From nobody Sat Sep 26 20:29:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E0B72F0C7E; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; cv=none; b=q9YqHFj9pMV1YdiaRkVUu5eZoc/llKGu5Ac8GP/2NKLxTp5dVgqz2vkpNFXWclKlTlZMhiUQ0TuKhlleh7wVPTgiahjMQEXzPhMLIvgSAMcxwQlA8yx7bkT8bc7b5WpVGqzHPJFPSj5w8MJIr8ivPs3MytV330prfDr0/LuMXeA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; c=relaxed/simple; bh=571fAvo+ZaIKBCUitIDqLYFldwlZ2o4hP7Qze7dNNWE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=M+k/n7BEOtKKqd3nn7NUMTTqVHoHws7Lf/5fjOqx0+3XGvJpiUsulne6z4GLCwVZP2BkE3pZYh0t3iUxKEXA6QWVALQIDtXB4gN+lex6vuZuhspZ3Fg2JMqDHDLYwMZ4TmBPYEYVuWQ+n28N/U87AnV5wQLJ8U0SAZrdyHNMYOQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=h8sS7y7U; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="h8sS7y7U" Received: by smtp.kernel.org (Postfix) with ESMTPS id BA871C2BCFB; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1788115417; bh=571fAvo+ZaIKBCUitIDqLYFldwlZ2o4hP7Qze7dNNWE=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=h8sS7y7UlJyAyYxGnPxj6GIsJRbFKD31MMGxqZ2UFVeXHlweaevtHRaW7q286JnXZ 1gye+JAOLeGJQg3tJi6Y2vsvamIRvNcbBqrjeaiyIreG2IeXJOusYNuLKR+jknwfq9 kCr5Mxe2HW5JJZgyfIvyGkngNjNWmdSJ61Mnj3cfFKpvhKGQV7quMGH3fg3SX+ZNzZ 41Kyj5kROXc9jwA/Iygdw0CmeqrD+/pFjOSZcwWs54OUP8dX39/ffQYnpQ9+q3LPQ4 R38HxYRzmUL+DDIlwNBM6GOenUjY2pRNz+ZdDxkaFuBgNqshFFXBzxMg5ZqfdFlfhE 3vN0X5oaQXUgA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 96861C61DB9; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) From: Kairui Song via B4 Relay Date: Mon, 31 Aug 2026 02:43:31 +0800 Subject: [PATCH v4 1/6] mm/memcontrol: make lru_zone_size atomic and simplify sanity check Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260831-mglru-flags-cleanup-v4-1-2d15dde0d7ee@tencent.com> References: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> In-Reply-To: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Ridong Chen , Lian Wang , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1788115415; l=3661; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=dZSJQRCK3EQ9sViTkUwC4Atda6qGT2eBA8Z4NTjwo2M=; b=QsPxwLTmieZHKBA2YEdznw6Sn+TafoOjMn4N23z5w0ahXZYooZTpq8HNxBGXj1/xdoKqAjqMk OED5XTVuKJFDFO4G8NRFK55XKBl3PT6Q7G3HrdniXlA73INl5QfoqTB X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song commit ca707239e8a7 ("mm: update_lru_size warn and reset bad lru_size") introduced a sanity check to catch memcg counter underflow, which was more of a workaround for another bug: lru_zone_size is unsigned, so underflow wraps it around and returns an enormously large number, then the memcg shrinker loops almost forever as the calculated number of folios to shrink is huge. That commit also checked if a zero value matches the empty LRU list, so we have to hold the LRU lock, and handle the positive and negative deltas separately. But later commit b4536f0c829c ("mm, memcg: fix the active list aging for lowmem requests when memcg is enabled") already removed the LRU emptiness check, so handling the deltas separately is no longer needed. And if we just turn it into an atomic long, underflow isn't a big issue either, and can be checked at the reader side, which is called much less frequently than the updater. So let's turn the counter into an atomic long and check at the reader side instead, which has a smaller overhead. The underflow correction is removed: a massive leak of the LRU size counter would indicate that something else has gone very wrong, and one should fix that leaking site instead. Besides, the updater-side sanity check is unlikely to catch the leaking site anyway: if a folio was removed without updating the counter while other folios remain on the LRU, the WARN only triggers much later, from a likely innocent callsite. Reviewed-by: Ridong Chen Reviewed-by: Barry Song Signed-off-by: Kairui Song --- include/linux/memcontrol.h | 9 +++++++-- mm/memcontrol.c | 18 +----------------- 2 files changed, 8 insertions(+), 19 deletions(-) diff --git a/include/linux/memcontrol.h b/include/linux/memcontrol.h index 7d1c0ce189a8..1b49d8b591da 100644 --- a/include/linux/memcontrol.h +++ b/include/linux/memcontrol.h @@ -113,7 +113,7 @@ struct mem_cgroup_per_node { /* Fields which get updated often at the end. */ struct lruvec lruvec; CACHELINE_PADDING(_pad2_); - unsigned long lru_zone_size[MAX_NR_ZONES][NR_LRU_LISTS]; + atomic_long_t lru_zone_size[MAX_NR_ZONES][NR_LRU_LISTS]; struct mem_cgroup_reclaim_iter iter; =20 /* @@ -902,10 +902,15 @@ static inline unsigned long mem_cgroup_get_zone_lru_size(struct lruvec *lruvec, enum lru_list lru, int zone_idx) { + long val; struct mem_cgroup_per_node *mz; =20 mz =3D container_of(lruvec, struct mem_cgroup_per_node, lruvec); - return READ_ONCE(mz->lru_zone_size[zone_idx][lru]); + val =3D atomic_long_read(&mz->lru_zone_size[zone_idx][lru]); + if (WARN_ON_ONCE(val < 0)) + return 0; + + return val; } =20 void __mem_cgroup_handle_over_high(gfp_t gfp_mask); diff --git a/mm/memcontrol.c b/mm/memcontrol.c index 1271d390b617..f91540feaf73 100644 --- a/mm/memcontrol.c +++ b/mm/memcontrol.c @@ -1529,28 +1529,12 @@ void mem_cgroup_update_lru_size(struct lruvec *lruv= ec, enum lru_list lru, int zid, long nr_pages) { struct mem_cgroup_per_node *mz; - unsigned long *lru_size; - long size; =20 if (mem_cgroup_disabled()) return; =20 mz =3D container_of(lruvec, struct mem_cgroup_per_node, lruvec); - lru_size =3D &mz->lru_zone_size[zid][lru]; - - if (nr_pages < 0) - *lru_size +=3D nr_pages; - - size =3D *lru_size; - if (WARN_ONCE(size < 0, - "%s(%p, %d, %ld): lru_size %ld\n", - __func__, lruvec, lru, nr_pages, size)) { - VM_BUG_ON(1); - *lru_size =3D 0; - } - - if (nr_pages > 0) - *lru_size +=3D nr_pages; + atomic_long_add(nr_pages, &mz->lru_zone_size[zid][lru]); } =20 /** --=20 2.55.0 From nobody Sat Sep 26 