From nobody Tue Jun 16 20:34:56 2026 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 0E11E39B4AD; Wed, 29 Apr 2026 10:28:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777458487; cv=none; b=kLiIdFEW+UyATzvqUQurGtAbr4TRfG5c4cOQwJYMgM++C0LDL5y8jch6DoydOYxU6LlCdZjTNdlK9W2EkxlXQKQ+JGfVDrO8IEfRp2n9YeHIF7QlhuYMHDu1wvuQEQLhYysVvD14MUkAcTnseo8B+1I9bvbBWru46M2aYSMgP1U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777458487; c=relaxed/simple; bh=YrVa8QM82FyivasB4c6vnJvcttIXWoFHfA8m9suAaJs=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=LDq2mBq2Ku+1nBtF7L6DQEx3pgx5lKzdLNL9aY81zMu0/gfclMlQVByAauA35Yi88raL1R3EEtx4azcMyPk/SL0alQLsc7b9ZbDFygF/2CEZoXLjQuvfM3V73wCn3eHUBePZZIc1ex7KutuCivCr8SaA9hn1K/AE+R9jVcd2Gzc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b=opc+blul; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b="opc+blul" Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 338632A68; Wed, 29 Apr 2026 03:27:58 -0700 (PDT) Received: from a080796.blr.arm.com (a080796.arm.com [10.164.21.51]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 5AF023F763; Wed, 29 Apr 2026 03:27:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1777458483; bh=YrVa8QM82FyivasB4c6vnJvcttIXWoFHfA8m9suAaJs=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=opc+blulF41XR2gdMM77FjNEu7ajZWNaYa0gS9RSolSJOFVKz7RXsOzo5BdWPydZx H3d72HfpHJ188WWApaaZeXaPT7fL7GAriBJ2izZYIXt/eOIKW2Ii03okk0tCtlZCno 0t4ESg+0jOqTYdL3fe+4f/92M5fvzvWBLYXP78DQ= From: Dev Jain To: akpm@linux-foundation.org, david@kernel.org, urezki@gmail.com, kees@kernel.org, mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org, arnd@arndb.de Cc: Muhammad Usama Anjum , ljs@kernel.org, Liam.Howlett@oracle.com, vbabka@kernel.org, rppt@kernel.org, surenb@google.com, mhocko@suse.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, tglx@kernel.org, mathieu.desnoyers@efficios.com, linux-arch@vger.kernel.org, ryan.roberts@arm.com, catalin.marinas@arm.com, Dev Jain Subject: [PATCH v4 1/3] vmalloc: add __GFP_SKIP_KASAN support Date: Wed, 29 Apr 2026 15:57:02 +0530 Message-Id: <20260429102704.680174-2-dev.jain@arm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260429102704.680174-1-dev.jain@arm.com> References: <20260429102704.680174-1-dev.jain@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Muhammad Usama Anjum For allocations that will be accessed only with match-all pointers (e.g., kernel stacks), setting tags is wasted work. If the caller already set __GFP_SKIP_KASAN, skip tag setting of vmalloc pages. Before this patch, __GFP_SKIP_KASAN wasn't being used with vmalloc APIs. So it wasn't being checked. Now its being checked and acted upon. Other KASAN modes are unchanged because __GFP_SKIP_KASAN is ignored for them in the page allocator, and in vmalloc too we ignore this flag for them. This is a preparatory patch for optimizing kernel stack allocations. Signed-off-by: Muhammad Usama Anjum Co-developed-by: Ryan Roberts Signed-off-by: Ryan Roberts Co-developed-by: Dev Jain Signed-off-by: Dev Jain Reviewed-by: Catalin Marinas --- include/linux/gfp_types.h | 6 +++--- mm/vmalloc.c | 13 +++++++++---- 2 files changed, 12 insertions(+), 7 deletions(-) diff --git a/include/linux/gfp_types.h b/include/linux/gfp_types.h index 6c75df30a281d..c2bd723c8ec62 100644 --- a/include/linux/gfp_types.h +++ b/include/linux/gfp_types.h @@ -281,9 +281,9 @@ enum { * * %__GFP_SKIP_KASAN makes KASAN skip unpoisoning on page allocation. * Used for userspace and vmalloc pages; the latter are unpoisoned by - * kasan_unpoison_vmalloc