[PATCH v5 2/2] alloc_tag: fix undetected compressed tag overflow when profiling is disabled

From: Hao Ge

Date: Wed Aug 12 2026 - 01:42:20 EST


In reserve_module_tags(), the tag overflow check is gated on
mem_alloc_profiling_enabled():

if (mem_alloc_profiling_enabled() && !tags_addressable())

If profiling is toggled off at runtime and a module is loaded whose
tags exceed the compressed-mode limit, shutdown_mem_profiling() is
skipped. vm_module_tags_populate() still maps memory for the tags and
the module loads successfully, but the total tag count now exceeds what
NR_UNUSED_PAGEFLAG_BITS can address.

Once profiling is re-enabled, ref_to_idx() computes each tag's index
as its position in the alloc_tag array. update_page_tag_ref() masks
it to alloc_tag_ref_mask before storing in page->flags. Indices
beyond the mask are truncated and idx_to_ref() resolves them to wrong
tags.

This silently corrupts /proc/allocinfo: allocated pages get attributed
to the wrong call sites, so the statistics it reports are wrong.

mem_alloc_profiling_enabled() and mem_profiling_compressed are
independent. Once compressed mode is established at boot, it stays
active regardless of runtime toggles of mem_profiling.

Remove the mem_alloc_profiling_enabled() guard. On overflow, shut down
profiling, release the reservation, and return -EAGAIN so that
layout_and_allocate() retries with profiling disabled: codetag sections
are then placed as regular module data and the module loads without
profiling rather than being rejected entirely.

Fixes: 4835f747d3ed ("alloc_tag: support for page allocation tag compression")
Cc: stable@xxxxxxxxxxxxxxx
Suggested-by: Suren Baghdasaryan <surenb@xxxxxxxxxx>
Signed-off-by: Hao Ge <hao.ge@xxxxxxxxx>
---
kernel/module/main.c | 25 +++++++++++++++++++++++--
mm/alloc_tag.c | 8 +++++---
2 files changed, 28 insertions(+), 5 deletions(-)

diff --git a/kernel/module/main.c b/kernel/module/main.c
index 46dd8d25a605..ed26f167be84 100644
--- a/kernel/module/main.c
+++ b/kernel/module/main.c
@@ -2944,6 +2944,7 @@ static struct module *layout_and_allocate(struct load_info *info, int flags)
{
struct module *mod;
int err;
+ unsigned long frob_size[MOD_MEM_NUM_TYPES];

/* Allow arches to frob section contents and sizes. */
err = module_frob_arch_sections(info->hdr, info->sechdrs,
@@ -2966,18 +2967,38 @@ static struct module *layout_and_allocate(struct load_info *info, int flags)
*/
module_mark_ro_after_init(info->hdr, info->sechdrs, info->secstrings);

+ /*
+ * Save the sizes reserved by module_frob_arch_sections() so they can
+ * be restored if we retry below.
+ */
+ for_each_mod_mem_type(type)
+ frob_size[type] = info->mod->mem[type].size;
+
/*
* Determine total sizes, and put offsets in sh_entsize. For now
* this is done generically; there doesn't appear to be any
* special cases for the architectures.
*/
+retry:
layout_sections(info->mod, info);
layout_symtab(info->mod, info);

/* Allocate and move to the final place */
err = move_module(info->mod, info);
- if (err)
- return ERR_PTR(err);
+ if (err) {
+ if (err != -EAGAIN)
+ return ERR_PTR(err);
+ /*
+ * -EAGAIN means profiling was disabled but the module
+ * can still load without it. Reset state and retry.
+ */
+ rewrite_section_headers(info, flags);
+ for_each_mod_mem_type(type)
+ info->mod->mem[type].size = frob_size[type];
+ info->sechdrs[info->index.sym].sh_flags &= ~(unsigned long)SHF_ALLOC;
+ info->sechdrs[info->index.str].sh_flags &= ~(unsigned long)SHF_ALLOC;
+ goto retry;
+ }

/* Module has been copied to its final place now: return it. */
mod = (void *)info->sechdrs[info->index.mod].sh_addr;
diff --git a/mm/alloc_tag.c b/mm/alloc_tag.c
index af44f90379f2..0a7b657fe2de 100644
--- a/mm/alloc_tag.c
+++ b/mm/alloc_tag.c
@@ -950,10 +950,12 @@ static void *reserve_module_tags(struct module *mod, unsigned long size,
int grow_res;

module_tags.size = offset + size;
- if (mem_alloc_profiling_enabled() && !tags_addressable()) {
+ if (!tags_addressable()) {
shutdown_mem_profiling(true);
- pr_warn("With module %s there are too many tags to fit in %d page flag bits. Memory allocation profiling is disabled!\n",
- mod->name, NR_UNUSED_PAGEFLAG_BITS);
+ pr_warn_once("With module %s there are too many tags to fit in %d page flag bits. Memory allocation profiling is disabled!\n",
+ mod->name, NR_UNUSED_PAGEFLAG_BITS);
+ release_module_tags(mod, false);
+ return ERR_PTR(-EAGAIN);
}

grow_res = vm_module_tags_populate();
--
2.25.1