From: Sang-Heon Jeon <ekffu200098@gmail.com>
To: Andrew Morton <akpm@linux-foundation.org>,
Harry Yoo <harry@kernel.org>, Vlastimil Babka <vbabka@kernel.org>
Cc: Christoph Lameter <cl@gentwo.org>,
David Rientjes <rientjes@google.com>, Hao Li <hao.li@linux.dev>,
linux-mm@kvack.org, Roman Gushchin <roman.gushchin@linux.dev>,
stable@vger.kernel.org
Subject: [PATCH] mm/slub: clamp slab_min_order to MAX_PAGE_ORDER
Date: Thu, 8 Oct 2026 01:34:02 +0900 [thread overview]
Message-ID: <20261007163403.1643768-1-ekffu200098@gmail.com> (raw)
setup_slub_max_order() clamps slab_max_order to MAX_PAGE_ORDER, but
setup_slub_min_order() has no such clamp.
The buddy allocator cannot allocate more than 2^MAX_PAGE_ORDER pages
at once, so slab_min_order above it makes no sense.
If slab_min_order is set above MAX_PAGE_ORDER, it can even panic at
boot or invoke undefined behavior in order_objects().
So clamp slab_min_order to MAX_PAGE_ORDER as well.
Fixes: 818cf5909701 ("slub: enforce MAX_ORDER")
Cc: stable@vger.kernel.org
Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com>
---
QEMU-based test results
- Booted with "slab_min_order=20"
1) AS-IS (before fix)
[ 0.094926] mem auto-init: stack:all(zero), heap alloc:off, heap free:off
[ 0.097776] Kernel panic - not syncing: Creation of kmalloc slab kmem_cache_node size=64 failed. Reason -22
[ 0.099542] CPU: 0 UID: 0 PID: 0 Comm: swapper Not tainted 7.2.0 #1 PREEMPT(undef)
[ 0.100903] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 0.102607] Call Trace:
[ 0.103040] <TASK>
[ 0.103417] vpanic+0x32a/0x4b0
[ 0.103976] panic+0x5e/0x60
[ 0.104491] create_boot_cache+0xe3/0xf0
[ 0.105194] kmem_cache_init+0x12d/0x410
[ 0.105890] ? mem_init+0x1fc/0x210
[ 0.106521] mm_core_init+0xba/0x140
[ 0.107153] start_kernel+0x441/0x8b0
[ 0.107814] x86_64_start_reservations+0x18/0x30
[ 0.108638] x86_64_start_kernel+0x10c/0x120
[ 0.109401] common_startup_64+0x13e/0x158
[ 0.110145] </TASK>
[ 0.110584] ---[ end Kernel panic - not syncing: Creation of kmalloc slab kmem_cache_node size=64 failed. Reason -22 ]---
2) TO-BE (after fix)
[ 0.008976] mem auto-init: stack:all(zero), heap alloc:off, heap free:off
[ 0.011366] SLUB: HWalign=64, Order=10-10, MinObjects=0, CPUs=4, Nodes=1
Also, I'm not sure about the Fixes commit. Please change it if you know
a better one.
---
mm/slub.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/mm/slub.c b/mm/slub.c
index 1559cbace469..8400df7c222e 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -8354,6 +8354,8 @@ static int __init setup_slub_min_order(const char *str, const struct kernel_para
if (ret)
return ret;
+ slub_min_order = min_t(unsigned int, slub_min_order, MAX_PAGE_ORDER);
+
if (slub_min_order > slub_max_order)
slub_max_order = slub_min_order;
base-commit: d755441b7672c74f29d1241ffdd2b067ecab1ca0
--
2.43.0
next reply other threads:[~2026-10-07 16:34 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 16:34 Sang-Heon Jeon [this message]
2026-10-07 17:47 ` [PATCH] mm/slub: clamp slab_min_order to MAX_PAGE_ORDER Harry Yoo
2026-10-08 15:06 ` Sang-Heon Jeon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007163403.1643768-1-ekffu200098@gmail.com \
--to=ekffu200098@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=cl@gentwo.org \
--cc=hao.li@linux.dev \
--cc=harry@kernel.org \
--cc=linux-mm@kvack.org \
--cc=rientjes@google.com \
--cc=roman.gushchin@linux.dev \
--cc=stable@vger.kernel.org \
--cc=vbabka@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox