From: "Vlastimil Babka (SUSE)" <vbabka@kernel.org>
To: Harry Yoo <harry@kernel.org>, Suren Baghdasaryan <surenb@google.com>
Cc: Hao Li <hao.li@linux.dev>, Shakeel Butt <shakeel.butt@linux.dev>,
Alexander Potapenko <glider@google.com>,
Marco Elver <elver@google.com>,
Andrew Morton <akpm@linux-foundation.org>,
Christoph Lameter <cl@gentwo.org>,
David Rientjes <rientjes@google.com>,
Roman Gushchin <roman.gushchin@linux.dev>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
cgroups@vger.kernel.org,
"Vlastimil Babka (SUSE)" <vbabka@kernel.org>
Subject: [PATCH v2 01/13] mm/slab: skip kfence objects in allocation profiling
Date: Mon, 20 Jul 2026 16:16:15 +0200 [thread overview]
Message-ID: <20260720-b4-objext_split-v2-1-2fa7c6f60dbe@kernel.org> (raw)
In-Reply-To: <20260720-b4-objext_split-v2-0-2fa7c6f60dbe@kernel.org>
struct kfence_metadata only contains struct slabobj_ext with
CONFIG_MEMCG, which is then used for the "fake" slab's obj_exts field.
If CONFIG_MEMCG is enabled, the struct can also end up used for memory
allocation profiling. If CONFIG_MEMCG is disabled but profiling is
enabled, it will end up allocating its obj_exts via
prepare_slab_obj_exts_hook() and assigning them to the fake struct slab.
These will probably then never be freed.
So things sorta work, but not always in the intended and optimal way.
The upcoming changes to slabobj_ext layout would additionally need a
proper refactoring to keep working.
However, there's little benefit in accounting KFENCE objects. KFENCE
allocations are rare and there can be only CONFIG_KFENCE_NUM_OBJECTS
(default to 255) outstanding ones at any time. For any callsite
prominent enough in the memory allocation profiling stats, allocations
served from KFENCE will be lost in the noise.
Thus let's not complicate things and simply stop accounting KFENCE
objects in allocation profiling and skip them in the related slab hooks.
We also need to skip kfence objects in mark_obj_codetag_empty() in case
a sheaf is allocated from kfence, per earlier sashiko review.
Signed-off-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
---
Documentation/mm/allocation-profiling.rst | 7 +++++++
mm/slub.c | 11 +++++++++++
2 files changed, 18 insertions(+)
diff --git a/Documentation/mm/allocation-profiling.rst b/Documentation/mm/allocation-profiling.rst
index 5389d241176a..d02eb54ee8f2 100644
--- a/Documentation/mm/allocation-profiling.rst
+++ b/Documentation/mm/allocation-profiling.rst
@@ -112,3 +112,10 @@ break it out by rhashtable type.
- Then, use the following form for your allocations:
alloc_hooks_tag(ht->your_saved_tag, kmalloc_noprof(...))
+
+Notes
+=====
+
+- When a slab object is allocated from KFENCE, its accounting is skipped.
+ KFENCE allocations are rare and limited to a small number, so this omission
+ is negligible.
diff --git a/mm/slub.c b/mm/slub.c
index 0337e60db5ac..76acb78f2655 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -2076,6 +2076,11 @@ static inline void mark_obj_codetag_empty(const void *obj)
struct slabobj_ext *ext = slab_obj_ext(obj_slab,
slab_exts, offs);
+ if (is_kfence_address(obj)) {
+ put_slab_obj_exts(slab_exts);
+ return;
+ }
+
if (unlikely(is_codetag_empty(&ext->ref))) {
put_slab_obj_exts(slab_exts);
return;
@@ -2352,6 +2357,9 @@ __alloc_tagging_slab_alloc_hook(struct kmem_cache *s, void *object, gfp_t flags,
if (alloc_flags & SLAB_ALLOC_NO_RECURSE)
return;
+ if (is_kfence_address(object))
+ return;
+
slab = virt_to_slab(object);
obj_exts = prepare_slab_obj_exts_hook(s, slab, flags, alloc_flags, object);
/*
@@ -2399,6 +2407,9 @@ __alloc_tagging_slab_free_hook(struct kmem_cache *s, struct slab *slab, void **p
for (i = 0; i < objects; i++) {
unsigned int off = obj_to_index(s, slab, p[i]);
+ if (is_kfence_address(p[i]))
+ continue;
+
alloc_tag_sub(&slab_obj_ext(slab, obj_exts, off)->ref, s->size);
}
put_slab_obj_exts(obj_exts);
--
2.55.0
next prev parent reply other threads:[~2026-07-20 14:16 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 14:16 [PATCH v2 00/13] mm/slab, alloc_tag: reduce obj_ext memory waste Vlastimil Babka (SUSE)
2026-07-20 14:16 ` Vlastimil Babka (SUSE) [this message]
2026-07-21 5:43 ` [PATCH v2 01/13] mm/slab: skip kfence objects in allocation profiling Harry Yoo
2026-07-21 9:20 ` Vlastimil Babka (SUSE)
2026-07-21 15:41 ` Harry Yoo
2026-07-20 14:16 ` [PATCH v2 02/13] mm/slub: skip handle_failed_objexts_alloc() with profiling disabled Vlastimil Babka (SUSE)
2026-07-21 5:51 ` Harry Yoo
2026-07-21 9:23 ` Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 03/13] mm/slab: remove objs_per_slab() Vlastimil Babka (SUSE)
2026-07-21 5:53 ` Harry Yoo
2026-07-20 14:16 ` [PATCH v2 04/13] mm: move struct slabobj_ext to mm/slab.h Vlastimil Babka (SUSE)
2026-07-21 5:55 ` Harry Yoo
2026-07-20 14:16 ` [PATCH v2 05/13] mm/slab: make slab_obj_ext() determine object index Vlastimil Babka (SUSE)
2026-07-21 6:02 ` Harry Yoo
2026-07-20 14:16 ` [PATCH v2 06/13] mm/slab: abstract slabobj_ext.objcg access Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 07/13] mm/slab: abstract slabobj_ext.ref access Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 08/13] mm/slab: replace slab.stride with obj_exts_in_object Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 09/13] mm/slab: change struct slabobj_ext to a union Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 10/13] mm/slab: introduce slab_obj_ext_has_codetag() Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 11/13] mm/slab: reduce slabobj_ext memory with allocation profiling disabled Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 12/13] mm/slab: add cache_ and slab_needs_objcg() helpers Vlastimil Babka (SUSE)
2026-07-20 14:16 ` [PATCH v2 13/13] mm/slab: stop allocating objcg pointers when unnecessary Vlastimil Babka (SUSE)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720-b4-objext_split-v2-1-2fa7c6f60dbe@kernel.org \
--to=vbabka@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=cgroups@vger.kernel.org \
--cc=cl@gentwo.org \
--cc=elver@google.com \
--cc=glider@google.com \
--cc=hao.li@linux.dev \
--cc=harry@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=rientjes@google.com \
--cc=roman.gushchin@linux.dev \
--cc=shakeel.butt@linux.dev \
--cc=surenb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.