mm/vmalloc.c | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-)
Since vmalloc() accepts non-blocking GFP flags, allocation
requests may fail when callers pass restrictive GFP masks.
va_clip() may return -ENOMEM when its GFP_NOWAIT fallback
allocation fails during NE_FIT_TYPE splitting. This is an
expected failure, so va_alloc() should return the error
without triggering a kernel splat.
Reported-by: syzbot+61c997e6be1d9bb300ba@syzkaller.appspotmail.com
Signed-off-by: Uladzislau Rezki (Sony) <urezki@gmail.com>
---
mm/vmalloc.c | 13 ++++++-------
1 file changed, 6 insertions(+), 7 deletions(-)
diff --git a/mm/vmalloc.c b/mm/vmalloc.c
index 1afca3568b9b..7a0cbba3d29d 100644
--- a/mm/vmalloc.c
+++ b/mm/vmalloc.c
@@ -1817,8 +1817,10 @@ va_alloc(struct vmap_area *va,
/* Update the free vmap_area. */
ret = va_clip(root, head, va, nva_start_addr, size);
- if (WARN_ON_ONCE(ret))
+ if (ret) {
+ WARN_ON_ONCE(ret != -ENOMEM);
return ret;
+ }
return nva_start_addr;
}
@@ -1891,12 +1893,9 @@ preload_this_cpu_lock(spinlock_t *lock, gfp_t gfp_mask, int node)
/*
* Preload this CPU with one extra vmap_area object. It is used
- * when fit type of free area is NE_FIT_TYPE. It guarantees that
- * a CPU that does an allocation is preloaded.
- *
- * We do it in non-atomic context, thus it allows us to use more
- * permissive allocation masks to be more stable under low memory
- * condition and high memory pressure.
+ * when fit type of free area is NE_FIT_TYPE. It is best effort
+ * pre-loading. If it fails va_clip() may return -ENOMEM from its
+ * GFP_NOWAIT fallback.
*/
if (!this_cpu_read(ne_fit_preload_node))
va = kmem_cache_alloc_node(vmap_area_cachep, gfp_mask, node);
--
2.47.3
On 08/02/26 at 12:46pm, Uladzislau Rezki (Sony) wrote:
> Since vmalloc() accepts non-blocking GFP flags, allocation
> requests may fail when callers pass restrictive GFP masks.
>
> va_clip() may return -ENOMEM when its GFP_NOWAIT fallback
> allocation fails during NE_FIT_TYPE splitting. This is an
> expected failure, so va_alloc() should return the error
> without triggering a kernel splat.
>
> Reported-by: syzbot+61c997e6be1d9bb300ba@syzkaller.appspotmail.com
> Signed-off-by: Uladzislau Rezki (Sony) <urezki@gmail.com>
> ---
> mm/vmalloc.c | 13 ++++++-------
> 1 file changed, 6 insertions(+), 7 deletions(-)
>
> diff --git a/mm/vmalloc.c b/mm/vmalloc.c
> index 1afca3568b9b..7a0cbba3d29d 100644
> --- a/mm/vmalloc.c
> +++ b/mm/vmalloc.c
> @@ -1817,8 +1817,10 @@ va_alloc(struct vmap_area *va,
>
> /* Update the free vmap_area. */
> ret = va_clip(root, head, va, nva_start_addr, size);
> - if (WARN_ON_ONCE(ret))
> + if (ret) {
> + WARN_ON_ONCE(ret != -ENOMEM);
> return ret;
> + }
>
> return nva_start_addr;
> }
> @@ -1891,12 +1893,9 @@ preload_this_cpu_lock(spinlock_t *lock, gfp_t gfp_mask, int node)
>
> /*
> * Preload this CPU with one extra vmap_area object. It is used
> - * when fit type of free area is NE_FIT_TYPE. It guarantees that
> - * a CPU that does an allocation is preloaded.
> - *
> - * We do it in non-atomic context, thus it allows us to use more
> - * permissive allocation masks to be more stable under low memory
> - * condition and high memory pressure.
