From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f50.google.com (mail-ej1-f50.google.com [209.85.218.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2030C41F5D4 for ; Thu, 6 Aug 2026 08:51:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786006276; cv=none; b=M/V4LAWJf2iWXTl3tgwPpgSA+3fqUfHIMY4kn7os681xlfwinwIvfYqkODg5sMxEIS/UgX/hq6U28potlU5TF30fOg9GG3QzEM9/ANqhLCvni/UyzokzXk8NOm1oNO+lFrfvHTZOEBcaGzkjuB0IeU8p0sZ0lpMQm9tZ9c4CKGw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786006276; c=relaxed/simple; bh=yNUPuuUhViTaM9u07LJ6jVcLW/UfOf0MzZKD4sGIweE=; h=From:Date:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=X13tX2Q3lI1oiQpXVTAFrBXySjF04P+abFZikq81PoN2TKYH0vVF75tkYkBysyzS/9JFhegMwVY9lJS/acZQkWH2O+VfGMTZ3dbxSLjqZVoqdCfK9suWRToilvymbcCBlObMYZCKOLLCNi9m7cFTTOxMPTD/b2NGJr617Dm7Vhg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SVE5JM9i; arc=none smtp.client-ip=209.85.218.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SVE5JM9i" Received: by mail-ej1-f50.google.com with SMTP id a640c23a62f3a-c15d3cd51b2so256512466b.3 for ; Thu, 06 Aug 2026 01:51:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786006270; x=1786611070; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:date:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=Avz2UJlhCHkynyE4R7iSfC5vbrndaS9xUbSktAymKgM=; b=SVE5JM9ilz+J+I4f9aDhfKONBPwZkSKnTVihleJ274vfuvTFKuNHzK1OgsAdBZ9nyU kYxBZQTg2kLS90X73iYnqPCTdhq6i7frCVhCvrpBIrT+VtOwYRefIe12BQ76CbWSBg2i LN/V8px7QddBaL2wW2CmKoyEKBtFJE87kyjGxoRH4HO/RHk9IlqplP9KtNcfmElDTuSl JKxLRdMpJx+uTeIHm8tdPzIPMLQ+UX+aYe3Mz9Wg+7cThg6bXCtdwPqdwerRm+Q5r659 SBrOjq70GSnkCRQleHGj193az8va+GkNqlwDwADaCJzjHl9ydZ81S6YlwUZ73IrxvnDO +E4w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786006270; x=1786611070; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Avz2UJlhCHkynyE4R7iSfC5vbrndaS9xUbSktAymKgM=; b=cjFCfvrN0cC2Q71nKRBn/XeymUgv+pfNosdIl5Y7Oed9gP5GnZSHvP5lCD3aSMc9bU nbxDgir7Vfq3LRkjvalTMbQkTIXV9HwR59HtyTCwL9iBMslsCvEVtltsZZQpxoIUfmp0 FxhP9WdpBKO635PKFeXyWKLOFZVPa3kLvM2J1gdk9bLO4c3EaTs6sqxcYpYvst7tSK5O ZSgT2Y9nv/fJ1OsJ3eXB2VRUvcoMR2XsuhDhIgm4l8bDtz3BCJz/4PTjYzkG/ivJ/QEj l02Ln8MyvPzSP1V7HwvKdZohJiD33bEMpHzttyUZG4ozzlX683lnm+PQctmpisn5STvt HfvQ== X-Forwarded-Encrypted: i=1; AHgh+Rraj0bt8faV00Hch1XjshfInNWWuc2rj5w8iC76WZgvaUGwOx93mBg7dgJr44fZM8NkKIfr2GRJXkeULcg=@vger.kernel.org X-Gm-Message-State: AOJu0YwFR8rOg3QOh1r9NkSM1cOjox5WBHKaRg+j9kXaRysFrjIegcM6 O1i7lPSEEcpGarsr8B1x0WDbTZUzjwmV4kLdkCjdiWzdanCcn1bI+ruF X-Gm-Gg: AR+sD123rNf7SwyFwwSbeX2ldFauU2dYlpPnGlhnyx9rDjAJTDCiV10ojxEA75WNhZD rzfjakoKNHXD+NqIhaeHy9xjfrJEGS8n4fIBf0anWdiBF7MeCWcNXBKip5y9HjhFAX7OAacw2Qh NqaXteEMNzpafllepq/LZCen7rAX+S5ifH38FJA1Uj9qfq2v4IgA0Jg2WREIKH/MeyHijWCgpdo xvq4bncsX95X2N6P3DZaND4/HmKxGEj4kdZdhcqEoWZUhc8+OiDyQIqxq88bWe3R38apOSVabBy q4jUyiMaPfayGh//fM8SefYo80PbMLgANz83JmJy5j9BhE9oMOEwpU9PmiPdX6URVRlR/SzHTJz pXAaQmvfDv/TTFyMPkjwoS+qkaFim8lJmMbdgcREYYUVTR7todf6HAQxinrZSVnIjhmAoPhDk50 JBAebawnAolqESpO1FASMCZBFTVXQ= X-Received: by 2002:a17:906:fe05:b0:c16:9edc:612e with SMTP id a640c23a62f3a-c2039ce6007mr719138066b.3.1786006269984; Thu, 06 Aug 2026 01:51:09 -0700 (PDT) Received: from milan ([2001:9b1:d5a0:a500::24b]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c2036254060sm234607666b.24.2026.08.06.01.51.