drivers/misc/lkdtm/core.c | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-)
lkdtm_debugfs_entry and direct_entry use __get_free_page to allocate a
temporary buffer, perform copy_from_user to get the crashtype name,
strim() to strip whitespace and find_crashtype to find the corresponding
crashtype that is being requested.
The lkdtm_debugfs_read uses __get_free_page to allocate a temporary
buffer to store all the available crashtypes, and then copy it to
userspace.
The buffers that are allocated can be allocated with kmalloc as there is
nothing special that requires a struct page, or the page allocator.
kmalloc() additionally provides a better API that doesn't require ugly
casts which obfuscate the code and kfree does not need to know the size
of the freed object.
Replace use of __get_free_page() with kmalloc().
Signed-off-by: Mahad Ibrahim <mahad.ibrahim.dev@gmail.com>
---
drivers/misc/lkdtm/core.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/drivers/misc/lkdtm/core.c b/drivers/misc/lkdtm/core.c
index ededa32d6744..01bebcb33bd4 100644
--- a/drivers/misc/lkdtm/core.c
+++ b/drivers/misc/lkdtm/core.c
@@ -236,11 +236,11 @@ static ssize_t lkdtm_debugfs_entry(struct file *f,
if (count >= PAGE_SIZE)
return -EINVAL;
- buf = (char *)__get_free_page(GFP_KERNEL);
+ buf = kmalloc(PAGE_SIZE, GFP_KERNEL);
if (!buf)
return -ENOMEM;
if (copy_from_user(buf, user_buf, count)) {
- free_page((unsigned long) buf);
+ kfree(buf);
return -EFAULT;
}
/* NULL-terminate and remove enter */
@@ -248,7 +248,7 @@ static ssize_t lkdtm_debugfs_entry(struct file *f,
strim(buf);
crashtype = find_crashtype(buf);
- free_page((unsigned long)buf);
+ kfree(buf);
if (!crashtype)
return -EINVAL;
@@ -271,7 +271,7 @@ static ssize_t lkdtm_debugfs_read(struct file *f, char __user *user_buf,
ssize_t out;
char *buf;
- buf = (char *)__get_free_page(GFP_KERNEL);
+ buf = kmalloc(PAGE_SIZE, GFP_KERNEL);
if (buf == NULL)
return -ENOMEM;
@@ -290,7 +290,7 @@ static ssize_t lkdtm_debugfs_read(struct file *f, char __user *user_buf,
out = simple_read_from_buffer(user_buf, count, off,
buf, n);
- free_page((unsigned long) buf);
+ kfree(buf);
return out;
}
@@ -313,11 +313,11 @@ static ssize_t direct_entry(struct file *f, const char __user *user_buf,
if (count < 1)
return -EINVAL;
- buf = (char *)__get_free_page(GFP_KERNEL);
+ buf = kmalloc(PAGE_SIZE, GFP_KERNEL);
if (!buf)
return -ENOMEM;
if (copy_from_user(buf, user_buf, count)) {
- free_page((unsigned long) buf);
+ kfree(buf);
return -EFAULT;
}
/* NULL-terminate and remove enter */
@@ -325,7 +325,7 @@ static ssize_t direct_entry(struct file *f, const char __user *user_buf,
strim(buf);
crashtype = find_crashtype(buf);
- free_page((unsigned long) buf);
+ kfree(buf);
if (!crashtype)
return -EINVAL;
--
2.54.0
On Wed, 22 Jul 2026 23:02:46 +0000
Mahad Ibrahim <mahad.ibrahim.dev@gmail.com> wrote:
> lkdtm_debugfs_entry and direct_entry use __get_free_page to allocate a
> temporary buffer, perform copy_from_user to get the crashtype name,
> strim() to strip whitespace and find_crashtype to find the corresponding
> crashtype that is being requested.
>
> The lkdtm_debugfs_read uses __get_free_page to allocate a temporary
> buffer to store all the available crashtypes, and then copy it to
> userspace.
>
> The buffers that are allocated can be allocated with kmalloc as there is
> nothing special that requires a struct page, or the page allocator.
>
> kmalloc() additionally provides a better API that doesn't require ugly
> casts which obfuscate the code and kfree does not need to know the size
> of the freed object.
>
> Replace use of __get_free_page() with kmalloc().
None of those buffers need to be PAGE_SIZE.
Even the sanity limit for overlong requests could be 4k.
The longest 'crashtype->name' is probably about 32 characters, so could
probably go on stack.
And can't this code use the sysfs/kernfs wrappers?
