Re: [PATCH v5 2/2] alloc_tag: fix undetected compressed tag overflow when profiling is disabled
From: Suren Baghdasaryan
Date: Sat Aug 15 2026 - 01:58:38 EST
On Tue, Aug 11, 2026 at 10:41 PM Hao Ge <hao.ge@xxxxxxxxx> wrote:
>
> In reserve_module_tags(), the tag overflow check is gated on
> mem_alloc_profiling_enabled():
>
> if (mem_alloc_profiling_enabled() && !tags_addressable())
>
> If profiling is toggled off at runtime and a module is loaded whose
> tags exceed the compressed-mode limit, shutdown_mem_profiling() is
> skipped. vm_module_tags_populate() still maps memory for the tags and
> the module loads successfully, but the total tag count now exceeds what
> NR_UNUSED_PAGEFLAG_BITS can address.
>
> Once profiling is re-enabled, ref_to_idx() computes each tag's index
> as its position in the alloc_tag array. update_page_tag_ref() masks
> it to alloc_tag_ref_mask before storing in page->flags. Indices
> beyond the mask are truncated and idx_to_ref() resolves them to wrong
> tags.
>
> This silently corrupts /proc/allocinfo: allocated pages get attributed
> to the wrong call sites, so the statistics it reports are wrong.
>
> mem_alloc_profiling_enabled() and mem_profiling_compressed are
> independent. Once compressed mode is established at boot, it stays
> active regardless of runtime toggles of mem_profiling.
>
> Remove the mem_alloc_profiling_enabled() guard. On overflow, shut down
> profiling, release the reservation, and return -EAGAIN so that
> layout_and_allocate() retries with profiling disabled: codetag sections
> are then placed as regular module data and the module loads without
> profiling rather than being rejected entirely.
>
> Fixes: 4835f747d3ed ("alloc_tag: support for page allocation tag compression")
> Cc: stable@xxxxxxxxxxxxxxx
> Suggested-by: Suren Baghdasaryan <surenb@xxxxxxxxxx>
> Signed-off-by: Hao Ge <hao.ge@xxxxxxxxx>
I'm looking at your fixes for pre-existing issues reported by Sashiko
but this patch looks correct to me.
Acked-by: Suren Baghdasaryan <surenb@xxxxxxxxxx>
> ---
> kernel/module/main.c | 25 +++++++++++++++++++++++--
> mm/alloc_tag.c | 8 +++++---
> 2 files changed, 28 insertions(+), 5 deletions(-)
>
> diff --git a/kernel/module/main.c b/kernel/module/main.c
> index 46dd8d25a605..ed26f167be84 100644
> --- a/kernel/module/main.c
> +++ b/kernel/module/main.c
> @@ -2944,6 +2944,7 @@ static struct module *layout_and_allocate(struct load_info *info, int flags)
> {
> struct module *mod;
> int err;
> + unsigned long frob_size[MOD_MEM_NUM_TYPES];
>
> /* Allow arches to frob section contents and sizes. */
> err = module_frob_arch_sections(info->hdr, info->sechdrs,
> @@ -2966,18 +2967,38 @@ static struct module *layout_and_allocate(struct load_info *info, int flags)
> */
> module_mark_ro_after_init(info->hdr, info->sechdrs, info->secstrings);
>
> + /*
> + * Save the sizes reserved by module_frob_arch_sections() so they can
> + * be restored if we retry below.
> + */
> + for_each_mod_mem_type(type)
> + frob_size[type] = info->mod->mem[type].size;
> +
> /*
> * Determine total sizes, and put offsets in sh_entsize. For now
> * this is done generically; there doesn't appear to be any
> * special cases for the architectures.
> */
> +retry:
> layout_sections(info->mod, info);
> layout_symtab(info->mod, info);
>
> /* Allocate and move to the final place */
> err = move_module(info->mod, info);
> - if (err)
> - return ERR_PTR(err);
> + if (err) {
> + if (err != -EAGAIN)
> + return ERR_PTR(err);
> + /*
> + * -EAGAIN means profiling was disabled but the module
> + * can still load without it. Reset state and retry.
> + */
> + rewrite_section_headers(info, flags);
> + for_each_mod_mem_type(type)
> + info->mod->mem[type].size = frob_size[type];
> + info->sechdrs[info->index.sym].sh_flags &= ~(unsigned long)SHF_ALLOC;
> + info->sechdrs[info->index.str].sh_flags &= ~(unsigned long)SHF_ALLOC;
> + goto retry;
> + }
>
> /* Module has been copied to its final place now: return it. */
> mod = (void *)info->sechdrs[info->index.mod].sh_addr;
> diff --git a/mm/alloc_tag.c b/mm/alloc_tag.c
> index af44f90379f2..0a7b657fe2de 100644
> --- a/mm/alloc_tag.c
> +++ b/mm/alloc_tag.c
> @@ -950,10 +950,12 @@ static void *reserve_module_tags(struct module *mod, unsigned long size,
> int grow_res;
>
> module_tags.size = offset + size;
> - if (mem_alloc_profiling_enabled() && !tags_addressable()) {
> + if (!tags_addressable()) {
> shutdown_mem_profiling(true);
> - pr_warn("With module %s there are too many tags to fit in %d page flag bits. Memory allocation profiling is disabled!\n",
> - mod->name, NR_UNUSED_PAGEFLAG_BITS);
> + pr_warn_once("With module %s there are too many tags to fit in %d page flag bits. Memory allocation profiling is disabled!\n",
> + mod->name, NR_UNUSED_PAGEFLAG_BITS);
> + release_module_tags(mod, false);
> + return ERR_PTR(-EAGAIN);
> }
>
> grow_res = vm_module_tags_populate();
> --
> 2.25.1
>