instead. For userspace pages, results in - * poisoning being skipped as well, see should_skip_kasan_poison for - * details. Only effective in HW_TAGS mode. + * kasan_unpoison_vmalloc instead. If passed to vmalloc, kasan_unpoison_vm= alloc + * is skipped too. For userspace pages, results in poisoning being skipped= as + * well, see should_skip_kasan_poison for details. Only effective in HW_TA= GS mode. */ #define __GFP_NOWARN ((__force gfp_t)___GFP_NOWARN) #define __GFP_COMP ((__force gfp_t)___GFP_COMP) diff --git a/mm/vmalloc.c b/mm/vmalloc.c index aa08651ec0df6..708ccac293cef 100644 --- a/mm/vmalloc.c +++ b/mm/vmalloc.c @@ -3939,7 +3939,7 @@ static void *__vmalloc_area_node(struct vm_struct *ar= ea, gfp_t gfp_mask, __GFP_NOFAIL | __GFP_ZERO |\ __GFP_NORETRY | __GFP_RETRY_MAYFAIL |\ GFP_NOFS | GFP_NOIO | GFP_KERNEL_ACCOUNT |\ - GFP_USER | __GFP_NOLOCKDEP) + GFP_USER | __GFP_NOLOCKDEP | __GFP_SKIP_KASAN) =20 static gfp_t vmalloc_fix_flags(gfp_t flags) { @@ -3980,6 +3980,9 @@ static gfp_t vmalloc_fix_flags(gfp_t flags) * * %__GFP_NOWARN can be used to suppress failure messages. * + * %__GFP_SKIP_KASAN can be used to skip unpoisoning of mapped pages + * (when prot=3D%PAGE_KERNEL). + * * Can not be called from interrupt nor NMI contexts. * Return: the address of the area or %NULL on failure */ @@ -3993,6 +3996,7 @@ void *__vmalloc_node_range_noprof(unsigned long size,= unsigned long align, kasan_vmalloc_flags_t kasan_flags =3D KASAN_VMALLOC_NONE; unsigned long original_align =3D align; unsigned int shift =3D PAGE_SHIFT; + bool skip_vmalloc_kasan =3D kasan_hw_tags_enabled() && (gfp_mask & __GFP_= SKIP_KASAN); =20 if (WARN_ON_ONCE(!size)) return NULL; @@ -4023,7 +4027,7 @@ void *__vmalloc_node_range_noprof(unsigned long size,= unsigned long align, again: area =3D __get_vm_area_node(size, align, shift, VM_ALLOC | VM_UNINITIALIZED | vm_flags, start, end, node, - gfp_mask, caller); + gfp_mask & ~__GFP_SKIP_KASAN, caller); if (!area) { bool nofail =3D gfp_mask & __GFP_NOFAIL; warn_alloc(gfp_mask, NULL, @@ -4041,7 +4045,7 @@ void *__vmalloc_node_range_noprof(unsigned long size,= unsigned long align, * kasan_unpoison_vmalloc(). */ if (pgprot_val(prot) =3D=3D pgprot_val(PAGE_KERNEL)) { - if (kasan_hw_tags_enabled()) { + if (kasan_hw_tags_enabled() && !skip_vmalloc_kasan) { /* * Modify protection bits to allow tagging. * This must be done before mapping. @@ -4078,7 +4082,8 @@ void *__vmalloc_node_range_noprof(unsigned long size,= unsigned long align, (gfp_mask & __GFP_SKIP_ZERO)) kasan_flags |=3D KASAN_VMALLOC_INIT; /* KASAN_VMALLOC_PROT_NORMAL already set if required. */ - area->addr =3D kasan_unpoison_vmalloc(area->addr, size, kasan_flags); + if (!skip_vmalloc_kasan) + area->addr =3D kasan_unpoison_vmalloc(area->addr, size, kasan_flags); =20 /* * In this function, newly allocated vm_struct has VM_UNINITIALIZED --=20 2.34.1 From nobody Tue Jun 16 20:34:56 2026 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 1C5553D5223; Wed, 29 Apr 2026 10:28:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777458493; cv=none; b=KOO2dWRZ0DK2cpWo+4e0SMMVUtYZfckp8CpeRRPm7FuL7MgBYtUPWE813VvNt53q6kTIiJ7NnuAS59F2hScKpXQjtHCVf+SqDr0B2sCUoNxVQIaqF6/6PHzP+IDkGMlMHDBryqNRe51JIz5+R9ONoe4lLlkYtDea73IHDc211A4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777458493; c=relaxed/simple; bh=orXsq89dfQMCSKEE6gPmHluNEOO7CXeI2G3nz7AJ8FI=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Hg71AJUBrwqw6CiKifKB9IyeuIYFpFzKz1G1RRlhcIiwS2MOKXAAKpYmnZaPpwXmTTAm6BooObUr20Jv1OKN5Ep8l1/ijy9bh2AKWzcoandKoi6w0tt9vqjoLDvmr3dSpqRwMK53zZ68LtD9iEOWvlRWYTJJ3SOGTQqtZFLC0pU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b=ESGGwOF8; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b="ESGGwOF8" Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id