]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
mm/hugetlb: fix surplus pages in dissolve_free_huge_page()
authorJinjiang Tu <tujinjiang@huawei.com>
Tue, 4 Mar 2025 13:21:06 +0000 (21:21 +0800)
committerAndrew Morton <akpm@linux-foundation.org>
Mon, 17 Mar 2025 00:40:23 +0000 (17:40 -0700)
In dissolve_free_huge_page(), free huge pages are dissolved without
adjusting surplus count. However, free huge pages may be accounted as
surplus pages, and will lead to wrong surplus count.

I reproduce this issue on qemu. The steps are:
1) Node1 is memory-less at first. Hot-add memory to node1 by executing
the two commands in qemu monitor:
  object_add memory-backend-ram,id=mem1,size=1G
  device_add pc-dimm,id=dimm1,memdev=mem1,node=1
2) online one memory block of Node1 with:
  echo online_movable > /sys/devices/system/node/node1/memoryX/state
3) create 64 huge pages for node1
4) run a program to reserve (don't consume) all the huge pages
5) echo 0 > nr_huge_pages for node1. After this step, free huge pages in
Node1 are surplus.
6) create 80 huge pages for node0
7) offline memory of node1, The memory range to offline contains the free
surplus huge pages created in step3) ~ step5)
  echo offline > /sys/devices/system/node/node1/memoryX/state
8) kill the program in step 4)

The result:
           Node0     Node1
total       80        0
free        80        0
surplus     0         61

To fix it, adjust surplus when destroying huge pages if the node has
surplus pages in dissolve_free_hugetlb_folio().

The result with this patch:
           Node0     Node1
total       80        0
free        80        0
surplus     0         0

Link: https://lkml.kernel.org/r/20250304132106.2872754-1-tujinjiang@huawei.com
Fixes: c8721bbbdd36 ("mm: memory-hotplug: enable memory hotplug to handle hugepage")
Signed-off-by: Jinjiang Tu <tujinjiang@huawei.com>
Acked-by: David Hildenbrand <david@redhat.com>
Acked-by: Oscar Salvador <osalvador@suse.de>
Cc: Jinjiang Tu <tujinjiang@huawei.com>
Cc: Kefeng Wang <wangkefeng.wang@huawei.com>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Nanyong Sun <sunnanyong@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
mm/hugetlb.c

index 97930d44d460eab1e3e12fd508ec3fa798e593e4..318624c9658444a529a63478bad298d5c1a4ad3d 100644 (file)
@@ -2135,6 +2135,8 @@ retry:
 
        if (!folio_ref_count(folio)) {
                struct hstate *h = folio_hstate(folio);
+               bool adjust_surplus = false;
+
                if (!available_huge_pages(h))
                        goto out;
 
@@ -2157,7 +2159,9 @@ retry:
                        goto retry;
                }
 
-               remove_hugetlb_folio(h, folio, false);
+               if (h->surplus_huge_pages_node[folio_nid(folio)])
+                       adjust_surplus = true;
+               remove_hugetlb_folio(h, folio, adjust_surplus);
                h->max_huge_pages--;
                spin_unlock_irq(&hugetlb_lock);
 
@@ -2177,7 +2181,7 @@ retry:
                        rc = hugetlb_vmemmap_restore_folio(h, folio);
                        if (rc) {
                                spin_lock_irq(&hugetlb_lock);
-                               add_hugetlb_folio(h, folio, false);
+                               add_hugetlb_folio(h, folio, adjust_surplus);
                                h->max_huge_pages++;
                                goto out;
                        }