 0)) + return 0; + + return val; } =20 void __mem_cgroup_handle_over_high(gfp_t gfp_mask); diff --git a/mm/memcontrol.c b/mm/memcontrol.c index 1d3339520809..9d0ee3d3bda7 100644 --- a/mm/memcontrol.c +++ b/mm/memcontrol.c @@ -1529,28 +1529,12 @@ void mem_cgroup_update_lru_size(struct lruvec *lruv= ec, enum lru_list lru, int zid, long nr_pages) { struct mem_cgroup_per_node *mz; - unsigned long *lru_size; - long size; =20 if (mem_cgroup_disabled()) return; =20 mz =3D container_of(lruvec, struct mem_cgroup_per_node, lruvec); - lru_size =3D &mz->lru_zone_size[zid][lru]; - - if (nr_pages < 0) - *lru_size +=3D nr_pages; - - size =3D *lru_size; - if (WARN_ONCE(size < 0, - "%s(%p, %d, %ld): lru_size %ld\n", - __func__, lruvec, lru, nr_pages, size)) { - VM_BUG_ON(1); - *lru_size =3D 0; - } - - if (nr_pages > 0) - *lru_size +=3D nr_pages; + atomic_long_add(nr_pages, &mz->lru_zone_size[zid][lru]); } =20 /** --=20 2.55.0 From nobody Mon Sep 28 20:05:41 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8F837282F0E; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; cv=none; b=OrbJZhpV9rlMC4Ob2nyWfUy0kdHV3TnMtnBxtqBU9/ij4LM4ueI/La10l9h0nrLw0bHGA7cwtVakWSPsXep+bFNKpPvw6jW3aRn9C1cTJBqdpfqCYbLr7qF1aZGMD5xVlVExTU7BG/Ld/lQOZBtSbW/w/1sM9qV2ao3H9Mp/yXY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; c=relaxed/simple; bh=S2YxUvVoRsdX+KAoTSjwnkcnBdRMGjOZ9TxxeruEFxA=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=F4FrFgU0KjlyFhEdhAsbSk1R9MCufpFPOvQT1pwnsIGdkE6RWOL9KvLM6AZPO3e7jmBinJh8HKhZKLjpSLBxDRu0IyloUi25AxlH7wNpTxLftbOwttpOvAExl+W3HGt/EX/EGLZ7flkkUQAzO6ktjLueT6EIbnzaYxS9DKvbvyU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=iA4wvUg+; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="iA4wvUg+" Received: by smtp.kernel.org (Postfix) with ESMTPS id 31181C2BCF4; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787031504; bh=S2YxUvVoRsdX+KAoTSjwnkcnBdRMGjOZ9TxxeruEFxA=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=iA4wvUg+QXlg4vsfmZwN86KLg2otcGOMwqBzCeulwp0B/MqnjqKzusxHJMWkebA6q SGEjHuAT24KffGyHjeMpdrfdWpgpAgLcPURLKVTJUTJEt4/QJrQBvWUc8/E1WU+O4w 0j8O5vW/12HXu34IL+nBBcQoxYAOywfUz0aH52uvTkT2wkWX8+2Qm+qkKv7tFBAi2+ 3Z1SY0wKAT2uAnBW/odUGusS5bVIHmxfkUDARHmrCpxiMMzrfcbSOuDrL2uAsfu4Id PBWLIYrseQzrYtKlGdbdKCjfn2sWF8qAjEupRz9RxD/7RxXcxIsn5xQLTLBjgTgzUV uxLBJ20w63AJw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0FEBEC5DF80; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) From: Kairui Song via B4 Relay Date: Tue, 18 Aug 2026 13:38:04 +0800 Subject: [PATCH 2/7] mm/mglru: introduce helpers for manipulating gen and refs flags Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-mglru-flags-cleanup-v1-2-8dbbdac0d28c@tencent.com> References: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> In-Reply-To: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787031500; l=12367; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=t6tpsoGqBavUMKtomG7mLs+lW1B48iITDCg65a5UNi0=; b=59j/+GELFwzrVx+fJxmkua+fN7tE2XIVjk7g7fHaQesCbrmI+f5R3WtRcz3vlnb0v7sPPpuNA +urmuaH2CNVAgrBlvMoe5AW+JwNrDFKsl0de564RpiFY2zuyyDMv5Xs X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song Instead of doing bit ops on folio->flags.f, introduce helpers for adjusting folio's refs and gen info, make the code easier to debug and understand. No functional change is intended: some combined atomic operations are split into two, which only creates harmless transient states. Signed-off-by: Kairui Song --- include/linux/mm_inline.h | 79 +++++++++++++++++++++++++++++++++++++++++--= ---- include/linux/mmzone.h | 2 ++ mm/folio.c | 19 +++++++----- mm/vmscan.c | 61 ++++++++++++++++++++---------------- 4 files changed, 117 insertions(+), 44 deletions(-) diff --git a/include/linux/mm_inline.h b/include/linux/mm_inline.h index 621c8653d8f7..93bf3fa221f8 100644 --- a/include/linux/mm_inline.h +++ b/include/linux/mm_inline.h @@ -142,10 +142,43 @@ static inline int lru_tier_from_refs(int refs, bool w= orkingset) return workingset ? MAX_NR_TIERS - 1 : order_base_2(refs); } =20 -static inline int folio_lru_refs(const struct folio *folio) +/** + * lru_gen_from_flags - Return the LRU generation number from folio flags. + * @flags: folio flags + * + * Returns: A number between 0 and LRU_GEN_MAX, inclusive. Returns -1 if t= he + * flags indicate the folio is off the list (e.g., isolated). + */ +static inline int lru_gen_from_flags(unsigned long flags) +{ + int gen =3D ((flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF); + + BUILD_BUG_ON(LRU_GEN_MASK & LRU_REFS_MASK); + gen -=3D 1; + VM_WARN_ON_ONCE(gen !=3D -1 && gen > LRU_GEN_MAX); + return gen; +} + +/** + * lru_gen_set_flags - Set the LRU generation number to specified folio fl= ags. + * @flags: pointer to the folio flags + * @gen: generation number, between 0 and LRU_GEN_MAX, inclusive. + */ +static inline void lru_gen_set_flags(unsigned long *flags, int gen) { - unsigned long flags =3D READ_ONCE(folio->flags.f); + VM_WARN_ON_ONCE(gen > LRU_GEN_MAX || gen < 0); + BUILD_BUG_ON((LRU_GEN_MAX + 1) !=3D MAX_NR_GENS); + + *flags &=3D ~LRU_GEN_MASK; + *flags |=3D (gen + 1UL) << LRU_GEN_PGOFF; +} =20 +/** + * lru_refs_from_flags - Return LRU referenced / access count from folio f= lags. + * @flags: folio flags + */ +static inline int lru_refs_from_flags(unsigned long flags) +{ if (!