Re: [PATCH slab/for-next-fixes v3 1/4] mm/slab: fix a memory leak due to bootstrapping sheaves twice

From: Suren Baghdasaryan

Date: Mon Jul 13 2026 - 11:34:35 EST


On Mon, Jul 13, 2026 at 7:29 AM Harry Yoo (Oracle) <harry@xxxxxxxxxx> wrote:
>
> When kmalloc caches are aliased, multiple cache pointers reference
> the same kmem_cache. As a result, iterating over kmalloc indices and
> bootstrapping sheaves can bootstrap the same cache more than once and
> leak memory.
>
> Currently, this could happen when the architecture specifies
> minimum alignment for slab caches that is larger than
> ARCH_KMALLOC_MINALIGN.
>
> Bootstrap sheaves only when the cache does not have them already.
> Add a warning when bootstrap_cache_sheaves() is called for a cache
> that already has sheaves enabled.
>
> Cc: stable@xxxxxxxxxxxxxxx
> Fixes: 913ffd3a1bf5 ("slab: handle kmalloc sheaves bootstrap")
> Signed-off-by: Harry Yoo (Oracle) <harry@xxxxxxxxxx>

nit: Don't know if we really need a warning... I would just do an
early return from bootstrap_cache_sheaves() if cache_has_sheaves() is
true. But that's not critical.

Reviewed-by: Suren Baghdasaryan <surenb@xxxxxxxxxx>

> ---
> mm/slub.c | 9 +++++++--
> 1 file changed, 7 insertions(+), 2 deletions(-)
>
> diff --git a/mm/slub.c b/mm/slub.c
> index 65febe957886..f9461a0c47d3 100644
> --- a/mm/slub.c
> +++ b/mm/slub.c
> @@ -8497,6 +8497,8 @@ static void __init bootstrap_cache_sheaves(struct kmem_cache *s)
> bool failed = false;
> int node, cpu;
>
> + VM_WARN_ON_ONCE(cache_has_sheaves(s));
> +
> capacity = calculate_sheaf_capacity(s, &empty_args);
>
> /* capacity can be 0 due to debugging or SLUB_TINY */
> @@ -8548,8 +8550,11 @@ static void __init bootstrap_kmalloc_sheaves(void)
>
> for (type = KMALLOC_NORMAL; type <= KMALLOC_PARTITION_END; type++) {
> for (int idx = 0; idx < KMALLOC_SHIFT_HIGH + 1; idx++) {
> - if (kmalloc_caches[type][idx])
> - bootstrap_cache_sheaves(kmalloc_caches[type][idx]);
> + struct kmem_cache *s = kmalloc_caches[type][idx];
> +
> + /* Do not bootstrap twice when caches are aliased */
> + if (s && !cache_has_sheaves(s))
> + bootstrap_cache_sheaves(s);
> }
> }
> }
>
> --
> 2.53.0
>