[PATCH net-next v6 5/8] mm/slab: Add kmem_buckets_destroy()

From: Kees Cook

Date: Tue Oct 06 2026 - 05:21:42 EST


kmem_buckets_create() intentionally had no "destroy" counterpart. Every
caller has lived in core kernel code and creates its set once at boot,
so nothing has needed to take one down. However, KUnit tests may be
built module, so we need it now to support the coming tests.

Some caches have size aliases, so the same pointer is stored at more
then one index, so we have to save it, clear all matching instances, and
then free the saved cache pointer. (This is what the bitmap was tracking
before in the "allocation failed" error path.)

When CONFIG_SLAB_BUCKETS=n the whole body compiles away, matching the
ZERO_SIZE_PTR that kmem_buckets_create() hands back in that configuration.

Link: https://lore.kernel.org/all/20240809073309.2134488-1-kees@xxxxxxxxxx/
Assisted-by: LLM
Signed-off-by: Kees Cook <kees@xxxxxxxxxx>
---
include/linux/slab.h | 1 +
mm/slab_common.c | 50 +++++++++++++++++++++++++++++++++++++-------
2 files changed, 44 insertions(+), 7 deletions(-)

diff --git a/include/linux/slab.h b/include/linux/slab.h
index 31f97e2579a7..034d4d0ece00 100644
--- a/include/linux/slab.h
+++ b/include/linux/slab.h
@@ -892,6 +892,7 @@ void kmem_cache_free(struct kmem_cache *s, void *objp);

kmem_buckets *kmem_buckets_create(const char *name, unsigned int useroffset,
unsigned int usersize);
+void kmem_buckets_destroy(kmem_buckets *bucket);

/*
* Bulk allocation and freeing operations. These are accelerated in an
diff --git a/mm/slab_common.c b/mm/slab_common.c
index 885aafa23da7..fb1dd15953a7 100644
--- a/mm/slab_common.c
+++ b/mm/slab_common.c
@@ -430,12 +430,9 @@ static struct kmem_cache *kmem_buckets_cache __ro_after_init;
kmem_buckets *kmem_buckets_create(const char *name, unsigned int useroffset,
unsigned int usersize)
{
- unsigned long mask = 0;
unsigned int idx;
kmem_buckets *b;

- BUILD_BUG_ON(ARRAY_SIZE(kmalloc_caches[KMALLOC_NORMAL]) > BITS_PER_LONG);
-
/*
* When the separate buckets API is not built in, just return
* a non-NULL value for the kmem_buckets pointer, which will be
@@ -487,7 +484,6 @@ kmem_buckets *kmem_buckets_create(const char *name, unsigned int useroffset,
kfree(cache_name);
if (WARN_ON(!(*b)[aligned_idx]))
goto fail;
- set_bit(aligned_idx, &mask);
}
if (idx != aligned_idx)
(*b)[idx] = (*b)[aligned_idx];
@@ -496,14 +492,54 @@ kmem_buckets *kmem_buckets_create(const char *name, unsigned int useroffset,
return b;

fail:
- for_each_set_bit(idx, &mask, ARRAY_SIZE(kmalloc_caches[KMALLOC_NORMAL]))
- kmem_cache_destroy((*b)[idx]);
- kmem_cache_free(kmem_buckets_cache, b);
+ kmem_buckets_destroy(b);

return NULL;
}
EXPORT_SYMBOL(kmem_buckets_create);

+/**
+ * kmem_buckets_destroy - Destroy a set of caches made by kmem_buckets_create()
+ * @bucket: The set to destroy, which may be NULL.
+ *
+ * Destroys each cache in @bucket and then frees @bucket itself. As for
+ * kmem_cache_destroy(), every object allocated from @bucket must have been
+ * freed beforehand, and @bucket must not be used afterwards.
+ *
+ * Context: Process context. May sleep, as kmem_cache_destroy() takes the
+ * slab mutex and can wait on RCU callbacks for each cache.
+ */
+void kmem_buckets_destroy(kmem_buckets *bucket)
+{
+ unsigned int idx, i;
+
+ if (!IS_ENABLED(CONFIG_SLAB_BUCKETS) || ZERO_OR_NULL_PTR(bucket))
+ return;
+
+ for (idx = 0; idx < ARRAY_SIZE(kmalloc_caches[KMALLOC_NORMAL]); idx++) {
+ struct kmem_cache *cache = (*bucket)[idx];
+
+ if (!cache)
+ continue;
+
+ /*
+ * Sizes that kmalloc rounds up to a larger size class share
+ * that class's cache, which kmem_buckets_create() then stores
+ * at each of their indices.
+ * Drop every reference to it before destroying it, so that no
+ * later pass reads a pointer to a cache that is already gone.
+ */
+ for (i = idx; i < ARRAY_SIZE(kmalloc_caches[KMALLOC_NORMAL]); i++)
+ if ((*bucket)[i] == cache)
+ (*bucket)[i] = NULL;
+
+ kmem_cache_destroy(cache);
+ }
+
+ kmem_cache_free(kmem_buckets_cache, bucket);
+}
+EXPORT_SYMBOL(kmem_buckets_destroy);
+
/*
* For a given kmem_cache, kmem_cache_destroy() should only be called
* once or there will be a use-after-free problem. The actual deletion
--
2.55.0