From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 67F33C25B75 for ; Mon, 3 Jun 2024 09:25:52 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id D43A46B0093; Mon, 3 Jun 2024 05:25:51 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id CCC106B0095; Mon, 3 Jun 2024 05:25:51 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id AD1EC6B0098; Mon, 3 Jun 2024 05:25:51 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0012.hostedemail.com [216.40.44.12]) by kanga.kvack.org (Postfix) with ESMTP id 8E0FD6B0093 for ; Mon, 3 Jun 2024 05:25:51 -0400 (EDT) Received: from smtpin19.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay09.hostedemail.com (Postfix) with ESMTP id E356D806EE for ; Mon, 3 Jun 2024 09:25:50 +0000 (UTC) X-FDA: 82189045260.19.F6E141B Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) by imf25.hostedemail.com (Postfix) with ESMTP id 98625A000E for ; Mon, 3 Jun 2024 09:25:47 +0000 (UTC) Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=suse.cz header.s=susede2_rsa header.b=KTQ0Xdje; dkim=pass header.d=suse.cz header.s=susede2_ed25519 header.b=sXpTYDg2; dkim=pass header.d=suse.cz header.s=susede2_rsa header.b=Z0tdEgK4; dkim=pass header.d=suse.cz header.s=susede2_ed25519 header.b=OwxJfucO; spf=pass (imf25.hostedemail.com: domain of vbabka@suse.cz designates 195.135.223.130 as permitted sender) smtp.mailfrom=vbabka@suse.cz; dmarc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1717406747; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=YCVlp6tqy0Lfw4pwRsglQ1xUSbV/yrMGt8kgMUKIWpo=; b=m4lMwTSPH7ZBvL6mPQrJV/pm91wqbdgb4TKSKNbntfGioNWawcn4+pqcfZA+3v5S2jBnlL ZKLf9IzGFyTu+cyYk+WIhIFqvMWQRGqPYWGnkn7u3KvDjnuWsq2uY/lY9epXbjI8olGLCQ wzhwvmnXeIplH0eTyfTHp+zi8vj6cXc= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=suse.cz header.s=susede2_rsa header.b=KTQ0Xdje; dkim=pass header.d=suse.cz header.s=susede2_ed25519 header.b=sXpTYDg2; dkim=pass header.d=suse.cz header.s=susede2_rsa header.b=Z0tdEgK4; dkim=pass header.d=suse.cz header.s=susede2_ed25519 header.b=OwxJfucO; spf=pass (imf25.hostedemail.com: domain of vbabka@suse.cz designates 195.135.223.130 as permitted sender) smtp.mailfrom=vbabka@suse.cz; dmarc=none ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1717406747; a=rsa-sha256; cv=none; b=KKMZomssiKp7pZXiG/iE9i/djvuiz0Er5ws3URZXdfXyvBs1w6Lu9BncJJuLt66oFdpKyR Fgciou1tn841RhpcEeWbgmBFy0Z6wneoN2TI2Dnr73Q+6JStmOtvNG5UF34RiZTqjgKE++ xZi3CHwr4PuICSssajEkuAlBLccEjN8= Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id DDA5422239; Mon, 3 Jun 2024 