20:29:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E0452F0661; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; cv=none; b=QER6GnnxdwTG/qBMZJ4MDvzUQIVZxi9ETQuSqEWV9ddvhDdU2Lm8nqGOER99KT562cEpcZytL5wuoyBJ4RLfviySUjJikYhj3sh1NEyvMEEIbjaAD8ByrWk39pOsT2zU9OGnqqUkupvVjOI1W39Ce7zzqDzTcUkLnA6LCuMEU6I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; c=relaxed/simple; bh=BmIJEHuM2IDbhjxzbujXYHOKiImgaACmoJFlhjiTrRQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=MmrTi6F0JOQeX1tCoYRJpsz4+uADrl3z/+U4nrNI0NUpZvQXQhizEXeyXFQb01cZLIKPBYi6TlvBlJdGMJIVdR1uR1sEnNVQuEDWt3YyIJLhPzeBYl3CnAIX7N1bXzSPZoBYxvaiMnbMje8S+j6Dcm9O5cQCtjLL4AGBIDKrWN8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=f14jp/nI; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="f14jp/nI" Received: by smtp.kernel.org (Postfix) with ESMTPS id D0C39C2BCFC; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1788115417; bh=BmIJEHuM2IDbhjxzbujXYHOKiImgaACmoJFlhjiTrRQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=f14jp/nIU7khpFSr2jVvUQaTcVBwjevKkDM0DvM2WYnrBooG3bpqtxSA+CghdbQbc U5R8Jpmxn0teDvPS3HPTxuvyk0//q2uyg+WQO3lcrwy8BPIWEMXHRe4bGhqO1E60xF rgb1TK4YaKkg16ZKmnYFrA4KlDHw7gkYZLxAx7dzEhHL4XPgIgMTTiqGGNGodtG/h8 oIA3wWbRCAFNpLEG4mHvtiftAnTbjBgENbdUAp6xQpDetfC1+E4tG+vc20Y81I8WBB ixOUZCQAIAi1o7VD6FV9MMipF40K4rWapi+hbZ2nm3C/jo4qg9+R6FQDnAuOmZh+wN /Gg6xBv2qDXcw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AFC48C61DE2; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) From: Kairui Song via B4 Relay Date: Mon, 31 Aug 2026 02:43:32 +0800 Subject: [PATCH v4 2/6] mm/mglru: introduce helpers for manipulating gen and refs flags Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260831-mglru-flags-cleanup-v4-2-2d15dde0d7ee@tencent.com> References: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> In-Reply-To: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Ridong Chen , Lian Wang , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1788115415; l=12684; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=9YR/yHPBoBzJHU5LqVAM1pdyJ1Ysbia718YddvWvXiU=; b=nrov2DFK/cj5nINZPA8E2X09keGEZ7abpXRNJXiPLWGjkAMMlhTp2oXjYOASYhOEjg/rcAo10 4qE5tAzT6g1Bm7LZ8abdXX8zLcqeBuaI0Mfi3hQ5N6SeJvoT6K0/cPR X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song Instead of doing bit ops on folio->flags.f, introduce helpers for adjusting a folio's refs and generation info, making the code easier to debug and understand. No functional change is intended: some combined atomic operations are split into two, which only creates harmless transient states. There is no measurable performance impact, and some paths even look slightly better in the generated assembly. Acked-by: Qi Zheng Signed-off-by: Kairui Song Reviewed-by: Baolin Wang Reviewed-by: Barry Song --- include/linux/mm_inline.h | 84 ++++++++++++++++++++++++++++++++++++++++++-= ---- include/linux/mmzone.h | 1 + mm/folio.c | 19 ++++++----- mm/vmscan.c | 61 +++++++++++++++++++--------------- 4 files changed, 122 insertions(+), 43 deletions(-) diff --git a/include/linux/mm_inline.h b/include/linux/mm_inline.h index 621c8653d8f7..3f4bd5b02b54 100644 --- a/include/linux/mm_inline.h +++ b/include/linux/mm_inline.h @@ -142,10 +142,66 @@ static inline int lru_tier_from_refs(int refs, bool w= orkingset) return workingset ? MAX_NR_TIERS - 1 : order_base_2(refs); } =20 -static inline int folio_lru_refs(const struct folio *folio) +/** + * lru_set_gen_flags - Set the LRU generation number to specified folio fl= ags. + * @flags: pointer to the folio flags + * @gen: generation number, between 0 and (MAX_NR_GENS - 1), inclusive. + */ +static inline void lru_set_gen_flags(unsigned long *flags, int gen) +{ + BUILD_BUG_ON(LRU_GEN_MASK & LRU_REFS_MASK); + VM_WARN_ON_ONCE(gen >=3D MAX_NR_GENS || gen < 0); + /* Store gen offset by 1, zero means the folio is off-list. */ + *flags &=3D ~LRU_GEN_MASK; + *flags |=3D (gen + 1UL) << LRU_GEN_PGOFF; +} + +/** + * lru_get_gen_flags - Return the LRU generation number from folio flags. + * @flags: folio flags + * + * Returns: A number between 0 and (MAX_NR_GENS - 1), inclusive. Returns + * -1 if the flags indicate the folio is off the list (e.g., isolated). + */ +static inline int lru_get_gen_flags(unsigned long flags) { - unsigned long flags =3D READ_ONCE(folio->flags.f); + int gen =3D ((flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; =20 + /* Exclude the legal -1 from the unsigned MAX_NR_GENS comparison */ + VM_WARN_ON_ONCE(gen !=3D -1 && gen >=3D MAX_NR_GENS); + return gen; +} + +/** + * lru_set_refs_flags - Set the LRU referenced count to folio flags. + * @flags: pointer to the folio flags + * @refs: referenced / access count number, between 0 and LRU_REFS_MAX, in= clusive. + * + * For MGLRU, PG_referenced holds the first ref, and the extra bits hold t= he + * remaining refs. For classical LRU the extra bits are not used, so it can + * also be seen as the refs count never exceeds 1. In both cases, refs =3D= =3D 1 + * means PG_referenced is set and the extra bits are zero, and refs =3D=3D= 0 means + * PG_referenced and the extra bits are all unset. + */ +static inline void lru_set_refs_flags(unsigned long *flags, unsigned int r= efs) +{ + VM_WARN_ON_ONCE(refs > LRU_REFS_MAX); + BUILD_BUG_ON(LRU_REFS_MAX !=3D (LRU_REFS_MASK >> LRU_REFS_PGOFF) + 1); + + *flags &=3D ~LRU_REFS_FLAGS; + if (!refs) + return; + *flags |=3D (BIT(PG_referenced) | ((refs - 1UL) << LRU_REFS_PGOFF)); +} + +/** + * lru_get_refs_flags - Return LRU referenced / access count from folio fl= ags. + * @flags: folio flags + * + * Reads the LRU referenced count set by lru_set_refs_flags(). + */ +static inline int lru_get_refs_flags(unsigned long flags) +{ if (!