From: Yunsheng Lin <hidden> Date: 2021-07-10 07:44:09
This patchset adds elevated refcnt support for page pool
and enable skb's page frag recycling based on page pool
in hns3 drvier.
RFC v2:
1. Split patch 1 to more reviewable one.
2. Repurpose the lower 12 bits of the dma address to store the
pagecnt_bias as suggested by Alexander.
3. support recycling to pool->alloc for elevated refcnt case
too.
Yunsheng Lin (5):
page_pool: keep pp info as long as page pool owns the page
page_pool: add interface for getting and setting pagecnt_bias
page_pool: add page recycling support based on elevated refcnt
page_pool: support page frag API for page pool
net: hns3: support skb's frag page recycling based on page pool
drivers/net/ethernet/hisilicon/hns3/hns3_enet.c | 79 ++++++++++-
drivers/net/ethernet/hisilicon/hns3/hns3_enet.h | 3 +
drivers/net/ethernet/marvell/mvneta.c | 6 +-
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 2 +-
drivers/net/ethernet/ti/cpsw.c | 2 +-
drivers/net/ethernet/ti/cpsw_new.c | 2 +-
include/linux/skbuff.h | 4 +-
include/net/page_pool.h | 50 +++++--
net/core/page_pool.c | 172 ++++++++++++++++++++----
9 files changed, 266 insertions(+), 54 deletions(-)
--
2.7.4
From: Yunsheng Lin <hidden> Date: 2021-07-10 07:44:12
Currently page pool only support page recycling only when
refcnt of page is one, which means it can not support the
split page recycling implemented in the most driver.
The expectation of page recycling based on elevated refcnt
is that we only do the recycling or freeing of page when the
last user has dropped the refcnt that has given to it.
The above expectation is based on that the last user will
always call page_pool_put_full_page() in order to do the
recycling or do the resource cleanup(dma unmaping..etc) and
freeing.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 5 ++-
net/core/page_pool.c | 106 ++++++++++++++++++++++++++++++++++++------------
2 files changed, 84 insertions(+), 27 deletions(-)
@@ -298,6 +310,23 @@ static struct page *__page_pool_alloc_pages_slow(struct page_pool *pool,returnpage;}+staticvoidpage_pool_sub_bias(structpage_pool*pool,+structpage*page,intnr)+{+intbias;++if(!(pool->p.flags&PP_FLAG_PAGECNT_BIAS))+return;++bias=page_pool_get_pagecnt_bias(page);+if(unlikely(bias<=nr)){+page_ref_add(page,BIAS_MAX-bias);+bias=BIAS_MAX;+}++page_pool_set_pagecnt_bias(page,bias-nr);+}+/* For using page_pool replace: alloc_pages() API calls, but provide*synchronizationguaranteeforallocationside.*/
@@ -307,11 +336,16 @@ struct page *page_pool_alloc_pages(struct page_pool *pool, gfp_t gfp)/* Fast-path: Get a page from cache */page=__page_pool_get_cached(pool);-if(page)+if(page){+page_pool_sub_bias(pool,page,1);returnpage;+}/* Slow-path: cache empty, do real allocation */page=__page_pool_alloc_pages_slow(pool,gfp);+if(likely(page))+page_pool_sub_bias(pool,page,1);+returnpage;}EXPORT_SYMBOL(page_pool_alloc_pages);
@@ -340,10 +374,11 @@ static s32 page_pool_inflight(struct page_pool *pool)*aregularpage(thatwilleventuallybereturnedtothenormal*page-allocatorviaput_page).*/-voidpage_pool_release_page(structpage_pool*pool,structpage*page)+staticint__page_pool_release_page(structpage_pool*pool,+structpage*page){+intbias,count;dma_addr_tdma;-intcount;if(!(pool->p.flags&PP_FLAG_DMA_MAP))/* Always account for inflight pages, even if we didn't
@@ -359,22 +394,30 @@ void page_pool_release_page(struct page_pool *pool, struct page *page)DMA_ATTR_SKIP_CPU_SYNC);page_pool_set_dma_addr(page,0);skip_dma_unmap:-page_pool_clear_pp_info(page);+bias=page_pool_clear_pp_info(page);/* This may be the last page returned, releasing the pool, so*itisnotsafetoreferencepoolafterwards.*/count=atomic_inc_return(&pool->pages_state_release_cnt);trace_page_pool_state_release(pool,page,count);++returnbias;+}++voidpage_pool_release_page(structpage_pool*pool,structpage*page)+{+intbias=__page_pool_release_page(pool,page);++WARN_ONCE(bias,"%s is called from driver with elevated refcnt\n",+__func__);}EXPORT_SYMBOL(page_pool_release_page);/* Return a page to the page allocator, cleaning up our state */staticvoidpage_pool_return_page(structpage_pool*pool,structpage*page){-page_pool_release_page(pool,page);--put_page(page);+__page_frag_cache_drain(page,__page_pool_release_page(pool,page)+1);/* An optimization would be to call __free_pages(page, pool->p.order)*knowingpageisnotpartofpage-cache(thusavoidinga*__page_cache_release()call).
@@ -409,6 +452,15 @@ static bool page_pool_recycle_in_cache(struct page *page,returntrue;}+staticboolpage_pool_bias_page_recyclable(structpage*page,intbias)+{+intref=page_ref_dec_return(page);++WARN_ON(ref<=bias);++returnref==bias+1;+}+/* If the page refcnt == 1, this will try to recycle the page.*ifPP_FLAG_DMA_SYNC_DEVisset,we'lltrytosynctheDMAareafor*theconfiguredsizemin(dma_sync_size,pool->max_len).
