From: Mike Kravetz <mike.kravetz@oracle.com>
To: Miaohe Lin <linmiaohe@huawei.com>,
Naoya Horiguchi <naoya.horiguchi@linux.dev>
Cc: Andrew Morton <akpm@linux-foundation.org>,
zhenwei pi <pizhenwei@bytedance.com>,
Naoya Horiguchi <naoya.horiguchi@nec.com>,
linux-kernel@vger.kernel.org, Linux-MM <linux-mm@kvack.org>
Subject: Re: [PATCH v1] mm,hwpoison: set PG_hwpoison for busy hugetlb pages
Date: Wed, 11 May 2022 20:06:47 -0700 [thread overview]
Message-ID: <f9236f0d-f70e-e078-84d2-9ea480060f27@oracle.com> (raw)
In-Reply-To: <d7f24648-2af5-3998-d265-c441538ce5fc@huawei.com>
On 5/11/22 19:54, Miaohe Lin wrote:
> On 2022/5/12 2:35, Mike Kravetz wrote:
>> On 5/11/22 08:19, Naoya Horiguchi wrote:
>>> From: Naoya Horiguchi <naoya.horiguchi@nec.com>
>>>
>>> If memory_failure() fails to grab page refcount on a hugetlb page
>>> because it's busy, it returns without setting PG_hwpoison on it.
>>> This not only loses a chance of error containment, but breaks the rule
>>> that action_result() should be called only when memory_failure() do
>>> any of handling work (even if that's just setting PG_hwpoison).
>>> This inconsistency could harm code maintainability.
>>>
>>> So set PG_hwpoison and call hugetlb_set_page_hwpoison() for such a case.
>
> I'm sorry but where is hugetlb_set_page_hwpoison() defined and used ? I can't find it.
>
>>>
>>> Fixes: 405ce051236c ("mm/hwpoison: fix race between hugetlb free/demotion and memory_failure_hugetlb()")
>>> Signed-off-by: Naoya Horiguchi <naoya.horiguchi@nec.com>
>>> ---
>>> include/linux/mm.h | 1 +
>>> mm/memory-failure.c | 8 ++++----
>>> 2 files changed, 5 insertions(+), 4 deletions(-)
>>>
>>> diff --git a/include/linux/mm.h b/include/linux/mm.h
>>> index d446e834a3e5..04de0c3e4f9f 100644
>>> --- a/include/linux/mm.h
>>> +++ b/include/linux/mm.h
>>> @@ -3187,6 +3187,7 @@ enum mf_flags {
>>> MF_MUST_KILL = 1 << 2,
>>> MF_SOFT_OFFLINE = 1 << 3,
>>> MF_UNPOISON = 1 << 4,
>>> + MF_NO_RETRY = 1 << 5,
>>> };
>>> extern int memory_failure(unsigned long pfn, int flags);
>>> extern void memory_failure_queue(unsigned long pfn, int flags);
>>> diff --git a/mm/memory-failure.c b/mm/memory-failure.c
>>> index 6a28d020a4da..e3269b991016 100644
>>> --- a/mm/memory-failure.c
>>> +++ b/mm/memory-failure.c
>>> @@ -1526,7 +1526,8 @@ int __get_huge_page_for_hwpoison(unsigned long pfn, int flags)
>>> count_increased = true;
>>> } else {
>>> ret = -EBUSY;
>>> - goto out;
>>> + if (!(flags & MF_NO_RETRY))
>>> + goto out;
>>> }
>>
>> Hi Naoya,
>>
>> We are in the else block because !HPageFreed() and !HPageMigratable().
>> IIUC, this likely means the page is isolated. One common reason for isolation
>> is migration. So, the page could be isolated and on a list for migration.
>>
>> I took a quick look at the hugetlb migration code and did not see any checks
>> for PageHWPoison after a hugetlb page is isolated. I could have missed
>> something? If there are no checks, we will read the PageHWPoison page
>> in kernel mode while copying to the migration target.
>>
>> Is this an issue? Is is something we need to be concerned with? Memory
>> errors can happen at any time, and gracefully handling them is best effort.
>
> It seems HWPoison hugetlb page will still be accessed before this patch. Can we do a
> get_page_unless_zero first here to ensure that hugetlb page migration should fail due
> to this extra page reference and thus not access the page content? If hugetlb page is
> already freezed, corrupted memory will still be consumed though. :(
Right. This potential issue was not introduced with this patch.
Also, I am not sure but it might be an issue with non-hugetlb pages as well.
As mentioned, memory error handling is a best effort. Since errors can
happen at any time, we can not handle all cases. Or, you could spend the
rest of your life trying. :)
The question is, should we worry about errors that happen when a page is
isolated for migration?
--
Mike Kravetz
next prev parent reply other threads:[~2022-05-12 3:07 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-05-11 15:19 [PATCH v1] mm,hwpoison: set PG_hwpoison for busy hugetlb pages Naoya Horiguchi
2022-05-11 18:35 ` Mike Kravetz
2022-05-12 2:54 ` Miaohe Lin
2022-05-12 3:06 ` Mike Kravetz [this message]
2022-05-12 4:50 ` HORIGUCHI NAOYA(堀口 直也)
2022-05-12 4:46 ` HORIGUCHI NAOYA(堀口 直也)
2022-05-12 4:32 ` HORIGUCHI NAOYA(堀口 直也)
2022-05-12 11:18 ` Miaohe Lin
2022-06-02 6:12 ` HORIGUCHI NAOYA(堀口 直也)
2022-06-06 3:12 ` Miaohe Lin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f9236f0d-f70e-e078-84d2-9ea480060f27@oracle.com \
--to=mike.kravetz@oracle.com \
--cc=akpm@linux-foundation.org \
--cc=linmiaohe@huawei.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=naoya.horiguchi@linux.dev \
--cc=naoya.horiguchi@nec.com \
--cc=pizhenwei@bytedance.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).