From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 839282DC765 for ; Tue, 25 Nov 2025 08:44:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764060266; cv=none; b=UeymZDISPl0bDnhyCRwXBAl6BEYso1C5jRYhztzM/9WiDnTgtsjyRZhxoOE8Fq/EMRmXEicxo77OvB1qhPehT5ctqspuaNLYiaEyAJ3Fnjg5+Y8dlhtuioD9aKuScGxUc5LMmCUnUn+LLryP0+ZDq2mE+ixp7K+QO3hcFhI2Chg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764060266; c=relaxed/simple; bh=15mAc/tt2wGXGcNMGP4LyBLJEQVFKv62vriGEdpK09U=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=i74xszSJu/KqrA+PutEJVB50xYJVPoYDwEqYZ7YcunjYooVUQKEe9P0mr95bPssIqioVTMCQ71G41sw+xCrER0gv7RGrWDJTtR2nsLxyR+rvU3Phi4rrf9R475Rz04BdbhYsU/li7mcIG7ylcOADccSXk/c8SYF9FOB7OMOltgw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=T6fqUPJV; arc=none smtp.client-ip=209.85.221.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="T6fqUPJV" Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-42b31507ed8so4405129f8f.1 for ; Tue, 25 Nov 2025 00:44:24 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1764060263; x=1764665063; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=CpZDRvAPn9u/AtsSK5qeLHqpt9GSFf5AtPp3g42dBA0=; b=T6fqUPJVn+5KL3UPVKbWh8q1xNjJHnsmFMLnU6HB2k17Rjahl/NALgdsrTKDox+0Bq uCMedIbGoJcutdfIFyxLcrNCTNOCDNmWCKgSehvG6I9u6D6VRnGbeaIWmWVXZjMi0Uth DwdfEbk0q0sfi9dLYT2QXPxGu6mRfDEr0fsgMiJ62iospGfiPEFyPCam7x1x3kFaoPzg kkellsvDXI5iwa3wPnbJBocZ8Ij9DOu8V94KDS+tlNnmOHbR4IV/RvzNPb78Mq3dgO98 OuSRH36/XB+zI1cRHywIpPMGvk7J4jsFlOIC5m9PDwhTfJCrM0LWUS3lfx48GvTZ5Kg1 IKvQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764060263; x=1764665063; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=CpZDRvAPn9u/AtsSK5qeLHqpt9GSFf5AtPp3g42dBA0=; b=pRioPHFNleOY3yCI1l4Nll95fzILWadTT2tcPagIWnOD9X/ENCDvTj0VNzbHpRBePr T+4Ju1VEPghtD6lH0ezAHi9ERxMdfOATXpWhMSwdU7aFZYvaMoHeot7UcIxPTE4LcaPA 4f4btamKfMgFYc7HEzSRxETmvVJIHYD0feVbqvhJWCb3yHxfpexZp52XCb/DTJ+B+BlN ewF0Y8LV05DpNJhwdEM1iJOb5dj/ROq93Vq7ZxkFvF1J0nA0mVmEDtplAQGC81KCFpfj tBWJJybrGIWNQ/s9LylZwZNwuhV+Zb22nfZrPNsuaO9qmYVVguNcXY/GbaUPJppJAEOK QkOA== X-Forwarded-Encrypted: i=1; AJvYcCWcZegHdvKZZI3S7xxiEpYLUV7RkK+lyt5HDXUv7KJmO5opHzeIfHLb3n/qjjnZRWepdwy1UbeLhNtz8Fg=@vger.kernel.org X-Gm-Message-State: AOJu0YxwXYNBmL0UsWnmJKj2b441nggjmaSOkF2/W5ll4m4A2x7TZLBs q6ICGbGOuZ61YMcCmH3LxOrpHG01NrvZomS6yXFHXKcHWAvXO+WxDNr9URcNmm5uf0U= X-Gm-Gg: ASbGncu6bXEJQa7/5gzeeLxxCwpNjvO9KzLHU7BXXEyJE3ojNFNHyTFRmbU1Gjz1pgY 9azB9ACa7GeLYsr7WXVZ6CLl0gb0TNAQnRLrp0LMYc87Z4HDBGMM9HBKHOKPvGR6I0ER493hHIk 6/MWsWGMXkVWUCSNsymilRY9A9Zrulud5bk0Y9ru0fziDEdmT5SrEBBmcckmbp/jZgexhZsH1X1 DKwYTlUh8yj7BhK07kzoxxs5OCeS0KeEWH2XWZpar9211OCWfvfV5a+oXUZqcwwV/A/Z2H0zlrF dv3zk6fep6kj/6gTU4Dx0zYNdCN9ICIZuiiTfp5Kn9sUa1pFImxkiuvOXBQ4jZwtmsXoV25uEkh up/BlhbOT+0dJ5VxbgKW+n5meJ8t/uJlAhLYNns+K3WGJDzYqIOdIsL/XnbnqmeZiNyRLbg800/ 7a9tkO5A24KOKLIm+esn5lNi85HchLR1iVt1I= X-Google-Smtp-Source: AGHT+IGrfzbQdwa3uuXjiaNeFV9Dw3QhirPceLI13Twim5XwJ+yUCFDBMt+GpCy2FfrTz80TdBlq2g== X-Received: by 2002:a05:6000:2507:b0:429:c711:229a with SMTP id ffacd0b85a97d-42e0f3626f0mr1935196f8f.56.1764060262771; Tue, 25 Nov 2025 00:44:22 -0800 (PST) Received: from localhost (109-81-29-251.rct.o2.cz. [109.81.29.251]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-42cb7f2e454sm32839188f8f.2.2025.11.25.00.44.