mirror of
https://github.com/hardkernel/linux.git
synced 2026-06-09 20:32:04 +09:00
UPSTREAM: kasan: avoid overflowing quarantine size on low memory systems
If the total amount of memory assigned to quarantine is less than the amount of memory assigned to per-cpu quarantines, |new_quarantine_size| may overflow. Instead, set it to zero. [akpm@linux-foundation.org: cleanup: use WARN_ONCE return value] Link: http://lkml.kernel.org/r/1470063563-96266-1-git-send-email-glider@google.com Fixes:55834c5909("mm: kasan: initial memory quarantine implementation") Signed-off-by: Alexander Potapenko <glider@google.com> Reported-by: Dmitry Vyukov <dvyukov@google.com> Cc: Andrey Ryabinin <aryabinin@virtuozzo.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> Bug: 64145065 (cherry-picked fromc3cee37228) Change-Id: I8a647e5ee5d9494698aa2a31d50d587d6ff8b65c Signed-off-by: Paul Lawrence <paullawrence@google.com>
This commit is contained in:
committed by
Paul Lawrence
parent
2771cfaf23
commit
a9674f4e53
@@ -198,7 +198,7 @@ void quarantine_put(struct kasan_free_meta *info, struct kmem_cache *cache)
|
||||
|
||||
void quarantine_reduce(void)
|
||||
{
|
||||
size_t new_quarantine_size;
|
||||
size_t new_quarantine_size, percpu_quarantines;
|
||||
unsigned long flags;
|
||||
struct qlist_head to_free = QLIST_INIT;
|
||||
size_t size_to_free = 0;
|
||||
@@ -216,7 +216,12 @@ void quarantine_reduce(void)
|
||||
*/
|
||||
new_quarantine_size = (READ_ONCE(totalram_pages) << PAGE_SHIFT) /
|
||||
QUARANTINE_FRACTION;
|
||||
new_quarantine_size -= QUARANTINE_PERCPU_SIZE * num_online_cpus();
|
||||
percpu_quarantines = QUARANTINE_PERCPU_SIZE * num_online_cpus();
|
||||
if (WARN_ONCE(new_quarantine_size < percpu_quarantines,
|
||||
"Too little memory, disabling global KASAN quarantine.\n"))
|
||||
new_quarantine_size = 0;
|
||||
else
|
||||
new_quarantine_size -= percpu_quarantines;
|
||||
WRITE_ONCE(quarantine_size, new_quarantine_size);
|
||||
|
||||
last = global_quarantine.head;
|
||||
|
||||
Reference in New Issue
Block a user