The patch titled Subject: ksm: cleanup stable_node chain collapse case has been added to the -mm tree. Its filename is ksm-cleanup-stable_node-chain-collapse-case.patch This patch should soon appear at http://ozlabs.org/~akpm/mmots/broken-out/ksm-cleanup-stable_node-chain-collapse-case.patch and later at http://ozlabs.org/~akpm/mmotm/broken-out/ksm-cleanup-stable_node-chain-collapse-case.patch Before you just go and hit "reply", please: a) Consider who else should be cc'ed b) Prefer to cc a suitable mailing list as well c) Ideally: find the original patch on the mailing list and do a reply-to-all to that, adding suitable additional cc's *** Remember to use Documentation/SubmitChecklist when testing your code *** The -mm tree is included into linux-next and is updated there every 3-4 working days ------------------------------------------------------ From: Andrea Arcangeli <aarcange@xxxxxxxxxx> Subject: ksm: cleanup stable_node chain collapse case Patch series "KSMscale cleanup/optimizations". There are no fixes here it's just minor cleanups and optimizations. 1/3 removes makes the "fix" for the stale stable_node fall in the standard case without introducing new cases. Setting stable_node to NULL was marginally safer, but stale pointer is still wiped from the caller, this looks cleaner. 2/3 should fix the false positive from Dan's static checker. 3/3 is a microoptimization to apply the the refile of future merge candidate dups at the head of the chain in all cases and to skip it in one case where we did it and but it was a noop (to avoid checking if it was already at the head but now we've to check it anyway so it got optimized away). This patch (of 3): When the stable_node chain is collapsed we can as well set the caller stable_node to match the returned stable_node_dup in chain_prune(). This way the collapse case becomes indistinguishable from the regular stable_node case and we can remove two branches from the KSM page migration handling slow paths. While it was all correct this looks cleaner (and faster) as the caller has to deal with fewer special cases. Link: http://lkml.kernel.org/r/20170518173721.22316-2-aarcange@xxxxxxxxxx Signed-off-by: Andrea Arcangeli <aarcange@xxxxxxxxxx> Cc: Evgheni Dereveanchin <ederevea@xxxxxxxxxx> Cc: Andrey Ryabinin <aryabinin@xxxxxxxxxxxxx> Cc: Petr Holasek <pholasek@xxxxxxxxxx> Cc: Hugh Dickins <hughd@xxxxxxxxxx> Cc: Arjan van de Ven <arjan@xxxxxxxxxxxxxxx> Cc: Davidlohr Bueso <dave@xxxxxxxxxxxx> Cc: Gavin Guo <gavin.guo@xxxxxxxxxxxxx> Cc: Jay Vosburgh <jay.vosburgh@xxxxxxxxxxxxx> Cc: Mel Gorman <mgorman@xxxxxxxxxxxxxxxxxxx> Cc: Dan Carpenter <dan.carpenter@xxxxxxxxxx> Signed-off-by: Andrew Morton <akpm@xxxxxxxxxxxxxxxxxxxx> --- mm/ksm.c | 50 ++++++++++++++++++++++++++++---------------------- 1 file changed, 28 insertions(+), 22 deletions(-) diff -puN mm/ksm.c~ksm-cleanup-stable_node-chain-collapse-case mm/ksm.c --- a/mm/ksm.c~ksm-cleanup-stable_node-chain-collapse-case +++ a/mm/ksm.c @@ -1392,14 +1392,18 @@ static struct stable_node *stable_node_d ksm_stable_node_chains--; ksm_stable_node_dups--; /* - * NOTE: the caller depends on the - * *_stable_node to become NULL if the chain - * was collapsed. Enforce that if anything - * uses a stale (freed) stable_node chain a - * visible crash will materialize (instead of - * an use after free). + * NOTE: the caller depends on the stable_node + * to be equal to stable_node_dup if the chain + * was collapsed. */ - *_stable_node = stable_node = NULL; + *_stable_node = found; + /* + * Just for robustneess as stable_node is + * otherwise left as a stable pointer, the + * compiler shall optimize it away at build + * time. + */ + stable_node = NULL; } else if (__is_page_sharing_candidate(found, 1)) { /* * Refile our candidate at the head @@ -1505,7 +1509,11 @@ again: * not NULL. stable_node_dup may have been inserted in * the rbtree instead as a regular stable_node (in * order to collapse the stable_node chain if a single - * stable_node dup was found in it). + * stable_node dup was found in it). In such case the + * stable_node is overwritten by the calleee to point + * to the stable_node_dup that was collapsed in the + * stable rbtree and stable_node will be equal to + * stable_node_dup like if the chain never existed. */ if (!stable_node_dup) { /* @@ -1623,15 +1631,13 @@ out: replace: /* * If stable_node was a chain and chain_prune collapsed it, - * stable_node will be NULL here. In that case the - * stable_node_dup is the regular stable_node that has - * replaced the chain. If stable_node is not NULL and equal to - * stable_node_dup there was no chain and stable_node_dup is - * the regular stable_node in the stable rbtree. Otherwise - * stable_node is the chain and stable_node_dup is the dup to - * replace. + * stable_node has been updated to be the new regular + * stable_node. A collapse of the chain is indistinguishable + * from the case there was no chain in the stable + * rbtree. Otherwise stable_node is the chain and + * stable_node_dup is the dup to replace. */ - if (!stable_node || stable_node_dup == stable_node) { + if (stable_node_dup == stable_node) { VM_BUG_ON(is_stable_node_chain(stable_node_dup)); VM_BUG_ON(is_stable_node_dup(stable_node_dup)); /* there is no chain */ @@ -1676,13 +1682,13 @@ chain_append: stable_node_dup = stable_node_any; /* * If stable_node was a chain and chain_prune collapsed it, - * stable_node will be NULL here. In that case the - * stable_node_dup is the regular stable_node that has - * replaced the chain. If stable_node is not NULL and equal to - * stable_node_dup there was no chain and stable_node_dup is - * the regular stable_node in the stable rbtree. + * stable_node has been updated to be the new regular + * stable_node. A collapse of the chain is indistinguishable + * from the case there was no chain in the stable + * rbtree. Otherwise stable_node is the chain and + * stable_node_dup is the dup to replace. */ - if (!stable_node || stable_node_dup == stable_node) { + if (stable_node_dup == stable_node) { VM_BUG_ON(is_stable_node_chain(stable_node_dup)); VM_BUG_ON(is_stable_node_dup(stable_node_dup)); /* chain is missing so create it */ _ Patches currently in -mm which might be from aarcange@xxxxxxxxxx are ksm-prevent-crash-after-write_protect_page-fails.patch ksm-introduce-ksm_max_page_sharing-per-page-deduplication-limit.patch ksm-fix-use-after-free-with-merge_across_nodes-=-0.patch ksm-cleanup-stable_node-chain-collapse-case.patch ksm-swap-the-two-output-parameters-of-chain-chain_prune.patch ksm-optimize-refile-of-stable_node_dup-at-the-head-of-the-chain.patch -- To unsubscribe from this list: send the line "unsubscribe mm-commits" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html