(flags & BIT(PG_referenced))) return 0; /* @@ -155,11 +211,24 @@ static inline int folio_lru_refs(const struct folio *= folio) return ((flags & LRU_REFS_MASK) >> LRU_REFS_PGOFF) + 1; } =20 -static inline int folio_lru_gen(const struct folio *folio) +static inline int folio_lru_refs(const struct folio *folio) { - unsigned long flags =3D READ_ONCE(folio->flags.f); + return lru_get_refs_flags(READ_ONCE(*const_folio_flags(folio, 0))); +} + +static inline void folio_set_lru_refs(struct folio *folio, unsigned int re= fs) +{ + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); + + do { + new_flags =3D old_flags; + lru_set_refs_flags(&new_flags, refs); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); +} =20 - return ((flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; +static inline int folio_lru_gen(const struct folio *folio) +{ + return lru_get_gen_flags(READ_ONCE(*const_folio_flags(folio, 0))); } =20 static inline bool lru_gen_is_active(const struct lruvec *lruvec, int gen) @@ -270,7 +339,7 @@ static inline bool lru_gen_add_folio(struct lruvec *lru= vec, struct folio *folio, gen =3D lru_gen_from_seq(seq); flags =3D (gen + 1UL) << LRU_GEN_PGOFF; /* see the comment on MIN_NR_GENS about PG_active */ - set_mask_bits(&folio->flags.f, LRU_GEN_MASK | BIT(PG_active), flags); + set_mask_bits(folio_flags(folio, 0), LRU_GEN_MASK | BIT(PG_active), flags= ); =20 lru_gen_update_size(lruvec, folio, -1, gen); /* for folio_rotate_reclaimable() */ @@ -295,7 +364,7 @@ static inline bool lru_gen_del_folio(struct lruvec *lru= vec, struct folio *folio, =20 /* for folio_migrate_flags() */ flags =3D !reclaiming && lru_gen_is_active(lruvec, gen) ? BIT(PG_active) = : 0; - flags =3D set_mask_bits(&folio->flags.f, LRU_GEN_MASK, flags); + flags =3D set_mask_bits(folio_flags(folio, 0), LRU_GEN_MASK, flags); gen =3D ((flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; =20 lru_gen_update_size(lruvec, folio, gen, -1); @@ -339,7 +408,6 @@ static inline bool lru_gen_del_folio(struct lruvec *lru= vec, struct folio *folio, =20 static inline void folio_migrate_refs(struct folio *new, const struct foli= o *old) { - } #endif /* CONFIG_LRU_GEN */ =20 diff --git a/include/linux/mmzone.h b/include/linux/mmzone.h index 94f9c3ff5416..c9ecf370cd9f 100644 --- a/include/linux/mmzone.h +++ b/include/linux/mmzone.h @@ -497,6 +497,7 @@ enum lruvec_flags { =20 #define LRU_GEN_MASK ((BIT(LRU_GEN_WIDTH) - 1) << LRU_GEN_PGOFF) #define LRU_REFS_MASK ((BIT(LRU_REFS_WIDTH) - 1) << LRU_REFS_PGOFF) +#define LRU_REFS_MAX BIT(LRU_REFS_WIDTH) =20 /* * For folios accessed multiple times through file descriptors, diff --git a/mm/folio.c b/mm/folio.c index c02dcea9c03c..fb874fe492b2 100644 --- a/mm/folio.c +++ b/mm/folio.c @@ -353,26 +353,28 @@ static void __lru_cache_activate_folio(struct folio *= folio) =20 static void lru_gen_inc_refs(struct folio *folio) { - unsigned long new_flags, old_flags =3D READ_ONCE(folio->flags.f); + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); + int refs; =20 if (folio_test_unevictable(folio)) return; =20 /* see the comment on LRU_REFS_FLAGS */ - if (!folio_test_referenced(folio)) { - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, BIT(PG_referenced)); + if (!folio_lru_refs(folio)) { + folio_set_lru_refs(folio, 1); return; } =20 do { - if ((old_flags & LRU_REFS_MASK) =3D=3D LRU_REFS_MASK) { + new_flags =3D old_flags; + refs =3D lru_get_refs_flags(old_flags); + if (refs =3D=3D LRU_REFS_MAX) { if (!folio_test_workingset(folio)) folio_set_workingset(folio); return; } - - new_flags =3D old_flags + BIT(LRU_REFS_PGOFF); - } while (!try_cmpxchg(&folio->flags.f, &old_flags, new_flags)); + lru_set_refs_flags(&new_flags, refs + 1); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); } =20 static bool lru_gen_clear_refs(struct folio *folio) @@ -384,7 +386,8 @@ static bool lru_gen_clear_refs(struct folio *folio) if (gen < 0) return true; =20 - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS | BIT(PG_workingset), 0); + folio_set_lru_refs(folio, 0); + folio_clear_workingset(folio); =20 rcu_read_lock(); seq =3D READ_ONCE(folio_lruvec(folio)->lrugen.min_seq[type]); diff --git a/mm/vmscan.c b/mm/vmscan.c index f11491ee9ed5..992d0d3e2311 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -843,19 +843,22 @@ static bool lru_gen_set_refs(struct folio *folio, con= st vma_flags_t *vma_flags) if (!folio_test_referenced(folio) && !folio_test_workingset(folio)) { /* Activate file-backed executable folios after first usage. */ if (is_exec_file_folio(folio, vma_flags)) { - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS, BIT(PG_workingset)); + folio_set_workingset(folio); + folio_set_lru_refs(folio, 0); return true; } =20 - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, BIT(PG_referenced)); + folio_set_lru_refs(folio, 1); return false; } =20 /* Promote on second access */ - if (folio_lru_refs(folio) > 1) - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS, BIT(PG_workingset)); - else + if (folio_lru_refs(folio) > 1) { + folio_set_workingset(folio); + folio_set_lru_refs(folio, 0); + } else { folio_mark_accessed(folio); + } return true; } #else @@ -3266,11 +3269,10 @@ static bool positive_ctrl_err(struct ctrl_pos *sp, = struct ctrl_pos *pv) *************************************************************************= *****/ =20 /* promote pages accessed through page tables */ -static int folio_update_gen(struct folio *folio, int gen, const vma_flags_= t *vma_flags) +static int folio_update_gen(struct folio *folio, int new_gen, const vma_fl= ags_t *vma_flags) { - unsigned long new_flags, old_flags =3D READ_ONCE(folio->flags.f); - - VM_WARN_ON_ONCE(gen >=3D MAX_NR_GENS); + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); + int old_gen; =20 /* * See the comment on LRU_REFS_FLAGS, and activate file-backed @@ -3279,20 +3281,24 @@ static int folio_update_gen(struct folio *folio, in= t gen, const vma_flags_t *vma */ if (!folio_test_referenced(folio) && !folio_test_workingset(folio) && !is_exec_file_folio(folio, vma_flags)) { - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, BIT(PG_referenced)); + folio_set_lru_refs(folio, 1); return -1; } =20 do { + old_gen =3D lru_get_gen_flags(old_flags); + new_flags =3D old_flags; + /* lru_gen_del_folio() has isolated this page? */ - if (!