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Nov 2025 00:44:22 -0800 (PST) Date: Tue, 25 Nov 2025 09:44:18 +0100 From: Michal Hocko To: Joshua Hahn Cc: Andrew Morton , Vlastimil Babka , Jonathan Corbet , Mike Rapoport , linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, kernel-team@meta.com Subject: Re: [PATCH v2 1/2] mm/mm_init: Introduce a boot parameter for check_pages Message-ID: References: <20251124225408.2243564-1-joshua.hahnjy@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20251124225408.2243564-1-joshua.hahnjy@gmail.com> On Mon 24-11-25 14:54:06, Joshua Hahn wrote: > Use-after-free and double-free bugs can be very difficult to track down. > The kernel is good at tracking these and preventing bad pages from being > used/created through simple checks gated behind "check_pages_enabled". > > Currently, the only ways to enable this flag is by building with > CONFIG_DEBUG_VM, or as a side effect of other checks such as > init_on_{alloc, free}, page_poisoning, or debug_pagealloc among others. > These solutions are powerful, but may often be too coarse in balancing > the performance vs. safety that a user may want, particularly in > latency-sensitive production environments. > > Introduce a new boot parameter "check_pages", which enables page checking > with no other side effects. It takes kstrbool-able inputs as an argument > (i.e. 0/1, true/false, on/off, ...). This patch is backwards-compatible; > setting CONFIG_DEBUG_VM still enables page checking. Arguing with performance without any performance numbers is not really convincing but the change makes some sense to me even without that. DEBUG_VM is just everything-in-one-bag thing which is not suitable for production use and bad_page checks might still be valuable for such a use. > Signed-off-by: Joshua Hahn Acked-by: Michal Hocko > --- > v1 --> v2: > - Changed check_pages from a build config into a boot config, as suggested > by Vlastimil. > - Introduced the second patch, which decouples page checking from > init_on_page_alloc and init_on_page_free. > --- > > Documentation/admin-guide/kernel-parameters.txt | 8 ++++++++ > mm/mm_init.c | 11 ++++++++++- > 2 files changed, 18 insertions(+), 1 deletion(-) > > diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt > index 6c42061ca20e..0ba9561440a7 100644 > --- a/Documentation/admin-guide/kernel-parameters.txt > +++ b/Documentation/admin-guide/kernel-parameters.txt > @@ -669,6 +669,14 @@ > nokmem -- Disable kernel memory accounting. > nobpf -- Disable BPF memory accounting. > > + check_pages= [MM,EARLY] Enable sanity checking of pages after > + allocations / before freeing. This adds checks to catch > + double-frees, use-after-frees, and other sources of > + page corruption by inspecting page internals (flags, > + mapcount/refcount, memcg_data, etc.). > + Format: { "0" | "1" } > + Default: 0 (1 if CONFIG_DEBUG_VM is set) > + > checkreqprot= [SELINUX] Set initial checkreqprot flag value. > Format: { "0" | "1" } > See security/selinux/Kconfig help text. > diff --git a/mm/mm_init.c b/mm/mm_init.c > index c6812b4dbb2e..01d46efc42b4 100644 > --- a/mm/mm_init.c > +++ b/mm/mm_init.c > @@ -2525,6 +2525,14 @@ early_param("init_on_free", early_init_on_free); > > DEFINE_STATIC_KEY_MAYBE(CONFIG_DEBUG_VM, check_pages_enabled); > > +static bool _check_pages_enabled_early __initdata; > + > +static int __init early_check_pages(char *buf) > +{ > + return kstrtobool(buf, &_check_pages_enabled_early); > +} > +early_param("check_pages", early_check_pages); > + > /* > * Enable static keys related to various memory debugging and hardening options. > * Some override others, and depend on early params that are evaluated in the > @@ -2591,7 +2599,8 @@ static void __init mem_debugging_and_hardening_init(void) > * of struct pages being allocated or freed. With CONFIG_DEBUG_VM it's > * enabled already. > */ > - if (!IS_ENABLED(CONFIG_DEBUG_VM) && want_check_pages) > + if (!IS_ENABLED(CONFIG_DEBUG_VM) && (_check_pages_enabled_early || > + want_check_pages)) > static_branch_enable(&check_pages_enabled); > } > > -- > 2.47.3 -- Michal Hocko SUSE Labs