From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9BA5A264A86 for ; Sun, 19 Jul 2026 15:21:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784474479; cv=none; b=RzR2B65n5Jn0ZpFCuQT5gogcv/NLkYDPfM1qlXinu/JEymw+Qy2wuir7SxcZU5cA8zJY/god5m6gAGb7nID2RMrcIa2DY657DtA20uZx1aSfxgTOt5eXeXId7Y76KtVePENPheLjHRirnr/tJV8zVw8a6QkY/HYmPg6X14145dk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784474479; c=relaxed/simple; bh=12sRXBEhI8qbDJ23neVCbttx22CsuuvcoveT87LowmQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=dAOh2np60SbN0SMVlxV++RZi6+F6YwqX9G37fCCE85qgfrGG+FCFmovlOpvZZ1gocerQdHlSKLBvjLiAoGgfrxduHL2swhk1zYv7jdIbUrhnfKHb9KsxODkaV5NORaNqHGx8E5kNRlYAUwhj+le7HhLMKZxusjamqIDiKOEXMGQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=oxXrnjkY; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="oxXrnjkY" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66JECJMO3629002; Sun, 19 Jul 2026 15:21:05 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:message-id :mime-version:subject:to; s=pp1; bh=BY/63bZJyLzxCE2BpeFSDlQRj/fi Wkd4w2gwfbjWu+0=; b=oxXrnjkY2IZAMtS1G19eQhblMMSiCVtFyQ2mSQAOUT70 LooLlcfowxh2xSH+xBUvtwOvp5bUXC0VDZnwUd/OB+Gaq15njZtesi27N5EyXRIs vaGiFcTjfOeR3ZHbkeZmh/ONLb4os705CIRIKZ5zjOtLITJPHFkncSlu2L4J0aRS Be6/HluOhyItAzFfnRpkGWmiWYkoADLENP3LkMoXkjgSRXr+gKNh+eLHhEdH4Xqf vIJlnpA0VFtRH7w6RN7Aw4fESrHlTfcYLTwnE4dsSN7HcRcigF3fm0G3iZAUu2J7 VUJ987acy8AigzyVXhNSU0nmaL5d4txarh15GtAO2g== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fg77juqky-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sun, 19 Jul 2026 15:21:05 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 66JFJcha003012; Sun, 19 Jul 2026 15:21:04 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fgnagsyk0-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sun, 19 Jul 2026 15:21:04 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (smtpav03.fra02v.mail.ibm.com [10.20.54.102]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 66JFL2dL48628054 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sun, 19 Jul 2026 15:21:02 GMT Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8AFDA20043; Sun, 19 Jul 2026 15:21:02 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 39A6D20040; Sun, 19 Jul 2026 15:21:00 +0000 (GMT) Received: from li-a84c74cc-2b13-11b2-a85c-acdd023f0674.ibm.com.com (unknown [9.43.82.60]) by smtpav03.fra02v.mail.ibm.com (Postfix) with ESMTP; Sun, 19 Jul 2026 15:20:59 +0000 (GMT) From: Nilay Shroff To: Peter Zijlstra , Ingo Molnar , Will Deacon , Boqun Feng , Waiman Long , linux-kernel@vger.kernel.org Cc: Nilay Shroff , "Shin'ichiro Kawasaki" , Geliang Tang Subject: [PATCH] lockdep: Fix subclass resource leak in lockdep_unregister_key() Date: Sun, 19 Jul 2026 20:50:03 +0530 Message-ID: <20260719152015.237188-1-nilay@linux.ibm.