(old_flags & LRU_GEN_MASK)) - return -1; + if (old_gen < 0) + break; =20 - new_flags =3D old_flags & ~(LRU_GEN_MASK | LRU_REFS_FLAGS); - new_flags |=3D ((gen + 1UL) << LRU_GEN_PGOFF) | BIT(PG_workingset); - } while (!try_cmpxchg(&folio->flags.f, &old_flags, new_flags)); + lru_set_gen_flags(&new_flags, new_gen); + lru_set_refs_flags(&new_flags, 0); + new_flags |=3D BIT(PG_workingset); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); =20 - return ((old_flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; + return old_gen; } =20 /* protect pages accessed multiple times through file descriptors */ @@ -3301,21 +3307,20 @@ static int folio_inc_gen(struct lruvec *lruvec, str= uct folio *folio) int type =3D folio_is_file_lru(folio); struct lru_gen_folio *lrugen =3D &lruvec->lrugen; int new_gen, old_gen =3D lru_gen_from_seq(lrugen->min_seq[type]); - unsigned long new_flags, old_flags =3D READ_ONCE(folio->flags.f); - - VM_WARN_ON_ONCE_FOLIO(!(old_flags & LRU_GEN_MASK), folio); + unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); =20 do { - new_gen =3D ((old_flags & LRU_GEN_MASK) >> LRU_GEN_PGOFF) - 1; + new_gen =3D lru_get_gen_flags(old_flags); + /* folio_update_gen() has promoted this page? */ if (new_gen >=3D 0 && new_gen !=3D old_gen) return new_gen; =20 + new_flags =3D old_flags; new_gen =3D (old_gen + 1) % MAX_NR_GENS; - - new_flags =3D old_flags & ~(LRU_GEN_MASK | LRU_REFS_FLAGS); - new_flags |=3D (new_gen + 1UL) << LRU_GEN_PGOFF; - } while (!try_cmpxchg(&folio->flags.f, &old_flags, new_flags)); + lru_set_gen_flags(&new_flags, new_gen); + lru_set_refs_flags(&new_flags, 0); + } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); =20 lru_gen_update_size(lruvec, folio, old_gen, new_gen); =20 @@ -4716,7 +4721,7 @@ static bool isolate_folio(struct lruvec *lruvec, stru= ct folio *folio, struct sca =20 /* see the comment on LRU_REFS_FLAGS */ if (!folio_test_referenced(folio)) - set_mask_bits(&folio->flags.f, LRU_REFS_MASK, 0); + folio_set_lru_refs(folio, 0); =20 success =3D lru_gen_del_folio(lruvec, folio, true); VM_WARN_ON_ONCE_FOLIO(!success, folio); @@ -4932,8 +4937,10 @@ static int evict_folios(unsigned long nr_to_scan, st= ruct lruvec *lruvec, } =20 /* don't add rejected folios to the oldest generation */ - if (lru_gen_folio_seq(lruvec, folio, false) =3D=3D min_seq[type]) - set_mask_bits(&folio->flags.f, LRU_REFS_FLAGS, BIT(PG_active)); + if (lru_gen_folio_seq(lruvec, folio, false) =3D=3D min_seq[type]) { + folio_set_lru_refs(folio, 0); + folio_set_active(folio); + } } =20 move_folios_to_lru(&list); --=20 2.55.0 From nobody Sat Sep 26 20:29:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E1272F361E; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; cv=none; b=ADk9uRnti2biA/lChgB81+p7JIMX0V+/u2VhcoDFxh8nWgbotuDYhwoMC/tWyjkAsbpzwCTozZs48vMZA21NYi6SzM/EEJ89/cf4LMXvEVFWHTJbEpzQdvu28ceGIm4sLfCLTAJbnA+G6MWOAwJT6hPrOR21coy5LRKB60+DAJI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; c=relaxed/simple; bh=ZFETDp6p9x9uvwIEd+HcIi3/dkthWZDx6+TpdJIY9to=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=mQOO+MhjiQL7BkGgvHWwaubWWVZq0zvwGjOAv2orYGA8olj3OKG43LN7Rh8oTwexidSb0atNCTsDOTPepuDxWyncFNM7uH09lpwLQfuhEUWhSfzDzqQg7bqxUaDNaZDtzjbmWHFMjEf3WutH0cdS3MI8hsUIdx7QpBqBzs+BGis= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=IwpDssWr; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="IwpDssWr" Received: by smtp.kernel.org (Postfix) with ESMTPS id DCC04C2BCFA; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1788115417; bh=ZFETDp6p9x9uvwIEd+HcIi3/dkthWZDx6+TpdJIY9to=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=IwpDssWr5dIJco4GLs7xC0a/HgybjcVwdRIl6Tcwfzxk3gMOQ82R4RnALWKZ+EGZr aUlA8RyWzZVDl1wNC9P2qTYgcxTRL82vLZEJzRrIl5Hqn2TCE8Ir2Y6E3Gbq6pUtqc Kbbm/wC1w6i5vcN6rqzwIAaNIAgRpI8q9gScnAXao7+GgYMHqn3XoQkVnAxjWS+0dk xk7VzPFN8OChgVB9Cwnv6VYoKxiYuD72daQv375HE5dSuRi9kL0QWt4yIQe+PmtZuX qxQ4Q04vGW+MIj9aU5hD41I7JOgTOlqEJZCPPvneuXHOmsJHIQiMk3Z0ndJSIUL74i QEWW9iQgPoa9w== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C55A5C61DEB; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) From: Kairui Song via B4 Relay Date: Mon, 31 Aug 2026 02:43:33 +0800 Subject: [PATCH v4 3/6] mm/migrate: copy all referenced state via folio_migrate_lru_refs Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260831-mglru-flags-cleanup-v4-3-2d15dde0d7ee@tencent.com> References: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> In-Reply-To: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Ridong Chen , Lian Wang , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1788115415; l=3683; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=Ox6zaP/QbfpF5dExxI36sjV5rWUkpJpYAOEG95FC1rw=; b=RRNloLKvM7frocsILPYsY3O4OIPv0mpSpvKYz622w+CfsR1eJguwROtQXXFwm28UYf03Aw2mt TP0N4BjNES4Az+ct6ITqrZDnqszgZ2G24r4wm4TrDbA4ru8l+CLKpL2 X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song folio_migrate_flags() copies PG_referenced separately from the MGLRU refs counter, which folio_migrate_refs() transfers. Yet under MGLRU, PG_referenced and the refs counter bits together describe the referenced status of a folio. Consolidate the two: rename folio_migrate_refs() to folio_migrate_lru_refs() and let it copy the complete referenced status, i.e., the MGLRU refs count including PG_referenced, or just PG_referenced for the active/inactive LRU. Drop the open-coded PG_referenced copy so the referenced status is transferred in one place. No behavior change is intended: under the active/inactive LRU the extra bits are unused, so operating on them is a noop. Transfer the reference state first, before the destination folio is