@@ -419,6 +471,20 @@ static __always_inline struct page *__page_pool_put_page(structpage_pool*pool,structpage*page,unsignedintdma_sync_size,boolallow_direct){+intbias=page_pool_get_pagecnt_bias(page);++/* Handle the elevated refcnt case first */+if(bias){+/* It is not the last user yet */+if(!page_pool_bias_page_recyclable(page,bias))+returnNULL;++if(likely(!page_is_pfmemalloc(page)))+gotorecyclable;+else+gotounrecyclable;+}+/* This allocator is optimized for the XDP mode that uses*one-frame-per-page,buthavefallbacksthatactlikethe*regularpageallocatorAPIs.
@@ -442,22 +508,9 @@ __page_pool_put_page(struct page_pool *pool, struct page *page,/* Page found as candidate for recycling */returnpage;}-/* Fallback/non-XDP mode: API user have elevated refcnt.-*-*Manydriverssplitupthepageintofragments,andsome-*wanttokeepdoingthistosavememoryanddorefcntbased-*recycling.Supportthisusecasetoo,toeasedrivers-*switchingbetweenXDP/non-XDP.-*-*In-casepage_poolmaintainstheDMAmapping,APIusermust-*callpage_pool_put_pageonce.Inthiselevatedrefcnt-*case,theDMAisunmapped/released,asdriverislikely-*doingrefcntbasedrecycletricks,meaninganotherprocess-*willbeinvokingput_page.-*/-/* Do not replace this with page_pool_return_page() */-page_pool_release_page(pool,page);-put_page(page);++unrecyclable:+page_pool_return_page(pool,page);returnNULL;}
@@ -518,7 +571,8 @@ static void page_pool_empty_ring(struct page_pool *pool)/* Empty recycle ring */while((page=ptr_ring_consume_bh(&pool->ring))){/* Verify the refcnt invariant of cached pages */-if(!(page_ref_count(page)==1))+if(!(page_ref_count(page)==+(page_pool_get_pagecnt_bias(page)+1)))pr_crit("%s() page_pool refcnt %d violation\n",__func__,page_ref_count(page));
From: Yunsheng Lin <hidden> Date: 2021-07-10 07:44:16
Currently, page->pp is cleared and set everytime the page
is recycled, which is unnecessary.
So only set the page->pp when the page is added to the page
pool and only clear it when the page is released from the
page pool.
This is also a preparation to support elevated refcnt in page
pool.
Signed-off-by: Yunsheng Lin <redacted>
---
drivers/net/ethernet/marvell/mvneta.c | 6 +-----
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 2 +-
drivers/net/ethernet/ti/cpsw.c | 2 +-
drivers/net/ethernet/ti/cpsw_new.c | 2 +-
include/linux/skbuff.h | 4 +---
include/net/page_pool.h | 7 -------
net/core/page_pool.c | 21 +++++++++++++++++----
7 files changed, 22 insertions(+), 22 deletions(-)
@@ -431,7 +431,7 @@ static void cpsw_rx_handler(void *token, int len, int status)skb->protocol=eth_type_trans(skb,ndev);/* mark skb for recycling */-skb_mark_for_recycle(skb,page,pool);+skb_mark_for_recycle(skb);netif_receive_skb(skb);ndev->stats.rx_bytes+=len;
@@ -374,7 +374,7 @@ static void cpsw_rx_handler(void *token, int len, int status)skb->protocol=eth_type_trans(skb,ndev);/* mark skb for recycling */-skb_mark_for_recycle(skb,page,pool);+skb_mark_for_recycle(skb);netif_receive_skb(skb);ndev->stats.rx_bytes+=len;
@@ -253,11 +253,4 @@ static inline void page_pool_ring_unlock(struct page_pool *pool)spin_unlock_bh(&pool->ring.producer_lock);}-/* Store mem_info on struct page and use it while recycling skb frags */-staticinline-voidpage_pool_store_mem_info(structpage*page,structpage_pool*pp)-{-page->pp=pp;-}-#endif /* _NET_PAGE_POOL_H */
@@ -222,7 +235,7 @@ static struct page *__page_pool_alloc_page_order(struct page_pool *pool,returnNULL;}-page->pp_magic|=PP_SIGNATURE;+page_pool_set_pp_info(pool,page);/* Track how many pages are held 'in-flight' */pool->pages_state_hold_cnt++;
@@ -266,7 +279,8 @@ static struct page *__page_pool_alloc_pages_slow(struct page_pool *pool,put_page(page);continue;}-page->pp_magic|=PP_SIGNATURE;++page_pool_set_pp_info(pool,page);pool->alloc.cache[pool->alloc.count++]=page;/* Track how many pages are held 'in-flight' */pool->pages_state_hold_cnt++;
@@ -345,7 +359,7 @@ void page_pool_release_page(struct page_pool *pool, struct page *page)DMA_ATTR_SKIP_CPU_SYNC);page_pool_set_dma_addr(page,0);skip_dma_unmap:-page->pp_magic=0;+page_pool_clear_pp_info(page);/* This may be the last page returned, releasing the pool, so*itisnotsafetoreferencepoolafterwards.
From: Yunsheng Lin <hidden> Date: 2021-07-10 07:44:17
This patch adds skb's frag page recycling support based on
the elevated refcnt support in page pool.
The performance improves above 10~20% with IOMMU disabled.
The performance improves about two times when IOMMU is enabled
and iperf server shares the same cpu with irq/NAPI.
