From: Hao Li <hao.li@linux.dev>
To: Longlong Xia <xialonglong2025@163.com>
Cc: vbabka@kernel.org, harry@kernel.org, akpm@linux-foundation.org,
cl@gentwo.org, rientjes@google.com, roman.gushchin@linux.dev,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
xialonglong@kylinos.cn
Subject: Re: [PATCH 1/1] mm/slab_common: reject zero object_size before calculate_alignment
Date: Tue, 25 Aug 2026 20:59:08 +0800 [thread overview]
Message-ID: <ao2RAVvU5g9Am7_J@fedora> (raw)
In-Reply-To: <20260824092454.1693745-1-xialonglong2025@163.com>
On Mon, Aug 24, 2026 at 05:24:54PM +0800, Longlong Xia wrote:
> From: Longlong Xia <xialonglong@kylinos.cn>
>
> calculate_alignment() with SLAB_HWCACHE_ALIGN halves ralign in a
> while (size <= ralign / 2) loop. When size is 0, ralign eventually
> reaches 0 and the condition stays true indefinitely, hanging the
> kernel.
>
> kmem_cache_sanity_check() rejected size > KMALLOC_MAX_SIZE but not
> size == 0, and the sanity check is compiled out without
> CONFIG_DEBUG_VM. Add a !object_size check in
> __kmem_cache_create_args(), which is always compiled, and add !size
> to the DEBUG_VM sanity check for diagnostics.
>
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Longlong Xia <xialonglong@kylinos.cn>
> ---
> mm/slab_common.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/mm/slab_common.c b/mm/slab_common.c
> index 657fd75776ea..209fe838fe71 100644
> --- a/mm/slab_common.c
> +++ b/mm/slab_common.c
> @@ -102,7 +102,7 @@ static bool kmem_cache_is_duplicate_name(const char *name)
>
> static int kmem_cache_sanity_check(const char *name, unsigned int size)
> {
> - if (!name || in_interrupt() || size > KMALLOC_MAX_SIZE) {
> + if (!name || in_interrupt() || !size || size > KMALLOC_MAX_SIZE) {
> pr_err("kmem_cache_create(%s) integrity check failed\n", name);
> return -EINVAL;
> }
> @@ -354,7 +354,7 @@ struct kmem_cache *__kmem_cache_create_args(const char *name,
> goto out_unlock;
> }
>
> - if (flags & ~SLAB_FLAGS_PERMITTED) {
> + if (!object_size || flags & ~SLAB_FLAGS_PERMITTED) {
under !CONFIG_DEBUG_VM, I think we ignore the sanity_check deliberately, so it
seems we don't need to add !object_size check here. right?
> err = -EINVAL;
> goto out_unlock;
> }
> --
> 2.43.0
>
next prev parent reply other threads:[~2026-08-25 12:59 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 9:24 [PATCH 1/1] mm/slab_common: reject zero object_size before calculate_alignment Longlong Xia
2026-08-25 12:59 ` Hao Li [this message]
2026-08-25 13:46 ` Longlong Xia
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ao2RAVvU5g9Am7_J@fedora \
--to=hao.li@linux.dev \
--cc=akpm@linux-foundation.org \
--cc=cl@gentwo.org \
--cc=harry@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=rientjes@google.com \
--cc=roman.gushchin@linux.dev \
--cc=vbabka@kernel.org \
--cc=xialonglong2025@163.com \
--cc=xialonglong@kylinos.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.