## Problem HAKMEM 4T crashed with "free(): invalid pointer" on startup: - System/mimalloc: 3.3M ops/s ✅ - HAKMEM 1T: 838K ops/s (-75%) ⚠️ - HAKMEM 4T: Crash (Exit 134) ❌ Error: superslab_refill returned NULL (OOM), active=0, bitmap=0x00000000 ## Root Cause (Ultrathink Task Agent Investigation) Active counter double-decrement when re-allocating from freelist: 1. Free → counter-- ✅ 2. Remote drain → add to freelist (no counter change) ✅ 3. P0 batch refill → move to TLS cache (forgot counter++) ❌ BUG! 4. Next free → counter-- ❌ Double decrement! Result: Counter underflow → SuperSlab appears "full" → OOM → crash ## Fix (1 line) File: core/hakmem_tiny_refill_p0.inc.h:103 +ss_active_add(tls->ss, from_freelist); Reason: Freelist re-allocation moves block from "free" to "allocated" state, so active counter MUST increment. ## Verification | Setting | Before | After | Result | |----------------|---------|----------------|--------------| | 4T default | ❌ Crash | ✅ 838,445 ops/s | 🎉 Stable | | Stability (2x) | - | ✅ Same score | Reproducible | ## Remaining Issue ❌ HAKMEM_TINY_REFILL_COUNT_HOT=64 triggers crash (class=4 OOM) - Suspected: TLS cache over-accumulation or memory leak - Next: Investigate HAKMEM_TINY_FAST_CAP interaction 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
150 lines
5.4 KiB
C
150 lines
5.4 KiB
C
// hakmem_tiny_refill_p0.inc.h
|
||
// ChatGPT Pro P0: Complete Batch Refill (SLL用)
|
||
//
|
||
// Purpose: Optimize sll_refill_small_from_ss with batch carving
|
||
// Based on: tls_refill_from_tls_slab (hakmem_tiny_tls_ops.h:115-126)
|
||
//
|
||
// Key optimization: ss_active_inc × 64 → ss_active_add × 1
|
||
//
|
||
// Maintains: Existing g_tls_sll_head fast path (no changes to hot path!)
|
||
//
|
||
// Enable P0 by default for testing (set to 0 to disable)
|
||
#ifndef HAKMEM_TINY_P0_BATCH_REFILL
|
||
#define HAKMEM_TINY_P0_BATCH_REFILL 1
|
||
#endif
|
||
|
||
#ifndef HAKMEM_TINY_REFILL_P0_INC_H
|
||
#define HAKMEM_TINY_REFILL_P0_INC_H
|
||
|
||
// Debug counters (compile-time gated)
|
||
#if HAKMEM_DEBUG_COUNTERS
|
||
extern unsigned long long g_rf_hit_slab[];
|
||
// Diagnostic counters for refill early returns
|
||
extern unsigned long long g_rf_early_no_ss[]; // Line 27: !g_use_superslab
|
||
extern unsigned long long g_rf_early_no_meta[]; // Line 35: !meta
|
||
extern unsigned long long g_rf_early_no_room[]; // Line 40: room <= 0
|
||
extern unsigned long long g_rf_early_want_zero[]; // Line 55: want == 0
|
||
#endif
|
||
|
||
// Refill TLS SLL from SuperSlab with batch carving (P0 optimization)
|
||
#include "tiny_refill_opt.h"
|
||
static inline int sll_refill_batch_from_ss(int class_idx, int max_take) {
|
||
if (!g_use_superslab || max_take <= 0) {
|
||
#if HAKMEM_DEBUG_COUNTERS
|
||
if (!g_use_superslab) g_rf_early_no_ss[class_idx]++;
|
||
#endif
|
||
return 0;
|
||
}
|
||
|
||
TinyTLSSlab* tls = &g_tls_slabs[class_idx];
|
||
if (!tls->ss) {
|
||
// Try to obtain a SuperSlab for this class
|
||
if (superslab_refill(class_idx) == NULL) return 0;
|
||
}
|
||
TinySlabMeta* meta = tls->meta;
|
||
if (!meta) {
|
||
#if HAKMEM_DEBUG_COUNTERS
|
||
g_rf_early_no_meta[class_idx]++;
|
||
#endif
|
||
return 0;
|
||
}
|
||
|
||
// Compute how many we can actually push into SLL without overflow
|
||
uint32_t sll_cap = sll_cap_for_class(class_idx, (uint32_t)TINY_TLS_MAG_CAP);
|
||
int room = (int)sll_cap - (int)g_tls_sll_count[class_idx];
