From: Andrew Morton <akpm@linux-foundation.org>
To: Breno Leitao <leitao@debian.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>,
Matthew Wilcox <willy@infradead.org>,
mm-commits@vger.kernel.org, kent.overstreet@linux.dev,
bigeasy@linutronix.de, arnd@arndb.de
Subject: Re: + radix-tree-fix-kmemleak-false-positives-on-tree-head-reassignment.patch added to mm-new branch
Date: Mon, 10 Aug 2026 20:18:14 -0700 [thread overview]
Message-ID: <20260810201814.52d1353d5c3f1ce27ba10186@linux-foundation.org> (raw)
In-Reply-To: <akzZSIN5ALd8iH52@gmail.com>
On Tue, 7 Jul 2026 04:26:43 -0700 Breno Leitao <leitao@debian.org> wrote:
> > Anyway, a better diff for the first idea below. I need to do more
> > testing and can turn it into a proper commit (if we don't deem it
> > redundant because of the other min_unref_count).
>
> Thanks for it. I've reviewed it and it looks sane.
>
> I am also testing it on my side.
This went quiet. I take it that we won't be proceeding with this
patch, "radix-tree: fix kmemleak false positives on tree head
reassignment", v2?
From: Breno Leitao <leitao@debian.org>
Subject: radix-tree: fix kmemleak false positives on tree head reassignment
Date: Fri, 03 Jul 2026 08:22:03 -0700
Kmemleak periodically reports transient false positives for radix tree
nodes allocated through the IDR, for example:
unreferenced object 0xffff0004d6ac4200 (size 576):
comm "tcpeventd", pid 6412
backtrace (crc 335d668a):
kmem_cache_alloc_noprof
radix_tree_node_alloc
radix_tree_extend
idr_get_free
idr_alloc_cyclic
map_create
__sys_bpf
radix_tree_extend() (grow) and radix_tree_shrink() (shrink) repoint
root->xa_head to a new node. If a kmemleak scan has already walked past
root->xa_head, the new head is not reachable from any scanned pointer
until the following scan, so kmemleak reports it as leaked even though it
is live.
This is the same race fixed for the XArray API in commit a1a029bcea59
("XArray: fix kmemleak false positive in xas_shrink()"). The IDR uses the
radix tree API directly and hits it on both the grow and the shrink path,
so mark the new head as a transient leak in both.
Add a matching kmemleak_transient_leak() stub to the radix tree test
harness so the userspace lib/radix-tree.c build keeps building.
Link: https://lore.kernel.org/20260703-radix-tree-v2-1-38bb6efb5f6e@debian.org
Signed-off-by: Breno Leitao <leitao@debian.org>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Kent Overstreet <kent.overstreet@linux.dev>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: Matthew Wilcox <willy@infradead.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
lib/radix-tree.c | 7 ++++++-
tools/testing/shared/linux/kmemleak.h | 1 +
2 files changed, 7 insertions(+), 1 deletion(-)
--- a/lib/radix-tree.c~radix-tree-fix-kmemleak-false-positives-on-tree-head-reassignment
+++ a/lib/radix-tree.c
@@ -455,6 +455,8 @@ static int radix_tree_extend(struct radi
node->slots[0] = (void __rcu *)entry;
entry = node_to_entry(node);
rcu_assign_pointer(root->xa_head, entry);
+ /* new head may be missed by an in-progress kmemleak scan */
+ kmemleak_transient_leak(node);
shift += RADIX_TREE_MAP_SHIFT;
} while (shift <= maxshift);
out:
@@ -495,8 +497,11 @@ static inline bool radix_tree_shrink(str
if (!node->shift && is_idr(root))
break;
- if (radix_tree_is_internal_node(child))
+ if (radix_tree_is_internal_node(child)) {
entry_to_node(child)->parent = NULL;
+ /* new head may be missed by an in-progress kmemleak scan */
+ kmemleak_transient_leak(entry_to_node(child));
+ }
/*
* We don't need rcu_assign_pointer(), since we are simply
--- a/tools/testing/shared/linux/kmemleak.h~radix-tree-fix-kmemleak-false-positives-on-tree-head-reassignment
+++ a/tools/testing/shared/linux/kmemleak.h
@@ -1 +1,2 @@
static inline void kmemleak_update_trace(const void *ptr) { }
+static inline void kmemleak_transient_leak(const void *ptr) { }
_
next prev parent reply other threads:[~2026-08-11 3:18 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-05 2:12 + radix-tree-fix-kmemleak-false-positives-on-tree-head-reassignment.patch added to mm-new branch Andrew Morton
2026-07-05 10:45 ` Matthew Wilcox
2026-07-05 18:15 ` Andrew Morton
2026-07-06 10:41 ` Breno Leitao
2026-07-06 11:39 ` Catalin Marinas
2026-07-06 14:53 ` Breno Leitao
2026-07-06 16:25 ` Catalin Marinas
2026-07-06 23:19 ` Catalin Marinas
2026-07-07 11:26 ` Breno Leitao
2026-07-07 14:01 ` Catalin Marinas
2026-08-11 3:18 ` Andrew Morton [this message]
2026-08-11 8:52 ` Catalin Marinas
2026-08-11 9:19 ` Breno Leitao
-- strict thread matches above, loose matches on Subject: below --
2026-07-05 2:11 Andrew Morton
2026-07-02 22:42 Andrew Morton
2026-07-03 15:26 ` Breno Leitao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810201814.52d1353d5c3f1ce27ba10186@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=arnd@arndb.de \
--cc=bigeasy@linutronix.de \
--cc=catalin.marinas@arm.com \
--cc=kent.overstreet@linux.dev \
--cc=leitao@debian.org \
--cc=mm-commits@vger.kernel.org \
--cc=willy@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.