marked uptodate, so a concurrent lockless reader cannot have its reference update overwritten by the copy. Reviewed-by: Baoquan He Reviewed-by: Baolin Wang Acked-by: David Hildenbrand (Arm) Reviewed-by: Lian Wang Reviewed-by: Barry Song Reviewed-by: Ridong Chen Signed-off-by: Kairui Song --- include/linux/mm_inline.h | 20 +++++++++++++++----- mm/migrate.c | 6 +++--- 2 files changed, 18 insertions(+), 8 deletions(-) diff --git a/include/linux/mm_inline.h b/include/linux/mm_inline.h index 3f4bd5b02b54..047295ae6e8a 100644 --- a/include/linux/mm_inline.h +++ b/include/linux/mm_inline.h @@ -373,11 +373,19 @@ static inline bool lru_gen_del_folio(struct lruvec *l= ruvec, struct folio *folio, return true; } =20 -static inline void folio_migrate_refs(struct folio *new, const struct foli= o *old) +/** + * folio_migrate_lru_refs - copy the reference state to a new folio + * @new: the destination folio + * @old: the source folio + * + * Transfer the reference state to @new during migration: the MGLRU + * refs count, including PG_referenced, or just PG_referenced for the + * active/inactive LRU. + */ +static inline void folio_migrate_lru_refs(struct folio *new, const struct = folio *old) { - unsigned long refs =3D READ_ONCE(old->flags.f) & LRU_REFS_MASK; - - set_mask_bits(&new->flags.f, LRU_REFS_MASK, refs); + BUILD_BUG_ON(LRU_REFS_MASK & BIT(PG_referenced)); + folio_set_lru_refs(new, folio_lru_refs(old)); } #else /* !CONFIG_LRU_GEN */ =20 @@ -406,8 +414,10 @@ static inline bool lru_gen_del_folio(struct lruvec *lr= uvec, struct folio *folio, return false; } =20 -static inline void folio_migrate_refs(struct folio *new, const struct foli= o *old) +static inline void folio_migrate_lru_refs(struct folio *new, const struct = folio *old) { + if (folio_test_referenced(old)) + folio_set_referenced(new); } #endif /* CONFIG_LRU_GEN */ =20 diff --git a/mm/migrate.c b/mm/migrate.c index 15b45832bcfa..a369d0c95c38 100644 --- a/mm/migrate.c +++ b/mm/migrate.c @@ -776,8 +776,9 @@ void folio_migrate_flags(struct folio *newfolio, struct= folio *folio) { int cpupid; =20 - if (folio_test_referenced(folio)) - folio_set_referenced(newfolio); + /* Copy the reference state, including PG_referenced */ + folio_migrate_lru_refs(newfolio, folio); + if (folio_test_uptodate(folio)) folio_mark_uptodate(newfolio); if (folio_test_clear_active(folio)) { @@ -807,7 +808,6 @@ void folio_migrate_flags(struct folio *newfolio, struct= folio *folio) if (folio_test_idle(folio)) folio_set_idle(newfolio); =20 - folio_migrate_refs(newfolio, folio); /* * Copy NUMA information to the new page, to prevent over-eager * future migrations of this same page. --=20 2.55.0 From nobody Sat Sep 26 20:29:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 382032F619D; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; cv=none; b=X2stQmvGx/xpD+GINJLatTKD8LIFumQLRL0klUaQNjaa1wuHq8OjCMyYoR6Ip4R2GPZq+YpvteY/KxLE0OOPucv5I10dJ1x4VRZ37KFYj0s5o8IHWvAWkoODDuCxtijBQ3z3Ok694DcW3XP6yIo1eR+MrR2Rq02zFO1e30QDBS0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; c=relaxed/simple; bh=Z4M/WPpzvepsYGJB+gWn8bv52ugodElvQ0+zzzD3630=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=iq0751hyYYwurODCfu+uYeKvZhPJdwpsKsPyYOI681HkJ4CgM1Ostg/QWmf1+TjUcsKcmc1XDFinQG3eY3CaEesDs8bfP7+pJlTSRdmlOV/ntwlHjmLygq4A74Jgb3VvC9M4z3eRHBxf47r4DP+zVEJICI2AnBgdH7t6RXJZX4k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=e0Tz3As/; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="e0Tz3As/" Received: by smtp.kernel.org (Postfix) with ESMTPS id EFA97C2BD00; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1788115418; bh=Z4M/WPpzvepsYGJB+gWn8bv52ugodElvQ0+zzzD3630=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=e0Tz3As/OezNV5CVe7W3YP6IKQ7VzZ2M9fPOu0zrPFlcE+DgNLYL6NGYNI1dKkD1T 4wohq+ffKmrBwCBxRVT9F3btNz3QydsSYVZFVUSR34/2v//OmjptI6UDqjWGARpYj6 auyXb10lG8TYEF/rEY93KHJu2/c0B8OFz9pnPwVF8h0IMx//qjCQZVLillJZBJOjKq VH0CCgmJDAH2UqAY0LUfoYTeS67liZY4MwK9+r3tghDOg4GHk72bwhY4HGqJ+0te5h BcAud9LbRwLzzIHWlVsv3KZJb04j0dVXaa0i2CZtN7Mt6c8WdzfbZ6F1QGgLQSIMgh F3JrGIqjcQsCA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D9EA2C61DE1; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) From: Kairui Song via B4 Relay Date: Mon, 31 Aug 2026 02:43:34 +0800 Subject: [PATCH v4 4/6] mm/mglru: move max_seq read into walk_update_folio Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260831-mglru-flags-cleanup-v4-4-2d15dde0d7ee@tencent.com> References: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> In-Reply-To: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Ridong Chen , Lian Wang , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1788115415; l=5248; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=MjFMt9GK+ni58sgBI6clUwzVmv/EoZkBPc5qdd6el6w=; b=OzC8dM84YUEAxm8bY4sff9mo8PnjTI/P4G95CJRxI3+jqnSHjANDU7owp297rlQqQwepJmv0q DAaRKCAcdG3DPwEwyuRHPPwcj2o59Cd6KMXlbc0n/d8j9gMyZEkn8sk X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song walk_pte_range(), walk_pmd_range_locked(), and lru_gen_look_around() each read lrugen->max_seq to compute the target generation used by walk_update_folio(), then pass it as a parameter. Move the read into walk_update_folio() itself so the callers no longer need to compute or pass the value. The max_seq read now happens once per folio update rather than once per walk range, so folios always get promoted to the current youngest generation. Reviewed-by: Baoquan He Reviewed-by: Baolin Wang Reviewed-by: Ridong Chen Reviewed-by: Lian Wang Reviewed-by: Barry Song Signed-off-by: Kairui Song --- mm/vmscan.c | 29 ++++++++++++----------------- 1 file changed, 12 insertions(+), 17 deletions(-) diff --git a/mm/vmscan.c b/mm/vmscan.c index 992d0d3e2311..88474d4af54b 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -3517,13 +3517,15 @@ static bool suitable_to_scan(int total, int young) } =20 static void walk_update_folio(struct lru_gen_mm_walk *walk, struct vm_area= _struct *vma, - struct folio *folio, int new_gen, bool dirty) + struct lruvec *lruvec, struct folio *folio, bool dirty) { - int old_gen; + int new_gen, old_gen; =20 if (!folio) return; =20 + new_gen =3D lru_gen_from_seq(READ_ONCE(lruvec->lrugen.max_seq)); + if (dirty && !folio_test_dirty(folio) && !