> + * when fit type of free area is NE_FIT_TYPE. It is best effort
> + * pre-loading. If it fails va_clip() may return -ENOMEM from its
> + * GFP_NOWAIT fallback.
> */
> if (!this_cpu_read(ne_fit_preload_node))
> va = kmem_cache_alloc_node(vmap_area_cachep, gfp_mask, node);
LGTM,
Reviewed-by: Baoquan He <baoquan.he@linux.dev>
On Sun, Aug 02, 2026 at 12:46:27PM +0200, Uladzislau Rezki (Sony) wrote:
> Since vmalloc() accepts non-blocking GFP flags, allocation
> requests may fail when callers pass restrictive GFP masks.
>
> va_clip() may return -ENOMEM when its GFP_NOWAIT fallback
> allocation fails during NE_FIT_TYPE splitting. This is an
> expected failure, so va_alloc() should return the error
> without triggering a kernel splat.
Dropping WARN_ON_ONCE() just for -ENOMEM while preserving this
warning for other returned errors does make sense.
>
> Reported-by: syzbot+61c997e6be1d9bb300ba@syzkaller.appspotmail.com
Very small nit.
If there is actual link for the problem report, probably it could
be added as an Link: or Closes: here.
> Signed-off-by: Uladzislau Rezki (Sony) <urezki@gmail.com>
Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com>
> ---
> mm/vmalloc.c | 13 ++++++-------
> 1 file changed, 6 insertions(+), 7 deletions(-)
>
> diff --git a/mm/vmalloc.c b/mm/vmalloc.c
> index 1afca3568b9b..7a0cbba3d29d 100644
> --- a/mm/vmalloc.c
> +++ b/mm/vmalloc.c
> @@ -1817,8 +1817,10 @@ va_alloc(struct vmap_area *va,
>
> /* Update the free vmap_area. */
> ret = va_clip(root, head, va, nva_start_addr, size);
> - if (WARN_ON_ONCE(ret))
> + if (ret) {
> + WARN_ON_ONCE(ret != -ENOMEM);
> return ret;
> + }
>
> return nva_start_addr;
> }
> @@ -1891,12 +1893,9 @@ preload_this_cpu_lock(spinlock_t *lock, gfp_t gfp_mask, int node)
>
> /*
> * Preload this CPU with one extra vmap_area object. It is used
> - * when fit type of free area is NE_FIT_TYPE. It guarantees that
> - * a CPU that does an allocation is preloaded.
> - *
> - * We do it in non-atomic context, thus it allows us to use more
> - * permissive allocation masks to be more stable under low memory
> - * condition and high memory pressure.
> + * when fit type of free area is NE_FIT_TYPE. It is best effort
> + * pre-loading. If it fails va_clip() may return -ENOMEM from its
> + * GFP_NOWAIT fallback.
> */
> if (!this_cpu_read(ne_fit_preload_node))
> va = kmem_cache_alloc_node(vmap_area_cachep, gfp_mask, node);
> --
> 2.47.3
>
On Mon, Aug 03, 2026 at 09:19:52AM +0530, Anshuman Khandual wrote: > On Sun, Aug 02, 2026 at 12:46:27PM +0200, Uladzislau Rezki (Sony) wrote: > > Since vmalloc() accepts non-blocking GFP flags, allocation > > requests may fail when callers pass restrictive GFP masks. > > > > va_clip() may return -ENOMEM when its GFP_NOWAIT fallback > > allocation fails during NE_FIT_TYPE splitting. This is an > > expected failure, so va_alloc() should return the error > > without triggering a kernel splat. > > Dropping WARN_ON_ONCE() just for -ENOMEM while preserving this > warning for other returned errors does make sense. > > > > > Reported-by: syzbot+61c997e6be1d9bb300ba@syzkaller.appspotmail.com > > Very small nit. > > If there is actual link for the problem report, probably it could > be added as an Link: or Closes: here. > I hope Andrew can help here. If not i will resend! Thank you! -- Uladzislau Rezki
© 2016 - 2026 Red Hat, Inc.