All of lore.kernel.org
 help / color / mirror / Atom feed
From: Harry Yoo <harry.yoo@oracle.com>
To: Vlastimil Babka <vbabka@suse.cz>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>,
	Christoph Lameter <cl@gentwo.org>,
	David Rientjes <rientjes@google.com>,
	Roman Gushchin <roman.gushchin@linux.dev>,
	Andrew Morton <akpm@linux-foundation.org>,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 6/6] slab: don't validate slab pointer in free_debug_processing()
Date: Fri, 12 Sep 2025 19:52:56 +0900	[thread overview]
Message-ID: <aMP7iOwAm-nC4ZYH@hyeyoo> (raw)
In-Reply-To: <20250911-slub-slab-validation-v1-6-8b67eb3b3dc5@suse.cz>

On Thu, Sep 11, 2025 at 07:02:39PM +0200, Vlastimil Babka wrote:
> The struct slab pointer has been obtained one from the object being
> freed on all the paths that lead to this function. In all cases this
> already includes the test for slab type of the struct page which struct
> slab is overlaying. Thus we would not reach this function if it was
> not a valid slab pointer in the first place.
> 
> One less obvious case is that kmem_cache_free() trusts virt_to_slab()
> blindly so it may be NULL if the slab type check is false. But with
> SLAB_CONSISTENCY_CHECKS, cache_from_obj() called also from
> kmem_cache_free() catches this and returns NULL, which terminates
> freeing immediately.

Oh, I thought it'll crash even with debug caches
but it won't and I misread the code.

> Signed-off-by: Vlastimil Babka <vbabka@suse.cz>
> ---

Looks good to me,
Reviewed-by: Harry Yoo <harry.yoo@oracle.com>

-- 
Cheers,
Harry / Hyeonggon


      reply	other threads:[~2025-09-12 10:53 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-09-11 17:02 [PATCH 0/6] slab: struct slab pointer validation improvements Vlastimil Babka
2025-09-11 17:02 ` [PATCH 1/6] slab: Remove dead code in free_consistency_checks() Vlastimil Babka
2025-09-11 17:02 ` [PATCH 2/6] slab: wrap debug slab validation in validate_slab_ptr() Vlastimil Babka
2025-09-12 10:20   ` Harry Yoo
2025-09-11 17:02 ` [PATCH 3/6] slab: move validate_slab_ptr() from check_slab() to its callers Vlastimil Babka
2025-09-12 10:24   ` Harry Yoo
2025-09-11 17:02 ` [PATCH 4/6] slab: move validate_slab_ptr() from alloc_consistency_checks() to its caller Vlastimil Babka
2025-09-12 10:41   ` Harry Yoo
2025-09-11 17:02 ` [PATCH 5/6] slab: validate slab before using it in alloc_single_from_partial() Vlastimil Babka
2025-09-12 10:48   ` Harry Yoo
2025-09-12 11:34     ` Vlastimil Babka
2025-09-11 17:02 ` [PATCH 6/6] slab: don't validate slab pointer in free_debug_processing() Vlastimil Babka
2025-09-12 10:52   ` Harry Yoo [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aMP7iOwAm-nC4ZYH@hyeyoo \
    --to=harry.yoo@oracle.com \
    --cc=akpm@linux-foundation.org \
    --cc=cl@gentwo.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=rientjes@google.com \
    --cc=roman.gushchin@linux.dev \
    --cc=vbabka@suse.cz \
    --cc=willy@infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.