From nobody Mon Sep 28 12:34:14 2026 Received: from mail-qt1-f169.google.com (mail-qt1-f169.google.com [209.85.160.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5D4E41DED49 for ; Fri, 21 Aug 2026 15:09:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787324971; cv=none; b=iTbNcJkvyfsTGBaoyrZfc+HhV9OmyAwB3LzL5EHODCbKt63hugKTFsBtwhwCYH+2KqCZFG8KAEIU7dXqRD6+0bVDygso0TC5pe6kaGEuMpDv8j9oiQ8pT8vii1bUQs6EswNRPYnp8VQr+prl4UeGr36Tu4a6ZHfR3v97OEHXnc8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787324971; c=relaxed/simple; bh=9NDTefgBlzWOckLtF/RAesPXLsekgCh7w2HNuIVrmVA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=GXhA47MbbOxkCISBYsAj6StTQBwxjvSSuJdjIixM1w338Ovhn7AtJ4OLuULPPt8ilAHLAh3jEZujDefyJU1hSKDiDrN/C1Dx80sXG4HJhGXoHFwGDU4tB+7/eB2KEv67VT3MErjFkXWMfVA004eOPsNObwQmQnQFcIRJbykqrgg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=gourry.net; spf=pass smtp.mailfrom=gourry.net; dkim=pass (2048-bit key) header.d=gourry.net header.i=@gourry.net header.b=stma2wBq; arc=none smtp.client-ip=209.85.160.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=gourry.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gourry.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gourry.net header.i=@gourry.net header.b="stma2wBq" Received: by mail-qt1-f169.google.com with SMTP id d75a77b69052e-51c08df8513so6827821cf.3 for ; Fri, 21 Aug 2026 08:09:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gourry.net; s=google; t=1787324968; x=1787929768; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=km/KnQoou2cC+qse6JnYkYGCCo/Enm/DijWAIfXBagw=; b=stma2wBqSZb/SNZrLUpfWnyG/PWOILJNseLDCq02ZM4KCai4k0kDzHajqXxQ8yx949 q3UnPyglbCbqsLSHT6keiCRkzH6+UmWaeio3jNRqtM69sJqRLUSip5VLY8zD6rRVGVWZ PLoPaiFyUkeMoQF7cJL/DDkEK4FYutBTO3MFOKMxx3M5uDrVDPGbZmIDgnGKw5udArhW JR4GRf4AHurkS5PoZTpayt50Uwxmtzyv/tXHJVoMt54odmJxAPThxIty4y6mMjMDStjx P6jysmfv4lgzTJsn3dLFYIgxa8nPDt6oiWV+lS1+subVlnC/CgpXcKbUyCQGSIy4FdTr IJ3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787324968; x=1787929768; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=km/KnQoou2cC+qse6JnYkYGCCo/Enm/DijWAIfXBagw=; b=r+9ad22FtT44YXBMXBGWr6J4uHXXHuH0mXEfraZ+gzL+WDJVEHxNGR8zejsiqF/icZ qAw9gYM2g56L37+/5wZo60FEumo0vwUmsLwy4JdlGOqQu/Cq6ykQKFhXM30O5aII8kEo 49GeQVz5ovhMWYDh944BzhnAZolkToRQT7zVbmZwbi68wv3gRZRz/VP2avFXjpSVYXsA Q3XP+X26CzHmvhZQxxewxcEfLlGEFtT4UaPBggEdu+hRrNrrETcdE24QnZFZMOxIaJ71 AvTszD+pXz77+JYmtGPW7fodk9mA4ZPqNp2wseSWlTk7OCGMRUhb0kRF65BJQqBX+EFQ JknQ== X-Gm-Message-State: AOJu0YwyKNZRaqfXwuyl5X7C00m0I5b5B6Xf3QYtzWSlwlrJLA5Ig9tm Wy4NM2Ew0yXcsdCBYrTXVRwLh5Nxrx7I4nsnSLw8cVWJCTgr6fUtJPXjduF+1O2Fn8g= X-Gm-Gg: AR+sD12JEvpt0BuRk6MGVx/jyhCMSfi3BCdhWBSIIfTE747hemEMQgt4zA40+Z+d6eB AfSugvJCKF8asCeEpib1WJ08A7OOAgRbnVi4VtZkaRXiIaUmOIA5LhSo7yCbKJNBPe2ms5lsiNT MixXoWXKvvqH3lUFJMFQaK9Ibx3kVlRbGXnDEeOKPoE1tNxwJR4769rnSltdE/qh15HlReq7MQG /xRBMCWA1+yDzwJP27uD3Sdp7V0284S797VaJYZHzlSmUlT37Jsu0XhZ1yRyVze1zh30X5CAXxK Jg2MKIugR4gPsmV7+dlB/R2TCmzPcNC/UNmpYpq6pjfRkS9KLCS9EaskNA9/TiwY02heqLsdsAe