From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5A632C43334 for ; Fri, 17 Jun 2022 01:43:08 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1379621AbiFQBnH (ORCPT ); Thu, 16 Jun 2022 21:43:07 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37054 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1379330AbiFQBnF (ORCPT ); Thu, 16 Jun 2022 21:43:05 -0400 Received: from mail-vk1-xa30.google.com (mail-vk1-xa30.google.com [IPv6:2607:f8b0:4864:20::a30]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 3B1C011A22 for ; Thu, 16 Jun 2022 18:43:03 -0700 (PDT) Received: by mail-vk1-xa30.google.com with SMTP id 140so1392409vky.10 for ; Thu, 16 Jun 2022 18:43:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=o21zxVymcDoocZqYnqtyLWw9WczAWnySXHM2icvTQIQ=; b=Rz8QM+1bp9KdwGXwr3uVXBhPGpjg5/YEBNW7Un6JsfjanqVYvrQ1rqnnFG5jHsdUZ6 oppHhUMtDyPoEvaBVWw/y5bAiYnAhlVaqQePo3Yox+Q1yXrF8W1cqeYxtRPrJYpvoIwQ sTti4eT1wr7lP1fOkQe3ibipSvqi5q6UZtUzc8UfKh58yb2QQdBn8l0PhcbBzgMKrVZy GWbCXfWCH13atYKA25YEN85xsGzCU0Ovg17L/g0K0b4C1erdDCPDwbwcQfE5jfQxaYuG 70K5nMSuITS55Te3jlXTIdHarc2TGl4b02M7Thx+rKG1aOLwS6fbAfG2S+gZlZIAU2ZN N4qQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=o21zxVymcDoocZqYnqtyLWw9WczAWnySXHM2icvTQIQ=; b=CXWYv0qsY6uONfWcyjQeL8IAm/mRTp1pQ+1F6U28JWh1BzIae2jHZrf5Phl/srHHaZ noMn1a8g8lKroHt3EQTiurgQDeOY37rNcJHdn+dIINQb73lOfclqNiGH6b21nWbCoLzS 7DUBFLNoYSLahljxucypLXSSq2tKwZoDNwAGdhtB263NJs0lSl8OP4IUmfe6/4RFl4QG CfpqPl9EiSOzPaBsk9T1GjTR0Ftd6nAdYM6bX28hXlm6SjIqf1bGgvlH0Jo+5JzIRI2Z erhvAVVuJJ3A+VXkGosL762vpXXgfJKJAvCTSscc6pCe4/SjAlQIkSL11TIyGC0KOzLW q2Lg== X-Gm-Message-State: AJIora+RtCuqW7q1HSJNnjFKaRsEvJD/5ucNDbQsfyxuQYCMbckvlhPA UC3FqdoCrY9kQByf+9XR89BBP3WiJw9VVSunMkGu4Q== X-Google-Smtp-Source: AGRyM1vDfbyUn4OY+TQe70MnwVcbhRK3DIMcjtAhCf2Jzx5dAcoHgGEq9Bg6S7NZU57gcgwPg0/koovMtDV4ObvKHqI= X-Received: by 2002:a1f:add0:0:b0:361:1bf:7c58 with SMTP id w199-20020a1fadd0000000b0036101bf7c58mr3575164vke.31.1655430181818; Thu, 16 Jun 2022 18:43:01 -0700 (PDT) MIME-Version: 1.0 References: <20220518014632.922072-1-yuzhao@google.com> <20220518014632.922072-8-yuzhao@google.com> <20220607102135.GA32448@willie-the-truck> <20220607104358.GA32583@willie-the-truck> In-Reply-To: From: Yu Zhao Date: Thu, 16 Jun 2022 19:42:25 -0600 Message-ID: Subject: Re: [PATCH v11 07/14] mm: multi-gen LRU: exploit locality in rmap To: Barry Song <21cnbao@gmail.com> Cc: Linus Torvalds , Will Deacon , Andrew Morton , Linux-MM , Andi Kleen , Aneesh Kumar , Catalin Marinas , Dave Hansen , Hillf Danton , Jens Axboe , Johannes Weiner , Jonathan Corbet , Matthew Wilcox , Mel Gorman , Michael Larabel , Michal Hocko , Mike Rapoport , Peter Zijlstra , Tejun Heo , Vlastimil Babka , LAK , Linux Doc Mailing List , LKML , x86 , Kernel Page Reclaim v2 , Brian Geffon , Jan Alexander Steffens , Oleksandr Natalenko , Steven Barrett , Suleiman Souhlal , Daniel Byrne , Donald Carr , =?UTF-8?Q?Holger_Hoffst=C3=A4tte?