From nobody Tue Sep 29 03:53:25 2026 Received: from mta0.migadu.com (out-251.mta0.migadu.com [91.218.175.251]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4AAC43BAD9F for ; Thu, 13 Aug 2026 09:34:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.251 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786613647; cv=none; b=h9nH9U/H9iP8h4K95DIX/WJ0UL/2dMew6uWOks3MqJhoa3+g074er+Xp0IExN0Xp3MCWsIOi8fU+roCV7/EEp5rPDCdKomcYktc26OZj/DHRLAaYFxda2NZYn1zQiYeaOl0r/n/yqVWugikLZ1IOjozAg0q8SjzUP3X1CDINJIY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786613647; c=relaxed/simple; bh=tn8UuuKtkL7oFhh/U1B37Ptewe1hVf6VZJL600BRXaI=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Vkmdw+R1LSgxRppv56LL3tfYqeoMPyQ+bVbpRJy2O49HjPbhk84o4vpWTCUqcOEAGs1XW23E5MATio5dEFjG+Envzx79cFCMukJVJTxyHWY/Z7xCYF8AP1d+ERDiezd3aieLCnaIvH8IX3SV8zhoZ74R46kk9mS4U1wHZS9Xy5o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=ns2Gado5; arc=none smtp.client-ip=91.218.175.251 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="ns2Gado5" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=tn8UuuKtkL7oFhh/U1B37Ptewe1hVf6VZJL600BRXaI=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1786613643; v=1; x=1787218443; b=ns2Gado5My663OsOlq6xH4Q/bnQS1hmgLKSrdDPs8vx+UeedXhTT7Z0gxpKI9yKmAXOGbsyA uIGKipHZfUJxhP85ftIQR51fkDMgWLpoDR8aMYRDnemhSegKfH/5aeto5uMYjvBeekVqzl6OPB8 7mfJQgGJ8O4OxlxSlVIeuX98= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.169) by smtp.migadu.com with ESMTPS id 7cdc111fd4b862bb; Thu, 13 Aug 2026 09:34:02 +0000 X-Migadu-Flow: FLOW_OUT From: Hao Ge To: Suren Baghdasaryan , Andrew Morton , Luis Chamberlain , Petr Pavlu , Daniel Gomez , Sami Tolvanen , Aaron Tomlin Cc: linux-modules@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, Hao Ge Subject: [RFC PATCH 1/3] alloc_tag: skip percpu counter allocation when profiling is disabled Date: Thu, 13 Aug 2026 17:34:19 +0800 Message-Id: <20260813093421.135230-2-hao.ge@linux.dev> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260813093421.135230-1-hao.ge@linux.dev> References: <20260813093421.135230-1-hao.ge@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" After shutdown_mem_profiling() clears mem_profiling_support, needs_section_mem() returns false, so later modules have their codetag section placed as regular data and never enter the alloc_tag maple tree. codetag_load_module() still called load_module(), which allocated a percpu counter for every tag; release_module_tags() could not find these modules on unload, so the counters leaked. Return CODETAG_MODULE_EXCLUDED from load_module() when profiling is off: codetag_module_init() drops the module's cmod and no counters are allocated. codetag_unload_module() now always calls free_section_mem(), since an excluded module may still hold a reserved section. Fixes: 4835f747d3ed ("alloc_tag: support for page allocation tag compressio= n") Signed-off-by: Hao Ge --- include/linux/codetag.h | 4 ++++ lib/codetag.c | 8 +++++--- mm/alloc_tag.c | 8 ++++++-- 3 files changed, 15 insertions(+), 5 deletions(-) diff --git a/include/linux/codetag.h b/include/linux/codetag.h index a25a085c2df1..88081c618673 100644 --- a/include/linux/codetag.h +++ b/include/linux/codetag.h @@ -52,6 +52,10 @@ struct codetag_type_desc { #endif }; =20 +/* module_load() return values */ +#define CODETAG_MODULE_LOAD 0 /* module loads with its tags */ +#define CODETAG_MODULE_EXCLUDED 1 /* module loads without its tags */ + struct codetag_iterator { struct codetag_type *cttype; struct codetag_module *cmod; diff --git a/lib/codetag.c b/lib/codetag.c index a9cda4c962a3..8506ecab9ea7 100644 --- a/lib/codetag.c +++ b/lib/codetag.c @@ -238,9 +238,10 @@ static int codetag_module_init(struct codetag_type *ct= type, struct module *mod) } up_write(&cttype->mod_lock); =20 - if (err < 0) { + if (err) { + /* Error or excluded: cmod is dropped, free it. */ kfree(cmod); - return err; + return err < 0 ? err : 0; } =20 return 0; @@ -388,7 +389,8 @@ void codetag_unload_module(struct module *mod) ++cttype->content_id; } up_write(&cttype->mod_lock); - if (found && cttype->desc.free_section_mem) + /* an excluded module may still hold section memory */ + if (cttype->desc.free_section_mem) cttype->desc.free_section_mem(mod, true); } mutex_unlock(&codetag_lock); diff --git a/mm/alloc_tag.c b/mm/alloc_tag.c index 0a7b657fe2de..461fa87fbb0b 100644 --- a/mm/alloc_tag.c +++ b/mm/alloc_tag.c @@ -977,9 +977,13 @@ static int load_module(struct module *mod, struct code= tag *start, struct codetag struct alloc_tag *stop_tag; struct alloc_tag *tag; =20 + /* Profiling disabled: load the module but exclude its tags. */ + if (!mem_profiling_support) + return CODETAG_MODULE_EXCLUDED; + /* percpu counters for core allocations are already statically allocated = */ if (!mod) - return 0; + return CODETAG_MODULE_LOAD; =20 start_tag =3D ct_to_alloc_tag(start); stop_tag =3D ct_to_alloc_tag(stop); @@ -1002,7 +1006,7 @@ static int load_module(struct module *mod, struct cod= etag *start, struct codetag */ kmemleak_ignore_percpu(tag->counters); } - return 0; + return CODETAG_MODULE_LOAD; } =20 static void replace_module(struct module *mod, struct module *new_mod) --=20 2.25.1 From nobody Tue Sep 29 03:53:25 2026 Received: from mta1.migadu.com (out-87.mta1.migadu.com [95.215.58.87]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A78093C8728 for ; Thu, 13 Aug 2026 09:34:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.87 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786613657; cv=none; b=g65kEF9cK/w01m9jGBb3UTDZoYXku8MNk37OiQds4e7eEdPMk0UNj92x4lTmmfqpd52Q46XxMUqFsXDnZmh0FnPdF1BkeG9UDbaTBvWLCCjEmzy3ilo1q/PsTEHUCI5d4I+kSvWe3mcmxJ+7ssl0iRM4+Q3C56llxrKYJlYODWM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786613657; c=relaxed/simple; bh=p4TFMUd9q6GnbcN5ey2myrD4Zw8jApQ5r7UvSVGLQQM=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=GBfXxI1iKNuPCopcLP4rNeWzfSVLh51rTJP82bN3iH5aW0cuyuaOQf1dHkLC4tL3dUw5+MoVyhkpU84EHLiIzixwHs5M083ExOMnei1zL+ygcx+h96I7xMThAvI03aKbIieHZyeh6NTAxC3r1lA//EAz7N+9DhKU0xu0ORTxSck= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=ZxW9+DB6; arc=none smtp.client-ip=95.215.58.87 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="ZxW9+DB6" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=p4TFMUd9q6GnbcN5ey2myrD4Zw8jApQ5r7UvSVGLQQM=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1786613651; v=1; x=1787218451; b=ZxW9+DB6bwXRqzZq8to0yNNVzyfWCIMwxMxlc5JgvV4rHQ3KWecsC7XHr0G4Xeh/h48qWaS2 qhMBoC3VqyRvFWWskbpQ4+TzVE/tiN2FlUJkrm8zTkkI6Vb7gX65e7MM9s7C2+TSjmfuYNBgg2X HP2JVkv+W56xc2ybPj/dKZDU= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.169) by smtp.migadu.com with ESMTPS id f70264e86958a884; Thu, 13 Aug 2026 09:34:11 +0000 X-Migadu-Flow: FLOW_OUT From: Hao Ge To: Suren Baghdasaryan , Andrew Morton , Luis Chamberlain , Petr Pavlu , Daniel Gomez , Sami Tolvanen , Aaron Tomlin Cc: linux-modules@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, Hao Ge Subject: [RFC PATCH 2/3] module: move codetag section placement decision to layout_sections() Date: Thu, 13 Aug 2026 17:34:20 +0800 Message-Id: <20260813093421.135230-3-hao.ge@linux.dev> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260813093421.135230-1-hao.ge@linux.dev> References: <20260813093421.135230-1-hao.ge@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" codetag_needs_module_section() is called twice per codetag section, once in layout_sections() and once in move_module(), and both depend on mem_profiling_support, which changes without a lock. If profiling is disabled between the two calls, layout excludes