From nobody Mon Sep 28 23:17:16 2026 Received: from mail-pl1-f173.google.com (mail-pl1-f173.google.com [209.85.214.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E7A6C39185C for ; Sat, 15 Aug 2026 10:36:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786790215; cv=none; b=ozHzy01OE6dBxQmWobtHc4vesXb07sLHr56CpA/G3wg/ACJCK+i4HDxEjkHAq59GhVkQKTNCi8sU4dReDqp4w6lXwt5UMBiGf9xOChnwuilbSyp5Q1FiJ6zYtP5sHx5OdzQemIqCsBJGQ2myNyaCh3m2ZyBjWjG6Xsb6BY/q3P4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786790215; c=relaxed/simple; bh=rfMjaCOvmJRa0bbW+d5HkY5VYdG1X8m8Ugnqw/d236I=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=X4qyDJ1wc1jZgBQnPyuTiasaPeaY1wtdL5P028TNMZ6TqoE1yQIQcUmFJAEx8kWuazGjonKAF5S+3sEpoZXR5pMwok5zAl7CiaSYZtyPU+C4AxEiZ9GL/63Z1qJZL349pvGigdmbms7MSzr+IPZYQf8Dtv7dyGxI9t7YkgiMnr8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ryZn4+4q; arc=none smtp.client-ip=209.85.214.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ryZn4+4q" Received: by mail-pl1-f173.google.com with SMTP id d9443c01a7336-2cc97653887so31581235ad.1 for ; Sat, 15 Aug 2026 03:36:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786790213; x=1787395013; darn=vger.kernel.org; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NO3qcNt9868NrnyM/QD7pq3oywENIyYI7Ixnody6czs=; b=ryZn4+4qh5Kl6OlsRH2xqofXWzMqMEvAgPD6ftip613gF5lZOdx7ijGwTSrKklXw3q uwz3x+dMHJHR1ivMrC+fSKW1qotUXgQ6xtFb5Grt2HYdpYhyzj8rq53LyRkmkEZp73s7 ec0eWGRnkCWmCszknUAh4hlnih+BZShuJhHlYeNZflnMECXSsk/E+c8PA+LyECHinikK I4YtGiX+G0XQe4AqAKXewJzBTyM+3d9VA3q3Bw405eutMbJmP+iogmKI8aIQX46PUGhV RCB8hgHv6d7J6DJE0X97wiyRNdpICN3gi1aoXsYH9IqbtAYZfSTmST/ayhZ3tKtGxmzC nQFg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786790213; x=1787395013; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=NO3qcNt9868NrnyM/QD7pq3oywENIyYI7Ixnody6czs=; b=M0YneQR45UTO7jEtWlf5o43tAO/ze/2z/7wiFLmvluHxlpDKYqJ5/hFaGNT5zqcnBI 1iAZeDGSaA4k9eSYcAWcYTQP2yrI3wiG5wd8G3m/wVRnLokUj+0s24/rGXGyPKvsgSWp XID4M7l9UWTSAt48Ov7CKw2teuf2RCOsSbqrHYOefOSgNjQrQ9aG0H5h/iYLRwqUazWo C0Qhw1obE9Fmmbb9Hz/2yc+AThU0LZgKT5Sb49QfzviMDi9WL19Zr0skTawmiTQU2niu xoUOs3AE5IXyYg04bBvlNphFMLWWWVgGR2vbx/2GXOMty1V06Mu0MyWsJAJWeRWBrKRi S2HA== X-Forwarded-Encrypted: i=1; AHgh+RpzgvCw6HWl7FBael9dxwcKugyrozd1TCf9grhCQtXCU9ji7mvlNx2UID5ZyOZMGSlVWPxmtro23+FEgcA=@vger.kernel.org X-Gm-Message-State: AOJu0Yw2jyUNwdVY8aokCf0ry/no90MxvOhNlwLRBPFLusdTWEzeCqn+ ZtzUF8y7yCR0kCIqqzO7wgW2bnr+6YC8NZZoyG4VrZ48/0PyjsrRF+U7 X-Gm-Gg: AR+sD10cdKznUahiDUoODEKpMMmPN25F52O6Wk+YF8+uF9ON24uwG2mcJmafDfv9J8S k8m8wwRVeheAH6rXdf7U8xVnmt6a7Noa8wyQajZnGhPTvRjXX1r/a+YduEnZ6gJ7j7ZeKhW8Ixc F9BLQCfe0D2V89BeplPYktbAlj3DlfqiQWp2y5fLp/7slFwnJajR8jFiWIT7iGjLXUqoPinMEY7 UVLsR01JLjCr61HTimmm4D2zfDjQ6I6Rs4+BtlHJN78PQCEGcsmrhu15A9ciflqijcNBv+Rb2Z+ GWtE6/fpzRvmXblNLXi13SIb1eLml3Yh6fLK+23cVke5V+TKLFvDnUiY9j4z/d2x2TQ34dxs0Bj ijVk0BCEe2svGnzIPJB/YqapK10jvm4MVBmYLNnNTGFtEaoK9jMBvbWjEMZpVY9oXvAshw8BaVo dIEZ8WD/VR1vRubi4K+F7Vicm8vpVOncbxzaOZpSiCZ3zmZfGvunjTFmQ4uIDuqXRasX9RfKE= X-Received: by 2002:a17:90b:3bce:b0:393:288:29e3 with SMTP id 98e67ed59e1d1-3933e5c8586mr13824749a91.10.1786790213210; Sat, 15 Aug 2026 03:36:53 -0700 (PDT) Received: from LAPTOP-N3B6U5LC.localdomain ([117.147.100.52]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-394ebc32b24sm5774757a91.17.2026.08.15.03.36.