From nobody Mon Sep 28 06:35:11 2026 Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A44F233D4F0 for ; Tue, 25 Aug 2026 16:17:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787674655; cv=none; b=L3mgynQ/aNHIWDq/HRt9nudcKC5PQ8L2wL0nDIJNH6YcHUjAFlUEoiiEuT+MF5+sMDQDjXK+7tmMdzjiGYmgAAapjzyoGxhRXENkSBpijdgm01ZhyYFkiamYwPyX9F6dU5DbzO2DsGeMcHW7TnihAIKH5oUVB/1rqQEJhK3JJzM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787674655; c=relaxed/simple; bh=zscTHb7YJ2cRDxeohBDLaajFLEvj+3VJkNm1DFrPM8w=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=R0DJHeUTDgAzlx7JzQRsqwn2pUhJmYuqQFsmXapD+C1NasNNzmEyDxJKGoaU178XVA36T5FG5bS7db5WG8KxkwsgqB/oYFRtMygUxECOnuAGbKJmKFT/3ES2Dn83YuVCLEGYacGCCa7GJe47GmEFyUPBKQq9qKJFqXbmdSVC4U4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Kv3AuWxi; arc=none smtp.client-ip=209.85.214.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Kv3AuWxi" Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2d6f55a7089so410565ad.3 for ; Tue, 25 Aug 2026 09:17:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787674653; x=1788279453; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=4Kv4zTQst5n5QrTxYvP5wKfU9fO9F9RsJkUjb2eOJKQ=; b=Kv3AuWxiD2PXCmkwlVHVldpsUVwk/Lx31u2jX2KemeRjQl/zu44DGmS2ASr1x8NN19 EiP+uS3uIqg8LQ2zmD5lSUlZDlEcvu8PXV8XErVFe0Xbqau9FXqC6TBSUGi2drnWf4sd MQYMFokzVHP0s0J8+d4yYgknR3U1RRPpRC1KxfZq8Fg6lho3YnoVlSy6FE3Z3MXBJUbp pqV3iSRHWoLzN9+qlWNGVPZJXjfFtTxVPUxSMgDDUWZIwmYa/GSsu/LCpI2EVNPOwiVm Ey59H3WusB0lnBKweb7mTiLL4F88QdvMV3A9gyrpUZp0piExNF/PICRfpRgiI6I1Vv8b wblA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787674653; x=1788279453; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4Kv4zTQst5n5QrTxYvP5wKfU9fO9F9RsJkUjb2eOJKQ=; b=oZe1xWiCN8hhTNvhU/N4jg9FhUmwyRmASj1OFi+jUxitAAOXSl/Fv9GO6etQVBYncL 8rPQUNV3GUklWBi1ovd5bipxS0yqtnH3N0xLjm/yyvXYzQuOoodGnVeMea626Ne2mpit RS3a0HlQfMEyWkshO8Ys+LbDWMpWX3rhtXdbVVDaAy8or+axm193gLIrDf5NzRkdFCtP e5eBjr20SZT5zTZuuyfTu2sRfdzlsPJzUrooSbUbkFoEb2910nyhP6FKTS5B7JwYfVyz 0h6+xE1blRhQTa6FWqmPElHn0r/cjiKaYQnvWSROsV9JLwFVMYCFwdiKgnWHN6u0ZbK0 SaRA== X-Gm-Message-State: AFuF++l6luOsvU5RX5kmg9FzuybIYxH3Rg8AtADKHCImd8qT36zsRkZ9 jW/MJVYsU8dU4FkvGavQ/U2sqDwvveSLqg2OgV/nCdWTnIW+vg2lgROpRpP34g2UdKQ= X-Gm-Gg: AR+sD10+p6T5iNq6KAmNw8NO6BBHyLDCyEB4i+KOzRuEvKHVsJV/N6RgcJLtMXpfSsY eDJvxFAYq/UWOXiA7r+vNIbvUPQp0ZFvC4+DY4FJ+zfJ5RWDfJeYDHOrSqvZtaD+JQr2x6+W200 SqIn6W8JUWJ6NU3a+U1d95hcDzM0Xu9pPEXQ2VX/LJqZCsuSH6sfDE3ft2+pxrF6FKsYPJPweXZ /3Tf7upwPuKDqqMBc5T4yRDqnupylR5bCVwTwqpFM5q4Wq2U+r8lrbU5q1M0QcWj1RUIlDm1W6a 8aBbXoxKYf3Us7fLvy035jlv1MpRGYGLVP5BYVMWkJpqZmI7lMFpDG/omyX0P3zUSN3HlHeTEoS rwwDccmO/7rPpvH1C7zTje/cPXpDTYlF5f3L11BbUx0O6cnc1j7wQKsWsOPa8/ykD5TkYEjJrru gEcYTauvrv3XcC3HYXYKlzdjPpBvo4hsNCQSCfLUF8CuoBdXyCiRw8TSiMtLshAtlCaW2ft701H uotLgKUXg/nZElMxuUJzdt5In67C7lZWGuwtIeNGAHrkcOBdAc6sofguzZ2iQ== X-Received: by 2002:a17:902:f685:b0:2ca:6c8:abd8 with SMTP id d9443c01a7336-2d670d5a2a6mr489202745ad.12.1787674652642; Tue, 25 Aug 2026 09:17:32 -0700 (PDT) Received: from localhost.localdomain (ppp-171-96-189-61.revip8.asianet.co.th. [171.96.189.61]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327f9209fafsm63722275eec.23.2026.08.25.09.17.29 