(folio_test_anon(folio) && folio_test_swapbacked(folio) && !folio_test_swapcache(folio))) @@ -3554,8 +3556,6 @@ static bool walk_pte_range(pmd_t *pmd, unsigned long = start, unsigned long end, struct lru_gen_mm_walk *walk =3D args->private; struct mem_cgroup *memcg =3D lruvec_memcg(walk->lruvec); struct pglist_data *pgdat =3D lruvec_pgdat(walk->lruvec); - DEFINE_MAX_SEQ(walk->lruvec); - int gen =3D lru_gen_from_seq(max_seq); unsigned int nr; pmd_t pmdval; =20 @@ -3606,7 +3606,7 @@ static bool walk_pte_range(pmd_t *pmd, unsigned long = start, unsigned long end, continue; =20 if (last !=3D folio) { - walk_update_folio(walk, args->vma, last, gen, dirty); + walk_update_folio(walk, args->vma, walk->lruvec, last, dirty); =20 last =3D folio; dirty =3D false; @@ -3619,7 +3619,7 @@ static bool walk_pte_range(pmd_t *pmd, unsigned long = start, unsigned long end, walk->mm_stats[MM_LEAF_YOUNG] +=3D nr; } =20 - walk_update_folio(walk, args->vma, last, gen, dirty); + walk_update_folio(walk, args->vma, walk->lruvec, last, dirty); last =3D NULL; =20 if (i < PTRS_PER_PTE && get_next_vma(PMD_MASK, PAGE_SIZE, args, &start, &= end)) @@ -3642,8 +3642,6 @@ static void walk_pmd_range_locked(pud_t *pud, unsigne= d long addr, struct vm_area struct lru_gen_mm_walk *walk =3D args->private; struct mem_cgroup *memcg =3D lruvec_memcg(walk->lruvec); struct pglist_data *pgdat =3D lruvec_pgdat(walk->lruvec); - DEFINE_MAX_SEQ(walk->lruvec); - int gen =3D lru_gen_from_seq(max_seq); =20 VM_WARN_ON_ONCE(pud_leaf(*pud)); =20 @@ -3697,7 +3695,7 @@ static void walk_pmd_range_locked(pud_t *pud, unsigne= d long addr, struct vm_area goto next; =20 if (last !=3D folio) { - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, walk->lruvec, last, dirty); =20 last =3D folio; dirty =3D false; @@ -3711,7 +3709,7 @@ static void walk_pmd_range_locked(pud_t *pud, unsigne= d long addr, struct vm_area i =3D i > MIN_LRU_BATCH ? 0 : find_next_bit(bitmap, MIN_LRU_BATCH, i) + = 1; } while (i <=3D MIN_LRU_BATCH); =20 - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, walk->lruvec, last, dirty); =20 lazy_mmu_mode_disable(); spin_unlock(ptl); @@ -4275,8 +4273,6 @@ bool lru_gen_look_around(struct page_vma_mapped_walk = *pvmw, unsigned int nr) struct pglist_data *pgdat =3D folio_pgdat(folio); struct lruvec *lruvec; struct lru_gen_mm_state *mm_state; - unsigned long max_seq; - int gen; =20 lockdep_assert_held(pvmw->ptl); VM_WARN_ON_ONCE_FOLIO(folio_test_lru(folio), folio); @@ -4313,8 +4309,6 @@ bool lru_gen_look_around(struct page_vma_mapped_walk = *pvmw, unsigned int nr) =20 memcg =3D get_mem_cgroup_from_folio(folio); lruvec =3D mem_cgroup_lruvec(memcg, pgdat); - max_seq =3D READ_ONCE((lruvec)->lrugen.max_seq); - gen =3D lru_gen_from_seq(max_seq); mm_state =3D get_mm_state(lruvec); =20 lazy_mmu_mode_enable(); @@ -4346,7 +4340,7 @@ bool lru_gen_look_around(struct page_vma_mapped_walk = *pvmw, unsigned int nr) continue; =20 if (last !=3D folio) { - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, lruvec, last, dirty); =20 last =3D folio; dirty =3D false; @@ -4358,13 +4352,14 @@ bool lru_gen_look_around(struct page_vma_mapped_wal= k *pvmw, unsigned int nr) young +=3D nr; } =20 - walk_update_folio(walk, vma, last, gen, dirty); + walk_update_folio(walk, vma, lruvec, last, dirty); =20 lazy_mmu_mode_disable(); =20 /* feedback from rmap walkers to page table walkers */ if (mm_state && suitable_to_scan(i, young)) - update_bloom_filter(mm_state, max_seq, pvmw->pmd); + update_bloom_filter(mm_state, READ_ONCE(lruvec->lrugen.max_seq), + pvmw->pmd); =20 mem_cgroup_put(memcg); =20 --=20 2.55.0 From nobody Sat Sep 26 20:29:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4598B2F690F; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; cv=none; b=bgU+BQ6qb+R0ZjG6mBNsLjhNgV7DKzRigEK2u9w9J7XHyVGbSzty5zR/Bd4X00BvL25JPFiaOHTOWZ+OJ89MGJYuIjnL05VR971W0VlmeeX0/Xnnwtv8yVh1yVLUQjAMUDPqLAD1TPMImZARmAQ/jCru/mheFigWl34fhxmxyj0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; c=relaxed/simple; bh=jyNA9Kp6+foaF24RdDxMnGyUAbbACor7vJmweV2u7Us=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=VCUU4Z7nqiqfP2yhrFOS6QeSAzcdk3c01SKpHZYJgqU9ka8m+u23IbO4cPUhputMaoxhNTviSTNN2+RXO0gSIPOkOqsYWq9fmLUQ8lexLOJ7gOkLHkuwVbA1de1+/pn6zTGZLKuC+90wlcf+y8jBO8WUE+HGvbA9Ei/Oji8FgdY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=LBtTBEdv; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="LBtTBEdv" Received: by smtp.kernel.org (Postfix) with ESMTPS id 16959C32781; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1788115418; bh=jyNA9Kp6+foaF24RdDxMnGyUAbbACor7vJmweV2u7Us=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=LBtTBEdvGgnWLFAOpKOJnOjurRX/4FRvNtRcwJ5JFDfbiRGishnRauOTfI6CW2mcL XJ13WLDnbP+HtAGxPdxcJiLGYziHXibIeYCoa0iojetBc6RpfyM07gcWY2MMZI9y9h f+czEuRePFsnNuuBkzn17oPvCuy+Yr3uAgpxiI1G69GADwbv0+565bkK56M4kyATBf 59hpfeiFj53wXQREOn5j22VKlrHZZuEdHfWdIOExtFIMoyjJw3btLPBv06cEHV5ppX sCXPRlyB4YYqrn3icGasUJeEqmefnLEGpXtSw6kdvCMovTHJtq2VrIU+NjMcBlT/jV BbGS5WlvJKwVw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EFC8AC61DF0; Sun, 30 Aug 2026 18:43:37 +0000 (UTC) From: Kairui Song via B4 Relay Date: Mon, 31 Aug 2026 02:43:35 +0800 Subject: [PATCH v4 5/6] mm/mglru: use explicit tier range in read_ctrl_pos() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260831-mglru-flags-cleanup-v4-5-2d15dde0d7ee@tencent.com> References: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> In-Reply-To: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Ridong