From nobody Tue Sep 29 07:00:19 2026 Received: from m16.mail.163.com (m16.mail.163.com [220.197.31.4]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 143E43FBB7D for ; Tue, 11 Aug 2026 07:34:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=220.197.31.4 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786433666; cv=none; b=OxUS/ZdzvsAXgnx6VU+ARvPs/9dg4OzEeLv2m8j1sXlTIxhY5/DXcxdwezuV1X4iE4kwcGJiqsIu8utLYkU6x88jZhKCq6QGQiugbXGFlr2jWsw0dgbCg59z8uOELYgd9VLFz6PRPlZi/+XrNF31Eo+uUcxXfpJ5SLDp7lBQLHM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786433666; c=relaxed/simple; bh=Ty1Z1Sz6ihRGAWscmvd33E11YjfyZmAqfvCz2/bPipo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IwRx5T2qqFPvg5siTlFaYwU6akbZQgNPxNBDspVe0foSknYVwMijRBDDc+CJzdJkjaHLHO9Uepa6AgXhUoXDtOZxjk0V8uF/d3800Vfhhet/4L+hx02wk1/h0S5cNpUzvXQMI7O2tUQQIa0eY+k7CblIhKockXmXoWc5TZciIsE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=163.com; spf=pass smtp.mailfrom=163.com; dkim=pass (1024-bit key) header.d=163.com header.i=@163.com header.b=FvV6vGCU; arc=none smtp.client-ip=220.197.31.4 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=163.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=163.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=163.com header.i=@163.com header.b="FvV6vGCU" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=From:To:Subject:Date:Message-ID:MIME-Version; bh=M4 X/pEDEhzJriqH/Dn3z9EQyrzergLRc+6vzfSJPFlQ=; b=FvV6vGCUbpByJVYo7Q imuR0kRpyhtDLcOFTVCAZA0ZoHCkMdKMdo6wC3GiJxHeLWtWsixuNUhTrxT0bjBp 5CYns4Of2WWyc/m1WDKEy53WaK1DdoYAx1r2i6oa6z/E/DPQ/YgC9KYXP5Yltc6T E+HE0hmX+50l6T/kmoe+H6dHk= Received: from localhost (unknown []) by gzga-smtp-mtada-g1-3 (Coremail) with SMTP id _____wAH3+lM0HpqmAU8NA--.183S2; Tue, 11 Aug 2026 15:33:35 +0800 (CST) From: Hui Su To: ryabinin.a.a@gmail.com Cc: glider@google.com, andreyknvl@gmail.com, dvyukov@google.com, vincenzo.frascino@arm.com, akpm@linux-foundation.org, kasan-dev@googlegroups.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, Hui Su , Sashiko Subject: [PATCH] kasan: fix quarantine_size accounting during cache removal Date: Tue, 11 Aug 2026 15:33:32 +0800 Message-ID: <20260811073332.1351893-1-sh_def@163.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: _____wAH3+lM0HpqmAU8NA--.183S2 X-Coremail-Antispam: 1Uf129KBjvJXoW7ZFW3Wr1fuF4kXF45XrykGrg_yoW5JF1DpF 1UJFnxCw1kJryxGr1UG3W5Wr1rWFZ8Jas8A3y8WrsayF1rG3W2qryrtryjvayYyws5XF4q qa4DGr1Fkr98CaUanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDUYxBIdaVFxhVjvjDU0xZFpf9x0piHa0PUUUUU= X-CM-SenderInfo: xvkbvvri6rljoofrz/xtbC6RCB4Gp60FCanQAA3P Content-Type: text/plain; charset="utf-8" quarantine_size tracks the total number of bytes stored in global_quarantine[]. It is incremented when per-CPU quarantine objects are moved into the global quarantine and decremented when a global batch is evicted by kasan_quarantine_reduce(). kasan_quarantine_remove_cache() also removes objects from the global quarantine. qlist_move_cache() rebuilds the source batch and updates its .bytes field, but quarantine_size is not adjusted accordingly. As a result, quarantine_size remains over-counted by the size of the removed objects. The stale accounting accumulates across cache removals. Once the inflated value exceeds quarantine_max_size, kasan_quarantine_reduce() can evict a batch even though the actual number of bytes in global_quarantine[] is still below quarantine_max_size, shortening the quarantine window. Fix the accounting by recording each batch's size before qlist_move_cache() and subtracting the number of bytes actually removed from quarantine_size while holding quarantine_lock. A KUnit reproducer used during testing observed the over-count grow by 4698864 bytes after one kasan_quarantine_remove_cache() call with the fix reverted. With this change applied, the over-count did not grow. Fixes: 64abdcb24351 ("kasan: eliminate long stalls during quarantine reduct= ion") Reported-by: Sashiko Closes: https://sashiko.dev/#/patchset/20260808031459.3032812-1-sh_def%4016= 3.com Signed-off-by: Hui Su Reviewed-by: Andrey Ryabinin --- mm/kasan/quarantine.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/mm/kasan/quarantine.c b/mm/kasan/quarantine.c index 6958aa713c67..c220f0d8ddd0 100644 --- a/mm/kasan/quarantine.c +++ b/mm/kasan/quarantine.c @@ -365,9 +365,14 @@ void kasan_quarantine_remove_cache(struct kmem_cache *= cache) =20 raw_spin_lock_irqsave(&quarantine_lock, flags); for (i =3D 0; i < QUARANTINE_BATCHES; i++) { + size_t old_bytes; + if (qlist_empty(&global_quarantine[i])) continue; + old_bytes =3D global_quarantine[i].bytes; qlist_move_cache(&global_quarantine[i], &to_free, cache); + WRITE_ONCE(quarantine_size, quarantine_size - + (old_bytes - global_quarantine[i].bytes)); /* Scanning whole quarantine can take a while. */ raw_spin_unlock_irqrestore(&quarantine_lock, flags); cond_resched(); base-commit: d58772d8520c7ef247c4b95c9bd76d3a25da9ff5 --=20 2.43.0