the section (offset 0) while move copies it as normal memory to offset 0: CPU0 (insmod A) CPU1 (insmod B) ---------------- ---------------- layout_sections() needs_section_mem() =3D=3D true sh_entsize: type, offset =3D 0 reserve_module_tags() overflows shutdown_mem_profiling() mem_profiling_support =3D false move_module() needs_section_mem() =3D=3D false offset =3D sh_entsize & MASK =3D 0 memcpy(mod->mem[type].base + 0, ...) -> overwrites the first section there Record the decision in layout_sections() in sh_entsize using a MOD_MEM_CODETAG type, and have move_module() use that instead of asking again. reserve_module_tags() returns -EAGAIN if profiling was disabled after layout, so the loader retries and places the section as normal memory. Fixes: 4835f747d3ed ("alloc_tag: support for page allocation tag compressio= n") Signed-off-by: Hao Ge --- include/linux/module.h | 11 +++++++++++ kernel/module/main.c | 17 ++++++----------- mm/alloc_tag.c | 8 ++++++++ 3 files changed, 25 insertions(+), 11 deletions(-) diff --git a/include/linux/module.h b/include/linux/module.h index 7566815fabbe..a02016528e1d 100644 --- a/include/linux/module.h +++ b/include/linux/module.h @@ -328,6 +328,17 @@ enum mod_mem_type { MOD_INVALID =3D -1, }; =20 +/* + * If CONFIG_CODE_TAGGING is on, modules get a .codetag section. + * codetag_needs_module_section() says where it goes: the usual + * mod->mem[], or off to the codetag region. + * + * Mark the codetag-region ones with MOD_MEM_NUM_TYPES. + * It's just past the real types, so it doesn't index into mod->mem[] + * and for_each_mod_mem_type() skips it. + */ +#define MOD_MEM_CODETAG MOD_MEM_NUM_TYPES + #define mod_mem_type_is_init(type) \ ((type) =3D=3D MOD_INIT_TEXT || \ (type) =3D=3D MOD_INIT_DATA || \ diff --git a/kernel/module/main.c b/kernel/module/main.c index ed26f167be84..2337bf604f58 100644 --- a/kernel/module/main.c +++ b/kernel/module/main.c @@ -1728,11 +1728,8 @@ static void __layout_sections(struct module *mod, st= ruct load_info *info, bool i * preallocated contiguous memory. */ if (codetag_needs_module_section(mod, sname, s->sh_size)) { - /* - * s->sh_entsize won't be used but populate the - * type field to avoid confusion. - */ - s->sh_entsize =3D ((unsigned long)(type) & SH_ENTSIZE_TYPE_MASK) + s->sh_entsize =3D ((unsigned long)MOD_MEM_CODETAG + & SH_ENTSIZE_TYPE_MASK) << SH_ENTSIZE_TYPE_SHIFT; continue; } @@ -2815,11 +2812,10 @@ static int move_module(struct module *mod, struct l= oad_info *info) continue; =20 sname =3D info->secstrings + shdr->sh_name; - /* - * Load codetag sections separately as they might still be used - * after module unload. - */ - if (codetag_needs_module_section(mod, sname, shdr->sh_size)) { + + enum mod_mem_type type =3D shdr->sh_entsize >> SH_ENTSIZE_TYPE_SHIFT; + + if (type =3D=3D MOD_MEM_CODETAG) { dest =3D codetag_alloc_module_section(mod, sname, shdr->sh_size, arch_mod_section_prepend(mod, i), shdr->sh_addralign); if (WARN_ON(!dest)) { @@ -2832,7 +2828,6 @@ static int move_module(struct module *mod, struct loa= d_info *info) } codetag_section_found =3D true; } else { - enum mod_mem_type type =3D shdr->sh_entsize >> SH_ENTSIZE_TYPE_SHIFT; unsigned long offset =3D shdr->sh_entsize & SH_ENTSIZE_OFFSET_MASK; =20 dest =3D mod->mem[type].base + offset; diff --git a/mm/alloc_tag.c b/mm/alloc_tag.c index 461fa87fbb0b..7481180dadd2 100644 --- a/mm/alloc_tag.c +++ b/mm/alloc_tag.c @@ -893,6 +893,14 @@ static void *reserve_module_tags(struct module *mod, u= nsigned long size, if (size < sizeof(struct alloc_tag)) return ERR_PTR(-EINVAL); =20 + /* + * Profiling may have been disabled by a concurrent module load. + * Return -EAGAIN so the loader retries with profiling off, laying + * the section out as ordinary module memory. + */ + if (!mem_profiling_support) + return