[PATCH net-next v6 0/8] net: skb: isolate skb data area allocations into a separate bucket
From: Kees Cook
Date: Tue Oct 06 2026 - 05:20:57 EST
Hi!
This gets the buckets able to handle memcg (GFP_KERNEL_ACCOUNT) with
isolation (since it's common due to AF_UNIX), and GFP_DMA with fall back
(since it's rare). It gave me an excuse to build out bucket kunit tests
too, and that (and LLM review) found a couple other issues that needed
fixing too, including msg_msg allocations going uncharged to their memcg
when CONFIG_SLAB_BUCKETS=n (fixed in 2/8).
Harry, on your v4 question[1] about bucket users giving their own
alignment: I tried that in v5, but a set's allocations don't always
come from its own caches. With CONFIG_SLAB_BUCKETS=n, after a failed
kmem_buckets_create(), and for the DMA and reclaimable fallbacks, they
come from the general kmalloc caches, which can only give kmalloc()'s
alignment. So v6 goes back to mirroring the kmalloc cache's alignment,
and drops the ctor and flags arguments for the same reason. And the whole
exploration made me realize I had a completely wrong understanding of
how memcg worked. :P
The bulk of this is mm/slab, but the final patch is netdev, which Paolo
acked in v4, so I'm hoping this whole series can go via slab?
Thanks!
-Kees
v6:
- drop v5's 6/7 ("Let a bucket set handle __GFP_ACCOUNT") and its
kmem_buckets_create_types(): memcg charges each object in whatever
cache serves it, so accounted allocations can stay in a set's single
row of caches, and the fallback now covers only DMA, reclaimable, and
no-obj-ext allocations (Sashiko)
- 2/8: new: account msg_msg with GFP_KERNEL_ACCOUNT again; with
CONFIG_SLAB_BUCKETS=n it went uncharged, since its accounting lived in
SLAB_ACCOUNT on bucket caches that are not created (Sashiko)
- 3/8: new: drop the ctor and flags arguments from kmem_buckets_create();
neither reaches allocations that fall back to the general kmalloc
caches, and no caller needs them any more (Sashiko)
- 4/8: go back to v4's form: no alignment argument, and each bucket cache
takes the alignment of the kmalloc cache it mirrors, since the fallbacks
to kmalloc can give no other (Sashiko, Harry)
- 5/8: say in the teardown comment that cache sharing comes from kmalloc
rounding sizes up to a larger class (Sashiko)
- 6/8: drop the explicit alignment tests; check that each size lands in
the cache of the size kmalloc() rounds it up to, not just a big enough
one; and in the destroy test, assert on the allocation, skip when KFENCE
serves it, and tear the set down through its KUnit cleanup action
(Sashiko)
- 7/8: keep __GFP_ACCOUNT allocations in the set, document what an
allocation that falls back loses, and test the reclaimable fallback
(Sashiko)
- 8/8: create the skb_data set with kmem_buckets_create(), and make the
comment above kmalloc_reserve() name no allocator (Sashiko)
- v5..v6 diff: https://git.kernel.org/pub/scm/linux/kernel/git/kees/linux.git/diff/?id=dev/v7.3-rc2/skb-buckets/v6&id2=dev/v7.3-rc2/skb-buckets/v5
v5: https://lore.kernel.org/all/20261002231120.late.500-kees@xxxxxxxxxx/
v4: https://lore.kernel.org/all/20260921075811.too.775-kees@xxxxxxxxxx/
v3: https://lore.kernel.org/all/20260702170728.168755-1-pfalcato@xxxxxxx/
[1] https://lore.kernel.org/all/arViR2Miz61-3fV4@thinkstation/
Kees Cook (7):
mm/slab: Mark the kmem_buckets_create() context as a Context: section
ipc, msg: Account msg_msg allocations with GFP_KERNEL_ACCOUNT again
mm/slab: Drop the ctor and flags arguments from kmem_buckets_create()
mm/slab: Give bucket caches the alignment of the caches they mirror
mm/slab: Add kmem_buckets_destroy()
mm/slab: Add tests for the existing kmem_buckets behaviour
mm/slab: Provide kmalloc type fallback for bucket allocations
Pedro Falcato (1):
net: skb: isolate skb data area allocations into a separate bucket
include/linux/slab.h | 6 +-
mm/slab.h | 19 ++-
ipc/msgutil.c | 8 +-
lib/tests/slub_kunit.c | 291 +++++++++++++++++++++++++++++++++++++++++
mm/slab_common.c | 74 ++++++++---
mm/util.c | 2 +-
net/core/skbuff.c | 10 +-
7 files changed, 378 insertions(+), 32 deletions(-)
--
2.55.0