Signed-off-by: Yunsheng Lin <redacted>
---
drivers/net/ethernet/hisilicon/hns3/hns3_enet.c | 79 +++++++++++++++++++++++--
drivers/net/ethernet/hisilicon/hns3/hns3_enet.h | 3 +
2 files changed, 77 insertions(+), 5 deletions(-)
@@ -3539,6 +3559,12 @@ static void hns3_nic_reuse_page(struct sk_buff *skb, int i,u32frag_size=size-pull_len;boolreused;+if(ring->page_pool){+skb_add_rx_frag(skb,i,desc_cb->priv,frag_offset,+frag_size,truesize);+return;+}+/* Avoid re-using remote or pfmem page */if(unlikely(!dev_page_is_reusable(desc_cb->priv)))gotoout;
@@ -3856,6 +3882,9 @@ static int hns3_alloc_skb(struct hns3_enet_ring *ring, unsigned int length,/* We can reuse buffer as-is, just make sure it is reusable */if(dev_page_is_reusable(desc_cb->priv))desc_cb->reuse_flag=1;+elseif(desc_cb->type&DESC_TYPE_FRAG)+page_pool_put_full_page(ring->page_pool,desc_cb->priv,+false);else/* This page cannot be reused so discard it */__page_frag_cache_drain(desc_cb->priv,desc_cb->pagecnt_bias);
@@ -3863,6 +3892,10 @@ static int hns3_alloc_skb(struct hns3_enet_ring *ring, unsigned int length,hns3_rx_ring_move_fw(ring);return0;}++if(ring->page_pool)+skb_mark_for_recycle(skb);+u64_stats_update_begin(&ring->syncp);ring->stats.seg_pkt_cnt++;u64_stats_update_end(&ring->syncp);
@@ -451,6 +453,7 @@ struct hns3_enet_ring {structhnae3_queue*tqp;intqueue_index;structdevice*dev;/* will be used for DMA mapping of descriptors */+structpage_pool*page_pool;/* statistic */structring_statsstats;
From: Yunsheng Lin <hidden> Date: 2021-07-10 07:44:21
As suggested by Alexander, "A DMA mapping should be page
aligned anyway so the lower 12 bits would be reserved 0",
so it might make more sense to repurpose the lower 12 bits
of the dma address to store the pagecnt_bias for elevated
refcnt case in page pool.
As newly added page_pool_get_pagecnt_bias() may be called
outside of the softirq context, so annotate the access to
page->dma_addr[0] with READ_ONCE() and WRITE_ONCE().
Other three interfaces using page->dma_addr[0] is only called
in the softirq context during normal rx processing, hopefully
the barrier in the rx processing will ensure the correct order
between getting and setting pagecnt_bias.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
From: Yunsheng Lin <hidden> Date: 2021-07-10 07:44:26
Currently each desc use a whole page to do ping-pong page
reusing in most driver. As the page pool has support page
recycling based on elevated refcnt, it makes sense to add
a page frag API in page pool to split a page to different
frag to serve multi descriptions.
This means a huge memory saving for kernel with page size of
64K, as a page can be used by 32 descriptions with 2k buffer
size, comparing to each desc using one page currently.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 14 ++++++++++++++
net/core/page_pool.c | 49 +++++++++++++++++++++++++++++++++++++++++++++++++
2 files changed, 63 insertions(+)
@@ -140,6 +143,17 @@ static inline struct page *page_pool_dev_alloc_pages(struct page_pool *pool)returnpage_pool_alloc_pages(pool,gfp);}+structpage*page_pool_alloc_frag(structpage_pool*pool,+unsignedint*offset,gfp_tgfp);++staticinlinestructpage*page_pool_dev_alloc_frag(structpage_pool*pool,+unsignedint*offset)+{+gfp_tgfp=(GFP_ATOMIC|__GFP_NOWARN);++returnpage_pool_alloc_frag(pool,offset,gfp);+}+/* get the stored dma direction. A driver might decide to treat this locally and*avoidtheextracachelinefrompage_pooltodeterminethedirection*/
On Sat, Jul 10, 2021 at 9:44 AM Yunsheng Lin [off-list ref] wrote:
This patchset adds elevated refcnt support for page pool
and enable skb's page frag recycling based on page pool
in hns3 drvier.
RFC v2:
1. Split patch 1 to more reviewable one.
2. Repurpose the lower 12 bits of the dma address to store the
pagecnt_bias as suggested by Alexander.
3. support recycling to pool->alloc for elevated refcnt case
too.
Yunsheng Lin (5):
page_pool: keep pp info as long as page pool owns the page
page_pool: add interface for getting and setting pagecnt_bias
page_pool: add page recycling support based on elevated refcnt
page_pool: support page frag API for page pool
net: hns3: support skb's frag page recycling based on page pool
drivers/net/ethernet/hisilicon/hns3/hns3_enet.c | 79 ++++++++++-
drivers/net/ethernet/hisilicon/hns3/hns3_enet.h | 3 +
drivers/net/ethernet/marvell/mvneta.c | 6 +-
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 2 +-
drivers/net/ethernet/ti/cpsw.c | 2 +-
drivers/net/ethernet/ti/cpsw_new.c | 2 +-
include/linux/skbuff.h | 4 +-
include/net/page_pool.h | 50 +++++--
net/core/page_pool.c | 172 ++++++++++++++++++++----
9 files changed, 266 insertions(+), 54 deletions(-)
--
2.7.4
For mvpp2:
Tested-by: Matteo Croce <redacted>
--
per aspera ad upstream
From: Alexander Duyck <hidden> Date: 2021-07-10 16:55:27
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
quoted hunk
As suggested by Alexander, "A DMA mapping should be page
aligned anyway so the lower 12 bits would be reserved 0",
so it might make more sense to repurpose the lower 12 bits
of the dma address to store the pagecnt_bias for elevated
refcnt case in page pool.