Chen , Lian Wang , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1788115415; l=3649; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=CWUxj/CQQzace6S+QxkJDRIrrH9jLNHsJ/crVKhgGbE=; b=FWk6b2RXyde5JYnHfKQSebvOwDlcdZYu+ics5x8yBjnEv1DTOr+mk6s0Kzs0JEfJnGmLmyVXE uFunTQEq+OtBL0CXaykFAju+MmG5A7LoemlTcpVRJVx4ydEfxRGhC4J X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song read_ctrl_pos() encodes the tier range in a single "tier" parameter via "tier % MAX_NR_TIERS" as the start and "min(tier, MAX_NR_TIERS-1)" as the end. This is hard to follow, maintain, or extend. Tier values 0..3 select a single tier, while tier =3D=3D MAX_NR_TIERS selects the full range. Replace it with explicit (tier_min, tier_max) parameters using a closed [tier_min, tier_max] interval, and add LRU_TIER_MIN and LRU_TIER_MAX for the tier bounds. The call sites now become self-documenting: - get_tier_idx: (LRU_TIER_MIN, LRU_TIER_MIN) for the first tier, (tier, tier) for each subsequent tier - get_type_to_scan: (LRU_TIER_MIN, LRU_TIER_MAX) for the full range No functional change. Reviewed-by: Baolin Wang Reviewed-by: Baoquan He Reviewed-by: Barry Song Reviewed-by: Ridong Chen Signed-off-by: Kairui Song --- include/linux/mmzone.h | 2 ++ mm/vmscan.c | 18 ++++++++++-------- 2 files changed, 12 insertions(+), 8 deletions(-) diff --git a/include/linux/mmzone.h b/include/linux/mmzone.h index c9ecf370cd9f..9b27cf53bdbc 100644 --- a/include/linux/mmzone.h +++ b/include/linux/mmzone.h @@ -492,6 +492,8 @@ enum lruvec_flags { * folio->flags, masked by LRU_REFS_MASK. */ #define MAX_NR_TIERS 4U +#define LRU_TIER_MIN 0U +#define LRU_TIER_MAX (MAX_NR_TIERS - 1) =20 #ifndef __GENERATING_BOUNDS_H =20 diff --git a/mm/vmscan.c b/mm/vmscan.c index 88474d4af54b..724b6e034e69 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -3198,8 +3198,8 @@ struct ctrl_pos { int gain; }; =20 -static void read_ctrl_pos(struct lruvec *lruvec, int type, int tier, int g= ain, - struct ctrl_pos *pos) +static void read_ctrl_pos(struct lruvec *lruvec, int type, int tier_min, + int tier_max, int gain, struct ctrl_pos *pos) { int i; struct lru_gen_folio *lrugen =3D &lruvec->lrugen; @@ -3208,7 +3208,7 @@ static void read_ctrl_pos(struct lruvec *lruvec, int = type, int tier, int gain, pos->gain =3D gain; pos->refaulted =3D pos->total =3D 0; =20 - for (i =3D tier % MAX_NR_TIERS; i <=3D min(tier, MAX_NR_TIERS - 1); i++) { + for (i =3D tier_min; i <=3D tier_max; i++) { pos->refaulted +=3D lrugen->avg_refaulted[type][i] + atomic_long_read(&lrugen->refaulted[hist][type][i]); pos->total +=3D lrugen->avg_total[type][i] + @@ -4809,9 +4809,9 @@ static int get_tier_idx(struct lruvec *lruvec, int ty= pe) * This value is chosen because any other tier would have at least twice * as many refaults as the first tier. */ - read_ctrl_pos(lruvec, type, 0, 2, &sp); - for (tier =3D 1; tier < MAX_NR_TIERS; tier++) { - read_ctrl_pos(lruvec, type, tier, 3, &pv); + read_ctrl_pos(lruvec, type, LRU_TIER_MIN, LRU_TIER_MIN, 2, &sp); + for (tier =3D LRU_TIER_MIN + 1; tier <=3D LRU_TIER_MAX; tier++) { + read_ctrl_pos(lruvec, type, tier, tier, 3, &pv); if (!positive_ctrl_err(&sp, &pv)) break; } @@ -4832,8 +4832,10 @@ static int get_type_to_scan(struct lruvec *lruvec, i= nt swappiness) * Compare the sum of all tiers of anon with that of file to determine * which type to scan. */ - read_ctrl_pos(lruvec, LRU_GEN_ANON, MAX_NR_TIERS, swappiness, &sp); - read_ctrl_pos(lruvec, LRU_GEN_FILE, MAX_NR_TIERS, MAX_SWAPPINESS - swappi= ness, &pv); + read_ctrl_pos(lruvec, LRU_GEN_ANON, LRU_TIER_MIN, LRU_TIER_MAX, + swappiness, &sp); + read_ctrl_pos(lruvec, LRU_GEN_FILE, LRU_TIER_MIN, LRU_TIER_MAX, + MAX_SWAPPINESS - swappiness, &pv); =20 return positive_ctrl_err(&sp, &pv); } --=20 2.55.0 From nobody Sat Sep 26 20:29:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 64F252FD1AA; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; cv=none; b=VLDa/ZAdvRYlcaNCHQoXGeMVdzeKlnNcjoIPYtIE+xCxjiwQbzB5pckB/2vIJD3g1X6gLAXx3LCJ+xz044K5BXDWwhU+5eyrAx8/wlF39SWH7g0RUgxvHHZGmF9PPQZsbwghk0XAinC9l76qURaqY6Iw44t6gynzZ5s5w1wUGvk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788115418; c=relaxed/simple; bh=spyvUXst4fUCAIZ0m+QJ4vENQfhFkGWKQfmvYUD3ZzQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=eGJlrRNcAm7Otr7Bii+KwBlBnFXPsaVE45OoE0X7cL8hBQsIipBGCNFH6euvmIWD+m9GuNuaXntVAlWB85McdHtvFlfZ1dcvZYisHQyiJsTmvWJxLyZ6mTNwh27Fbb0yENIqOxDS9PBh6L3kKNkq0VW6FEeULqarXUNSqhN6dEE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=mhhKTrs3; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="mhhKTrs3" Received: by smtp.kernel.org (Postfix) with ESMTPS id 276FEC2BD01; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1788115418; bh=spyvUXst4fUCAIZ0m+QJ4vENQfhFkGWKQfmvYUD3ZzQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=mhhKTrs3i+PPC9sd4Kcn6L8dCzynom7LL6TgEvgJqpMoYE9yHSLfpXPiV3e6ph8HH qRz50dDocsS2n0L4zMtbmBLeamqr4RcSZCoGwg0bYkjLETcyaYjZ31kXX7L6dnUM5w gXOe7Sx5PnoCWu5+DtUF+3TNtKR2eu2x6t5kyPgKUqTWVposz3NKWWCuTbcmRxxY09 jrEJS86hmCFhZai4uMaLiz58F0bsy0c9CI70bCM+xKN77vCkCZIKFR+bKGNEiXu8f2 IAr788FjVTtHHC394YAJXaUjb6s9lzb9LNYA/WLR6sxUYNNy0YqTNItbQVHKAtaPSJ 2ByEtKCNOMlQg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 13E70C61DB9; Sun, 30 Aug 2026 18:43:38 +0000 (UTC) From: Kairui Song via B4 Relay Date: Mon, 31 Aug 2026 02:43:36 +0800 Subject: [PATCH v4 6/6] mm/mglru: fix potential generation folio number leak Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260831-mglru-flags-cleanup-v4-6-2d15dde0d7ee@tencent.com> References: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> In-Reply-To: <20260831-mglru-flags-cleanup-v4-0-2d15dde0d7ee@tencent.com> To: linux-mm@kvack.org Cc: Andrew Morton , Barry Song , Axel Rasmussen , Yuanchu Xie , Wei Xu , Baoquan He , Shakeel Butt , Johannes Weiner , Michal Hocko , Roman Gushchin , Muchun Song , Chris