= , Konstantin Kharlamov , Shuang Zhai , Sofia Trinh , Vaibhav Jain , huzhanyuan@oppo.com Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, Jun 16, 2022 at 5:29 PM Yu Zhao wrote: > > On Thu, Jun 16, 2022 at 4:33 PM Barry Song <21cnbao@gmail.com> wrote: > > > > On Fri, Jun 17, 2022 at 9:56 AM Yu Zhao wrote: > > > > > > On Wed, Jun 8, 2022 at 4:46 PM Barry Song <21cnbao@gmail.com> wrote: > > > > > > > > On Thu, Jun 9, 2022 at 3:52 AM Linus Torvalds > > > > wrote: > > > > > > > > > > On Tue, Jun 7, 2022 at 5:43 PM Barry Song <21cnbao@gmail.com> wrote: > > > > > > > > > > > > Given we used to have a flush for clear pte young in LRU, right now we are > > > > > > moving to nop in almost all cases for the flush unless the address becomes > > > > > > young exactly after look_around and before ptep_clear_flush_young_notify. > > > > > > It means we are actually dropping flush. So the question is, were we > > > > > > overcautious? we actually don't need the flush at all even without mglru? > > > > > > > > > > We stopped flushing the TLB on A bit clears on x86 back in 2014. > > > > > > > > > > See commit b13b1d2d8692 ("x86/mm: In the PTE swapout page reclaim case > > > > > clear the accessed bit instead of flushing the TLB"). > > > > > > > > This is true for x86, RISC-V, powerpc and S390. but it is not true for > > > > most platforms. > > > > > > > > There was an attempt to do the same thing in arm64: > > > > https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1793830.html > > > > but arm64 still sent a nosync tlbi and depent on a deferred to dsb : > > > > https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1794484.html > > > > > > Barry, you've already answered your own question. > > > > > > Without commit 07509e10dcc7 arm64: pgtable: Fix pte_accessible(): > > > #define pte_accessible(mm, pte) \ > > > - (mm_tlb_flush_pending(mm) ? pte_present(pte) : pte_valid_young(pte)) > > > + (mm_tlb_flush_pending(mm) ? pte_present(pte) : pte_valid(pte)) > > > > > > You missed all TLB flushes for PTEs that have gone through > > > ptep_test_and_clear_young() on the reclaim path. But most of the time, > > > you got away with it, only occasional app crashes: > > > https://lore.kernel.org/r/CAGsJ_4w6JjuG4rn2P=d974wBOUtXUUnaZKnx+-G6a8_mSROa+Q@mail.gmail.com/ > > > > > > Why? > > > > Yes. On the arm64 platform, ptep_test_and_clear_young() without flush > > can cause random > > App to crash. > > ptep_test_and_clear_young() + flush won't have this kind of crashes though. > > But after applying commit 07509e10dcc7 arm64: pgtable: Fix > > pte_accessible(), on arm64, > > ptep_test_and_clear_young() without flush won't cause App to crash. > > > > ptep_test_and_clear_young(), with flush, without commit 07509e10dcc7: OK > > ptep_test_and_clear_young(), without flush, with commit 07509e10dcc7: OK > > ptep_test_and_clear_young(), without flush, without commit 07509e10dcc7: CRASH > > I agree -- my question was rhetorical :) > > I was trying to imply this logic: > 1. We cleared the A-bit in PTEs with ptep_test_and_clear_young() > 2. We missed TLB flush for those PTEs on the reclaim path, i.e., case > 3 (case 1 & 2 guarantee flushes) > 3. We saw crashes, but only occasionally > > Assuming TLB cached those PTEs, we would have seen the crashes more > often, which contradicts our observation. So the conclusion is TLB > didn't cache them most of the time, meaning flushing TLB just for the > sake of the A-bit isn't necessary. > > > do you think it is safe to totally remove the flush code even for > > the original > > LRU? > > Affirmative, based on not only my words, but 3rd parties': > 1. Your (indirect) observation > 2. Alexander's benchmark: > https://lore.kernel.org/r/BYAPR12MB271295B398729E07F31082A7CFAA0@BYAPR12MB2712.namprd12.prod.outlook.com/ > 3. The fundamental hardware limitation in terms of the TLB scalability > (Fig. 1): https://www.usenix.org/legacy/events/osdi02/tech/full_papers/navarro/navarro.pdf 4. Intel's commit b13b1d2d8692 ("x86/mm: In the PTE swapout page reclaim case clear the accessed bit instead of flushing the TLB") From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 034B4C43334 for ; Fri, 17 Jun 2022 01:44:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:Cc:To:Subject:Message-ID:Date:From: In-Reply-To:References:MIME-Version:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=XA6AMIiPU/Q1dc0MPKA31btWPfTZ14/vPXMAFZao8Ho=; b=ceiwf1OppvCTXC lpbuBAGTArxAgvYwbNX3AAqXNCKDqZP03LnSdCWDRhcEAYQ9Tn6p+Kw9DcjK7ZrNhZ5izvDDBcm3/ jZdm5/pPpy6JD81aN01H2BQpLoqr1gIdrsRJHVJQWNGfMJ4TmsNOiq8/HWIL47lofhdZSW89ED+Ti q23C5H7tbIV2dRbyRYMq3hWQOKZfPu7XuvYSYs0e480b7XiUbdmMXSYdXJTtbQaNjFXS/tgJTD1X+ M5405XGQ7tA2kxysQq15VpMCrPiKgmETbL9W4PS2a015FUXySfAMAsJJ/E7zQfs7MryMZSJfRffNh lrPHagliyx+kSfPrD/pg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1o210v-0051m8-EI; Fri, 17 Jun 2022 01:43:09 +0000 Received: from mail-vk1-xa36.google.com ([2607:f8b0:4864:20::a36]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1o210q-0051jJ-4F for linux-arm-kernel@lists.infradead.org; Fri, 17 Jun 2022 01:43:07 +0000 Received: by mail-vk1-xa36.google.com with SMTP id q186so1389961vkh.8 for ; Thu, 16 Jun 2022 18:43:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=o21zxVymcDoocZqYnqtyLWw9WczAWnySXHM2icvTQIQ=; b=Rz8QM+1bp9KdwGXwr3uVXBhPGpjg5/YEBNW7Un6JsfjanqVYvrQ1rqnnFG5jHsdUZ6 oppHhUMtDyPoEvaBVWw/y5bAiYnAhlVaqQePo3Yox+Q1yXrF8W1cqeYxtRPrJYpvoIwQ sTti4eT1wr7lP1fOkQe3ibipSvqi5q6UZtUzc8UfKh58yb2QQdBn8l0PhcbBzgMKrVZy GWbCXfWCH13atYKA25YEN85xsGzCU0Ovg17L/g0K0b4C1erdDCPDwbwcQfE5jfQxaYuG 70K5nMSuITS55Te3jlXTIdHarc2TGl4b02M7Thx+rKG1aOLwS6fbAfG2S+gZlZIAU2ZN N4qQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=o21zxVymcDoocZqYnqtyLWw9WczAWnySXHM2icvTQIQ=; b=SKb2zwrNxXabwvDu1IF8mJN6qAKoAzFQVweUQl9+7DeBt5qspiY2i5wu8QEsmhUqQb ZLj31Ta64KytBc6GO+bIKpwCywRngFUxyff7i1op9azEmAi6MBtJluxKSHh8ntDmmGZE