As newly added page_pool_get_pagecnt_bias() may be called
outside of the softirq context, so annotate the access to
page->dma_addr[0] with READ_ONCE() and WRITE_ONCE().
Other three interfaces using page->dma_addr[0] is only called
in the softirq context during normal rx processing, hopefully
the barrier in the rx processing will ensure the correct order
between getting and setting pagecnt_bias.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
So rather than doing all this testing and clearing it would probably
be better to add a return value to the function and do something like:
if (WARN_ON(dma_addr_0 & ~PAGE_MASK))
return -1;
That way you could have page_pool_dma_map unmap, free the page, and
return false indicating that the DMA mapping failed with a visible
error in the event that our expectionat that the dma_addr is page
aligned is ever violated.
From: Alexander Duyck <hidden> Date: 2021-07-10 17:25:10
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
quoted hunk
Currently page pool only support page recycling only when
refcnt of page is one, which means it can not support the
split page recycling implemented in the most driver.
The expectation of page recycling based on elevated refcnt
is that we only do the recycling or freeing of page when the
last user has dropped the refcnt that has given to it.
The above expectation is based on that the last user will
always call page_pool_put_full_page() in order to do the
recycling or do the resource cleanup(dma unmaping..etc) and
freeing.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 5 ++-
net/core/page_pool.c | 106 ++++++++++++++++++++++++++++++++++++------------
2 files changed, 84 insertions(+), 27 deletions(-)
@@ -298,6 +310,23 @@ static struct page *__page_pool_alloc_pages_slow(struct page_pool *pool, return page; }+static void page_pool_sub_bias(struct page_pool *pool,+ struct page *page, int nr)+{+ int bias;++ if (!(pool->p.flags & PP_FLAG_PAGECNT_BIAS))+ return;++ bias = page_pool_get_pagecnt_bias(page);+ if (unlikely(bias <= nr)) {+ page_ref_add(page, BIAS_MAX - bias);+ bias = BIAS_MAX;+ }++ page_pool_set_pagecnt_bias(page, bias - nr);+}+ /* For using page_pool replace: alloc_pages() API calls, but provide * synchronization guarantee for allocation side. */
@@ -307,11 +336,16 @@ struct page *page_pool_alloc_pages(struct page_pool *pool, gfp_t gfp) /* Fast-path: Get a page from cache */ page = __page_pool_get_cached(pool);- if (page)+ if (page) {+ page_pool_sub_bias(pool, page, 1); return page;+ } /* Slow-path: cache empty, do real allocation */ page = __page_pool_alloc_pages_slow(pool, gfp);+ if (likely(page))+ page_pool_sub_bias(pool, page, 1);+ return page;
I would probably just reorder this a bit. Do something like:
page = __page_pool_get_cached()
if (!page) {
page = __page_pool_alloc_pages_slow()
if (!page)
return NULL;
}
page_pool_sub_bias()
return page;
quoted hunk
}
EXPORT_SYMBOL(page_pool_alloc_pages);
@@ -340,10 +374,11 @@ static s32 page_pool_inflight(struct page_pool *pool) * a regular page (that will eventually be returned to the normal * page-allocator via put_page). */-void page_pool_release_page(struct page_pool *pool, struct page *page)+static int __page_pool_release_page(struct page_pool *pool,+ struct page *page) {+ int bias, count; dma_addr_t dma;- int count; if (!(pool->p.flags & PP_FLAG_DMA_MAP)) /* Always account for inflight pages, even if we didn't
@@ -359,22 +394,30 @@ void page_pool_release_page(struct page_pool *pool, struct page *page) DMA_ATTR_SKIP_CPU_SYNC); page_pool_set_dma_addr(page, 0); skip_dma_unmap:- page_pool_clear_pp_info(page);+ bias = page_pool_clear_pp_info(page); /* This may be the last page returned, releasing the pool, so * it is not safe to reference pool afterwards. */ count = atomic_inc_return(&pool->pages_state_release_cnt); trace_page_pool_state_release(pool, page, count);++ return bias;+}++void page_pool_release_page(struct page_pool *pool, struct page *page)+{+ int bias = __page_pool_release_page(pool, page);++ WARN_ONCE(bias, "%s is called from driver with elevated refcnt\n",+ __func__); }
I'm not sure it makes sense to have a warning about this. There are
multiple scenarios where you will still have to release the page early
and deduct the pagecnt_bias.
quoted hunk
EXPORT_SYMBOL(page_pool_release_page);
/* Return a page to the page allocator, cleaning up our state */
static void page_pool_return_page(struct page_pool *pool, struct page *page)
{
- page_pool_release_page(pool, page);
-
- put_page(page);
+ __page_frag_cache_drain(page, __page_pool_release_page(pool, page) + 1);
/* An optimization would be to call __free_pages(page, pool->p.order)
* knowing page is not part of page-cache (thus avoiding a
* __page_cache_release() call).
@@ -409,6 +452,15 @@ static bool page_pool_recycle_in_cache(struct page *page, return true; }+static bool page_pool_bias_page_recyclable(struct page *page, int bias)+{+ int ref = page_ref_dec_return(page);++ WARN_ON(ref <= bias);++ return ref == bias + 1;+}+ /* If the page refcnt == 1, this will try to recycle the page. * if PP_FLAG_DMA_SYNC_DEV is set, we'll try to sync the DMA area for * the configured size min(dma_sync_size, pool->max_len).