(flags & BIT(PG_referenced))) return 0; /* @@ -155,18 +188,47 @@ static inline int folio_lru_refs(const struct folio *= folio) return ((flags & LRU_REFS_MASK) >> LRU_REFS_PGOFF) + 1; } =20 -static inline int folio_lru_gen(const struct folio *folio) +/** + * lru_refs_set_flags - Set the LRU referenced / access count to specified= folio flags. + * @flags: pointer to the folio flags + * @refs: referenced / access count number, between 0 and LRU_REFS_MAX, in= clusive. + */ +static inline void lru_refs_set_flags(unsigned long *flags, unsigned int r= efs) +{ + VM_WARN_ON_ONCE(refs > LRU_REFS_MAX); + BUILD_BUG_ON(LRU_REFS_MAX !=3D (LRU_REFS_MASK >> LRU_REFS_PGOFF) + 1); + + *flags &=3D ~LRU_REFS_FLAGS; + if (!refs) + return; + *flags |=3D (BIT(PG_referenced) | ((refs - 1UL) << LRU_REFS_PGOFF)); +} + +static inline int folio_lru_refs(const struct folio *folio) { - unsigned long flags =3D READ_ONCE(folio->flags.f); + return lru_refs_from_flags(READ_ONCE(*const_folio_flags(folio, 0))); +} + +static inline void folio_set_lru_refs(struct folio *folio, unsigned int re= fs) +{ + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); + + do { + new_flags =3D old_flags; + lru_refs_set_flags(&new_flags, refs); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); +} =20 - return ((flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; +static inline int folio_lru_gen(const struct folio *folio) +{ + return lru_gen_from_flags(READ_ONCE(*const_folio_flags(folio, 0))); } =20 static inline bool lru_gen_is_active(const struct lruvec *lruvec, int gen) { unsigned long max_seq =3D lruvec->lrugen.max_seq; =20 - VM_WARN_ON_ONCE(gen >=3D MAX_NR_GENS); + VM_WARN_ON_ONCE(gen > LRU_GEN_MAX); =20 /* see the comment on MIN_NR_GENS */ return gen =3D=3D lru_gen_from_seq(max_seq) || gen =3D=3D lru_gen_from_se= q(max_seq - 1); @@ -270,7 +332,7 @@ static inline bool lru_gen_add_folio(struct lruvec *lru= vec, struct folio *folio, gen =3D lru_gen_from_seq(seq); flags =3D (gen + 1UL) << LRU_GEN_PGOFF; /* see the comment on MIN_NR_GENS about PG_active */ - set_mask_bits(&folio->flags.f, LRU_GEN_MASK | BIT(PG_active), flags); + set_mask_bits(folio_flags(folio, 0), LRU_GEN_MASK | BIT(PG_active), flags= ); =20 lru_gen_update_size(lruvec, folio, -1, gen); /* for folio_rotate_reclaimable() */ @@ -295,7 +357,7 @@ static inline bool lru_gen_del_folio(struct lruvec *lru= vec, struct folio *folio, =20 /* for folio_migrate_flags() */ flags =3D !reclaiming && lru_gen_is_active(lruvec, gen) ? BIT(PG_active) = : 0; - flags =3D set_mask_bits(&folio->flags.f, LRU_GEN_MASK, flags); + flags =3D set_mask_bits(folio_flags(folio, 0), LRU_GEN_MASK, flags); gen =3D ((flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; =20 lru_gen_update_size(lruvec, folio, gen, -1); @@ -339,7 +401,6 @@ static inline bool lru_gen_del_folio(struct lruvec *lru= vec, struct folio *folio, =20 static inline void folio_migrate_refs(struct folio *new, const struct foli= o *old) { - } #endif /* CONFIG_LRU_GEN */ =20 diff --git a/include/linux/mmzone.h b/include/linux/mmzone.h index 94f9c3ff5416..32d9354a754f 100644 --- a/include/linux/mmzone.h +++ b/include/linux/mmzone.h @@ -496,7 +496,9 @@ enum lruvec_flags { #ifndef __GENERATING_BOUNDS_H =20 #define LRU_GEN_MASK ((BIT(LRU_GEN_WIDTH) - 1) << LRU_GEN_PGOFF) +#define LRU_GEN_MAX (BIT(LRU_GEN_WIDTH - 1) - 1) #define LRU_REFS_MASK ((BIT(LRU_REFS_WIDTH) - 1) << LRU_REFS_PGOFF) +#define LRU_REFS_MAX BIT(LRU_REFS_WIDTH) =20 /* * For folios accessed multiple times through file descriptors, diff --git a/mm/folio.c b/mm/folio.c index 59c477120b9a..0adfe4f5ef72 100644 --- a/mm/folio.c +++ b/mm/folio.c @@ -353,26 +353,28 @@ static void __lru_cache_activate_folio(struct folio *= folio) =20 static void lru_gen_inc_refs(struct folio *folio) { - unsigned long new_flags, old_flags =3D READ_ONCE(folio->flags.f); + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); + int refs; =20 if (folio_test_unevictable(folio)) return; =20 /* see the comment on LRU_REFS_FLAGS */ - if (!folio_test_referenced(folio)) { - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, BIT(PG_referenced)); + if (!folio_lru_refs(folio)) { + folio_set_lru_refs(folio, 1); return; } =20 do { - if ((old_flags & LRU_REFS_MASK) =3D=3D LRU_REFS_MASK) { + new_flags =3D old_flags; + refs =3D lru_refs_from_flags(old_flags); + if (refs =3D=3D LRU_REFS_MAX) { if (!folio_test_workingset(folio)) folio_set_workingset(folio); return; } - - new_flags =3D old_flags + BIT(LRU_REFS_PGOFF); - } while (!try_cmpxchg(&folio->flags.f, &old_flags, new_flags)); + lru_refs_set_flags(&new_flags, refs + 1); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); } =20 static bool lru_gen_clear_refs(struct folio *folio) @@ -384,7 +386,8 @@ static bool lru_gen_clear_refs(struct folio *folio) if (gen < 0) return true; =20 - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS | BIT(PG_workingset), 0); + folio_set_lru_refs(folio, 0); + folio_clear_workingset(folio); =20 rcu_read_lock(); seq =3D READ_ONCE(folio_lruvec(folio)->lrugen.min_seq[type]); diff --git a/mm/vmscan.c b/mm/vmscan.c index c1404a59523d..080132997d87 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -843,19 +843,22 @@ static bool lru_gen_set_refs(struct folio *folio, con= st vma_flags_t *vma_flags) if (!folio_test_referenced(folio) && !folio_test_workingset(folio)) { /* Activate file-backed executable folios after first usage. */ if (is_exec_file_folio(folio, vma_flags)) { - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS, BIT(PG_workingset)); + folio_set_lru_refs(folio, 0); + folio_set_workingset(folio); return true; } =20 - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, BIT(PG_referenced)); + folio_set_lru_refs(folio, 1); return false; } =20 /* Promote on second access */ - if (folio_lru_refs(folio) > 1) - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS, BIT(PG_workingset)); - else + if (folio_lru_refs(folio) > 1) { + folio_set_lru_refs(folio, 0); + folio_set_workingset(folio); + } else { folio_mark_accessed(folio); + } return true; } #else @@ -3266,11 +3269,10 @@ static bool positive_ctrl_err(struct ctrl_pos *sp, = struct ctrl_pos *pv) *************************************************************************= *****/ =20 /* promote pages accessed through page tables */ -static int folio_update_gen(struct folio *folio, int gen, const vma_flags_= t *vma_flags) +static int folio_update_gen(struct folio *folio, int new_gen, const vma_fl= ags_t *vma_flags) { - unsigned long new_flags, old_flags =3D READ_ONCE(folio->flags.f); - - VM_WARN_ON_ONCE(gen >=3D MAX_NR_GENS); + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); + int old_gen; =20 /* * See the comment on LRU_REFS_FLAGS, and activate file-backed @@ -3279,20 +3281,24 @@ static int folio_update_gen(struct folio *folio, in= t gen, const vma_flags_t *vma */ if (!folio_test_referenced(folio) && !folio_test_workingset(folio) && !is_exec_file_folio(folio, vma_flags)) { - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, BIT(PG_referenced)); + folio_set_lru_refs(folio, 1); return -1; } =20 do { + old_gen =3D lru_gen_from_flags(old_flags); + new_flags =3D old_flags; + /* lru_gen_del_folio() has isolated this page? */ - if (!(old_flags & LRU_GEN_MASK)) - return -1; + if (old_gen < 0) + break; =20 - new_flags =3D old_flags & ~(LRU_GEN_MASK | LRU_REFS_FLAGS); - new_flags |=3D ((gen + 1UL) << LRU_GEN_PGOFF) | BIT(PG_workingset); - } while (!try_cmpxchg(&folio->flags.f, &old_flags, new_flags)); + lru_gen_set_flags(&new_flags, new_gen); + lru_refs_set_flags(&new_flags, 0); + new_flags |=3D BIT(PG_workingset); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); =20 - return ((old_flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; + return old_gen; } =20 /* protect pages accessed multiple times through file descriptors */ @@ -3301,21 +3307,20 @@ static int folio_inc_gen(struct lruvec *lruvec, str= uct folio *folio) int type =3D folio_is_file_lru(folio); struct lru_gen_folio *lrugen =3D &lruvec->lrugen; int new_gen, old_gen =3D lru_gen_from_seq(lrugen->min_seq[type]); - unsigned long new_flags, old_flags =3D READ_ONCE(folio->flags.f); - - VM_WARN_ON_ONCE_FOLIO(!(old_flags & LRU_GEN_MASK), folio); + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); =20 do { - new_gen =3D ((old_flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; + new_gen =3D lru_gen_from_flags(old_flags); + /* folio_update_gen() has promoted this page? */ if (new_gen >=3D 0 && new_gen !=3D old_gen) return new_gen; =20 + new_flags =3D old_flags; new_gen =3D (old_gen + 1) % MAX_NR_GENS; - - new_flags =3D old_flags & ~(LRU_GEN_MASK | LRU_REFS_FLAGS); - new_flags |=3D (new_gen + 1UL) << LRU_GEN_PGOFF; - } while (!try_cmpxchg(&folio->flags.f, &old_flags, new_flags)); + lru_gen_set_flags(&new_flags, new_gen); + lru_refs_set_flags(&new_flags, 0); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); =20 lru_gen_update_size(lruvec, folio, old_gen, new_gen); =20 @@ -4711,7 +4716,7 @@ static bool isolate_folio(struct lruvec *lruvec, stru= ct folio *folio, struct sca =20 /* see the comment on LRU_REFS_FLAGS */ if (!folio_test_referenced(folio)) - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, 0); + folio_set_lru_refs(folio, 0); =20 success =3D lru_gen_del_folio(lruvec, folio, true); VM_WARN_ON_ONCE_FOLIO(!success, folio); @@ -4927,8 +4932,10 @@ static int evict_folios(unsigned long nr_to_scan, st= ruct lruvec *lruvec, } =20 /* don't add rejected folios to the oldest generation */ - if (lru_gen_folio_seq(lruvec, folio, false) =3D=3D min_seq[type]) - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS, BIT(PG_active)); + if (lru_gen_folio_seq(lruvec, folio, false) =3D=3D min_seq[type]) { + folio_set_lru_refs(folio, 0); + folio_set_active(folio); + } } =20 move_folios_to_lru(&list); --=20 2.55.0 From nobody Mon Sep 28 20:05:41 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9998D331A5B; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; cv=none; b=qkkv0vExO1zszz1HKbojIXxLaBSlX9WQCHOJk9Unmspreq2DA0YKl+e6jC3YIMDjW3ECFSuJpQws13xDzKm01T8pu9gNyYaEc2iIjwCaXEAC/oKxRmz+IKDQeSr7yGGyz5XyFdS/4GxnRKm7/VHBAn0X/FJkyo99OvKZDwOaa4s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; c=relaxed/simple; bh=/Dap8HX+JALspR15co61JO/ZEe5sgXMBY1Lvt6lrf0U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=qWIs7ELeGzwfPx1rBqZPn/Ag5hZcZYc9OWxOHMOJoGvDStiHvPhvqjvLdFlSHLS+QxZGt3NVMLiQn4LsEsZh7Ezg9yw7czA7c00C93JkmugtTXgFuLGjqoc9V0fnBAY83J6ETxx+TF73T8BhZybmrhcCc3MBYdZVlJqIGoApuVA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=KpA3xO6c; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="KpA3xO6c" Received: by smtp.kernel.org (Postfix) with ESMTPS id 