From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2A59A32C305 for ; Tue, 13 Jan 2026 15:56:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768319794; cv=none; b=qfL9ttTy4ArHqk/jDwC6peaRAzuX4h5PIuadG4Gw1zGPUPI2EnIGzorCoVM/RL9+H9WmaiexUOTBFtoTLFsx1HENq4NUqsSE5Vd2isXIbLGY0URXM296/teD+G+77ASTXy1RLU00JwmyXno46+9X88k4pv7m5G4lTWOL0NfB0fw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768319794; c=relaxed/simple; bh=XmmO4eigvsjhYZsKYVguJ3MD+xURrXSOfaIeJSmmkzU=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=b3RW9ZVTrx7AxXxN8x7hnBsZxNxFHJdvvbCBxusWhlCxCx0ViNm0DOJ688tbdzPxNScLHnqJKL8eqx2U/imnEWNmTbnV1OIS+DIzZJWwDi2dJc8JnMOgAYZhDoZ6JcVHBYscmcFFNoViaBmKcoSEStJcnYK0kot8zVOVW2Yogbo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=uSfoIVOb; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="uSfoIVOb" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 547ACC116C6; Tue, 13 Jan 2026 15:56:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1768319793; bh=XmmO4eigvsjhYZsKYVguJ3MD+xURrXSOfaIeJSmmkzU=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=uSfoIVObSK1ZHvp48d0wP9bpnVJIp/Mqv+0QSOcJFL4eofct0tFh+RV4UY6Ce6Xza imS1H3EonpbiPriEgQX4ZbQl+NrRj7Iws8fD+jyqeLkwl9JPJHPB328ljaiLHsJJ1l UmPhFHyTubshC6zSHdyKUheoQJH1H5yEpmIQepSx5j03b3SYK8pnRxlvz4/Klkb3/L 46HtF9Jo8oD2KRgFkkOUyEHQab8iD6wcxjb01dWLdImkUmD05zXeW+YBcITviUK0Wd FOyPsLHiwN8wAWlZ+Sj9M0GwC6/qGtGBmJnoI1m3ixU3xg2atj0dLefGAyn8iMgjWZ HYIAJyhYukNmw== Date: Tue, 13 Jan 2026 16:56:31 +0100 From: Maxime Ripard To: Xiao Kan <814091656@qq.com> Cc: maarten.lankhorst@linux.intel.com, tzimmermann@suse.de, airlied@gmail.com, simona@ffwll.ch, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, w@1wt.eu, security@kernel.org, kanxiao666@gmail.com, xiao.kan@samsung.com Subject: Re: [PATCH v2] drm: Account property blob allocations to memcg Message-ID: <20260113-kickass-sensible-basilisk-66d487@houat> References: <20260105-abiding-aloof-locust-dcadac@houat> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha384; protocol="application/pgp-signature"; boundary="nockj24eq2mz3xjv" Content-Disposition: inline In-Reply-To: --nockj24eq2mz3xjv Content-Type: text/plain; protected-headers=v1; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Subject: Re: [PATCH v2] drm: Account property blob allocations to memcg MIME-Version: 1.0 Hi, On Mon, Jan 05, 2026 at 11:14:13AM -0500, Xiao Kan wrote: > DRM_IOCTL_MODE_CREATEPROPBLOB allows userspace to allocate arbitrary-sized > property blobs backed by kernel memory. >=20 > Currently, the blob data allocation is not accounted to the allocating > process's memory cgroup, allowing unprivileged users to trigger unbounded > kernel memory consumption and potentially cause system-wide OOM. >=20 > Mark the property blob data allocation with GFP_ACCOUNT so that the memory > is properly charged to the caller's memcg. This ensures existing cgroup > memory limits apply and prevents uncontrolled kernel memory growth without > introducing additional policy or per-file limits. >=20 > Changes since v1: > - Drop the per-drm_file blob count limit. > - Account blob data allocations to memcg via GFP_KERNEL_ACCOUNT instead. >=20 > Signed-off-by: Xiao Kan <814091656@qq.com> > Signed-off-by: Xiao Kan It looks like you sent two different patches labelled v2? Sending a new version in itself is not a problem (and even encourage), but you should always bump the version number. Maxime --nockj24eq2mz3xjv Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iJUEABMJAB0WIQTkHFbLp4ejekA/qfgnX84Zoj2+dgUCaWZrKgAKCRAnX84Zoj2+ dke0AX0XqaaweRGyv7Lfp2P44eeacopKQH3Ngpyh3UWZO2fk4XmKMyveOr/lWhXN h8WEF1ABgOPlCUbB12J/wp0yiavQjIGP+LrfJ07ImS6Sj9t5dGzvIS47mApwbC3m 9Vk2EDZk3w== =5oNp -----END PGP SIGNATURE----- --nockj24eq2mz3xjv--