@@ -419,6 +471,20 @@ static __always_inline struct page * __page_pool_put_page(struct page_pool *pool, struct page *page, unsigned int dma_sync_size, bool allow_direct) {+ int bias = page_pool_get_pagecnt_bias(page);++ /* Handle the elevated refcnt case first */+ if (bias) {+ /* It is not the last user yet */+ if (!page_pool_bias_page_recyclable(page, bias))+ return NULL;++ if (likely(!page_is_pfmemalloc(page)))+ goto recyclable;+ else+ goto unrecyclable;+ }+ /* This allocator is optimized for the XDP mode that uses * one-frame-per-page, but have fallbacks that act like the * regular page allocator APIs.
@@ -442,22 +508,9 @@ __page_pool_put_page(struct page_pool *pool, struct page *page, /* Page found as candidate for recycling */ return page; }- /* Fallback/non-XDP mode: API user have elevated refcnt.- *- * Many drivers split up the page into fragments, and some- * want to keep doing this to save memory and do refcnt based- * recycling. Support this use case too, to ease drivers- * switching between XDP/non-XDP.- *- * In-case page_pool maintains the DMA mapping, API user must- * call page_pool_put_page once. In this elevated refcnt- * case, the DMA is unmapped/released, as driver is likely- * doing refcnt based recycle tricks, meaning another process- * will be invoking put_page.- */- /* Do not replace this with page_pool_return_page() */- page_pool_release_page(pool, page);- put_page(page);++unrecyclable:+ page_pool_return_page(pool, page); return NULL; }
@@ -518,7 +571,8 @@ static void page_pool_empty_ring(struct page_pool *pool) /* Empty recycle ring */ while ((page = ptr_ring_consume_bh(&pool->ring))) { /* Verify the refcnt invariant of cached pages */- if (!(page_ref_count(page) == 1))+ if (!(page_ref_count(page) ==+ (page_pool_get_pagecnt_bias(page) + 1))) pr_crit("%s() page_pool refcnt %d violation\n", __func__, page_ref_count(page));
So I am not sure this is entirely useful since there are cases where
the mm subsystem will take references on pages like I mentioned
before.
Also we should probably be caching the output from page_ref_count
instead of calling it twice as it would guarantee that we will see the
actual value the test saw versus performing the read twice which might
indicate two different values if somebody else is messing with the
page.
From: Alexander Duyck <hidden> Date: 2021-07-10 17:31:56
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
<snip>
quoted hunk
@@ -419,6 +471,20 @@ static __always_inline struct page * __page_pool_put_page(struct page_pool *pool, struct page *page, unsigned int dma_sync_size, bool allow_direct) {+ int bias = page_pool_get_pagecnt_bias(page);++ /* Handle the elevated refcnt case first */+ if (bias) {+ /* It is not the last user yet */+ if (!page_pool_bias_page_recyclable(page, bias))+ return NULL;++ if (likely(!page_is_pfmemalloc(page)))+ goto recyclable;+ else+ goto unrecyclable;+ }+
So this part is still broken. Anything that takes a reference to the
page and holds it while this is called will cause it to break. For
example with the recent fixes we put in place all it would take is a
skb_clone followed by pskb_expand_head and this starts leaking memory.
One of the key bits in order for pagecnt_bias to work is that you have
to deduct the bias once there are no more parties using it. Otherwise
you leave the reference count artificially inflated and the page will
never be freed. It works fine for the single producer single consumer
case but once you introduce multiple consumers this is going to fall
apart.
From: Alexander Duyck <hidden> Date: 2021-07-10 17:43:31
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
quoted hunk
Currently each desc use a whole page to do ping-pong page
reusing in most driver. As the page pool has support page
recycling based on elevated refcnt, it makes sense to add
a page frag API in page pool to split a page to different
frag to serve multi descriptions.
This means a huge memory saving for kernel with page size of
64K, as a page can be used by 32 descriptions with 2k buffer
size, comparing to each desc using one page currently.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 14 ++++++++++++++
net/core/page_pool.c | 49 +++++++++++++++++++++++++++++++++++++++++++++++++
2 files changed, 63 insertions(+)
@@ -140,6 +143,17 @@ static inline struct page *page_pool_dev_alloc_pages(struct page_pool *pool)returnpage_pool_alloc_pages(pool,gfp);}+structpage*page_pool_alloc_frag(structpage_pool*pool,+unsignedint*offset,gfp_tgfp);++staticinlinestructpage*page_pool_dev_alloc_frag(structpage_pool*pool,+unsignedint*offset)+{+gfp_tgfp=(GFP_ATOMIC|__GFP_NOWARN);++returnpage_pool_alloc_frag(pool,offset,gfp);+}+/* get the stored dma direction. A driver might decide to treat this locally and*avoidtheextracachelinefrompage_pooltodeterminethedirection*/
I'm still not a fan of the fixed implementation. For the cost of the
division as I said before you could make this flexible like
page_frag_alloc_align and just decrement the bias by one per
allocation instead of trying to batch it.
I'm sure there would likely be implementations that might need to
operate at two different sizes, for example a header and payload size.
Having to call this to free the page seems confusing. Rather than
reserving multiple and having to free the page multiple times I really
think you would be better off just holding one bias reservation on the
page at a time.
From: Yunsheng Lin <hidden> Date: 2021-07-12 02:06:32
On 2021/7/11 1:31, Alexander Duyck wrote:
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
<snip>
quoted
@@ -419,6 +471,20 @@ static __always_inline struct page * __page_pool_put_page(struct page_pool *pool, struct page *page, unsigned int dma_sync_size, bool allow_direct) {+ int bias = page_pool_get_pagecnt_bias(page);++ /* Handle the elevated refcnt case first */+ if (bias) {+ /* It is not the last user yet */+ if (!page_pool_bias_page_recyclable(page, bias))+ return NULL;++ if (likely(!page_is_pfmemalloc(page)))+ goto recyclable;+ else+ goto unrecyclable;+ }+
So this part is still broken. Anything that takes a reference to the
page and holds it while this is called will cause it to break. For
example with the recent fixes we put in place all it would take is a
skb_clone followed by pskb_expand_head and this starts leaking memory.