41221C2BCFD; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787031504; bh=/Dap8HX+JALspR15co61JO/ZEe5sgXMBY1Lvt6lrf0U=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=KpA3xO6c41IaXbmqmCFFQNGgoiKoADBI9iIN5v1UtOj5mM5iCtENnL3NuKy0jae6Y saGmVezGKNIRYu8komaX1eDr3C+spdAJdi1wB6tPXleDN8/7T++ZqESkDbPfmhxYuI Cvk4cqMjQuRFLZjUHLHHWHfUWGXHRka/450fgn2lPYrZCMSNGaXWmxd/gieSKlnhFG 9N+cxxdoUt9gHa38bAozYxLZRWsDp0JirwdS5lk1u73wU9CUy9IP3HKh1y1g/W3NCK M7Bc01TLYjpmzv/bWS4ZONcjF/ZmpCnl9/bf/VsWH6VDXHgoPn9FL5tnT/6nm9ZeaN ZQPFwMA/qgt9A== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2A8CCC5DF82; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) From: Kairui Song via B4 Relay Date: Tue, 18 Aug 2026 13:38:05 +0800 Subject: [PATCH 3/7] mm/migrate: copy the referenced state via folio_migrate_refs() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-mglru-flags-cleanup-v1-3-8dbbdac0d28c@tencent.com> References: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> In-Reply-To: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787031500; l=2602; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=MnXqCrD+kNnVgk+e93wC9DHznJeWbyePZC5TTqXqepo=; b=11ce+XvCl2hD19O2/CuCgrvBrmVTUm6nz/9U0YfjPuhZy1wZ8IJb0amYtFNhwztQfIB/4LtWh dx0NKZPYnYMBdFtD1f5AZ3c3/MzE+JFMBVWgnVPkcoVz/2/dB4v2kvE X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song folio_migrate_flags() copies PG_referenced separately, while folio_migrate_refs() copies the rest of the reference state. Make folio_migrate_refs() copy the complete state, i.e., PG_referenced plus the MGLRU refs counter, in both LRU implementations, and drop the open-coded copy so the reference state is transferred in one place. Signed-off-by: Kairui Song Reviewed-by: Baoquan He --- include/linux/mm_inline.h | 16 +++++++++++++--- mm/migrate.c | 4 ++-- 2 files changed, 15 insertions(+), 5 deletions(-) diff --git a/include/linux/mm_inline.h b/include/linux/mm_inline.h index 93bf3fa221f8..df62daaa2ee7 100644 --- a/include/linux/mm_inline.h +++ b/include/linux/mm_inline.h @@ -366,11 +366,19 @@ static inline bool lru_gen_del_folio(struct lruvec *l= ruvec, struct folio *folio, return true; } =20 +/** + * folio_migrate_refs - copy the reference state to a new folio + * @new: the destination folio + * @old: the source folio + * + * Transfer the reference state to @new during migration: the MGLRU + * refs count, including PG_referenced, or just PG_referenced for the + * active/inactive LRU. + */ static inline void folio_migrate_refs(struct folio *new, const struct foli= o *old) { - unsigned long refs =3D READ_ONCE(old->flags.f) & LRU_REFS_MASK; - - set_mask_bits(&new->flags.f, LRU_REFS_MASK, refs); + BUILD_BUG_ON(LRU_REFS_MASK & BIT(PG_referenced)); + folio_set_lru_refs(new, folio_lru_refs(old)); } #else /* !CONFIG_LRU_GEN */ =20 @@ -401,6 +409,8 @@ static inline bool lru_gen_del_folio(struct lruvec *lru= vec, struct folio *folio, =20 static inline void folio_migrate_refs(struct folio *new, const struct foli= o *old) { + if (folio_test_referenced(old)) + folio_set_referenced(new); } #endif /* CONFIG_LRU_GEN */ =20 diff --git a/mm/migrate.c b/mm/migrate.c index 15b45832bcfa..82307332711f 100644 --- a/mm/migrate.c +++ b/mm/migrate.c @@ -776,8 +776,6 @@ void folio_migrate_flags(struct folio *newfolio, struct= folio *folio) { int cpupid; =20 - if (folio_test_referenced(folio)) - folio_set_referenced(newfolio); if (folio_test_uptodate(folio)) folio_mark_uptodate(newfolio); if (folio_test_clear_active(folio)) { @@ -807,7 +805,9 @@ void folio_migrate_flags(struct folio *newfolio, struct= folio *folio) if (folio_test_idle(folio)) folio_set_idle(newfolio); =20 + /* Copy the reference state, including PG_referenced */ folio_migrate_refs(newfolio, folio); + /* * Copy NUMA information to the new page, to prevent over-eager * future migrations of this same page. --=20 2.55.0 From nobody Mon Sep 28 20:05:41 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BB29B3AD52E; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; cv=none; b=MbhMWgIr6/qSPD+0BtLXV7N+7yr83v841sHgbYM/QlIgoPvKSLcSu/WRWa5NEBIr/1xNAHHJEjd4cXbCB1QX2IQgrF/+ytJJ40b1+nkyoBh5i3YSqnK+Y2jUgnOEf/RSS6evkmkxxlBKaqzsA6+DcaVWsGMMShOzBNyyiV8Gr5I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; c=relaxed/simple; bh=OAEYAHvRDn/KTY3S+lBibMczmqVpBxMms7NDi/kgmjY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=M6sj+jCuPaJHrNSy2Y/SrNHzJgPBdTf3G/QD9SSX8ckXrCZdhTtC8dt5Sxts5AnCWLKz347qF2HnSARX4fZBqPz7TJ/woepcxk4vRoZWEBJqOzW+hSfMYazhMvUBz4TEHkBEO52t2sK3USkxOMQYAodows8sKUSjQSuieHNDyN0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=CDhDxJ/+; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="CDhDxJ/+" Received: by smtp.kernel.org (Postfix) with ESMTPS id 54B7EC32786; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787031504; bh=OAEYAHvRDn/KTY3S+lBibMczmqVpBxMms7NDi/kgmjY=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=CDhDxJ/+TQh30FoHM+NxivNH1JG2DRH7QhmDrXC7BbvEHeEYqm1kd5bkAtfmZUOlp pVKjvVKLQ8TFB3gq9QUN8rW5NpwPX1sfImb5wvZS0WMvF7pPMUyRUWC9RSPHXypCHZ /3EhppiEwOKBJERmLnPf/0sOYpLgHf9THs10LlFtm4BKbMittHzwA52pkI3rIPzZHx A12xUaMLDV2/jYO9/FHyJ4QM+XVS90Xsl1w5x+0eYdlX3zMvzoAKNhWZnFURADtSjO drVDEP5RpM0xqykVEhCQENQmrJnvnURtCcZWtS44I7eOErJmtSQa+FA8jeb77KeioM m98o1MqooY7Ng== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3F0C3C5DF70; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) From: Kairui Song via B4 Relay Date: Tue, 18 Aug 