ERR_PTR(-EAGAIN); + /* * align is always power of 2, so we can use IS_ALIGNED and ALIGN. * align 0 or 1 means no alignment, to simplify set to 1. --=20 2.25.1 From nobody Tue Sep 29 03:53:25 2026 Received: from mta0.migadu.com (out-2.mta0.migadu.com [91.218.175.2]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 939B43D170E for ; Thu, 13 Aug 2026 09:34:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.2 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786613661; cv=none; b=GkDDyWBf2/vbVBiOSvTToHgd7XPPiPWN4rb3PK9TJidlFxDXZJqBv8hjGxcVgZd5jawyASyO7yCrGyMBe5UTrrnqBp+aWhc3ya3727yqCj7Hku2i05703B8FM0mC7vaoAdGMAzVOOvtzXGr2oqrnqVY6c0bHTXD3/abQpDmlt9s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786613661; c=relaxed/simple; bh=hPN6+ldNa92yVfg5JXt1vgfrSMYfaiItc5ke6iFo9is=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=AYEHGYVQuhaGyYNujsgr7Zboy+H7wm4ttI53enAXglDAckBPZpPTMgM9TFZqsqSpT/B/1569WsnDkg3VmfGX6Xv5LU8aT6vB7FPHl31KQjWQ4WbvTYVVevTw47dZGQ7I1zjh5v6bgjZeBo6HWRQmipkU4VuAAg5EHR9oDUAiJVk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=Ve/BuX7Y; arc=none smtp.client-ip=91.218.175.2 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="Ve/BuX7Y" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=hPN6+ldNa92yVfg5JXt1vgfrSMYfaiItc5ke6iFo9is=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1786613655; v=1; x=1787218455; b=Ve/BuX7YWVqBo/ABZYgyXwpdHXANW8oh1K46WtEot5WlWwmlYaJrvYjXQhvPqtcxqNv57CDf J3fVIefYJeNAyVzqJeKfPvoOncCJ+do2gCvzPN3p5/YS+zYWDfd1LnSSeOla5eG+PQtsyl95qRp iuKV9mdSoApubKNnmXlRU5JM= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.169) by smtp.migadu.com with ESMTPS id 20da645f262052b9; Thu, 13 Aug 2026 09:34:15 +0000 X-Migadu-Flow: FLOW_OUT From: Hao Ge To: Suren Baghdasaryan , Andrew Morton , Luis Chamberlain , Petr Pavlu , Daniel Gomez , Sami Tolvanen , Aaron Tomlin Cc: linux-modules@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, Hao Ge Subject: [RFC PATCH 3/3] alloc_tag: remove /proc/allocinfo outside of mod_lock Date: Thu, 13 Aug 2026 17:34:21 +0800 Message-Id: <20260813093421.135230-4-hao.ge@linux.dev> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260813093421.135230-1-hao.ge@linux.dev> References: <20260813093421.135230-1-hao.ge@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" shutdown_mem_profiling() calls remove_proc_entry() from reserve_module_tags(), which runs under mod_lock held for write. remove_proc_entry() waits for readers, and a reader takes mod_lock for read in allocinfo_start(): CPU0 (insmod) CPU1 (read /proc/allocinfo) ---------------- ---------------------------- reserve_module_tags() down_write(&mod_lock) [held] use_pde() [in_use++] allocinfo_start() down_read(&mod_lock) <- blocks shutdown_mem_profiling() remove_proc_entry() wait for in_use =3D=3D 0 <- blocks Move remove_proc_entry() to a workqueue. Fixes: 4835f747d3ed ("alloc_tag: support for page allocation tag compressio= n") Signed-off-by: Hao Ge Reported-by tag. --- mm/alloc_tag.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/mm/alloc_tag.c b/mm/alloc_tag.c index 7481180dadd2..b80f5a151f28 100644 --- a/mm/alloc_tag.c +++ b/mm/alloc_tag.c @@ -591,6 +591,13 @@ void pgalloc_tag_swap(struct folio *new, struct folio = *old) put_page_tag_ref(handle_new); } =20 +static void remove_allocinfo_file(struct work_struct *work) +{ + remove_proc_entry(ALLOCINFO_FILE_NAME, NULL); +} + +static DECLARE_WORK(remove_allocinfo_work, remove_allocinfo_file); + static void shutdown_mem_profiling(bool remove_file) { if (mem_alloc_profiling_enabled()) @@ -600,7 +607,7 @@ static void shutdown_mem_profiling(bool remove_file) return; =20 if (remove_file) - remove_proc_entry(ALLOCINFO_FILE_NAME, NULL); + schedule_work(&remove_allocinfo_work); mem_profiling_support =3D false; } =20 --=20 2.25.1