Ok, it seems the fix is confilcting with the expectation this patch is
based, which is "the last user will always call page_pool_put_full_page()
in order to do the recycling or do the resource cleanup(dma unmaping..etc)
and freeing.".
As the user of the new skb after skb_clone() and pskb_expand_head() is
not aware of that their frag page may still be in the page pool after
the fix?
One of the key bits in order for pagecnt_bias to work is that you have
to deduct the bias once there are no more parties using it. Otherwise
you leave the reference count artificially inflated and the page will
never be freed. It works fine for the single producer single consumer
case but once you introduce multiple consumers this is going to fall
apart.
It seems we have diffferent understanding about consumer, I treat the
above user of new skb after skb_clone() and pskb_expand_head() as the
consumer of the page pool too, so that new skb should keep the recycle
bit in order for that to happen.
If the semantic is "the new user of a page should not be handled by page
pool if page pool is not aware of the new user(the new user is added by
calling page allocator API instead of calling the page pool API, like the
skb_clone() and pskb_expand_head() above) ", I suppose I am ok with that
semantic too as long as the above semantic is aligned with the people
involved.
Also, it seems _refcount and dma_addr in "struct page" is in the same cache
line, which means there is already cache line bouncing already between _refcount
and dma_addr updating, so it may makes senses to only use bias to indicate
number of the page pool user for a page, instead of using "bias - page_ref_count",
as the page_ref_count is not reliable if somebody is using the page allocator API
directly.
And the trick part seems to be how to make the bias atomic for allocating and
freeing.
Any better idea?
From: Alexander Duyck <hidden> Date: 2021-07-12 03:31:04
On Sun, Jul 11, 2021 at 7:06 PM Yunsheng Lin [off-list ref] wrote:
On 2021/7/11 1:31, Alexander Duyck wrote:
quoted
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
<snip>
quoted
@@ -419,6 +471,20 @@ static __always_inline struct page * __page_pool_put_page(struct page_pool *pool, struct page *page, unsigned int dma_sync_size, bool allow_direct) {+ int bias = page_pool_get_pagecnt_bias(page);++ /* Handle the elevated refcnt case first */+ if (bias) {+ /* It is not the last user yet */+ if (!page_pool_bias_page_recyclable(page, bias))+ return NULL;++ if (likely(!page_is_pfmemalloc(page)))+ goto recyclable;+ else+ goto unrecyclable;+ }+
So this part is still broken. Anything that takes a reference to the
page and holds it while this is called will cause it to break. For
example with the recent fixes we put in place all it would take is a
skb_clone followed by pskb_expand_head and this starts leaking memory.
Ok, it seems the fix is confilcting with the expectation this patch is
based, which is "the last user will always call page_pool_put_full_page()
in order to do the recycling or do the resource cleanup(dma unmaping..etc)
and freeing.".
As the user of the new skb after skb_clone() and pskb_expand_head() is
not aware of that their frag page may still be in the page pool after
the fix?
No it isn't the fix that is conflicting. It is the fundamental
assumption that is flawed.
We cannot guarantee that some other entity will not take a reference
on the page. In order for this to work you have to guarantee that no
other entity will use get_page/put_page on this page while you are
using it.
This is the reason why all the other implementations that do
pagecnt_bias always remove the leftover count once they are done with
the page. What was throwing me off before is that I was assuming you
were doing that somewhere and you weren't. Instead this patch
effectively turned the page count into a ticket lock of sorts and the
problem is this approach only works as long as no other entities can
take a reference on the page.
quoted
One of the key bits in order for pagecnt_bias to work is that you have
to deduct the bias once there are no more parties using it. Otherwise
you leave the reference count artificially inflated and the page will
never be freed. It works fine for the single producer single consumer
case but once you introduce multiple consumers this is going to fall
apart.
It seems we have diffferent understanding about consumer, I treat the
above user of new skb after skb_clone() and pskb_expand_head() as the
consumer of the page pool too, so that new skb should keep the recycle
bit in order for that to happen.
The problem is updating pskb_expand_head to call
page_pool_return_skb_page still wouldn't resolve the issue. The
fundamental assumption is flawed that the thread holding the skb will
always be the last one to free the page.
If the semantic is "the new user of a page should not be handled by page
pool if page pool is not aware of the new user(the new user is added by
calling page allocator API instead of calling the page pool API, like the
skb_clone() and pskb_expand_head() above) ", I suppose I am ok with that
semantic too as long as the above semantic is aligned with the people
involved.
The bigger issue is that this use of the page_ref_count violates how
the page struct is meant to be used. The count is meant to be atomic
and capable of getting to 0. The fact that we are now leaving the bias
floating is going to introduce a number of issues.
Also, it seems _refcount and dma_addr in "struct page" is in the same cache
line, which means there is already cache line bouncing already between _refcount
and dma_addr updating, so it may makes senses to only use bias to indicate
number of the page pool user for a page, instead of using "bias - page_ref_count",
as the page_ref_count is not reliable if somebody is using the page allocator API
directly.
And the trick part seems to be how to make the bias atomic for allocating and
freeing.
What we end up essentially needing to do is duplicate that
page_ref_count as a page_frag_count and just leave the original
page_ref_count at 1. If we do that and then just decrement that new
count instead it would allow us to defer the unmapping/recycling and
we just fall back into the original path when we finally hit 0.
The only limitation then is the fact that we would be looking at
potentially 2 atomic operations in the worst case if we release the
page as you would need one to get the frag_count to 0, and then
another to decrement the ref_count. For the standard case that would
work about the same as what you already had though, as you were
already having to perform an atomic_dec_and_test on the page_ref_count
anyway.