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=HJXz0Itv c=1 sm=1 tr=0 ts=6a5ceb61 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=JF9118EUAAAA:8 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=q9tL8JvT_fKMGbGa0EwA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=xVlTc564ipvMDusKsbsT:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzE5MDE2OCBTYWx0ZWRfX5Vmc1Z1ZGXfg YvvwC7zjDFdpS6KGHKVEi+CskXXC4VzuSGnjXI+87SizCUZOiuKSOjNMyvM+HG0D9Z/zdaooLtV 8/3Hg55YufHXJtGFyXzrafi63T2S8+hRtnmIoH6xgbiSvN9MeJ8v/1KQXw6CPFsWwuZLfYyBlaI QkoXJfgDqO5q112+ME+Ni1qGcoXVDh+JSM8Yj5HHf7KagEUX4x3bNnLLsp//VB+J6j2jBq0ioJ1 U7ooxOO1UUnvAjvzzDJ/qPOr7Hl3m/IxJfbBe6xH2XzglX+3XsWya3jlHMtQbsYTjYJOHw0k/rq eX6tlOcxpu03uyfuPKtVD8ZhMxCaCwGyksS8Jgh7M3FEAC+cZdsduJm4mhRLGioVNHPNMxiPbzq FPnong4S09RiTPQqwf7AAyCGs53CYdL+yHoaMtjVHFp+c3ccLMh2wO4oejyCRauS93MsgbIU4BM VCH5dgR35tiOclZrRZw== X-Proofpoint-ORIG-GUID: T758r3UXA59kqEqC_RmKdWKE3tQNIdeh X-Proofpoint-Spam-Info: AW1haW4tMjYwNzE5MDE2OCBTYWx0ZWRfXz9mdlvQv5wfx DC3evdx7ZvQyL20iN891pfOQt1tbspI/pL5wds93KAMfbEbG/JbZs+H5UhYsW/0aMJ0mVkfmTVr aHHLnp+DOIkwjIN+s3uImDqDdGgFNNs= X-Proofpoint-GUID: T758r3UXA59kqEqC_RmKdWKE3tQNIdeh X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-19_05,2026-07-17_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 malwarescore=0 impostorscore=0 clxscore=1011 phishscore=0 spamscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607190168 When a dynamic lock key is unregistered using lockdep_unregister_key(), lockdep routes the cleanup sequence through __lockdep_free_key_range() with a hardcoded size of 1. This layout model assumes that a dynamic key only occupies its base registration address (subclass 0). However, when a lock utilizes nested acquisitions—either implicitly via networking paths (e.g., bh_lock_sock_nested() passing SINGLE_DEPTH_NESTING) or explicitly via mutex_lock_nested()—lockdep calculates virtual class tracking nodes using pointer math offsets: Virtual Class Pointer = Base Address of Key + Subclass Index Because the unregister range size is strictly constrained to 1, lockdep completely skips evaluating adjacent virtual subclass slots (key + 1 through key + 7). Consequently, when dynamic structures (such as per- queue network sockets) are repeatedly created, teardowned, and allocated at fresh memory blocks, the subclass /1 structures and their historical dependency chains are permanently orphaned in the global graph. Over prolonged runtime and frequent reconnect loops, this asymmetry leads to the absolute exhaustion of MAX_LOCKDEP_CHAIN_HLOCKS. Fix this by instructing lockdep_unregister_key() to look ahead across the entire valid subclass allocation block range (MAX_LOCKDEP_SUBCLASSES), ensuring that all related subclass matrix definitions are completely zapped alongside the primary key. Cc: Shin'ichiro Kawasaki Reported-by: Geliang Tang Tested-by: Geliang Tang Signed-off-by: Nilay Shroff --- kernel/locking/lockdep.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/locking/lockdep.c b/kernel/locking/lockdep.c index 2d4c5bab5af8..490904bee63e 100644 --- a/kernel/locking/lockdep.c +++ b/kernel/locking/lockdep.c @@ -6606,7 +6606,7 @@ void lockdep_unregister_key(struct lock_class_key *key) WARN_ON_ONCE(!found && debug_locks); if (found) { pf = get_pending_free(); - __lockdep_free_key_range(pf, key, 1); + __lockdep_free_key_range(pf, key, MAX_LOCKDEP_SUBCLASSES); need_callback = prepare_call_rcu_zapped(pf); nr_dynamic_keys--; } -- 2.53.0