From: Maxime Ripard <mripard@kernel.org>
To: Xiao Kan <814091656@qq.com>
Cc: maarten.lankhorst@linux.intel.com, tzimmermann@suse.de,
airlied@gmail.com, simona@ffwll.ch,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
w@1wt.eu, security@kernel.org, kanxiao666@gmail.com,
xiao.kan@samsung.com
Subject: Re: [PATCH v2] drm: Account property blob allocations to memcg
Date: Tue, 13 Jan 2026 16:56:31 +0100 [thread overview]
Message-ID: <20260113-kickass-sensible-basilisk-66d487@houat> (raw)
In-Reply-To: <tencent_817B74448A3DED2A1535F6290308666E4206@qq.com>
[-- Attachment #1: Type: text/plain, Size: 1139 bytes --]
Hi,
On Mon, Jan 05, 2026 at 11:14:13AM -0500, Xiao Kan wrote:
> DRM_IOCTL_MODE_CREATEPROPBLOB allows userspace to allocate arbitrary-sized
> property blobs backed by kernel memory.
>
> Currently, the blob data allocation is not accounted to the allocating
> process's memory cgroup, allowing unprivileged users to trigger unbounded
> kernel memory consumption and potentially cause system-wide OOM.
>
> Mark the property blob data allocation with GFP_ACCOUNT so that the memory
> is properly charged to the caller's memcg. This ensures existing cgroup
> memory limits apply and prevents uncontrolled kernel memory growth without
> introducing additional policy or per-file limits.
>
> Changes since v1:
> - Drop the per-drm_file blob count limit.
> - Account blob data allocations to memcg via GFP_KERNEL_ACCOUNT instead.
>
> Signed-off-by: Xiao Kan <814091656@qq.com>
> Signed-off-by: Xiao Kan <xiao.kan@samsung.com>
It looks like you sent two different patches labelled v2? Sending a new
version in itself is not a problem (and even encourage), but you should
always bump the version number.
Maxime
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 273 bytes --]
next prev parent reply other threads:[~2026-01-13 15:56 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-03 15:25 [PATCH] drm: limit property blob creation per file Xiao Kan
2026-01-05 10:36 ` Maxime Ripard
2026-01-05 15:40 ` [PATCH v2] drm: Account property blob allocations to memcg Xiao Kan
2026-01-05 16:14 ` Xiao Kan
2026-01-13 15:56 ` Maxime Ripard [this message]
2026-01-14 13:22 ` [PATCH v3] " Xiao Kan
2026-01-16 10:26 ` Maxime Ripard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260113-kickass-sensible-basilisk-66d487@houat \
--to=mripard@kernel.org \
--cc=814091656@qq.com \
--cc=airlied@gmail.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=kanxiao666@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=maarten.lankhorst@linux.intel.com \
--cc=security@kernel.org \
--cc=simona@ffwll.ch \
--cc=tzimmermann@suse.de \
--cc=w@1wt.eu \
--cc=xiao.kan@samsung.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®