]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
kho: fix unpreservation of higher-order vmalloc preservations
authorPratyush Yadav <pratyush@kernel.org>
Mon, 3 Nov 2025 18:02:31 +0000 (19:02 +0100)
committerAndrew Morton <akpm@linux-foundation.org>
Mon, 10 Nov 2025 05:19:47 +0000 (21:19 -0800)
kho_vmalloc_unpreserve_chunk() calls __kho_unpreserve() with end_pfn as
pfn + 1.  This happens to work for 0-order pages, but leaks higher order
pages.

For example, say order 2 pages back the allocation.  During preservation,
they get preserved in the order 2 bitmaps, but
kho_vmalloc_unpreserve_chunk() would try to unpreserve them from the order
0 bitmaps, which should not have these bits set anyway, leaving the order
2 bitmaps untouched.  This results in the pages being carried over to the
next kernel.  Nothing will free those pages in the next boot, leaking
them.

Fix this by taking the order into account when calculating the end PFN for
__kho_unpreserve().

Link: https://lkml.kernel.org/r/20251103180235.71409-2-pratyush@kernel.org
Fixes: a667300bd53f ("kho: add support for preserving vmalloc allocations")
Signed-off-by: Pratyush Yadav <pratyush@kernel.org>
Reviewed-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Cc: Alexander Graf <graf@amazon.com>
Cc: Baoquan He <bhe@redhat.com>
Cc: Pasha Tatashin <pasha.tatashin@soleen.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
kernel/kexec_handover.c

index 36fdce2667c5613d9a989a4195c36b9382873257..e0bafe7c0ded794c79cc0713674c96604a2ab99a 100644 (file)
@@ -882,7 +882,8 @@ err_free:
        return NULL;
 }
 
-static void kho_vmalloc_unpreserve_chunk(struct kho_vmalloc_chunk *chunk)
+static void kho_vmalloc_unpreserve_chunk(struct kho_vmalloc_chunk *chunk,
+                                        unsigned short order)
 {
        struct kho_mem_track *track = &kho_out.ser.track;
        unsigned long pfn = PHYS_PFN(virt_to_phys(chunk));
@@ -891,7 +892,7 @@ static void kho_vmalloc_unpreserve_chunk(struct kho_vmalloc_chunk *chunk)
 
        for (int i = 0; i < ARRAY_SIZE(chunk->phys) && chunk->phys[i]; i++) {
                pfn = PHYS_PFN(chunk->phys[i]);
-               __kho_unpreserve(track, pfn, pfn + 1);
+               __kho_unpreserve(track, pfn, pfn + (1 << order));
        }
 }
 
@@ -902,7 +903,7 @@ static void kho_vmalloc_free_chunks(struct kho_vmalloc *kho_vmalloc)
        while (chunk) {
                struct kho_vmalloc_chunk *tmp = chunk;
 
-               kho_vmalloc_unpreserve_chunk(chunk);
+               kho_vmalloc_unpreserve_chunk(chunk, kho_vmalloc->order);
 
                chunk = KHOSER_LOAD_PTR(chunk->hdr.next);
                free_page((unsigned long)tmp);