09:25:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_rsa; t=1717406746; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=YCVlp6tqy0Lfw4pwRsglQ1xUSbV/yrMGt8kgMUKIWpo=; b=KTQ0XdjeFkuuPIxFdUX3/E5sTw4Mp+ELZUtdVuhOxumhQ9d1SyCWDWxWrgUyWvgar93YQe VTCzqf6FaE7bSlrc9nDcUsb5ZcG6b2C9tGqSMMExC03REW3VAOUYKHvoQpt+Oeb13NBGEJ CHxILInrH233d+7QRhzOSlWw6ukWGdM= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_ed25519; t=1717406746; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=YCVlp6tqy0Lfw4pwRsglQ1xUSbV/yrMGt8kgMUKIWpo=; b=sXpTYDg2GUEbDjEtqgvm3LKiOHMj5bR2ObvG2bDGV2+UD3w1FLsmX9Mb3fIZYwb+r8H2hY gMmG6TXGeGJgYpCQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_rsa; t=1717406745; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=YCVlp6tqy0Lfw4pwRsglQ1xUSbV/yrMGt8kgMUKIWpo=; b=Z0tdEgK4ftWiqI220aQJrowTImlICDL6S2ws7G5UYAvVUM5jMviOt07CXUj6H9B7JdP2eV J/88zVoDkMJ8xjLHNhjyNZvrrRyVGLzNgSbjIPFd6Oxd7YvQwAGZrpvg8uy/PYAkOnqW6W VcdwrdzK4JgSS+jhOmnfyun/cxLS1Ho= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_ed25519; t=1717406745; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=YCVlp6tqy0Lfw4pwRsglQ1xUSbV/yrMGt8kgMUKIWpo=; b=OwxJfucOPMM7lIuNU5VFpT/vsLjj5ajuyIpGkCIIQWt0aYiZYXie/xixgtyCsc54qOuou+ wQ9GMR9N+zPEuNCw== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id C0CB5139CB; Mon, 3 Jun 2024 09:25:45 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id lmeULhmMXWbkAQAAD6G6ig (envelope-from ); Mon, 03 Jun 2024 09:25:45 +0000 Message-ID: <5a09e348-9eeb-4502-9aa9-ef5da2f94218@suse.cz> Date: Mon, 3 Jun 2024 11:25:45 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 2/3] slab: don't put freepointer outside of object if only orig_size Content-Language: en-US To: Chengming Zhou , Christoph Lameter , Pekka Enberg , David Rientjes , Joonsoo Kim , Andrew Morton , Roman Gushchin , Hyeonggon Yoo <42.hyeyoo@gmail.com>, Feng Tang Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, zhouchengming@bytedance.com References: <20240528-b4-slab-debug-v1-0-8694ef4802df@linux.dev> <20240528-b4-slab-debug-v1-2-8694ef4802df@linux.dev> From: Vlastimil Babka Autocrypt: addr=vbabka@suse.cz; keydata= xsFNBFZdmxYBEADsw/SiUSjB0dM+vSh95UkgcHjzEVBlby/Fg+g42O7LAEkCYXi/vvq31JTB KxRWDHX0R2tgpFDXHnzZcQywawu8eSq0LxzxFNYMvtB7sV1pxYwej2qx9B75qW2plBs+7+YB 87tMFA+u+L4Z5xAzIimfLD5EKC56kJ1CsXlM8S/LHcmdD9Ctkn3trYDNnat0eoAcfPIP2OZ+ 9oe9IF/R28zmh0ifLXyJQQz5ofdj4bPf8ecEW0rhcqHfTD8k4yK0xxt3xW+6Exqp9n9bydiy tcSAw/TahjW6yrA+6JhSBv1v2tIm+itQc073zjSX8OFL51qQVzRFr7H2UQG33lw2QrvHRXqD Ot7ViKam7v0Ho9wEWiQOOZlHItOOXFphWb2yq3nzrKe45oWoSgkxKb97MVsQ+q2SYjJRBBH4 