|
||
if (room <= 0) {
|
||
#if HAKMEM_DEBUG_COUNTERS
|
||
g_rf_early_no_room[class_idx]++;
|
||
#endif
|
||
return 0;
|
||
}
|
||
|
||
// For hot tiny classes (0..3), allow an env override to increase batch size
|
||
uint32_t want = (uint32_t)max_take;
|
||
if (class_idx <= 3) {
|
||
static int g_hot_override = -2; // -2 = uninitialized, -1 = no override, >0 = value
|
||
if (__builtin_expect(g_hot_override == -2, 0)) {
|
||
const char* e = getenv("HAKMEM_TINY_REFILL_COUNT_HOT");
|
||
int v = (e && *e) ? atoi(e) : -1;
|
||
if (v < 0) v = -1; if (v > 256) v = 256; // clamp
|
||
g_hot_override = v;
|
||
}
|
||
if (g_hot_override > 0) want = (uint32_t)g_hot_override;
|
||
} else {
|
||
// Mid classes (>=4): optional override for batch size
|
||
static int g_mid_override = -2; // -2 = uninitialized, -1 = no override, >0 = value
|
||
if (__builtin_expect(g_mid_override == -2, 0)) {
|
||
const char* e = getenv("HAKMEM_TINY_REFILL_COUNT_MID");
|
||
int v = (e && *e) ? atoi(e) : -1;
|
||
if (v < 0) v = -1; if (v > 256) v = 256; // clamp
|
||
g_mid_override = v;
|
||
}
|
||
if (g_mid_override > 0) want = (uint32_t)g_mid_override;
|
||
}
|
||
if (want > (uint32_t)room) want = (uint32_t)room;
|
||
if (want == 0) {
|
||
#if HAKMEM_DEBUG_COUNTERS
|
||
g_rf_early_want_zero[class_idx]++;
|
||
#endif
|
||
return 0;
|
||
}
|
||
|
||
size_t bs = g_tiny_class_sizes[class_idx];
|
||
int total_taken = 0;
|
||
|
||
// === P0 Batch Carving Loop ===
|
||
while (want > 0) {
|
||
// Handle freelist items first (usually 0)
|
||
TinyRefillChain chain;
|
||
uint32_t from_freelist = trc_pop_from_freelist(meta, want, &chain);
|
||
if (from_freelist > 0) {
|
||
trc_splice_to_sll(class_idx, &chain, &g_tls_sll_head[class_idx], &g_tls_sll_count[class_idx]);
|
||
// FIX: Blocks from freelist were decremented when freed, must increment when allocated
|
||
ss_active_add(tls->ss, from_freelist);
|
||
extern unsigned long long g_rf_freelist_items[];
|
||
g_rf_freelist_items[class_idx] += from_freelist;
|
||
total_taken += from_freelist;
|
||
want -= from_freelist;
|
||
if (want == 0) break;
|
||
}
|
||
|
||
// === Linear Carve (P0 Key Optimization!) ===
|
||
if (meta->used >= meta->capacity) {
|
||
// Slab exhausted, try to get another
|
||
if (superslab_refill(class_idx) == NULL) break;
|
||
meta = tls->meta;
|
||
if (!meta) break;
|
||
continue;
|
||
}
|
||
|
||
uint32_t available = meta->capacity - meta->used;
|
||
uint32_t batch = want;
|
||
if (batch > available) batch = available;
|
||
if (batch == 0) break;
|
||
|
||
// Get slab base
|
||
uint8_t* slab_base = tls->slab_base ? tls->slab_base
|
||
: tiny_slab_base_for(tls->ss, tls->slab_idx);
|
||
TinyRefillChain carve;
|
||
trc_linear_carve(slab_base, bs, meta, batch, &carve);
|
||
trc_splice_to_sll(class_idx, &carve, &g_tls_sll_head[class_idx], &g_tls_sll_count[class_idx]);
|
||
// FIX: Update SuperSlab active counter (was missing!)
|
||
ss_active_add(tls->ss, batch);
|
||
extern unsigned long long g_rf_carve_items[];
|
||
g_rf_carve_items[class_idx] += batch;
|
||
|
||
total_taken += batch;
|
||
want -= batch;
|
||
}
|
||
|
||
#if HAKMEM_DEBUG_COUNTERS
|
||
// Track successful SLL refills from SuperSlab (compile-time gated)
|
||
// NOTE: Increment unconditionally to verify counter is working
|
||
g_rf_hit_slab[class_idx]++;
|
||
#endif
|
||
|
||
return total_taken;
|
||
}
|
||
|
||
#endif // HAKMEM_TINY_REFILL_P0_INC_H
|