From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mta1.migadu.com (out-73.mta1.migadu.com [95.215.58.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7BC353A59BA for ; Mon, 10 Aug 2026 09:40:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.73 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786354847; cv=none; b=Eylfz3RopPNShcWRrl1bXMgAJGEHnBaEod4VFDXR6LBagu2+k8c36oh0MIutEVQ63Jqj8sAttDSCtcB56D2VIPVmMRDHFZKXlHCzASthN0NrOS641DkoL1x/CBvR8cU7wZ/FrpOt0NU3JbEAdtbdUFEjhpg5wKucLBgrQftW078= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786354847; c=relaxed/simple; bh=UIktgvsGULxryLMUxmq1Oes31GkwUNqAwQdlsQG+ahw=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=VFGxoKuHIUyEansZQ6DU62EujcpNJTDbqsvZOzqC5wcg5rDIdVEyYzzSULV77vHU/YmirJJNVdA1xXRyWwUQ8+c5AiL/pUpgRMn9igfHuKpGDfheDEMhUF/n9PhSIwjE6sLbnatp6fWhMUV/6v/02Bc5soOBuRe/yPpGlhiFnAA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=Cl56nNtM; arc=none smtp.client-ip=95.215.58.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="Cl56nNtM" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=UIktgvsGULxryLMUxmq1Oes31GkwUNqAwQdlsQG+ahw=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1786354843; v=1; x=1786959643; b=Cl56nNtMgk/RljPg3vz0g8cMPkcI0Yoz227xtw147wMBg9kGuixnDBKTcJ1gHZhYcO2mYGMb /Bs4Xm5iePFeg++wGzw5RMwUjtQnItD2cVmqldDgidcxN3rKqx/GPk43W6Ya0eQ9mc00mmnhtkl J7QzVzbu0yzvovEBMJx9Y5YY= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.169) by mta10.migadu.com with ESMTPS id fd542074912682a9; Mon, 10 Aug 2026 09:39:37 +0000 Authentication-Results: mta10.migadu.com; none X-Migadu-Scanner: mta10.migadu.com From: Hao Ge To: Suren Baghdasaryan , Andrew Morton , Luis Chamberlain , Petr Pavlu , Daniel Gomez , Sami Tolvanen , Aaron Tomlin Cc: linux-modules@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, Hao Ge Subject: [PATCH v4 0/2] alloc_tag: fix undetected compressed tag overflow when profiling is disabled Date: Mon, 10 Aug 2026 17:39:53 +0800 Message-Id: <20260810093955.153015-1-hao.ge@linux.dev> X-Mailer: git-send-email 2.25.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit v3 was a single patch. After discussion with Suren and Andrew we went for a more graceful approach: rather than failing the module load on overflow, let it load without profiling. Once profiling is disabled, codetag_needs_module_section() returns false, so on retry the codetag section is placed as regular module data. A new patch (1/2) is added to move release_module_tags() above reserve_module_tags(), since the overflow path now has to call it and the helper sits below it. release_module_tags() is what module unload calls to drop a module's reservation from the maple tree. By the time reserve_module_tags() detects the overflow it has already stored that reservation, and the -EAGAIN return skips vm_module_tags_populate(), so the backing pages never get mapped. If reserve_module_tags() returns without calling release_module_tags(), the stale entry keeps pointing at that unmapped range; when the module is later unloaded, release_module_tags() walks it and panics. Tested on an x86_64 virtual machine: # insmod overflow_tag.ko # dmesg With module overflow_tag there are too many tags to fit in 13 page flag bits. Memory allocation profiling is disabled! # rmmod overflow_tag The module loads without profiling. Changes in v4: - add a new patch (1/2) to move release_module_tags() above reserve_module_tags(); the overflow fix is 2/2 - release the reservation on the -EAGAIN path - return -EAGAIN instead of -ENOMEM so the module can still load without profiling (Suren) - reset sh_addr, mem[type].size and sym/str SHF_ALLOC before retry - skip percpu counters in load_module() when profiling is off Changes in v3: - use pr_warn_once() instead of pr_warn() - return -ENOMEM instead of -ENOSPC (Suren) - expand the commit message to describe the /proc/allocinfo impact (Andrew) Changes in v2: - return an error after shutdown_mem_profiling() to skip vm_module_tags_populate() v1: https://lore.kernel.org/all/20260804064408.105033-1-hao.ge@linux.dev/ v2: https://lore.kernel.org/all/20260804122038.190270-1-hao.ge@linux.dev/ v3: https://lore.kernel.org/all/20260805090633.141001-1-hao.ge@linux.dev/ Hao Ge (2): alloc_tag: move release_module_tags() above reserve_module_tags() alloc_tag: fix undetected compressed tag overflow when profiling is disabled kernel/module/main.c | 17 ++++++++- mm/alloc_tag.c | 103 +++++++++++++++++++++++++++------------------------ 2 files changed, 69 insertions(+), 51 deletions(-) -- 2.25.1