8qKhphADYxkIP6yut/eaj9ImvRUZZRi0DTc8xfnvHGTjKbJzC2xpFcY0DQbZzuwsIZ8OPJCc LM4S7mT25NE5kUTG/TKQCk922vRdGVMoLA7dIQrgXnRXtyT61sg8PG4wcfOnuWf8577aXP1x 6mzw3/jh3F+oSBHb/GcLC7mvWreJifUL2gEdssGfXhGWBo6zLS3qhgtwjay0Jl+kza1lo+Cv BB2T79D4WGdDuVa4eOrQ02TxqGN7G0Biz5ZLRSFzQSQwLn8fbwARAQABzSBWbGFzdGltaWwg QmFia2EgPHZiYWJrYUBzdXNlLmN6PsLBlAQTAQoAPgIbAwULCQgHAwUVCgkICwUWAgMBAAIe AQIXgBYhBKlA1DSZLC6OmRA9UCJPp+fMgqZkBQJkBREIBQkRadznAAoJECJPp+fMgqZkNxIQ ALZRqwdUGzqL2aeSavbum/VF/+td+nZfuH0xeWiO2w8mG0+nPd5j9ujYeHcUP1edE7uQrjOC Gs9sm8+W1xYnbClMJTsXiAV88D2btFUdU1mCXURAL9wWZ8Jsmz5ZH2V6AUszvNezsS/VIT87 AmTtj31TLDGwdxaZTSYLwAOOOtyqafOEq+gJB30RxTRE3h3G1zpO7OM9K6ysLdAlwAGYWgJJ V4JqGsQ/lyEtxxFpUCjb5Pztp7cQxhlkil0oBYHkudiG8j1U3DG8iC6rnB4yJaLphKx57NuQ PIY0Bccg+r9gIQ4XeSK2PQhdXdy3UWBr913ZQ9AI2usid3s5vabo4iBvpJNFLgUmxFnr73SJ KsRh/2OBsg1XXF/wRQGBO9vRuJUAbnaIVcmGOUogdBVS9Sun/Sy4GNA++KtFZK95U7J417/J Hub2xV6Ehc7UGW6fIvIQmzJ3zaTEfuriU1P8ayfddrAgZb25JnOW7L1zdYL8rXiezOyYZ8Fm ZyXjzWdO0RpxcUEp6GsJr11Bc4F3aae9OZtwtLL/jxc7y6pUugB00PodgnQ6CMcfR/HjXlae h2VS3zl9+tQWHu6s1R58t5BuMS2FNA58wU/IazImc/ZQA+slDBfhRDGYlExjg19UXWe/gMcl De3P1kxYPgZdGE2eZpRLIbt+rYnqQKy8UxlszsBNBFsZNTUBCACfQfpSsWJZyi+SHoRdVyX5 J6rI7okc4+b571a7RXD5UhS9dlVRVVAtrU9ANSLqPTQKGVxHrqD39XSw8hxK61pw8p90pg4G /N3iuWEvyt+t0SxDDkClnGsDyRhlUyEWYFEoBrrCizbmahOUwqkJbNMfzj5Y7n7OIJOxNRkB IBOjPdF26dMP69BwePQao1M8Acrrex9sAHYjQGyVmReRjVEtv9iG4DoTsnIR3amKVk6si4Ea X/mrapJqSCcBUVYUFH8M7bsm4CSxier5ofy8jTEa/CfvkqpKThTMCQPNZKY7hke5qEq1CBk2 wxhX48ZrJEFf1v3NuV3OimgsF2odzieNABEBAAHCwXwEGAEKACYCGwwWIQSpQNQ0mSwujpkQ PVAiT6fnzIKmZAUCZAUSmwUJDK5EZgAKCRAiT6fnzIKmZOJGEACOKABgo9wJXsbWhGWYO7mD 8R8mUyJHqbvaz+yTLnvRwfe/VwafFfDMx5GYVYzMY9TWpA8psFTKTUIIQmx2scYsRBUwm5VI EurRWKqENcDRjyo+ol59j0FViYysjQQeobXBDDE31t5SBg++veI6tXfpco/UiKEsDswL1WAr tEAZaruo7254TyH+gydURl2wJuzo/aZ7Y7PpqaODbYv727Dvm5eX64HCyyAH0s6sOCyGF5/p eIhrOn24oBf67KtdAN3H9JoFNUVTYJc1VJU3R1JtVdgwEdr+NEciEfYl0O19VpLE/PZxP4wX PWnhf5WjdoNI1Xec+RcJ5p/pSel0jnvBX8L2cmniYnmI883NhtGZsEWj++wyKiS4NranDFlA HdDM3b4lUth1pTtABKQ1YuTvehj7EfoWD3bv9kuGZGPrAeFNiHPdOT7DaXKeHpW9homgtBxj 8aX/UkSvEGJKUEbFL9cVa5tzyialGkSiZJNkWgeHe+jEcfRT6pJZOJidSCdzvJpbdJmm+eED w9XOLH1IIWh7RURU7G1iOfEfmImFeC3cbbS73LQEFGe1urxvIH5K/7vX+FkNcr9ujwWuPE9b 1C2o4i/yZPLXIVy387EjA6GZMqvQUFuSTs/GeBcv0NjIQi8867H3uLjz+mQy63fAitsDwLmR EP+ylKVEKb0Q2A== In-Reply-To: <20240528-b4-slab-debug-v1-2-8694ef4802df@linux.dev> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Rspam-User: X-Rspamd-Server: rspam09 X-Rspamd-Queue-Id: 98625A000E X-Stat-Signature: hez1p6ypucmnyjyon7wrmjdn5jsj4d3f X-HE-Tag: 1717406747-304252 X-HE-Meta: U2FsdGVkX1++z+XTKpaHJp2QecpTUzSjHDVqrc2fiL65KYeOBwPx5dv3TThb3RaxxLcvWYHZ6/mK1hmz1vhOti6cBv7AeVPbUMVhMAyWhE1Jf+KWsQba4m9vJyPZTGW5mknpLCoS8ddazANI9VN/1xkusMDLt0t48+XD5aLkXKMnDDj3xTSRTjlp0PqBVq7OpgMB4sIw0r21+ZKv1nPSo6BEf3EpZ9IGihNb2VkDmivGyA+SOBJcG+PYpdWzmZyNhULCn/Wk/4j6yUkNk9/v6KE5kwvg9c2f765RhmV/jCbk/mu7NF49VxybIPg4GRbJ+lbEdyFRJvgMR2xOfOTm8WX7cCc1lvekHPCSboAUsyvGJkuFSHkMx+DRhiX6PlU3Rr9K82e3qK+woIReGVeHbM+RZwC20/5f9fKLpcCsVYKnL08wXBILw89Sqcnexh4E8Pa/oOMPsghmFJlJQVxq6k+Ey4apbtIjmmZo9fMAgG5CvwPPpjvzBa0YLZEM065io1nUxBJcSBOYR5HFR8quvjOfxhUJMECXSKlJLtVDBeZ5M0RdP0Et5+5e8dcVFw13iBcHTJ56gGLOSz6BYs1JqDsVCEfvZRUAZDnZvw2LT/Hlbyntf0ht+r75LSMFx6dqr4rX1AxHRFVjRUgsa1dInortYQArVpDITZ+JR+LDgL39/jBMsLEYQ5WoQhPw1dEMW4s5TCv/oMFHYLIgekkS4V+dgbhBbz4epUX0WnOr6hFvi+RC+E2gqEXdLNPweM3v9V1QEztthJdhGD80kpSP59UZiiaTP3uRLS0Ebr/o3BlDTb7qnUzH1jWfAqIB5ow0dA517bcdqWWnHDEdVvlCRJpE5CYhHpbQ2I2QOzKDFoR9anG44KMj8rZjSCihSxDeRoMc2VCPnBxvWsIZ/XQuLFTRE/XtorZnnq45Ag6c4XlHMxr3bvX+zUSu0ypvQTa0QlmvppCFBJJxUtJUHEP TvSEBeRg H7aRZuKSB0OviRwM4Ff4uW1yHyWP+0WBPke7gUwG06Dv3MS38DoVwgB3+5Z7IqI03bIaPMSLX1WL/0VPYC4802QIZdmYVzKMxrhRecYD2pnCM/2t7G6bFR68EVhEB5OXa3idWyjIQQkrs6GqviDnOE19tbUpGz28q1s5/KIMWgnQHRCTnVy/GC/Q3+Q4J1A0/naTrf++9+DAGVh6VYImS4ambT9+9P5qUuUdvJKS8OpDZYl4w/U4hQi/1HU0hutgKpfH4MoJ+fyFh7v40PpFuOLn1geN30+qEURK/hP+DN5wwd2Kvh/vqVwPmBIKWkoFAn5pjpL5akfFxWunCpWeL1o8ul1Qvf+xX1biKTVFebCEu6h2B9/cZXrSVWRVdOmSEV9raCi43LaWxqiNuy2lXniJfHI/MYLz6ahDB X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On 5/28/24 9:16 AM, Chengming Zhou wrote: > The commit 946fa0dbf2d8 ("mm/slub: extend redzone check to extra > allocated kmalloc space than requested") will extend right redzone > when allocating for orig_size < object_size. So we can't overlay the > freepointer in the object space in this case. > > But the code looks like it forgot to check SLAB_RED_ZONE, since there > won't be extended right redzone if only orig_size enabled. > > Signed-off-by: Chengming Zhou Seems OK. > --- > mm/slub.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/mm/slub.c b/mm/slub.c > index de57512734ac..b92d9a557852 100644 > --- a/mm/slub.c > +++ b/mm/slub.c > @@ -5150,7 +5150,7 @@ static int calculate_sizes(struct kmem_cache *s) > */ > s->inuse = size; > > - if (slub_debug_orig_size(s) || > + if (((flags & SLAB_RED_ZONE) && slub_debug_orig_size(s)) || > (flags & (SLAB_TYPESAFE_BY_RCU | SLAB_POISON)) || > ((flags & SLAB_RED_ZONE) && s->object_size < sizeof(void *)) || Should we consolidate the two cases with flags & SLAB_RED_ZONE? Also below this is a comment that could also mention the slub_debug_orig_size(). > s->ctor) { >