]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
mm/kmemleak: fix checksum computation for per-cpu objects
authorBreno Leitao <leitao@debian.org>
Fri, 3 Jul 2026 16:17:24 +0000 (09:17 -0700)
committerAndrew Morton <akpm@linux-foundation.org>
Thu, 9 Jul 2026 22:48:55 +0000 (15:48 -0700)
The per-cpu object checksum folds each CPU's CRC together with XOR and
seeds every CRC with 0.  Both choices make update_checksum() miss content
changes:

  - XOR is self-cancelling, so equal contents on two CPUs cancel out and
    simultaneous identical changes leave the checksum unchanged.
  - crc32(0, ...) over all-zero content is 0, so a freshly allocated,
    zeroed per-cpu area checksums to 0, matching the initial value, and
    the object is never seen to change.

See discussions at [0].

When update_checksum() wrongly reports an actively modified object as
unchanged, kmemleak stops greying it for an extra scan and can report a
live per-cpu object as a leak.

Fold the per-cpu CRC as a single rolling checksum across all CPUs and
initialise the object checksum to ~0 so the first computed value always
registers as a change, even for content that hashes to 0.
reset_checksum() is seeded the same way.

Link: https://lore.kernel.org/all/akfYImSNDh3OjIfR@gmail.com
Link: https://lore.kernel.org/20260703-kmemleak_checksum-v1-1-5e0ab7d6966f@debian.org
Fixes: 6c99d4eb7c5e ("kmemleak: enable tracking for percpu pointers")
Signed-off-by: Breno Leitao <leitao@debian.org>
Co-developed-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Reviewed-by: Pavel Tikhomirov <ptikhomirov@virtuozzo.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
mm/kmemleak.c

index 7c7ba17ce7af00331380eb91b57dd00e88ae1183..e196f53f9b46205374868874f835a93031586fb8 100644 (file)
@@ -687,7 +687,7 @@ static struct kmemleak_object *__alloc_object(gfp_t gfp)
        atomic_set(&object->use_count, 1);
        object->excess_ref = 0;
        object->count = 0;                      /* white color initially */
-       object->checksum = 0;
+       object->checksum = ~0;
        object->del_state = 0;
 
        /* task information */
@@ -981,7 +981,7 @@ static void reset_checksum(unsigned long ptr)
        }
 
        raw_spin_lock_irqsave(&object->lock, flags);
-       object->checksum = 0;
+       object->checksum = ~0;
        raw_spin_unlock_irqrestore(&object->lock, flags);
        put_object(object);
 }
@@ -1410,7 +1410,8 @@ static bool update_checksum(struct kmemleak_object *object)
                for_each_possible_cpu(cpu) {
                        void *ptr = per_cpu_ptr((void __percpu *)object->pointer, cpu);
 
-                       object->checksum ^= crc32(0, kasan_reset_tag((void *)ptr), object->size);
+                       object->checksum = crc32(object->checksum,
+                                                kasan_reset_tag((void *)ptr), object->size);
                }
        } else {
                object->checksum = crc32(0, kasan_reset_tag((void *)object->pointer), object->size);