F315C2A68; Wed, 29 Apr 2026 03:28:05 -0700 (PDT) Received: from a080796.blr.arm.com (a080796.arm.com [10.164.21.51]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 27B373F763; Wed, 29 Apr 2026 03:28:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1777458491; bh=orXsq89dfQMCSKEE6gPmHluNEOO7CXeI2G3nz7AJ8FI=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=ESGGwOF8xqj5DfideHRgMZPn34oyBQ6v/NvyCJ/O6ZI8vg7vKVveDC/MpnPb6fhwj aw3fI5JsSJb1H0svna9O1P6MJOvk+cOzwAzkiPO5rCLHD8VxJuCWDKgok+U8ys1LOi YzxVjTJulqfYNz6cPeW/GcShU6dm60uDJwDqghz4= From: Dev Jain To: akpm@linux-foundation.org, david@kernel.org, urezki@gmail.com, kees@kernel.org, mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org, arnd@arndb.de Cc: Muhammad Usama Anjum , ljs@kernel.org, Liam.Howlett@oracle.com, vbabka@kernel.org, rppt@kernel.org, surenb@google.com, mhocko@suse.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, tglx@kernel.org, mathieu.desnoyers@efficios.com, linux-arch@vger.kernel.org, ryan.roberts@arm.com, catalin.marinas@arm.com, Dev Jain Subject: [PATCH v4 2/3] kasan: skip HW tagging for all kernel thread stacks Date: Wed, 29 Apr 2026 15:57:03 +0530 Message-Id: <20260429102704.680174-3-dev.jain@arm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260429102704.680174-1-dev.jain@arm.com> References: <20260429102704.680174-1-dev.jain@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Muhammad Usama Anjum HW-tag KASAN never checks kernel stacks because stack pointers carry the match-all tag, so setting/poisoning tags is pure overhead. - Add __GFP_SKIP_KASAN to THREADINFO_GFP so every stack allocator that uses it skips tagging (fork path plus arch users) - Add __GFP_SKIP_KASAN to GFP_VMAP_STACK for the fork-specific vmap stacks. - When reusing cached vmap stacks, skip kasan_unpoison_range() if HW tags are enabled. Software KASAN is unchanged; this only affects tag-based KASAN. Signed-off-by: Muhammad Usama Anjum Signed-off-by: Dev Jain Reviewed-by: Catalin Marinas --- include/linux/thread_info.h | 2 +- kernel/fork.c | 5 +++-- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/include/linux/thread_info.h b/include/linux/thread_info.h index 051e429026904..307b8390fc670 100644 --- a/include/linux/thread_info.h +++ b/include/linux/thread_info.h @@ -92,7 +92,7 @@ static inline long set_restart_fn(struct restart_block *r= estart, #define THREAD_ALIGN THREAD_SIZE #endif =20 -#define THREADINFO_GFP (GFP_KERNEL_ACCOUNT | __GFP_ZERO) +#define THREADINFO_GFP (GFP_KERNEL_ACCOUNT | __GFP_ZERO | __GFP_SKIP_KASA= N) =20 /* * flag set/clear/test wrappers diff --git a/kernel/fork.c b/kernel/fork.c index f1ad69c6dc2d4..0d97fd71d7f60 100644 --- a/kernel/fork.c +++ b/kernel/fork.c @@ -204,7 +204,7 @@ static DEFINE_PER_CPU(struct vm_struct *, cached_stacks= [NR_CACHED_STACKS]); * accounting is performed by the code assigning/releasing stacks to tasks. * We need a zeroed memory without __GFP_ACCOUNT. */ -#define GFP_VMAP_STACK (GFP_KERNEL | __GFP_ZERO) +#define GFP_VMAP_STACK (GFP_KERNEL | __GFP_ZERO | __GFP_SKIP_KASAN) =20 struct vm_stack { struct rcu_head rcu; @@ -342,7 +342,8 @@ static int alloc_thread_stack_node(struct task_struct *= tsk, int node) } =20 /* Reset stack metadata. */ - kasan_unpoison_range(vm_area->addr, THREAD_SIZE); + if (!kasan_hw_tags_enabled()) + kasan_unpoison_range(vm_area->addr, THREAD_SIZE); =20 stack =3D kasan_reset_tag(vm_area->addr); =20 --=20 2.34.1 From nobody Tue Jun 16 20:34:56 2026 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id CBE7C390C9F; Wed, 29 Apr 2026 10:28:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777458501; cv=none; b=LMS8T9AYDHAu7XnaINfeGUjQfoAUSA9YWP/gtaBW8gWh+MkbExDfXSPwDoueAyfwva6ii4NGolDXbP6RMe/EhJglRQX7lX4bdixTW6UiebhxDA4X9xt5C0Q3arai7MU+JNwJF3eSen6sLslL1JmyQs9gB0QfHIaW+fRRs/17CZ8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777458501; c=relaxed/simple; bh=Wk7w9lhH1k+YWbLTG0ALVUDnoHIRsitzS6tZ9UC4swc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=aH+eASBsObfsp98Kzl6L8j66Z4h5Kx9o9zuzRw4A96/gW1hOsqBayd65/sMf5gFACw3YRbPCQ8e1vIjDE11V1jJ03qEgwR8qyFE9GpZJSzWjdJkGfHcUg17oS9qFIPRi15s4XuE8XnBrt2cOTJOUkesy8FzOQmk+obYxGAxG/kU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b=T6QBMkrR; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b="T6QBMkrR" Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id CBD562A68; Wed, 29 Apr 2026 03:28:13 -0700 (PDT) Received: from a080796.blr.arm.com (a080796.arm.com [10.164.21.51]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id EA4B63F763; Wed, 29 Apr 2026 03:28:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1777458499; bh=Wk7w9lhH1k+YWbLTG0ALVUDnoHIRsitzS6tZ9UC4swc=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=T6QBMkrRy4jK7cyGHC88StfkMlvC7TKCLOf4uKVKSxH0q5oOE7SFbPc/FukftUdc5 s1nYC8B8aMvQLMUmQTHVG4LAktohXf0VpI1n02HmiFkLc7jEpu6EsiGLIfUCkWBrPh ya7TyfdwFxyc1myoadrkLjQOXFWQkf9o6I9zkBfU= From: Dev Jain To: akpm@linux-foundation.org, david@kernel.org, urezki@gmail.com, kees@kernel.org, mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org, arnd@arndb.de Cc: Muhammad Usama Anjum , ljs@kernel.org, Liam.Howlett@oracle.com, vbabka@kernel.org, rppt@kernel.org, surenb@google.com, mhocko@suse.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, tglx@kernel.org, mathieu.desnoyers@efficios.com, linux-arch@vger.kernel.org, ryan.roberts@arm.com, catalin.marinas@arm.com, Dev Jain Subject: [PATCH v4 3/3] mm: skip KASAN tagging for page-allocated page tables Date: Wed, 29 Apr 2026 15:57:04 +0530 Message-Id: <20260429102704.680174-4-dev.jain@arm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260429102704.680174-1-dev.jain@arm.com> References: <20260429102704.680174-1-dev.jain@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Muhammad Usama Anjum Page tables are always accessed via the linear mapping with a match-all tag, so HW-tag KASAN never checks them. For page-allocated tables (PTEs and PGDs etc), avoid the tag setup and poisoning overhead by using __GFP_SKIP_KASAN. SLUB-backed page tables are unchanged for now. (They aren't widely used and require more SLUB related skip logic. Leave it later.) Reviewed-by: Ryan Roberts Reviewed-by: Catalin Marinas Acked-by: David Hildenbrand (Arm) Signed-off-by: Muhammad Usama Anjum Signed-off-by: Dev Jain --- include/asm-generic/pgalloc.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/include/asm-generic/pgalloc.h b/include/asm-generic/pgalloc.h index 57137d3ac1592..051aa1331051c 100644 --- a/include/asm-generic/pgalloc.h +++ b/include/asm-generic/pgalloc.h @@ -4,7 +4,7 @@ =20 #ifdef CONFIG_MMU =20 -#define GFP_PGTABLE_KERNEL (GFP_KERNEL | __GFP_ZERO) +#define GFP_PGTABLE_KERNEL (GFP_KERNEL | __GFP_ZERO | __GFP_SKIP_KASAN) #define GFP_PGTABLE_USER (GFP_PGTABLE_KERNEL | __GFP_ACCOUNT) =20 /** --=20 2.34.1