From: Yunsheng Lin <hidden> Date: 2021-07-12 08:33:56
On 2021/7/11 0:55, Alexander Duyck wrote:
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
quoted
As suggested by Alexander, "A DMA mapping should be page
aligned anyway so the lower 12 bits would be reserved 0",
so it might make more sense to repurpose the lower 12 bits
of the dma address to store the pagecnt_bias for elevated
refcnt case in page pool.
As newly added page_pool_get_pagecnt_bias() may be called
outside of the softirq context, so annotate the access to
page->dma_addr[0] with READ_ONCE() and WRITE_ONCE().
Other three interfaces using page->dma_addr[0] is only called
in the softirq context during normal rx processing, hopefully
the barrier in the rx processing will ensure the correct order
between getting and setting pagecnt_bias.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
So rather than doing all this testing and clearing it would probably
be better to add a return value to the function and do something like:
if (WARN_ON(dma_addr_0 & ~PAGE_MASK))
return -1;
That way you could have page_pool_dma_map unmap, free the page, and
return false indicating that the DMA mapping failed with a visible
error in the event that our expectionat that the dma_addr is page
aligned is ever violated.
I suppose the above is based on that page_pool_set_dma_addr() is called
only once before page_pool_set_pagecnt_bias(), right? so we could:
static inline bool page_pool_set_dma_addr(struct page *page, dma_addr_t addr)
{
if (WARN_ON(dma_addr_0 & ~PAGE_MASK))
return false;
page->dma_addr[0] = addr;
if (sizeof(dma_addr_t) > sizeof(unsigned long))
page->dma_addr[1] = upper_32_bits(addr);
return true;
}
From: Yunsheng Lin <hidden> Date: 2021-07-12 08:51:06
On 2021/7/11 1:24, Alexander Duyck wrote:
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
quoted
Currently page pool only support page recycling only when
refcnt of page is one, which means it can not support the
split page recycling implemented in the most driver.
The expectation of page recycling based on elevated refcnt
is that we only do the recycling or freeing of page when the
last user has dropped the refcnt that has given to it.
The above expectation is based on that the last user will
always call page_pool_put_full_page() in order to do the
recycling or do the resource cleanup(dma unmaping..etc) and
freeing.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 5 ++-
net/core/page_pool.c | 106 ++++++++++++++++++++++++++++++++++++------------
2 files changed, 84 insertions(+), 27 deletions(-)
I think this piece makes more sense as a part of
__page_pool_alloc_page_order. Basically have it run parallel to the
DMA mapping setup.
When implementing the semantic of "page recycling only wait for the
page pool user instead of all user of a page", I have merged this patch
with the next patch, because it seems we do not need the elevated refcnt
case if the frag page is not supported.
So all of comment in this patch does not exist in new version, at least
that is what I checked, thanks for the reviewing.
@@ -298,6 +310,23 @@ static struct page *__page_pool_alloc_pages_slow(struct page_pool *pool, return page; }+static void page_pool_sub_bias(struct page_pool *pool,+ struct page *page, int nr)+{+ int bias;++ if (!(pool->p.flags & PP_FLAG_PAGECNT_BIAS))+ return;++ bias = page_pool_get_pagecnt_bias(page);+ if (unlikely(bias <= nr)) {+ page_ref_add(page, BIAS_MAX - bias);+ bias = BIAS_MAX;+ }++ page_pool_set_pagecnt_bias(page, bias - nr);+}+ /* For using page_pool replace: alloc_pages() API calls, but provide * synchronization guarantee for allocation side. */
@@ -307,11 +336,16 @@ struct page *page_pool_alloc_pages(struct page_pool *pool, gfp_t gfp) /* Fast-path: Get a page from cache */ page = __page_pool_get_cached(pool);- if (page)+ if (page) {+ page_pool_sub_bias(pool, page, 1); return page;+ } /* Slow-path: cache empty, do real allocation */ page = __page_pool_alloc_pages_slow(pool, gfp);+ if (likely(page))+ page_pool_sub_bias(pool, page, 1);+ return page;
I would probably just reorder this a bit. Do something like:
page = __page_pool_get_cached()
if (!page) {
page = __page_pool_alloc_pages_slow()
if (!page)
return NULL;
}
page_pool_sub_bias()
return page;
quoted
}
EXPORT_SYMBOL(page_pool_alloc_pages);
@@ -340,10 +374,11 @@ static s32 page_pool_inflight(struct page_pool *pool) * a regular page (that will eventually be returned to the normal * page-allocator via put_page). */-void page_pool_release_page(struct page_pool *pool, struct page *page)+static int __page_pool_release_page(struct page_pool *pool,+ struct page *page) {+ int bias, count; dma_addr_t dma;- int count; if (!(pool->p.flags & PP_FLAG_DMA_MAP)) /* Always account for inflight pages, even if we didn't
@@ -359,22 +394,30 @@ void page_pool_release_page(struct page_pool *pool, struct page *page) DMA_ATTR_SKIP_CPU_SYNC); page_pool_set_dma_addr(page, 0); skip_dma_unmap:- page_pool_clear_pp_info(page);+ bias = page_pool_clear_pp_info(page); /* This may be the last page returned, releasing the pool, so * it is not safe to reference pool afterwards. */ count = atomic_inc_return(&pool->pages_state_release_cnt); trace_page_pool_state_release(pool, page, count);++ return bias;+}++void page_pool_release_page(struct page_pool *pool, struct page *page)+{+ int bias = __page_pool_release_page(pool, page);++ WARN_ONCE(bias, "%s is called from driver with elevated refcnt\n",+ __func__); }
I'm not sure it makes sense to have a warning about this. There are
multiple scenarios where you will still have to release the page early
and deduct the pagecnt_bias.
quoted
EXPORT_SYMBOL(page_pool_release_page);
/* Return a page to the page allocator, cleaning up our state */
static void page_pool_return_page(struct page_pool *pool, struct page *page)
{
- page_pool_release_page(pool, page);
-
- put_page(page);
+ __page_frag_cache_drain(page, __page_pool_release_page(pool, page) + 1);
/* An optimization would be to call __free_pages(page, pool->p.order)
* knowing page is not part of page-cache (thus avoiding a
* __page_cache_release() call).
