On Wed, Aug 26, 2026 at 10:04:27AM +0200, Michal Hocko wrote:
> On Tue 25-08-26 16:58:51, Eric Chanudet wrote:
> > On Tue, Aug 25, 2026 at 09:19:21PM +0200, Michal Hocko wrote:
> > > On Tue 25-08-26 14:33:48, Eric Chanudet wrote:
> > > > On Tue, Aug 25, 2026 at 04:59:52PM +0200, Michal Hocko wrote:
> > > > [...]
> > > > The administrator opts in by mounting cgroupfs with
> > > > memory_cma_accounting. At which point the cma allocator will charge CMA
> > > > allocations against memcg and manages a per area counter depending on
> > > > what area the allocation was made into.
> > > 
> > > So each CMA area will have its own counter and limits?
> > 
> > Yes, in order to enforce a limit per CMA area this series add a page
> > counter for each area. Areas are fixed and discovered early so the
> > counters are added to struct mem_cgroup and initialized when the cgroup
> > is created.
> > 
> > An admin would then use the cgroupfs entries to assign an area limit to
> > a given cgroup, something like the following, using the reserved area
> > for example:
> >   mount -o remount,memory_cma_accounting /sys/fs/cgroup
> >   echo +memory > /sys/fs/cgroup/cgroup.subtree_control
> >   mkdir /sys/fs/cgroup/mycg
> >   echo 16M > /sys/fs/cgroup/mycg/memory.cma.reserved.max
> >   echo 64M > /sys/fs/cgroup/mycg/memory.max
> 
> OK, thanks for the clarification. This confirms my initial suspicion but
> it is better to have it clearly articulated. I can see several problems
> with this approach. First and formost I do not think dealing with all
> cmas this way is manageable. This can become a mess very quickly if we
> have one limit per cma and too coarse if there is a single one. I also
> have my doubts about space allocation control through a simple limit for
> something that is effectively a reserved physical space.
> 
> I might be proven wrong but unless cma serves objects of a uniform
> size then this will simply not work in practice. Hitting ENOSPC without
> hitting limits and thus impractical for shared space management.

Isn't that an inherent limit with CMA as it is? If the area gets
fragmented, some buffers may no longer be allocated since there is no
remaining hole big enough to accommodate them? I do hear that putting
arbitrary limits would make this worse, which might breach the threshold
at which it becomes a problem.

> 
> [...]
> 
> > > > It looked consistent to use memcg since movable pages from regular
> > > > allocations may end up in available CMA regions until a CMA allocation
> > > > needs the space and has them moved. So in an extreme case, hogging the
> > > > CMA space of a large enough area could trigger system memory pressure.
> > > 
> > > I really do not understand what you mean here. 
> > 
> > Non-CMA allocations can end up in CMA physical regions when necessary
> > (ALLOC_CMA flag).
> 
> Correct. But those are a subject of migration so any such placement
> should not be blocking real CMA allocations.
> 
> > Since both CMA allocations and other system
> > allocations are represented the same way, with differences only in
> > properties, and they can live in the same regions, it sounds reasonable
> > to account for both under the same counter.
> 
> From the memcg POV we do account physically consumed memory. So yes,
> it makes no difference where the memory comes from. We only care about
> the overall capacity you can constrain or protect. Generally speaking it
> makes sense to charge heavy memory consumers directly triggerable from
> the userspace.
> 
> That is all memcg can provide you with. Specific requirements for
> specific types of memory is a different story. We currently cannot
> control per-numa node for example. There is an ongoing work to make
> memcg memory tier aware. 
> 
> > > > > > memcg looked like a good fit to achieve this, albeit
> > > > > > handling the areas, so a cgroup has a quota in a given CMA
> > > > > > resource.
> > > > > 
> > > > > Please expand more on why do you think this fits into the memcg model.
> > > > > AFAIU we are talking about a unreclaimable memory and reservations of
> > > > > CMA areas.
> > > > 
> > > > Since memcg already accounts for some unreclaimable memory (kmem,
> > > > hugetlb),
> > > 
> > > hugetlb pages have their own controller
> > > 
> > > > or induces failure if no reclamation is possible, I did not
> > > > see CMA allocations being unreclaimable to be a blocker to track what is
> > > > otherwise system memory.
> > > 
> > > yes, we can have unreclaimable memory charged to memcg, that is not a
> > > real problem. We have all sorts of memory consumers that need to be
> > > capped charged to the memcg. If dmabufs are another ones then fine, just
> > > charge allocated pages from the cma area. It is the "make all cma users
> > > memcg aware and have per cma limits" that I am really struggling with.
> > 
> > CMA is system memory independently from its usage though, and in cases
> > with shared CMA areas multiple users can allocate from them. Yet the
> > kernel cannot enforce usage limits.
> 
> Correct. Those are effectively a shared memory pools without any
> control. I do not think memcg is a good method to enfore any usage
> limits for that though for reasons mentioned above. Memcg is effective
> at capping the overall memory consumption of a workload. Not really
> great when it comes to a specific memory pool control.

Understood, that makes sense, and with the reclaim scenario mentioned
earlier, it doesn't fit.

> > > You cannot really assume usecase, requirements, lifetime etc. for an
> > > arbitrary cma area. I do not think this is a viable way forward. Focus
> > > on your real usecase, which seems to be dmabufs.
> > 
> > While dmabufs are indeed my main use case, they are quite generic and
> > may not always have system memory backing them (device memory). Working
> > at the CMA allocator alleviated these disparities.
> > 
> > > Explain what do you want to achieve and then we can think whether memcg
> > > is the right model for that usecase
> > 
> > Hopefully I expressed this in a better way by now. In short, enforce
> > usage limits for concurrent CMA users using shared CMA resources.
> 
> Thanks. Yes this is more clear now. And it resembles hugetlb situation
> more than memcg. You simply need a memory pool specific access and usage
> control. Dispersing that to a global memcg limit seems rather coarse and 
> I would say impractical. So it really calls for a per pool control with
> an understanding of how the specific pool really works.

Thank you for the feedback. It looks like this won't work. It also
excludes the attempt through double charging dmem[1] as it would have
similar issues trying to use memcg.

>From your last sentence, would this rather call for a different
controller entirely that would handle CMA semantics? Referencing the
other thread[2] it would also make the charging separate from the
allocator, but simplify making it opt-in at the user's implementation,
e.g, the dmabuf heap would call some cma_cgroup_try_charge() and
cma_cgroup_uncharge() around cma_alloc()/cma_release().

[1] 
https://lore.kernel.org/all/20260519-cgroup-dmem-memcg-double-charge-v2-0-db4d14070...@redhat.com/
[2] https://lore.kernel.org/all/[email protected]/

> -- 
> Michal Hocko
> SUSE Labs
> 

-- 
Eric Chanudet


Reply via email to