From: Longlong Xia <xialonglong2025@163.com>
To: Hao Li <hao.li@linux.dev>
Cc: vbabka@kernel.org, harry@kernel.org, akpm@linux-foundation.org,
cl@gentwo.org, rientjes@google.com, roman.gushchin@linux.dev,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
xialonglong@kylinos.cn
Subject: Re: [PATCH 1/1] mm/slab_common: reject zero object_size before calculate_alignment
Date: Tue, 25 Aug 2026 21:46:29 +0800 [thread overview]
Message-ID: <93d6e366-e7f2-4cd6-b8e7-96a9f79813d3@163.com> (raw)
In-Reply-To: <ao2RAVvU5g9Am7_J@fedora>
在 2026/8/25 20:59, Hao Li 写道:
> On Mon, Aug 24, 2026 at 05:24:54PM +0800, Longlong Xia wrote:
>> From: Longlong Xia <xialonglong@kylinos.cn>
>>
>> calculate_alignment() with SLAB_HWCACHE_ALIGN halves ralign in a
>> while (size <= ralign / 2) loop. When size is 0, ralign eventually
>> reaches 0 and the condition stays true indefinitely, hanging the
>> kernel.
>>
>> kmem_cache_sanity_check() rejected size > KMALLOC_MAX_SIZE but not
>> size == 0, and the sanity check is compiled out without
>> CONFIG_DEBUG_VM. Add a !object_size check in
>> __kmem_cache_create_args(), which is always compiled, and add !size
>> to the DEBUG_VM sanity check for diagnostics.
>>
>> Assisted-by: Codex:gpt-5.6-sol
>> Signed-off-by: Longlong Xia <xialonglong@kylinos.cn>
>> ---
>> mm/slab_common.c | 4 ++--
>> 1 file changed, 2 insertions(+), 2 deletions(-)
>>
>> diff --git a/mm/slab_common.c b/mm/slab_common.c
>> index 657fd75776ea..209fe838fe71 100644
>> --- a/mm/slab_common.c
>> +++ b/mm/slab_common.c
>> @@ -102,7 +102,7 @@ static bool kmem_cache_is_duplicate_name(const char *name)
>>
>> static int kmem_cache_sanity_check(const char *name, unsigned int size)
>> {
>> - if (!name || in_interrupt() || size > KMALLOC_MAX_SIZE) {
>> + if (!name || in_interrupt() || !size || size > KMALLOC_MAX_SIZE) {
>> pr_err("kmem_cache_create(%s) integrity check failed\n", name);
>> return -EINVAL;
>> }
>> @@ -354,7 +354,7 @@ struct kmem_cache *__kmem_cache_create_args(const char *name,
>> goto out_unlock;
>> }
>>
>> - if (flags & ~SLAB_FLAGS_PERMITTED) {
>> + if (!object_size || flags & ~SLAB_FLAGS_PERMITTED) {
> under !CONFIG_DEBUG_VM, I think we ignore the sanity_check deliberately, so it
> seems we don't need to add !object_size check here. right?
Thanks for the review.
Right, agreed. The !object_size check duplicates what
kmem_cache_sanity_check()
is for, and that one is intentionally debug-only. I'll drop the
__kmem_cache_create_args() hunk in v2 and keep only the !size addition in
kmem_cache_sanity_check().
Thanks,
Longlong
>> err = -EINVAL;
>> goto out_unlock;
>> }
>> --
>> 2.43.0
>>
prev parent reply other threads:[~2026-08-25 13:47 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 9:24 [PATCH 1/1] mm/slab_common: reject zero object_size before calculate_alignment Longlong Xia
2026-08-25 12:59 ` Hao Li
2026-08-25 13:46 ` Longlong Xia [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=93d6e366-e7f2-4cd6-b8e7-96a9f79813d3@163.com \
--to=xialonglong2025@163.com \
--cc=akpm@linux-foundation.org \
--cc=cl@gentwo.org \
--cc=hao.li@linux.dev \
--cc=harry@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=rientjes@google.com \
--cc=roman.gushchin@linux.dev \
--cc=vbabka@kernel.org \
--cc=xialonglong@kylinos.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.