@@ -409,6 +452,15 @@ static bool page_pool_recycle_in_cache(struct page *page, return true; }+static bool page_pool_bias_page_recyclable(struct page *page, int bias)+{+ int ref = page_ref_dec_return(page);++ WARN_ON(ref <= bias);++ return ref == bias + 1;+}+ /* If the page refcnt == 1, this will try to recycle the page. * if PP_FLAG_DMA_SYNC_DEV is set, we'll try to sync the DMA area for * the configured size min(dma_sync_size, pool->max_len).
@@ -419,6 +471,20 @@ static __always_inline struct page * __page_pool_put_page(struct page_pool *pool, struct page *page, unsigned int dma_sync_size, bool allow_direct) {+ int bias = page_pool_get_pagecnt_bias(page);++ /* Handle the elevated refcnt case first */+ if (bias) {+ /* It is not the last user yet */+ if (!page_pool_bias_page_recyclable(page, bias))+ return NULL;++ if (likely(!page_is_pfmemalloc(page)))+ goto recyclable;+ else+ goto unrecyclable;+ }+ /* This allocator is optimized for the XDP mode that uses * one-frame-per-page, but have fallbacks that act like the * regular page allocator APIs.
@@ -442,22 +508,9 @@ __page_pool_put_page(struct page_pool *pool, struct page *page, /* Page found as candidate for recycling */ return page; }- /* Fallback/non-XDP mode: API user have elevated refcnt.- *- * Many drivers split up the page into fragments, and some- * want to keep doing this to save memory and do refcnt based- * recycling. Support this use case too, to ease drivers- * switching between XDP/non-XDP.- *- * In-case page_pool maintains the DMA mapping, API user must- * call page_pool_put_page once. In this elevated refcnt- * case, the DMA is unmapped/released, as driver is likely- * doing refcnt based recycle tricks, meaning another process- * will be invoking put_page.- */- /* Do not replace this with page_pool_return_page() */- page_pool_release_page(pool, page);- put_page(page);++unrecyclable:+ page_pool_return_page(pool, page); return NULL; }
@@ -518,7 +571,8 @@ static void page_pool_empty_ring(struct page_pool *pool) /* Empty recycle ring */ while ((page = ptr_ring_consume_bh(&pool->ring))) { /* Verify the refcnt invariant of cached pages */- if (!(page_ref_count(page) == 1))+ if (!(page_ref_count(page) ==+ (page_pool_get_pagecnt_bias(page) + 1))) pr_crit("%s() page_pool refcnt %d violation\n", __func__, page_ref_count(page));
So I am not sure this is entirely useful since there are cases where
the mm subsystem will take references on pages like I mentioned
before.
Also we should probably be caching the output from page_ref_count
instead of calling it twice as it would guarantee that we will see the
actual value the test saw versus performing the read twice which might
indicate two different values if somebody else is messing with the
page.
.
From: Yunsheng Lin <hidden> Date: 2021-07-12 09:03:27
On 2021/7/11 1:43, Alexander Duyck wrote:
On Sat, Jul 10, 2021 at 12:44 AM Yunsheng Lin [off-list ref] wrote:
quoted
Currently each desc use a whole page to do ping-pong page
reusing in most driver. As the page pool has support page
recycling based on elevated refcnt, it makes sense to add
a page frag API in page pool to split a page to different
frag to serve multi descriptions.
This means a huge memory saving for kernel with page size of
64K, as a page can be used by 32 descriptions with 2k buffer
size, comparing to each desc using one page currently.
Signed-off-by: Yunsheng Lin <redacted>
---
include/net/page_pool.h | 14 ++++++++++++++
net/core/page_pool.c | 49 +++++++++++++++++++++++++++++++++++++++++++++++++
2 files changed, 63 insertions(+)
@@ -140,6 +143,17 @@ static inline struct page *page_pool_dev_alloc_pages(struct page_pool *pool)returnpage_pool_alloc_pages(pool,gfp);}+structpage*page_pool_alloc_frag(structpage_pool*pool,+unsignedint*offset,gfp_tgfp);++staticinlinestructpage*page_pool_dev_alloc_frag(structpage_pool*pool,+unsignedint*offset)+{+gfp_tgfp=(GFP_ATOMIC|__GFP_NOWARN);++returnpage_pool_alloc_frag(pool,offset,gfp);+}+/* get the stored dma direction. A driver might decide to treat this locally and*avoidtheextracachelinefrompage_pooltodeterminethedirection*/
I'm still not a fan of the fixed implementation. For the cost of the
division as I said before you could make this flexible like
page_frag_alloc_align and just decrement the bias by one per
allocation instead of trying to batch it.
I'm sure there would likely be implementations that might need to
operate at two different sizes, for example a header and payload size.
Will try to implement the frag allocation of different sizes
in new version.
Having to call this to free the page seems confusing. Rather than
reserving multiple and having to free the page multiple times I really
think you would be better off just holding one bias reservation on the
page at a time.
will remove the above freeing the page multiple times.