2026 13:38:06 +0800 Subject: [PATCH 4/7] mm/mglru: move max_seq read into walk_update_folio Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-mglru-flags-cleanup-v1-4-8dbbdac0d28c@tencent.com> References: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> In-Reply-To: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787031500; l=5056; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=xJliWtARqDMjztdZd0y51LBdqAE6bS5BXiS6nqiKTh0=; b=kE0rlnG7UORkiVh+WKvTvRn6/woWdPxys4/uv7e6m4BR0rOIriUl/7Jmyu83XFDkyjHEt/8J9 jJA7X49biR3Byh4lQigV51i9AyJdJFqg1Wh0jt7fQA0jhva1/yKtx9D X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song walk_pte_range(), walk_pmd_range_locked(), and lru_gen_look_around() each read lrugen->max_seq to compute the target generation used by walk_update_folio(), then pass it as a parameter. Move the read into walk_update_folio() itself so the callers no longer need to compute or pass the value. The max_seq read now happens once per folio update rather than once per walk range, so folios always get promoted to the current youngest generation. Signed-off-by: Kairui Song Reviewed-by: Baoquan He Reviewed-by: Baolin Wang Reviewed-by: Ridong Chen --- mm/vmscan.c | 29 ++++++++++++----------------- 1 file changed, 12 insertions(+), 17 deletions(-) diff --git a/mm/vmscan.c b/mm/vmscan.c index 080132997d87..a819be6b7ae9 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -3517,13 +3517,15 @@ static bool suitable_to_scan(int total, int young) } =20 static void walk_update_folio(struct lru_gen_mm_walk *walk, struct vm_area= _struct *vma, - struct folio *folio, int new_gen, bool dirty) + struct lruvec *lruvec, struct folio *folio, bool dirty) { - int old_gen; + int new_gen, old_gen; =20 if (!folio) return; =20 + new_gen =3D lru_gen_from_seq(READ_ONCE(lruvec->lrugen.max_seq)); + if (dirty && !folio_test_dirty(folio) && !(folio_test_anon(folio) && folio_test_swapbacked(folio) && !folio_test_swapcache(folio))) @@ -3554,8 +3556,6 @@ static bool walk_pte_range(pmd_t *pmd, unsigned long = start, unsigned long end, struct lru_gen_mm_walk *walk =3D args->private; struct mem_cgroup *memcg =3D lruvec_memcg(walk->lruvec); struct pglist_data *pgdat =3D lruvec_pgdat(walk->lruvec); - DEFINE_MAX_SEQ(walk->lruvec); - int gen =3D lru_gen_from_seq(max_seq); unsigned int nr; pmd_t pmdval; =20 @@ -3606,7 +3606,7 @@ static bool walk_pte_range(pmd_t *pmd, unsigned long = start, unsigned long end, continue; =20 if (last !=3D folio) { - walk_update_folio(walk, args->vma, last, gen, dirty); + walk_update_folio(walk, args->vma, walk->lruvec, last, dirty); =20 last =3D folio; dirty =3D false; @@ -3619,7 +3619,7 @@ static bool walk_pte_range(pmd_t *pmd, unsigned long = start, unsigned long end, walk->mm_stats[MM_LEAF_YOUNG] +=3D nr; } =20 - walk_update_folio(walk, args->vma, last, gen, dirty); + walk_update_folio(walk, args->vma, walk->lruvec, last, dirty); last =3D NULL; =20 if (i < PTRS_PER_PTE && get_next_vma(PMD_MASK, PAGE_SIZE, args, &start, &= end)) @@ -3642,8 +3642,6 @@ static void walk_pmd_range_locked(pud_t *pud, unsigne= d long addr, struct vm_area struct lru_gen_mm_walk *walk =3D args->private; struct mem_cgroup *memcg =3D lruvec_memcg(walk->lruvec); struct pglist_data *pgdat =3D lruvec_pgdat(walk->lruvec); - DEFINE_MAX_SEQ(walk->lruvec); - int gen =3D lru_gen_from_seq(max_seq); =20 VM_WARN_ON_ONCE(pud_leaf(*pud)); =20 @@ -3697,7 +3695,7 @@ static void walk_pmd_range_locked(pud_t *pud, unsigne= d long addr, struct vm_area goto next; =20 if (last !=3D folio) { - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, walk->lruvec, last, dirty); =20 last =3D folio; dirty =3D false; @@ -3711,7 +3709,7 @@ static void walk_pmd_range_locked(pud_t *pud, unsigne= d long addr, struct vm_area i =3D i > MIN_LRU_BATCH ? 0 : find_next_bit(bitmap, MIN_LRU_BATCH, i) + = 1; } while (i <=3D MIN_LRU_BATCH); =20 - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, walk->lruvec, last, dirty); =20 lazy_mmu_mode_disable(); spin_unlock(ptl); @@ -4275,8 +4273,6 @@ bool lru_gen_look_around(struct page_vma_mapped_walk = *pvmw, unsigned int nr) struct pglist_data *pgdat =3D folio_pgdat(folio); struct lruvec *lruvec; struct lru_gen_mm_state *mm_state; - unsigned long max_seq; - int gen; =20 lockdep_assert_held(pvmw->ptl); VM_WARN_ON_ONCE_FOLIO(folio_test_lru(folio), folio); @@ -4313,8 +4309,6 @@ bool lru_gen_look_around(struct page_vma_mapped_walk = *pvmw, unsigned int nr) =20 memcg =3D get_mem_cgroup_from_folio(folio); lruvec =3D mem_cgroup_lruvec(memcg, pgdat); - max_seq =3D READ_ONCE((lruvec)->lrugen.max_seq); - gen =3D lru_gen_from_seq(max_seq); mm_state =3D get_mm_state(lruvec); =20 lazy_mmu_mode_enable(); @@ -4346,7 +4340,7 @@ bool lru_gen_look_around(struct page_vma_mapped_walk = *pvmw, unsigned int nr) continue; =20 if (last !