r+a8+BqdPsLgcrfQfSGv6gtgMzPCjJtSTT6mUFOhsFtWtK805PalS/s9Q7RYePsSNHXRV+T9gS8 zYLub6uS0IRCgUuzGb7f5pvigqV4SL8muuftTKXPJtxcWFyGtYoCGR38ruGnKGg4XFGfhae+zvH BmdlRXrP0NFhcVKLA18u97BUVydTgGsTFlKV4gfNpj5EiKW0Q== X-Received: by 2002:a05:622a:17c7:b0:51b:cdc2:fb99 with SMTP id d75a77b69052e-52df5a08502mr70705551cf.24.1787324967962; Fri, 21 Aug 2026 08:09:27 -0700 (PDT) Received: from gourry-fedora-PF4VCD3F.lan (pool-173-79-60-52.washdc.fios.verizon.net. [173.79.60.52]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52df40eb50csm19708061cf.0.2026.08.21.08.09.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 08:09:27 -0700 (PDT) From: Gregory Price To: linux-mm@kvack.org Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com, akpm@linux-foundation.org, liam@infradead.org, ljs@kernel.org, david@kernel.org, vbabka@kernel.org, jannh@google.com, sashiko-bot , "Gregory Price (Meta)" Subject: [PATCH] mm/madvise: use folio_trylock() in the cold/pageout PMD split Date: Fri, 21 Aug 2026 11:09:12 -0400 Message-ID: <20260821150912.183976-1-gourry@gourry.net> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" MADV_COLD or MADV_PAGEOUT over part of a PMD splits the THP in madvise_cold_or_pageout_pte_range(). Two threads doing that to the same THP create spurious failures. CPU0 CPU1 ---- ---- folio_get() spin_unlock(ptl) folio_lock() folio_get() spin_unlock(ptl) folio_lock() <- blocks, keeps its ref split_folio() folio_expected_ref_count(folio) !=3D folio_ref_count(folio) - 1 -EAGAIN CPU1 cannot drop its reference until it gets the lock CPU0 holds, so CPU0's split always fails. folio_trylock() makes CPU1 leave without ever taking a reference. The PTE branch of this same function already does this, as do madvise_free_pte_range() and madvise_free_huge_pmd(). Reproducer: 400 rounds of eight threads calling MADV_COLD on half of each of eight THPs, re-formed with MADV_COLLAPSE between rounds. From /proc/vmstat: thp_split_page thp_split_page_failed before 3186 860 after 3200 0 The short before count is rounds where every thread failed and the advice was dropped for that THP entirely. On failure the walker returns 0 and nothing retries. The PMD path becomes best effort when the folio lock is held elsewhere - same as the PTE path. Reported-by: sashiko-bot Closes: https://sashiko.dev/#/patchset/20260817220810.1175596-1-gourry%40go= urry.net Assisted-by: Claude:claude-opus-5 Signed-off-by: Gregory Price (Meta) Acked-by: Lorenzo Stoakes (ARM) --- mm/madvise.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/mm/madvise.c b/mm/madvise.c index 07a21ca31bad..bd9119880ef2 100644 --- a/mm/madvise.c +++ b/mm/madvise.c @@ -405,9 +405,10 @@ static int madvise_cold_or_pageout_pte_range(pmd_t *pm= d, if (next - addr !=3D HPAGE_PMD_SIZE) { int err; =20 + if (!folio_trylock(folio)) + goto huge_unlock; folio_get(folio); spin_unlock(ptl); - folio_lock(folio); err =3D split_folio(folio); folio_unlock(folio); folio_put(folio); --=20 2.55.0