[PATCH v2 0/3] KASAN: HW_TAGS: Disable tagging for stack and page-tables
From: Muhammad Usama Anjum
Date: Tue Mar 24 2026 - 09:32:20 EST
Stacks and page tables are always accessed with the match‑all tag,
so assigning a new random tag every time at allocation and setting
invalid tag at deallocation time, just adds overhead without improving
the detection.
With __GFP_SKIP_KASAN the page keeps its poison tag and KASAN_TAG_KERNEL
(match-all tag) is stored in the page flags while keeping the poison tag
in the hardware. The benefit of it is that 256 tag setting instruction
per 4 kB page aren't needed at allocation and deallocation time.
Thus match‑all pointers still work, while non‑match tags (other than
poison tag) still fault.
__GFP_SKIP_KASAN only skips for KASAN_HW_TAGS mode, so coverage is
unchanged.
Benchmark:
The benchmark has two modes. In thread mode, the child process forks
and creates N threads. In pgtable mode, the parent maps and faults a
specified memory size and then forks repeatedly with children exiting
immediately.
Thread benchmark:
2000 iterations, 2000 threads: 2.575 s → 2.229 s (~13.4% faster)
The pgtable samples:
- 2048 MB, 2000 iters 19.08 s → 17.62 s (~7.6% faster)
---
Changes since v1: (summary only)
- Update description/title
- Patch 1: Simplify skip conditions based on the fact that __GFP_SKIP_KASAN
- Patch 2: Specify _GFP_SKIP_KASAN in THREADINFO_GFP and GFP_VMAP_STACK
Muhammad Usama Anjum (3):
vmalloc: add __GFP_SKIP_KASAN support
kasan: skip HW tagging for all kernel thread stacks
mm: skip KASAN tagging for page-allocated page tables
include/asm-generic/pgalloc.h | 2 +-
include/linux/thread_info.h | 2 +-
kernel/fork.c | 5 +++--
mm/vmalloc.c | 11 ++++++++---
4 files changed, 13 insertions(+), 7 deletions(-)
--
2.47.3