Li , Baolin Wang , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Ridong Chen , Lian Wang , Yu Zhao , Zi Yan , Qi Zheng , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Kairui Song , Kairui Song X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1788115415; l=5305; i=kasong@tencent.com; s=kasong-sign-tencent; h=from:subject:message-id; bh=Z2J6CC3Ye9renPiwGZhbUdZHuoUS/IyRTK+jViwM/8c=; b=z+rZLYptLZpoPbh9exaTA303vLangU8/qr4wFS5iTEHnCVR9t9TxpRlGMDO/sY2UI6BoAE/88 Kr/Z1J5HZyTB/ek9655augLaRbqwYrilnoLKRiOj9xE7eilBE5I/EmA X-Developer-Key: i=kasong@tencent.com; a=ed25519; pk=kCdoBuwrYph+KrkJnrr7Sm1pwwhGDdZKcKrqiK8Y1mI= X-Endpoint-Received: by B4 Relay for kasong@tencent.com/kasong-sign-tencent with auth_id=562 X-Original-From: Kairui Song Reply-To: kasong@tencent.com From: Kairui Song Each generation of MGLRU accounts anon and file folio numbers separately, and the page table walker updates each generation's counters in batch once the walk is done. The walker promotes a folio's generation with a cmpxchg on folio->flags, and update_batch_size() then reads the live flags again to pick the anon/file column to charge. The walk holds neither the lruvec lock nor the folio lock, so the type can flip between the cmpxchg and that read: the lazyfree path clears PG_swapbacked, and reclaim sets it back on a dirty lazyfree folio. The batched delta pair is then recorded in the wrong type column. Nothing reconciles it afterwards, permanently skewing lrugen->nr_pages and the reclaim budgets derived from it. Fix it by capturing the type from the flags snapshot the cmpxchg linearized against: folio_update_gen() returns the type of the state it transitioned from, and update_batch_size() accounts with that. A folio's type only changes while it is off the LRU list, inside a del/add pair under the lruvec lock, with the gen bits cleared in between. The generation and PG_swapbacked sit in the same folio->flags word, so the cmpxchg snapshot captures them together. Let G be the generation that snapshot captured (old_gen) and G' the one it wrote (new_gen); the CAS can land in only three places: - before the del: the folio is anon at G; the batch records anon G -> G', and the del later removes the folio from the anon counters; - between del and add: gen =3D=3D -1, so folio_update_gen() returns -1 without touching the flags and no batch is recorded; the del/add pair accounts for the move alone; - after the add: the folio is file at the fresh generation the add charged; the batch records file, that gen -> G', matching that charge. Unlike the drift of lazy promotions, which sort_folio() repairs under the lruvec lock, the phantom deltas from before this fix land in a column the folio never occupies again, so nothing ever repairs them. Fixes: 018ee47f1489 ("mm: multi-gen LRU: exploit locality in rmap") Signed-off-by: Kairui Song --- include/linux/mm_inline.h | 7 ++++++- mm/vmscan.c | 13 +++++++------ 2 files changed, 13 insertions(+), 7 deletions(-) diff --git a/include/linux/mm_inline.h b/include/linux/mm_inline.h index 047295ae6e8a..7e487c23aff7 100644 --- a/include/linux/mm_inline.h +++ b/include/linux/mm_inline.h @@ -10,6 +10,11 @@ #include #include =20 +static inline int folio_flags_is_file_lru(const unsigned long *flags) +{ + return !test_bit(PG_swapbacked, flags); +} + /** * folio_is_file_lru - Should the folio be on a file LRU or anon LRU? * @folio: The folio to test. @@ -27,7 +32,7 @@ */ static inline int folio_is_file_lru(const struct folio *folio) { - return !folio_test_swapbacked(folio); + return folio_flags_is_file_lru(const_folio_flags(folio, 0)); } =20 static __always_inline void __update_lru_size(struct lruvec *lruvec, diff --git a/mm/vmscan.c b/mm/vmscan.c index 724b6e034e69..87e667c410ed 100644 --- a/mm/vmscan.c +++ b/mm/vmscan.c @@ -3269,7 +3269,8 @@ static bool positive_ctrl_err(struct ctrl_pos *sp, st= ruct ctrl_pos *pv) *************************************************************************= *****/ =20 /* promote pages accessed through page tables */ -static int folio_update_gen(struct folio *folio, int new_gen, const vma_fl= ags_t *vma_flags) +static int folio_update_gen(struct folio *folio, int new_gen, int *is_file, + const vma_flags_t *vma_flags) { unsigned long new_flags, old_flags =3D READ_ONCE(*folio_flags(folio, 0)); int old_gen; @@ -3298,6 +3299,7 @@ static int folio_update_gen(struct folio *folio, int = new_gen, const vma_flags_t new_flags |=3D BIT(PG_workingset); } while (!try_cmpxchg(folio_flags(folio, 0), &old_flags, new_flags)); =20 + *is_file =3D folio_flags_is_file_lru(&old_flags); return old_gen; } =20 @@ -3328,9 +3330,8 @@ static int folio_inc_gen(struct lruvec *lruvec, struc= t folio *folio) } =20 static void update_batch_size(struct lru_gen_mm_walk *walk, struct folio *= folio, - int old_gen, int new_gen) + int old_gen, int new_gen, int type) { - int type =3D folio_is_file_lru(folio); int zone =3D folio_zonenum(folio); int delta =3D folio_nr_pages(folio); =20 @@ -3519,7 +3520,7 @@ static bool suitable_to_scan(int total, int young) static void walk_update_folio(struct lru_gen_mm_walk *walk, struct vm_area= _struct *vma, struct lruvec *lruvec, struct folio *folio, bool dirty) { - int new_gen, old_gen; + int new_gen, old_gen, file; =20 if (!folio) return; @@ -3532,9 +3533,9 @@ static void walk_update_folio(struct lru_gen_mm_walk = *walk, struct vm_area_struc folio_mark_dirty(folio); =20 if (walk) { - old_gen =3D folio_update_gen(folio, new_gen, &vma->flags); + old_gen =3D folio_update_gen(folio, new_gen, &file, &vma->flags); if (old_gen >=3D 0 && old_gen !=3D new_gen) - update_batch_size(walk, folio, old_gen, new_gen); + update_batch_size(walk, folio, old_gen, new_gen, file); } else if (lru_gen_set_refs(folio, &vma->flags)) { old_gen =3D folio_lru_gen(folio); if (old_gen >=3D 0 && old_gen !=3D new_gen) --=20 2.55.0