N_MEMORY_PRIVATE nodes must be invisible to ordinary allocation, no allocations may reach one unless explicitly called for.
Make this isolation structural in the zonelists: N_MEMORY_PRIVATE nodes are excluded from FALLBACK and NOFALLBACK entirely, making them effectively invisible to all normal callers of page_alloc. Add ZONELIST_PRIVATE, which spans (N_MEMORY | N_MEMORY_PRIVATE). When !CONFIG_NUMA, it aliases ZONELIST_FALLBACK and compiles out. Add ZONELIST_PRIVATE_NOFALLBACK as the __GFP_THISNODE target for private node allocations. Zonelist selection rides the allocator's alloc_flags. Add ALLOC_ZONELIST_PRIVATE and resolve it in select_zonelist(), which prepare_alloc_pages() applies from ac->alloc_flags; the default (ALLOC_DEFAULT) keeps node_zonelist()'s gfp-based selection. Add explicit private-node alloc() functions to prevent open-coding (both ride ALLOC_ZONELIST_PRIVATE through the alloc_flags-carrying entry points): - alloc_pages_node_private_noprof() - folio_alloc_node_private_noprof() alloc_contig_range adds an explicit node_is_private() guard because it dervices its target zones from PFNs rather than zonelists. All in-tree callers use N_MEMORY ranges, but the check prevents future callers from violating node isolation. Important note: By design this zonelist isolates N_MEMORY_PRIVATE from unintentional allocations, but does NOT isolate private-node allocations from falling back to non-private nodes. Signed-off-by: Gregory Price <[email protected]> --- include/linux/gfp.h | 11 ++++++++ include/linux/mmzone.h | 11 +++++++- mm/mm_init.c | 2 +- mm/page_alloc.c | 64 ++++++++++++++++++++++++++++++++++++++++-- mm/page_alloc.h | 26 +++++++++++++++++ 5 files changed, 109 insertions(+), 5 deletions(-) diff --git a/include/linux/gfp.h b/include/linux/gfp.h index a327e58c313f8..f3e867de744f6 100644 --- a/include/linux/gfp.h +++ b/include/linux/gfp.h @@ -204,6 +204,17 @@ static inline void arch_free_page(struct page *page, int order) { } static inline void arch_alloc_page(struct page *page, int order) { } #endif +/* Allocate from an N_MEMORY_PRIVATE node (selects the private zonelist). */ +struct page *alloc_pages_node_private_noprof(gfp_t gfp, unsigned int order, + int nid); +#define alloc_pages_node_private(...) \ + alloc_hooks(alloc_pages_node_private_noprof(__VA_ARGS__)) + +struct folio *folio_alloc_node_private_noprof(gfp_t gfp, unsigned int order, + int nid); +#define folio_alloc_node_private(...) \ + alloc_hooks(folio_alloc_node_private_noprof(__VA_ARGS__)) + unsigned long alloc_pages_bulk_noprof(gfp_t gfp, int preferred_nid, nodemask_t *nodemask, int nr_pages, struct page **page_array); diff --git a/include/linux/mmzone.h b/include/linux/mmzone.h index 9815e48c03b97..654c5111f7cec 100644 --- a/include/linux/mmzone.h +++ b/include/linux/mmzone.h @@ -1392,13 +1392,22 @@ enum { #ifdef CONFIG_NUMA /* * The NUMA zonelists are doubled because we need zonelists that - * restrict the allocations to a single node for __GFP_THISNODE. + * restrict the allocations to a single node for __GFP_THISNODE + * and N_MEMORY_PRIVATE nodes (isolated from default lists). */ ZONELIST_NOFALLBACK, /* zonelist without fallback (__GFP_THISNODE) */ + ZONELIST_PRIVATE, /* N_MEMORY_PRIVATE access, falls back to DRAM */ + ZONELIST_PRIVATE_NOFALLBACK, /* N_MEMORY_PRIVATE access, __GFP_THISNODE */ #endif MAX_ZONELISTS }; +#ifndef CONFIG_NUMA +/* Without NUMA only ZONELIST_FALLBACK exists so everything collapses there */ +#define ZONELIST_PRIVATE ZONELIST_FALLBACK +#define ZONELIST_PRIVATE_NOFALLBACK ZONELIST_FALLBACK +#endif + /* * This struct contains information about a zone in a zonelist. It is stored * here to avoid dereferences into large structures and lookups of tables diff --git a/mm/mm_init.c b/mm/mm_init.c index 711f821f7b3c7..adb50647d29ca 100644 --- a/mm/mm_init.c +++ b/mm/mm_init.c @@ -2701,7 +2701,7 @@ void __init mm_core_init(void) init_zero_page_pfn(); /* Initializations relying on SMP setup */ - BUILD_BUG_ON(MAX_ZONELISTS > 2); + BUILD_BUG_ON(MAX_ZONELISTS > 4); build_all_zonelists(NULL); page_alloc_init_cpuhp(); alloc_tag_sec_init(); diff --git a/mm/page_alloc.c b/mm/page_alloc.c index aa35bbe5d4c3e..78755a55b1540 100644 --- a/mm/page_alloc.c +++ b/mm/page_alloc.c @@ -5040,7 +5040,7 @@ static inline bool prepare_alloc_pages(gfp_t gfp_mask, unsigned int order, unsigned int *alloc_flags) { ac->highest_zoneidx = gfp_zone(gfp_mask); - ac->zonelist = node_zonelist(preferred_nid, gfp_mask); + ac->zonelist = select_zonelist(preferred_nid, gfp_mask, ac->alloc_flags); ac->nodemask = nodemask; ac->migratetype = gfp_migratetype(gfp_mask); @@ -5346,7 +5346,7 @@ struct page *__alloc_frozen_pages_noprof(gfp_t gfp, unsigned int order, unsigned int fastpath_alloc_flags = alloc_flags; /* Other flags could be supported later if needed. */ - if (WARN_ON(alloc_flags & ~(ALLOC_NOLOCK | ALLOC_NO_CODETAG))) + if (WARN_ON(alloc_flags & ~(ALLOC_NOLOCK | ALLOC_NO_CODETAG | ALLOC_ZONELIST_PRIVATE))) return NULL; if (!alloc_order_allowed(gfp, order, alloc_flags)) @@ -5457,6 +5457,22 @@ struct folio *__folio_alloc_node_noprof(gfp_t gfp, unsigned int order, int nid) } EXPORT_SYMBOL(__folio_alloc_node_noprof); +struct page *alloc_pages_node_private_noprof(gfp_t gfp, unsigned int order, + int nid) +{ + return __alloc_pages_noprof(gfp, order, nid, NULL, + ALLOC_ZONELIST_PRIVATE); +} +EXPORT_SYMBOL_GPL(alloc_pages_node_private_noprof); + +struct folio *folio_alloc_node_private_noprof(gfp_t gfp, unsigned int order, + int nid) +{ + return __folio_alloc_noprof(gfp, order, nid, NULL, + ALLOC_ZONELIST_PRIVATE); +} +EXPORT_SYMBOL_GPL(folio_alloc_node_private_noprof); + /* * Common helper functions. Never use with __GFP_HIGHMEM because the returned * address cannot represent highmem pages. Use alloc_pages and then kmap if @@ -5854,9 +5870,21 @@ static void build_zonelists_in_node_order(pg_data_t *pgdat, int *node_order, static void build_thisnode_zonelists(pg_data_t *pgdat) { struct zoneref *zonerefs; - int nr_zones; + int nr_zones = 0; + /* + * NOFALLBACK: the node's own zones. EMPTY for private nodes so a + * stray __GFP_THISNODE allocation can't violate isolation. + */ zonerefs = pgdat->node_zonelists[ZONELIST_NOFALLBACK]._zonerefs; + if (!node_is_private(pgdat->node_id)) + nr_zones = build_zonerefs_node(pgdat, zonerefs); + zonerefs += nr_zones; + zonerefs->zone = NULL; + zonerefs->zone_idx = 0; + + /* PRIVATE_NOFALLBACK: the node's own zones, private nodes included. */ + zonerefs = pgdat->node_zonelists[ZONELIST_PRIVATE_NOFALLBACK]._zonerefs; nr_zones = build_zonerefs_node(pgdat, zonerefs); zonerefs += nr_zones; zonerefs->zone = NULL; @@ -5899,11 +5927,28 @@ static void build_node_zonelist(pg_data_t *pgdat, const nodemask_t *candidates, static void build_zonelists(pg_data_t *pgdat) { static int node_order[MAX_NUMNODES]; + nodemask_t tier_nodes; int local_node = pgdat->node_id; int node, nr_nodes = 0; memset(node_order, 0, sizeof(node_order)); + /* + * Zonelists: FALLBACK, NOFALLBACK, PRIVATE + * + * FALLBACK: Allocation order for all nodes. Private nodes have lists + * but never appear as an entry in any list. Allocations + * targeting a private node w/ FALLBACK land on N_MEMORY. + * + * NOFALLBACK: A list for each node containing only itself. + * Allocations targeting a private node w/ NOFALLBACK + * will always fail (their NOFALLBACK is empty) + * + * PRIVATE: (N_MEMORY | N_MEMORY_PRIVATE) - allows access to + * private nodes, and falls back to normal memory unless + * __GFP_THISNODE otherwise constrains it. + */ + build_node_zonelist(pgdat, &node_states[N_MEMORY], ZONELIST_FALLBACK, true, node_order, &nr_nodes); build_thisnode_zonelists(pgdat); @@ -5912,6 +5957,10 @@ static void build_zonelists(pg_data_t *pgdat) for (node = 0; node < nr_nodes; node++) pr_cont("%d ", node_order[node]); pr_cont("\n"); + + nodes_or(tier_nodes, node_states[N_MEMORY], node_states[N_MEMORY_PRIVATE]); + build_node_zonelist(pgdat, &tier_nodes, ZONELIST_PRIVATE, false, + node_order, &nr_nodes); } #ifdef CONFIG_HAVE_MEMORYLESS_NODES @@ -7282,6 +7331,15 @@ int alloc_contig_frozen_range_noprof(unsigned long start, unsigned long end, if (__alloc_contig_verify_gfp_mask(gfp_mask, (gfp_t *)&cc.gfp_mask)) return -EINVAL; + /* + * Private nodes are kept unreachable via the zonelists, but + * alloc_contig works directly on a zone derived from the caller's + * pfn range, bypassing that. Reject this operation explicitly + * rather than silently carving memory out of an isolated node. + */ + if (unlikely(node_is_private(zone_to_nid(cc.zone)))) + return -EBUSY; + /* * What we do here is we mark all pageblocks in range as * MIGRATE_ISOLATE. Because pageblock and max order pages may diff --git a/mm/page_alloc.h b/mm/page_alloc.h index 23fc79ce97b60..741448d83ce77 100644 --- a/mm/page_alloc.h +++ b/mm/page_alloc.h @@ -57,6 +57,9 @@ */ #define ALLOC_NO_CODETAG 0x1000 +/* Select the N_MEMORY_PRIVATE zonelist family (see select_zonelist()). */ +#define ALLOC_ZONELIST_PRIVATE 0x2000 + /* Flags that allow allocations below the min watermark. */ #define ALLOC_RESERVES (ALLOC_NON_BLOCK|ALLOC_MIN_RESERVE|ALLOC_HIGHATOMIC|ALLOC_OOM) @@ -95,6 +98,29 @@ struct alloc_context { unsigned int alloc_flags; }; +#ifdef CONFIG_NUMA +static_assert(ZONELIST_PRIVATE + 1 == ZONELIST_PRIVATE_NOFALLBACK); +#endif + +/* + * select_zonelist - resolve the zonelist for an allocation + * + * The default matches node_zonelist(); ALLOC_ZONELIST_PRIVATE selects the + * private-node family so an allocation may reach an N_MEMORY_PRIVATE node. + */ +static inline struct zonelist * +select_zonelist(int nid, gfp_t gfp, unsigned int alloc_flags) +{ +#ifdef CONFIG_NUMA + if (alloc_flags & ALLOC_ZONELIST_PRIVATE) { + int idx = ZONELIST_PRIVATE + !!(gfp & __GFP_THISNODE); + + return &NODE_DATA(nid)->node_zonelists[idx]; + } +#endif + return node_zonelist(nid, gfp); +} + /* * This function returns the order of a free page in the buddy system. In * general, page_zone(page)->lock must be held by the caller to prevent the -- 2.53.0-Meta

