From: Baoquan He <bhe@redhat.com>
To: "Uladzislau Rezki (Sony)" <urezki@gmail.com>
Cc: linux-mm@kvack.org, Andrew Morton <akpm@linux-foundation.org>,
Michal Hocko <mhocko@kernel.org>,
LKML <linux-kernel@vger.kernel.org>,
Michal Hocko <mhocko@suse.com>
Subject: Re: [PATCH v2 05/10] mm/vmalloc: Defer freeing partly initialized vm_struct
Date: Thu, 18 Sep 2025 10:59:39 +0800 [thread overview]
Message-ID: <aMt1myQHpxit3Zbo@MiWiFi-R3L-srv> (raw)
In-Reply-To: <20250915134041.151462-6-urezki@gmail.com>
On 09/15/25 at 03:40pm, Uladzislau Rezki (Sony) wrote:
> __vmalloc_area_node() may call free_vmap_area() or vfree() on
> error paths, both of which can sleep. This becomes problematic
> if the function is invoked from an atomic context, such as when
> GFP_ATOMIC or GFP_NOWAIT is passed via gfp_mask.
>
> To fix this, unify error paths and defer the cleanup of partly
> initialized vm_struct objects to a workqueue. This ensures that
> freeing happens in a process context and avoids invalid sleeps
> in atomic regions.
>
> Acked-by: Michal Hocko <mhocko@suse.com>
> Signed-off-by: Uladzislau Rezki (Sony) <urezki@gmail.com>
> ---
> include/linux/vmalloc.h | 6 +++++-
> mm/vmalloc.c | 34 +++++++++++++++++++++++++++++++---
> 2 files changed, 36 insertions(+), 4 deletions(-)
Reviewed-by: Baoquan He <bhe@redhat.com>
>
> diff --git a/include/linux/vmalloc.h b/include/linux/vmalloc.h
> index 2759dac6be44..97252078a3dc 100644
> --- a/include/linux/vmalloc.h
> +++ b/include/linux/vmalloc.h
> @@ -50,7 +50,11 @@ struct iov_iter; /* in uio.h */
> #endif
>
> struct vm_struct {
> - struct vm_struct *next;
> + union {
> + struct vm_struct *next; /* Early registration of vm_areas. */
> + struct llist_node llnode; /* Asynchronous freeing on error paths. */
> + };
> +
> void *addr;
> unsigned long size;
> unsigned long flags;
> diff --git a/mm/vmalloc.c b/mm/vmalloc.c
> index b77e8be75f10..e61e62872372 100644
> --- a/mm/vmalloc.c
> +++ b/mm/vmalloc.c
> @@ -3686,6 +3686,35 @@ vm_area_alloc_pages(gfp_t gfp, int nid,
> return nr_allocated;
> }
>
> +static LLIST_HEAD(pending_vm_area_cleanup);
> +static void cleanup_vm_area_work(struct work_struct *work)
> +{
> + struct vm_struct *area, *tmp;
> + struct llist_node *head;
> +
> + head = llist_del_all(&pending_vm_area_cleanup);
> + if (!head)
> + return;
> +
> + llist_for_each_entry_safe(area, tmp, head, llnode) {
> + if (!area->pages)
> + free_vm_area(area);
> + else
> + vfree(area->addr);
> + }
> +}
> +
> +/*
> + * Helper for __vmalloc_area_node() to defer cleanup
> + * of partially initialized vm_struct in error paths.
> + */
> +static DECLARE_WORK(cleanup_vm_area, cleanup_vm_area_work);
> +static void defer_vm_area_cleanup(struct vm_struct *area)
> +{
> + if (llist_add(&area->llnode, &pending_vm_area_cleanup))
> + schedule_work(&cleanup_vm_area);
> +}
> +
> static void *__vmalloc_area_node(struct vm_struct *area, gfp_t gfp_mask,
> pgprot_t prot, unsigned int page_shift,
> int node)
> @@ -3717,8 +3746,7 @@ static void *__vmalloc_area_node(struct vm_struct *area, gfp_t gfp_mask,
> warn_alloc(gfp_mask, NULL,
> "vmalloc error: size %lu, failed to allocated page array size %lu",
> nr_small_pages * PAGE_SIZE, array_size);
> - free_vm_area(area);
> - return NULL;
> + goto fail;
> }
>
> set_vm_area_page_order(area, page_shift - PAGE_SHIFT);
> @@ -3795,7 +3823,7 @@ static void *__vmalloc_area_node(struct vm_struct *area, gfp_t gfp_mask,
> return area->addr;
>
> fail:
> - vfree(area->addr);
> + defer_vm_area_cleanup(area);
> return NULL;
> }
>
> --
> 2.47.3
>
next prev parent reply other threads:[~2025-09-18 2:59 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-09-15 13:40 [PATCH v2 00/10] __vmalloc() and no-block support(v2) Uladzislau Rezki (Sony)
2025-09-15 13:40 ` [PATCH v2 01/10] lib/test_vmalloc: add no_block_alloc_test case Uladzislau Rezki (Sony)
2025-09-15 13:40 ` [PATCH v2 02/10] lib/test_vmalloc: Remove xfail condition check Uladzislau Rezki (Sony)
2025-09-15 13:40 ` [PATCH v2 03/10] mm/vmalloc: Support non-blocking GFP flags in alloc_vmap_area() Uladzislau Rezki (Sony)
2025-09-18 2:56 ` Baoquan He
2025-09-15 13:40 ` [PATCH v2 04/10] mm/vmalloc: Avoid cond_resched() when blocking is not permitted Uladzislau Rezki (Sony)
2025-09-15 17:11 ` Michal Hocko
2025-09-16 15:28 ` Uladzislau Rezki
2025-09-16 18:08 ` Michal Hocko
2025-09-17 5:22 ` Uladzislau Rezki
2025-09-18 2:57 ` Baoquan He
2025-09-15 13:40 ` [PATCH v2 05/10] mm/vmalloc: Defer freeing partly initialized vm_struct Uladzislau Rezki (Sony)
2025-09-18 2:59 ` Baoquan He [this message]
2025-09-15 13:40 ` [PATCH v2 06/10] mm/vmalloc: Handle non-blocking GFP in __vmalloc_area_node() Uladzislau Rezki (Sony)
2025-09-18 3:01 ` Baoquan He
2025-09-15 13:40 ` [PATCH v2 07/10] mm/kasan: Support non-blocking GFP in kasan_populate_vmalloc() Uladzislau Rezki (Sony)
2025-09-18 3:02 ` Baoquan He
2025-09-18 14:56 ` Andrey Ryabinin
2025-09-15 13:40 ` [PATCH v2 08/10] kmsan: Remove hard-coded GFP_KERNEL flags Uladzislau Rezki (Sony)
2025-09-15 13:40 ` [PATCH v2 09/10] mm: Skip might_alloc() warnings when PF_MEMALLOC is set Uladzislau Rezki (Sony)
2025-09-15 17:16 ` Michal Hocko
2025-09-16 15:23 ` Uladzislau Rezki
2025-09-15 13:40 ` [PATCH v2 10/10] mm/vmalloc: Update __vmalloc_node_range() documentation Uladzislau Rezki (Sony)
2025-09-15 17:13 ` Michal Hocko
2025-09-16 15:34 ` Uladzislau Rezki
2025-09-16 0:34 ` kernel test robot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aMt1myQHpxit3Zbo@MiWiFi-R3L-srv \
--to=bhe@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mhocko@kernel.org \
--cc=mhocko@suse.com \
--cc=urezki@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.