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 06 Aug 2026 01:51:09 -0700 (PDT) From: Uladzislau Rezki X-Google-Original-From: Uladzislau Rezki Date: Thu, 6 Aug 2026 10:51:07 +0200 To: Andrew Morton Cc: Uladzislau Rezki , Artem Lytkin , linux-mm@kvack.org, willy@infradead.org, shivamkalra98@zohomail.in, linux-kernel@vger.kernel.org Subject: Re: [PATCH v4] mm/vmalloc: make vm_struct.nr_pages an unsigned long Message-ID: References: <20260730130923.9e71be5f477ee3db333cf0f8@linux-foundation.org> <20260801114915.115224-1-iprintercanon@gmail.com> <20260801115202.ccba41ddac9f7a4f6fb1ca9f@linux-foundation.org> <20260803173935.132156ba2b86293ffecb0e8f@linux-foundation.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260803173935.132156ba2b86293ffecb0e8f@linux-foundation.org> On Mon, Aug 03, 2026 at 05:39:35PM -0700, Andrew Morton wrote: > On Sun, 2 Aug 2026 17:52:26 +0200 Uladzislau Rezki wrote: > > > On Sat, Aug 01, 2026 at 11:52:02AM -0700, Andrew Morton wrote: > > > On Sat, 1 Aug 2026 14:49:15 +0300 Artem Lytkin wrote: > > > > > > > ... > > > > > Ulad, AI review suggests that vrealloc() has an issue handling > > > __GFP_ZERO. Can you please check? > > > > > > https://sashiko.dev/#/patchset/20260801114915.115224-1-iprintercanon@gmail.com > > > > > I have checked. I think the AI is missing at least one point. > > AI argument which is: > > > > > > If a driver initially allocates memory using vmalloc() without __GFP_ZERO > > (leaving spare page capacity uninitialized), and then grows the allocation > > using vrealloc() with __GFP_ZERO, the caller expects the newly exposed bytes > > to be zeroed. > > > > > > In the vrealloc_node_align_noprof() header documentation there is a statement: > > > > > > * If __GFP_ZERO logic is requested, callers must ensure that, starting with the > > * initial memory allocation, every subsequent call to this API for the same > > * memory allocation is flagged with __GFP_ZERO. Otherwise, it is possible that > > * __GFP_ZERO is not fully honored by this API. > > > > > > AI argument violates the documentation, i.e. mixing __GFP_ZERO is not allowed. > > Sashiko is talking about the initial allocation not using __GFP_ZERO > but vrealloc() *does* use __GFP_ZERO. The documentation you quoted > doesn't address that case? > But this is not allowed according to doc :) ... callers must ensure that, starting with the initial memory allocation ... Also, AI describes the situation like: vmalloc() vrealloc(grow, since need more) i.e. from the description: and then grows the allocation using vrealloc() with __GFP_ZERO, the caller expects the newly exposed bytes to be zeroed. and it will be zeroed in fact, because the path would be: need_realloc: /* TODO: Grow the vm_area, i.e. allocate and map additional pages. */ n = __vmalloc_node_noprof(size, align, flags, nid, __builtin_return_address(0)); if (!n) return NULL; and not the one which AI pointed to. The real scenario is: 1. vmalloc(!GFP_ZERO) - alloc size 10 2. vrealloc(!GFP_ZERO) - realloc to size 5 3. vrealloc(GFP_ZERO) - realloc back to 10. 