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 15 Aug 2026 03:36:52 -0700 (PDT) From: Zhenhao Wan Date: Sat, 15 Aug 2026 18:32:03 +0800 Subject: [PATCH] powerpc/spufs: account SPU context save area to memcg Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260815-spufs-lscsa-unaccounted-v1-1-3ee0949de787@gmail.com> X-B4-Tracking: v=1; b=H4sIACJAgGoC/yWMywrCMBBFf6XM2oG22Af+iriYTCY2omnJJCKU/ ruJLs/lnrODSvSicGl2iPL26tdQoDs1wAuFu6C3haFv+7GduwF1y07xqayEORDzmkMSi5OhwY0 yze5sodhbFOc/v/L19mfN5iGcaq4+DKmgiRR4qdOLNEmE4/gCsoFg8JQAAAA= X-Change-ID: 20260815-spufs-lscsa-unaccounted-7ba5f6e78f4d To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Yuhao Jiang , Zhenhao Wan X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786790206; l=2340; i=whi4ed0g@gmail.com; h=from:subject:message-id; bh=rfMjaCOvmJRa0bbW+d5HkY5VYdG1X8m8Ugnqw/d236I=; b=wg58LxDZIXz1hpQmLQwgWCGJJTZT2uI4XeLYPtgnYerF32KxQGvId9qgFmti5zPlOEulIMrIq QIQF7gZb76KDYjB5QPlPu+2grZXfQklZRiO0u8neFCHRpH48zYPHuEt X-Developer-Key: i=whi4ed0g@gmail.com; a=ed25519; pk=zRTKlstE0LmilshGwJsFYEVjiT6RiXMBXK8Og6VmuVQ= Creating an SPU context with the spu_create(2) syscall allocates a struct spu_lscsa in spu_alloc_lscsa() to hold the context's save area. struct spu_lscsa embeds the 256 KiB local store and aligns it to a 64 KiB boundary, so sizeof(struct spu_lscsa) is 320 KiB and each context pins a 320 KiB vmalloc allocation. The allocation uses plain vzalloc() (GFP_KERNEL | __GFP_ZERO), so it carries no __GFP_ACCOUNT and is not charged to any memory cgroup. The default spu_create() path (flags =3D=3D 0) performs no capability check -- it is gated only by ordinary directory write permission on the spufs mount -- and spufs imposes no limit of its own on how many contexts a caller may hold open (nr_spu_contexts is only a statistic, never compared against a limit). An unprivileged user with spufs access can therefore hold many contexts open, pinning kernel memory that is not attributed to, and so cannot be limited by, their memory cgroup. Charge the save area to the allocating task's memory cgroup by switching to __vmalloc() with GFP_KERNEL_ACCOUNT. __GFP_ZERO preserves the zeroing that vzalloc() provided; the local store pages are mapped into user space via the context's "mem" file, so they must not expose stale memory. This mirrors commit ec403e2ae0df ("memcg: enable accounting for ldt_struct objects"), which accounts the x86 LDT the same way. Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Signed-off-by: Zhenhao Wan --- arch/powerpc/platforms/cell/spufs/lscsa_alloc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/powerpc/platforms/cell/spufs/lscsa_alloc.c b/arch/powerpc= /platforms/cell/spufs/lscsa_alloc.c index 43b9dde7fd0d..df93e65bc7c1 100644 --- a/arch/powerpc/platforms/cell/spufs/lscsa_alloc.c +++ b/arch/powerpc/platforms/cell/spufs/lscsa_alloc.c @@ -23,7 +23,7 @@ int spu_alloc_lscsa(struct spu_state *csa) struct spu_lscsa *lscsa; unsigned char *p; =20 - lscsa =3D vzalloc(sizeof(*lscsa)); + lscsa =3D __vmalloc(sizeof(*lscsa), GFP_KERNEL_ACCOUNT | __GFP_ZERO); if (!lscsa) return -ENOMEM; csa->lscsa =3D lscsa; --- base-commit: f80f8c5c68a5e4d68a829ca1d8717b943a26b334 change-id: 20260815-spufs-lscsa-unaccounted-7ba5f6e78f4d Best regards, -- =20 Zhenhao Wan