David
>
> Signed-off-by: Mahad Ibrahim <mahad.ibrahim.dev@gmail.com>
> ---
> drivers/misc/lkdtm/core.c | 16 ++++++++--------
> 1 file changed, 8 insertions(+), 8 deletions(-)
>
> diff --git a/drivers/misc/lkdtm/core.c b/drivers/misc/lkdtm/core.c
> index ededa32d6744..01bebcb33bd4 100644
> --- a/drivers/misc/lkdtm/core.c
> +++ b/drivers/misc/lkdtm/core.c
> @@ -236,11 +236,11 @@ static ssize_t lkdtm_debugfs_entry(struct file *f,
> if (count >= PAGE_SIZE)
> return -EINVAL;
>
> - buf = (char *)__get_free_page(GFP_KERNEL);
> + buf = kmalloc(PAGE_SIZE, GFP_KERNEL);
> if (!buf)
> return -ENOMEM;
> if (copy_from_user(buf, user_buf, count)) {
> - free_page((unsigned long) buf);
> + kfree(buf);
> return -EFAULT;
> }
> /* NULL-terminate and remove enter */
> @@ -248,7 +248,7 @@ static ssize_t lkdtm_debugfs_entry(struct file *f,
> strim(buf);
>
> crashtype = find_crashtype(buf);
> - free_page((unsigned long)buf);
> + kfree(buf);
>
> if (!crashtype)
> return -EINVAL;
> @@ -271,7 +271,7 @@ static ssize_t lkdtm_debugfs_read(struct file *f, char __user *user_buf,
> ssize_t out;
> char *buf;
>
> - buf = (char *)__get_free_page(GFP_KERNEL);
> + buf = kmalloc(PAGE_SIZE, GFP_KERNEL);
> if (buf == NULL)
> return -ENOMEM;
>
> @@ -290,7 +290,7 @@ static ssize_t lkdtm_debugfs_read(struct file *f, char __user *user_buf,
>
> out = simple_read_from_buffer(user_buf, count, off,
> buf, n);
> - free_page((unsigned long) buf);
> + kfree(buf);
>
> return out;
> }
> @@ -313,11 +313,11 @@ static ssize_t direct_entry(struct file *f, const char __user *user_buf,
> if (count < 1)
> return -EINVAL;
>
> - buf = (char *)__get_free_page(GFP_KERNEL);
> + buf = kmalloc(PAGE_SIZE, GFP_KERNEL);
> if (!buf)
> return -ENOMEM;
> if (copy_from_user(buf, user_buf, count)) {
> - free_page((unsigned long) buf);
> + kfree(buf);
> return -EFAULT;
> }
> /* NULL-terminate and remove enter */
> @@ -325,7 +325,7 @@ static ssize_t direct_entry(struct file *f, const char __user *user_buf,
> strim(buf);
>
> crashtype = find_crashtype(buf);
> - free_page((unsigned long) buf);
> + kfree(buf);
> if (!crashtype)
> return -EINVAL;
>
On Thu, Jul 23, 2026, at 10:45, David Laight wrote:
> On Wed, 22 Jul 2026 23:02:46 +0000
> Mahad Ibrahim <mahad.ibrahim.dev@gmail.com> wrote:
>
>> lkdtm_debugfs_entry and direct_entry use __get_free_page to allocate a
>> temporary buffer, perform copy_from_user to get the crashtype name,
>> strim() to strip whitespace and find_crashtype to find the corresponding
>> crashtype that is being requested.
>>
>> The lkdtm_debugfs_read uses __get_free_page to allocate a temporary
>> buffer to store all the available crashtypes, and then copy it to
>> userspace.
>>
>> The buffers that are allocated can be allocated with kmalloc as there is
>> nothing special that requires a struct page, or the page allocator.
>>
>> kmalloc() additionally provides a better API that doesn't require ugly
>> casts which obfuscate the code and kfree does not need to know the size
>> of the freed object.
>>
>> Replace use of __get_free_page() with kmalloc().
>
> None of those buffers need to be PAGE_SIZE.
> Even the sanity limit for overlong requests could be 4k.
> The longest 'crashtype->name' is probably about 32 characters, so could
> probably go on stack.
It is a straightforward change with a very low risk of regression,
so I see nothing wrong with this version.
If we wanted to improve readability here, I would suggest
using strndup_user() to fold ten lines into one.
Arnd
Hello Arnd, Thank you for the feedback and review. Your suggestion would replace the write paths; if Kees would prefer, I can send it as a v2, if not I can do it as a follow up patch. Thank you, Mahad Ibrahim
For context, this is part of the broader __get_free_page() -> kmalloc() transition Mike Rapoport is performing. I noticed it on the mailing lists and found this site which wasn't covered. Some background: [1] https://lore.kernel.org/all/CA+55aFwp4iy4rtX2gE2WjBGFL=NxMVnoFeHqYa2j1dYOMMGqxg@mail.gmail.com/ [2] https://lore.kernel.org/linux-scsi/20260704-b4-scsi-v2-0-7d2d21a810de@kernel.org/T/#t I apologize for this messy reply. I thought I had added the context, but I didn't. Best regards, Mahad Ibrahim
On Wed, Jul 22, 2026 at 11:42:25PM +0000, Mahad Ibrahim wrote: > For context, this is part of the broader __get_free_page() -> kmalloc() > transition Mike Rapoport is performing. I noticed it on the mailing > lists and found this site which wasn't covered. > > Some background: > > [1] https://lore.kernel.org/all/CA+55aFwp4iy4rtX2gE2WjBGFL=NxMVnoFeHqYa2j1dYOMMGqxg@mail.gmail.com/ > [2] https://lore.kernel.org/linux-scsi/20260704-b4-scsi-v2-0-7d2d21a810de@kernel.org/T/#t > > I apologize for this messy reply. I thought I had added the context, but > I didn't. Do you want this to land via my tree or via the series Mike is doing? -- Kees Cook
© 2016 - 2026 Red Hat, Inc.