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 25 Aug 2026 09:17:32 -0700 (PDT) From: scadastrangelove To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , =?UTF-8?q?Arve=20Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Sergey Gordeychik Subject: rust_binder: use KVVec for files_to_translate Date: Tue, 25 Aug 2026 19:17:12 +0300 Message-Id: <20260825161712.41471-1-scadastrangelove@gmail.com> X-Mailer: git-send-email 2.39.2 (Apple Git-143) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Sergey Gordeychik The num_fds value in a binder_fd_array_object is bounded by the transaction buffer. However, its in-kernel metadata is larger than the u32 array on the wire. On 64-bit systems, FileEntry occupies 24 bytes. About 900,000 entries therefore make files_to_translate request roughly 20.6 MiB of physically contiguous memory, triggering a warning in __alloc_frozen_pages_noprof. translate_fds() later allocates Reservation entries from the same count. At 16 bytes per entry, this requires another 13.7 MiB contiguous allocation. Neither vector requires physical contiguity. Use KVVec for both so large allocations can fall back to vmalloc. Keep close_on_free as KVec because its u32 storage matches the wire representation and does not reach the allocation sizes above. Tested under QEMU/KVM. The 900,000-entry reproducer no longer triggers a page allocator warning, and a 300,000-entry transaction that repeats one valid fd reaches translate_fds() without WARN or BUG. Suggested-by: rust-in-peace agentic pipeline Signed-off-by: Sergey Gordeychik Reviewed-by: Alice Ryhl --- drivers/android/binder/allocation.rs | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/android/binder/allocation.rs b/drivers/android/binder/= allocation.rs index ea5846e4d..6a95298f2 100644 --- a/drivers/android/binder/allocation.rs +++ b/drivers/android/binder/allocation.rs @@ -208,7 +208,7 @@ pub(crate) fn translate_fds(&mut self) -> Result { let num_close_on_free =3D files.iter().filter(|entry| entry.close_= on_free).count(); let mut close_on_free =3D KVec::with_capacity(num_close_on_free, G= FP_KERNEL)?; - let mut reservations =3D KVec::with_capacity(files.len(), GFP_KERN= EL)?; + let mut reservations =3D KVVec::with_capacity(files.len(), GFP_KER= NEL)?; for file_info in files { let res =3D FileDescriptorReservation::get_unused_fd_flags(bin= dings::O_CLOEXEC)?; let fd =3D res.reserved_fd(); @@ -567,7 +567,7 @@ fn type_to_size(type_: u32) -> Option { #[derive(Default)] struct FileList { - files_to_translate: KVec, + files_to_translate: KVVec, close_on_free: KVec, } @@ -581,7 +581,7 @@ struct FileEntry { } pub(crate) struct TranslatedFds { - reservations: KVec, + reservations: KVVec, /// If commit is called, then these fds should be closed. (If commit i= s not called, then they /// shouldn't be closed.) close_on_free: FdsCloseOnFree, @@ -595,7 +595,7 @@ struct Reservation { impl TranslatedFds { pub(crate) fn new() -> Self { Self { - reservations: KVec::new(), + reservations: KVVec::new(), close_on_free: FdsCloseOnFree(KVec::new()), } } -- 2.43.0