3 - will not zeroed. As noted in doc ZERO should be used starting from the beginning [1]. But in __most__ cases it will be zeroed anyway because we free/unmap tail pages and if: /* * Free tail pages when shrink crosses a page boundary. * * Skip huge page allocations (page_order > 0) as partial * freeing would require splitting. * * Skip VM_FLUSH_RESET_PERMS, as direct-map permissions must * be reset before pages are returned to the allocator. * * Skip VM_USERMAP, as remap_vmalloc_range_partial() validates * mapping requests against the unchanged vm->size; freeing * tail pages would cause vmalloc_to_page() to return NULL for * the unmapped range. * * Skip if either GFP_NOFS or GFP_NOIO are used. * kmemleak_free_part() internally allocates with * GFP_KERNEL, which could trigger a recursive deadlock * if we are under filesystem or I/O reclaim. */ if (new_nr_pages < vm->nr_pages && !vm_area_page_order(vm) && !(vm->flags & (VM_FLUSH_RESET_PERMS | VM_USERMAP)) && gfp_has_io_fs(flags)) { is true the next grow with GFP_ZERO will be zeroed. For huge alloc it will not be zeroed and for other conditions. > Also, developers don't read documentation ;) What happens if some > caller *does* use vmalloc(!__GFP_ZERO) then vrealloc(__GFP_ZERO)? > Silent misbehavior would be bad - it would be good if vrealloc() were > to drop a WARN() then ignore the __GFP_ZERO. > > > --- a/mm/vmalloc.c > > +++ b/mm/vmalloc.c > > @@ -4294,11 +4294,6 @@ EXPORT_SYMBOL(vzalloc_node_noprof); > > * __GFP_THISNODE flag should be set, otherwise the function will try to avoid > > * reallocation and possibly disregard the specified @nid. > > * > > - * If __GFP_ZERO logic is requested, callers must ensure that, starting with the > > - * initial memory allocation, every subsequent call to this API for the same > > - * memory allocation is flagged with __GFP_ZERO. Otherwise, it is possible that > > - * __GFP_ZERO is not fully honored by this API. > > - * > > * Requesting an alignment that is bigger than the alignment of the existing > > * allocation will fail. > > * > > @@ -4415,13 +4410,12 @@ void *vrealloc_node_align_noprof(const void *p, size_t size, unsigned long align > > * We already have the bytes available in the allocation; use them. > > */ > > if (size <= vm->nr_pages << PAGE_SHIFT) { > > - /* > > - * No need to zero memory here, as unused memory will have > > - * already been zeroed at initial allocation time or during > > - * realloc shrink time. > > - */ > > - vm->requested_size = size; > > kasan_vrealloc(p, old_size, size); > > + > > + if (want_init_on_alloc(flags)) > > + memset((void *)p + old_size, 0, size - old_size); > > + > > + vm->requested_size = size; > > return (void *)p; > > } > > OK, thanks, I'll assume you'll prepare this for real when convenient. > OK. I will prepare something and send out the patch after testing. -- Uladzislau Rezki