=3D folio) { - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, lruvec, last, dirty); =20 last =3D folio; dirty =3D false; @@ -4358,13 +4352,14 @@ bool lru_gen_look_around(struct page_vma_mapped_wal= k *pvmw, unsigned int nr) young +=3D nr; } =20 - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, lruvec, last, dirty); =20 lazy_mmu_mode_disable(); =20 /* feedback from rmap walkers to page table walkers */ if (mm_state && suitable_to_scan(i, young)) - update_bloom_filter(mm_state, max_seq, pvmw->pmd); + update_bloom_filter(mm_state, READ_ONCE(lruvec->lrugen.max_seq), + pvmw->pmd); =20 mem_cgroup_put(memcg); =20 --=20 2.55.0 From nobody Mon Sep 28 20:05:41 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C08083C73D7; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; cv=none; b=ad+bN3+rOtGUP/RmE5RF8R/KC11ecud07NjcEfo6oZkMY7WFcBdqt79PaGKJSkOTdDurFQiW6fm4P/EKmhC3Sy4fYjL18y8L5vJq1FaN2ss0WXg/ztjoFC0UzdbESsAI5fx9tSyxiBCE48/H8q+h+pD30mCs5wxK6AOekPCtHSE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; c=relaxed/simple; bh=Sx8EIzWCQwmQ5nLlhTfCRcDmg7PW3HdfIWlqtAUVtug=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=bxgT1zObnrqBD1Q95mPkPkaRReaFrcQGLo69W8foOdJM4e+d8HIihzFA5i+dIEf3NRGDJvQPXlSkb4V0qV3+FFCO3oymnZquODylt8N7dRx5dwbkRMMF3ZTdxrNM/RmnbKB6kLU6kYyJlnkk9rGUlzC5AnkBY0QcgxrfR/YG4QI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=kKAKg1hL; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="kKAKg1hL" Received: by smtp.kernel.org (Postfix) with ESMTPS id 72091C4AF1A; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787031504; bh=Sx8EIzWCQwmQ5nLlhTfCRcDmg7PW3HdfIWlqtAUVtug=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=kKAKg1hL8/QJ6S0wakilKwr0s1rR7LJsgNCNefhuFRVEv8PUwaWU9/SSo2PhnEhZn HVKQ9xn+0mBjwgJV4cWk66CGmEVELNGV4V7QqIzj4K95A/LY1fJixWtIBpIr04SrFf DBlbgwCurQ10l/B4NqBwnexoc8HLfHMwzuZ+B49662MrfentTkxYsUwdlYU7l2BzZa SnXLgolF2haIKbQz4jZvJttKu8WCYkfMSufzF+wQQhKdZjM82gQbnAc/t2D4jgB49A lT0pEkpbCsOUH5Wcwz0fwpdWc0Cqd2mUBsOITguRHS3xBi0rbG8F6iowhhHfiQ5WGJ EJeOrv0s/cWPg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5A915C5DF67; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) From: Kairui Song via B4 Relay Date: Tue, 18 Aug 2026 13:38:07 +0800 Subject: [PATCH 5/7] mm/mglru: use explicit tier range in read_ctrl_pos() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-mglru-flags-cleanup-v1-5-8dbbdac0d28c@tencent.com> References: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> In-Reply-To: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787031500; l=3448; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=GYBGb1xTYAtwF8ULj9QKeuy7M/IFOhc3aBT9Nkjj2Us=; b=hZsipqcQnctqC9gaBUbfHO2y8v0AyYm5uSBYOqOLuZZpuIPS1tItIjOSQv7M5GcDMTYwSIrAD Vygm8AIFzatCFz7bA7FXXGfPRfwCpMJd9W58MsRsA4lbht1gCaM74wm X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song read_ctrl_pos() encodes the tier range in a single "tier" parameter via "tier % MAX_NR_TIERS" as the start and "min(tier, MAX_NR_TIERS-1)" as the end. This is hard to follow, maintain, or extend. Tier values 0..3 select a single tier, while tier =3D=3D MAX_NR_TIERS selects the full range. Replace it with explicit (tier_min, tier_max) parameters using a closed [tier_min, tier_max] interval, and add LRU_TIER_MIN and LRU_TIER_MAX for the tier bounds. The call sites now become self-documenting: - get_tier_idx: (LRU_TIER_MIN, LRU_TIER_MIN) for the first tier, (tier, tier) for each subsequent tier - get_type_to_scan: (LRU_TIER_MIN, LRU_TIER_MAX) for the full range No functional change. Signed-off-by: Kairui Song Reviewed-by: Baolin Wang Reviewed-by: Baoquan He Reviewed-by: Barry Song --- include/linux/mmzone.h | 2 ++ mm/vmscan.c | 18 ++++++++++-------- 2 files changed, 12 insertions(+), 8 deletions(-) diff --git a/include/linux/mmzone.h b/include/linux/mmzone.h index 32d9354a754f..d0b5c6217d25 100644 --- a/include/linux/mmzone.h +++ b/include/linux/mmzone.h @@ -492,6 +492,8 @@ enum lruvec_flags { * folio->flags, masked by LRU_REFS_MASK. */ #define MAX_NR_TIERS 4U +#define LRU_TIER_MIN 0U +#define LRU_TIER_MAX (MAX_NR_TIERS - 1) =20 #ifndef __GENERATING_BOUNDS_H =20 diff --git a/mm/vmscan.c b/mm/vmscan.c index a819be6b7ae9..a613bb8d7271 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -3198,8 +3198,8 @@ struct ctrl_pos { int gain; }; =20 -static void read_ctrl_pos(struct lruvec *lruvec, int type, int tier, int g= ain, - struct ctrl_pos *pos) +static void read_ctrl_pos(struct lruvec *lruvec, int type, int tier_min, + int tier_max, int gain, struct ctrl_pos *pos) { int i; struct lru_gen_folio *lrugen =3D &lruvec->lrugen; @@ -3208,7 +3208,7 @@ static void read_ctrl_pos(struct lruvec *lruvec, int = type, int tier, int gain, pos->gain =3D gain; pos->refaulted =3D pos->total =3D 0; =20 - for (i =3D tier % MAX_NR_TIERS; i <=3D min(tier, MAX_NR_TIERS - 1); i++) { + for (i =3D tier_min; i <=3D tier_max; i++) { pos->refaulted +=3D lrugen->avg_refaulted[type][i] + atomic_long_read(&lrugen->refaulted[hist][type][i]); pos->total +=3D lrugen->avg_total[type][i] + @@ -4804,9 +4804,9 @@ static int get_tier_idx(struct lruvec *lruvec, int ty= pe) * This value is chosen because any other tier would have at least twice * as many refaults as the first tier. */ - read_ctrl_pos(lruvec, type, 0, 2, &sp); - for (tier =3D 1; tier < MAX_NR_TIERS; tier++) { - read_ctrl_pos(lruvec, type, tier, 3, &pv); + read_ctrl_pos(lruvec, type, LRU_TIER_MIN, LRU_TIER_MIN, 2, &sp); + for (tier =3D LRU_TIER_MIN + 1; tier <=3D LRU_TIER_MAX; tier++) { + read_ctrl_pos(lruvec, type, tier, tier, 3, &pv); if (!positive_ctrl_err(&sp, &pv)) break; } @@ -4827,8 +4827,10 @@ static int get_type_to_scan(struct lruvec *lruvec, i= nt swappiness) * Compare the sum of all tiers of anon with that of file to determine * which type to scan. */ - read_ctrl_pos(lruvec, LRU_GEN_ANON, MAX_NR_TIERS, swappiness, &sp); - read_ctrl_pos(lruvec, LRU_GEN_FILE, MAX_NR_TIERS, MAX_SWAPPINESS - swappi= ness, &pv); + read_ctrl_pos(lruvec, LRU_GEN_ANON, LRU_TIER_MIN, LRU_TIER_MAX, + swappiness, &sp); + read_ctrl_pos(lruvec, LRU_GEN_FILE, LRU_TIER_MIN, LRU_TIER_MAX, + MAX_SWAPPINESS - swappiness, &pv); =20 return positive_ctrl_err(&sp, &pv); } --=20 2.55.0 From nobody Mon Sep 28 20:05:41 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C76FB3CC7EC; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; cv=none; b=QDKXkqzQCjoazyU+SpuZsfkRdb889QQLMNDIxHObzbR2NMlpZsZkTGG0zSuDk49VAIPWsweXEcBSyNIrUssBYBGPBx4iETwxMmw3FaH3xPDJuxnCA4WddF3EytECPS6N8CDa1EMUYC/nkRkf57h/JWVWX2F4hxAycQ1rPhNQuN0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; c=relaxed/simple; bh=sQcddfGPGWpgil3snuuOfjff6hNZ59AO94B/J9asvAQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=FA7uo/kGwM/fz2/sdogBQGpXD5ak35SbzElOuFY/eiH5P1UPY+KaCWy1gX2yqaAmI2FV+fRiZDa4IZffxBEb2LRgFaE5LQaGAn/MfnA+QCqAJpGTcLIOrgUdvi5RaxKeqhoyz28AWHyXii5NnVYU0BPRLgXD0FfJqSPEs16BHq4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Ks1Otgoo; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Ks1Otgoo" Received: by smtp.kernel.org (Postfix) with ESMTPS id 84F7BC2BCFF; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787031504; bh=sQcddfGPGWpgil3snuuOfjff6hNZ59AO94B/J9asvAQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=Ks1OtgooAkhlZ9BEfLD8zNw/0RdXJER1xD8oZsV5FnRqqq4mIrONZJQalSFH1NPqA 5jo+MCmWXefEKvy1HrDrNwVzH9dFJlBkQZJj1r0UZNqKbo0HCOpguhGV49I3HksP9m MEVdxxIHjJRpdJQwTQpjGybbh+qBQn5LyJa5DNxbQRMKQkfP+gnXj011sTxypp3YGY tFaPRpBfbZmOzVirp1KBWFVlXbatHv3GkUuFRGs77l8u7eZYg9grVTZWgC487eyloU nQKem1xQveV1UtSdjj3XqjosxP5wu2UaeNE8Je5WhSpWBSj4Xkku2mzj+q5TIHvOIV C9JshW/V+omcw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 71C86C5DF70; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) From: Kairui Song via B4 Relay Date: Tue, 18 Aug 2026 13:38:08 +0800 Subject: [PATCH 6/7] mm/mglru: fix potential generation folio number leak Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-mglru-flags-cleanup-v1-6-8dbbdac0d28c@tencent.com> References: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> In-Reply-To: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787031500; l=4447; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=RQ+/yXu5Ad8B7H0/N8WrVK9khx+u3YPD4VofNalxc64=; b=cfXZesEt3HAFlRTwsJTeSktOmQNsfJsb5vwfLGKcBYj5CBIRCSV1MsCNF4o1W99XR2XRVNn9C Ys4Vr2qcYhqDmbxB9rHcNo3vZlGDHEOJ4R6A9Gbmih2jVq/1NJ5Cd5y X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song Each generation of MGLRU accounts anon and file folio numbers separately. The page table walker's update_batch_size() derives the anon / file type of a folio from its current flags, but the page table walk holds neither the lruvec lock nor the folio lock, so the type can change during that period. MADV_FREE's lazyfree path clears PG_swapbacked under the lruvec lock, so the folio is no longer considered on the anon LRU list. Lazyfreed folios can also be changed back to the anon list again. If the flip lands between folio_update_gen()'s cmpxchg and the type read in update_batch_size(), the batched delta pair is applied to the wrong type. The anon and file generation counters then carry phantom deltas that nothing reconciles, permanently skewing lrugen->nr_pages and the reclaim budgets derived from it. Fix it by capturing the type from the flags snapshot the cmpxchg linearized against: folio_update_gen() returns the type of the state it transitioned from, and update_batch_size() accounts with it instead of re-reading the live flags. The batched deltas then always match the type of the state the cmpxchg transitioned from. Fixes: 018ee47f1489 ("mm: multi-gen LRU: exploit locality in rmap") Signed-off-by: Kairui Song --- include/linux/mm_inline.h | 7 ++++++- mm/vmscan.c | 13 +++++++------ 2 files changed, 13 insertions(+), 7 deletions(-) diff --git a/include/linux/mm_inline.h b/include/linux/mm_inline.h index df62daaa2ee7..4bb390d9516e 100644 --- a/include/linux/mm_inline.h +++ b/include/linux/mm_inline.h @@ -10,6 +10,11 @@ #include #include =20 +static inline int folio_flags_is_file_lru(const unsigned long *flags) +{ + return !test_bit(PG_swapbacked, flags); +} + /** * folio_is_file_lru - Should the folio be on a file LRU or anon LRU? * @folio: The folio to test. @@ -27,7 +32,7 @@ */ static inline int folio_is_file_lru(const struct folio *folio) { - return !folio_test_swapbacked(folio); + return folio_flags_is_file_lru(const_folio_flags(folio, 0)); } =20 static __always_inline void __update_lru_size(struct lruvec *lruvec, diff --git a/mm/vmscan.c b/mm/vmscan.c index a613bb8d7271..7169cac60869 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -3269,7 +3269,8 @@ static bool positive_ctrl_err(struct ctrl_pos *sp, st= ruct ctrl_pos *pv) *************************************************************************= *****/ =20 /* promote pages accessed through page tables */ -static int folio_update_gen(struct folio *folio, int new_gen, const vma_fl= ags_t *vma_flags) +static int folio_update_gen(struct folio *folio, int new_gen, int *is_file, + const vma_flags_t *vma_flags) { unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); int old_gen; @@ -3298,6 +3299,7 @@ static int folio_update_gen(struct folio *folio, int = new_gen, const vma_flags_t new_flags |=3D BIT(PG_workingset); } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); =20 + *is_file =3D folio_flags_is_file_lru(&old_flags); return old_gen; } =20 @@ -3328,9 +3330,8 @@ static int folio_inc_gen(struct lruvec *lruvec, struc= t folio *folio) } =20 static void update_batch_size(struct lru_gen_mm_walk *walk, struct folio *= folio, - int old_gen, int new_gen) + int old_gen, int new_gen, int type) { - int type =3D folio_is_file_lru(folio); int zone =3D folio_zonenum(folio); int delta =3D folio_nr_pages(folio); =20 @@ -3519,7 +3520,7 @@ static bool suitable_to_scan(int total, int young) static void walk_update_folio(struct lru_gen_mm_walk *walk, struct vm_area= _struct *vma, struct lruvec *lruvec, struct folio *folio, bool dirty) { - int new_gen, old_gen; + int new_gen, old_gen, file; =20 if (!folio) return; @@ -3532,9 +3533,9 @@ static void walk_update_folio(struct lru_gen_mm_walk = *walk, struct vm_area_struc folio_mark_dirty(folio); =20 if (walk) { - old_gen =3D folio_update_gen(folio, new_gen, &vma->flags); + old_gen =3D folio_update_gen(folio, new_gen, &file, &vma->flags); if (old_gen >=3D 0 && old_gen !=3D new_gen) - update_batch_size(walk, folio, old_gen, new_gen); + update_batch_size(walk, folio, old_gen, new_gen, file); } else if (lru_gen_set_refs(folio, &vma->flags)) { old_gen =3D folio_lru_gen(folio); if (old_gen >=3D 0 && old_gen !=3D new_gen) --=20 2.55.0 From nobody Mon Sep 28 20:05:41 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CF1B73D1CC1; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; cv=none; b=OHBOEe+Gemol38yQNvoH0aayX0DyFOD+PbER6tAm+SKqJEMEArGGaAeYht8AxcL8CHA36XAQkha4lSuTUnfbQlA6HJZdwK8fQfraaLCuHKdxj1tMSPwmoNddMmWFJJLMpQSHSaJFCeosloLv7iWy6uE7w9jPcRckdWpobNXOLCk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787031504; c=relaxed/simple; bh=vf7uUbNRQoieyYFfFFIOjDq7Zps04yMwcdb5rXbBTqQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=bu9mEd+FQJOgRdo7rUVD7l6ecq0cSiTVDocSOGn410WLsdjokbKMcJCnJ+IKosRQQsA8dV4vgPBX8p/DnK5fXa6NOm+qIlcvDETIRddvAE2e2dfBKVT2GPqu2ijntIKbGB9WRJET2e9gyhOcK70VfsUqvdJZPHNdKWZnCl1hW70= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=LTGab89Q; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="LTGab89Q" Received: by smtp.kernel.org (Postfix) with ESMTPS id 9DC97C2BD04; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787031504; bh=vf7uUbNRQoieyYFfFFIOjDq7Zps04yMwcdb5rXbBTqQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=LTGab89QxsH+2wOkBE11hQkp5+C3ffibZSkFOVGgVBY/t9R6+5V4buuIn2akRMsBP DbU4oKpvnnxkytOuhdWYLe7dU20+pv55FuTpEpH5YcKmCJs3HBuw2yd33R3EiWNMUH WWicCJLDsSdCrC0DzserL9vFumBLpygQTm6dWtuHcKHnkMBzbxaJiA1oDhidQ/1Jfc EcuXXm21Nl6RRTo8y2EymKXn9PNTOIGlUEBZXZC04C0O7Rh73UWzXN8s48k7Y2eRV1 jafAMoFq82epiQ7ItDOT0gw10W4uHFF6GtMs0hhINHVzxUCma9cK8j+HrK2BawiN+A 7Zt2GcdKD3Frg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 88C04C5DF80; Tue, 18 Aug 2026 05:38:24 +0000 (UTC) From: Kairui Song via B4 Relay Date: Tue, 18 Aug 2026 13:38:09 +0800 Subject: [PATCH 7/7] mm/mglru: improve code readability and harden folio_inc_gen Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-mglru-flags-cleanup-v1-7-8dbbdac0d28c@tencent.com> References: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> In-Reply-To: <20260818-mglru-flags-cleanup-v1-0-8dbbdac0d28c@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787031501; l=1891; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=VAAQ2yiZ5J1ZoI2nmEdgdm+eoSsfABEBNy6fHJoC/Ao=; b=vfv8/0vJNXjl4xfANa0zvplr3gsB8l5c6I3ZE3bYCfgQRy1JPhuV/RfkOve+UzP3ZSo3ThysQ 4bzJd3exJcxDOzcNw7VQ6D4JMMsKi6+5BvFKSfMgZ+wrxOLJtBX/l/a X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song The helper should never be called for an off-list folio, and it always expects the folio to be in the oldest generation before doing any cmpxchg. Add a sanity check for the off-list case: if it is ever violated, bail out and keep the folio flags untouched to minimize the damage, instead of silently treating the folio as if it were in the oldest generation and promoting it updating the flags to an unexpected status. Also rename the variables to clearly distinguish the folio's current gen from the oldest gen. Signed-off-by: Kairui Song --- mm/vmscan.c | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/mm/vmscan.c b/mm/vmscan.c index 7169cac60869..7e3ae0c6cba3 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -3308,18 +3308,22 @@ static int folio_inc_gen(struct lruvec *lruvec, str= uct folio *folio) { int type =3D folio_is_file_lru(folio); struct lru_gen_folio *lrugen =3D &lruvec->lrugen; - int new_gen, old_gen =3D lru_gen_from_seq(lrugen->min_seq[type]); + int new_gen, old_gen, min_gen =3D lru_gen_from_seq(lrugen->min_seq[type]); unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); =20 do { - new_gen =3D lru_gen_from_flags(old_flags); + old_gen =3D lru_gen_from_flags(old_flags); + /* This helper should never be called for off-list folios */ + VM_WARN_ON_ONCE(old_gen < 0); + if (old_gen < 0) + return min_gen; =20 /* folio_update_gen() has promoted this page? */ - if (new_gen >=3D 0 && new_gen !=3D old_gen) - return new_gen; + if (old_gen !=3D min_gen) + return old_gen; =20 new_flags =3D old_flags; - new_gen =3D (old_gen + 1) % MAX_NR_GENS; + new_gen =3D (min_gen + 1) % MAX_NR_GENS; lru_gen_set_flags(&new_flags, new_gen); lru_refs_set_flags(&new_flags, 0); } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); --=20 2.55.0