GEI72E3YwA2gAYbh+k13ejWfNTq4McKr9JexBE+e46rXK8VhyFyqRjCI/oC81ENhdhyp VuLCYi6guG0AhdpAJPL7xSitWBFA1vSxnzFcYO7HlFGtlr2DLTeKDSXMg3u00NuRJWRt yq+RvokfzNJPJo4VZhoCMSop/eZVJkBSeY94SQLFG7oJtO6ulINiG0L0zNVOyGF+ctqQ KOsA== X-Gm-Message-State: AJIora9SaDGSU0XqyohF8eN9qru9lcIwr+XKlVkd+X8We6zgJRm7UCvT ILwpmXvReYkqwLPi4gXrA/1S2MkQEL5hIRFOa45m1Q== X-Google-Smtp-Source: AGRyM1vDfbyUn4OY+TQe70MnwVcbhRK3DIMcjtAhCf2Jzx5dAcoHgGEq9Bg6S7NZU57gcgwPg0/koovMtDV4ObvKHqI= X-Received: by 2002:a1f:add0:0:b0:361:1bf:7c58 with SMTP id w199-20020a1fadd0000000b0036101bf7c58mr3575164vke.31.1655430181818; Thu, 16 Jun 2022 18:43:01 -0700 (PDT) MIME-Version: 1.0 References: <20220518014632.922072-1-yuzhao@google.com> <20220518014632.922072-8-yuzhao@google.com> <20220607102135.GA32448@willie-the-truck> <20220607104358.GA32583@willie-the-truck> In-Reply-To: From: Yu Zhao Date: Thu, 16 Jun 2022 19:42:25 -0600 Message-ID: Subject: Re: [PATCH v11 07/14] mm: multi-gen LRU: exploit locality in rmap To: Barry Song <21cnbao@gmail.com> Cc: Linus Torvalds , Will Deacon , Andrew Morton , Linux-MM , Andi Kleen , Aneesh Kumar , Catalin Marinas , Dave Hansen , Hillf Danton , Jens Axboe , Johannes Weiner , Jonathan Corbet , Matthew Wilcox , Mel Gorman , Michael Larabel , Michal Hocko , Mike Rapoport , Peter Zijlstra , Tejun Heo , Vlastimil Babka , LAK , Linux Doc Mailing List , LKML , x86 , Kernel Page Reclaim v2 , Brian Geffon , Jan Alexander Steffens , Oleksandr Natalenko , Steven Barrett , Suleiman Souhlal , Daniel Byrne , Donald Carr , =?UTF-8?Q?Holger_Hoffst=C3=A4tte?= , Konstantin Kharlamov , Shuang Zhai , Sofia Trinh , Vaibhav Jain , huzhanyuan@oppo.com X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20220616_184304_262952_49E554BB X-CRM114-Status: GOOD ( 32.22 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Thu, Jun 16, 2022 at 5:29 PM Yu Zhao wrote: > > On Thu, Jun 16, 2022 at 4:33 PM Barry Song <21cnbao@gmail.com> wrote: > > > > On Fri, Jun 17, 2022 at 9:56 AM Yu Zhao wrote: > > > > > > On Wed, Jun 8, 2022 at 4:46 PM Barry Song <21cnbao@gmail.com> wrote: > > > > > > > > On Thu, Jun 9, 2022 at 3:52 AM Linus Torvalds > > > > wrote: > > > > > > > > > > On Tue, Jun 7, 2022 at 5:43 PM Barry Song <21cnbao@gmail.com> wrote: > > > > > > > > > > > > Given we used to have a flush for clear pte young in LRU, right now we are > > > > > > moving to nop in almost all cases for the flush unless the address becomes > > > > > > young exactly after look_around and before ptep_clear_flush_young_notify. > > > > > > It means we are actually dropping flush. So the question is, were we > > > > > > overcautious? we actually don't need the flush at all even without mglru? > > > > > > > > > > We stopped flushing the TLB on A bit clears on x86 back in 2014. > > > > > > > > > > See commit b13b1d2d8692 ("x86/mm: In the PTE swapout page reclaim case > > > > > clear the accessed bit instead of flushing the TLB"). > > > > > > > > This is true for x86, RISC-V, powerpc and S390. but it is not true for > > > > most platforms. > > > > > > > > There was an attempt to do the same thing in arm64: > > > > https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1793830.html > > > > but arm64 still sent a nosync tlbi and depent on a deferred to dsb : > > > > https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1794484.html > > > > > > Barry, you've already answered your own question. > > > > > > Without commit 07509e10dcc7 arm64: pgtable: Fix pte_accessible(): > > > #define pte_accessible(mm, pte) \ > > > - (mm_tlb_flush_pending(mm) ? pte_present(pte) : pte_valid_young(pte)) > > > + (mm_tlb_flush_pending(mm) ? pte_present(pte) : pte_valid(pte)) > > > > > > You missed all TLB flushes for PTEs that have gone through > > > ptep_test_and_clear_young() on the reclaim path. But most of the time, > > > you got away with it, only occasional app crashes: > > > https://lore.kernel.org/r/CAGsJ_4w6JjuG4rn2P=d974wBOUtXUUnaZKnx+-G6a8_mSROa+Q@mail.gmail.com/ > > > > > > Why? > > > > Yes. On the arm64 platform, ptep_test_and_clear_young() without flush > > can cause random > > App to crash. > > ptep_test_and_clear_young() + flush won't have this kind of crashes though. > > But after applying commit 07509e10dcc7 arm64: pgtable: Fix > > pte_accessible(), on arm64, > > ptep_test_and_clear_young() without flush won't cause App to crash. > > > > ptep_test_and_clear_young(), with flush, without commit 07509e10dcc7: OK > > ptep_test_and_clear_young(), without flush, with commit 07509e10dcc7: OK > > ptep_test_and_clear_young(), without flush, without commit 07509e10dcc7: CRASH > > I agree -- my question was rhetorical :) > > I was trying to imply this logic: > 1. We cleared the A-bit in PTEs with ptep_test_and_clear_young() > 2. We missed TLB flush for those PTEs on the reclaim path, i.e., case > 3 (case 1 & 2 guarantee flushes) > 3. We saw crashes, but only occasionally > > Assuming TLB cached those PTEs, we would have seen the crashes more > often, which contradicts our observation. So the conclusion is TLB > didn't cache them most of the time, meaning flushing TLB just for the > sake of the A-bit isn't necessary. > > > do you think it is safe to totally remove the flush code even for > > the original > > LRU? > > Affirmative, based on not only my words, but 3rd parties': > 1. Your (indirect) observation > 2. Alexander's benchmark: > https://lore.kernel.org/r/BYAPR12MB271295B398729E07F31082A7CFAA0@BYAPR12MB2712.namprd12.prod.outlook.com/ > 3. The fundamental hardware limitation in terms of the TLB scalability > (Fig. 1): https://www.usenix.org/legacy/events/osdi02/tech/full_papers/navarro/navarro.pdf 4. Intel's commit b13b1d2d8692 ("x86/mm: In the PTE swapout page reclaim case clear the accessed bit instead of flushing the TLB") _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel