From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f49.google.com (mail-ej1-f49.google.com [209.85.218.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C05F141D236 for ; Mon, 17 Aug 2026 12:43:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786970588; cv=none; b=Cin+ho1yrwkFmXIO/ufsBfQ8gOr+cjkj8pj5/NDRKZ6ezDCoKe8b4+2Qa9SY19o/BVpqo/UcZB2w3iK/nEljaTvL2f2EE/V+PXTB7cRjZit8vCYcGYaJWeuNmaxzcIfb15okRa3zzRm4feAE/LnLaHGVg4ezKvqN3qc3c4PeRUg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786970588; c=relaxed/simple; bh=0RLaQ+92eQAJAGljPWO672IUauMEYT9qdG3jEOmsWHM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=AuVinPTFe0yByaqNOFsHnxJc/ESs1wsHsPnMoPaGChPFYvj/l8itfeiNaR36RcFomGV55BF6K03mYKYz5fXcBQ6zoksi4+lEW9BQNqoryrlgiU7wDJp/ofz2PDoH7IkKS4yu7ayJUsZnFBbYqgBYoyWhdO41BcGbMNpGV9Kdcc8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ooxdBXKP; arc=none smtp.client-ip=209.85.218.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ooxdBXKP" Received: by mail-ej1-f49.google.com with SMTP id a640c23a62f3a-c15d111ca99so354093566b.0 for ; Mon, 17 Aug 2026 05:43:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786970585; x=1787575385; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZNN86hXrdrGG1E/YizrMzJjnTH3T1mAw0aE/Reny4I4=; b=ooxdBXKPw70ZILb3zJRUY3jO8R7vCmC+96Me5K7eedsVd3exrATd+fQo5H2e8BHSnR 8gvnrdDJj1zMY75r6zFh1Mveh2NMfHWvr/DbIsWJMjmZ68hAOqKvonggSxYU9qzDtr4O VnR7vpxDpRPiBWj58Ufe8b4a9SHmjaGRs8JZzKZcPsJZkR7tx+jcwsnTlgEsseJh4IBE s5+G8Cdo+EEueJeuduXKTx3eU1Csl/Yw/yEBV/oWdUdGg7WfEswj3c8cWCr/WAFtoc+v wJUPOKANiYbxCphQmNAbtatlj9+hyJllzWGxAG/PSHoDn5/7kfEmdvU4pNsdQjRJf6Dk nb4g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786970585; x=1787575385; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ZNN86hXrdrGG1E/YizrMzJjnTH3T1mAw0aE/Reny4I4=; b=P7GYQ7WMxqi6OrLZxKH5DYm1h03u++rEUWjB6qBpVjGI70wSckYFxmSE2E8NZs9DdR 4bjCJHs8Sk4FWw0gbzuTpZmRvDMvxeJ3wthp8VkxUS+UYoCRLKa33BuRzGyXTmC+iTUg Pa6J5K7+/yfg5EGX3ligbEixIQoXaTMduSBjXriDrk8aZyNFY6BntVje0rGwPUwHfU7O tDzWTds97ws5Qagoa+FfPp+jtuVQaGBkJJhGP3p7b9/SKDD6HYvYsudFXuigrcs1AcpC s4Osv+qVBEuYcPuY6sTibv4t/Xc0t/wMAHQBNenbOHJBXwdMhYxG/ZHhmwFOpDo3+7Ac gDDw== X-Forwarded-Encrypted: i=1; AHgh+RomM5llquPg01FRvPIUrfa3UE6tP0IAr6oZS5qKJa6++0a7AKEMhFlfYL6ZIIBYHft4WFjcs1AbRpDQHtc=@vger.kernel.org X-Gm-Message-State: AOJu0YzxltWR8yCB86EBQqibGOLQGzUiXS6JPQbYxDLa0DsjQ6RDg2Sk nLE/svrjiMxwK3MlUo/6XRUTVVtPLPOaKun7b5ReXlv5T6plB1O7ies5 X-Gm-Gg: AR+sD1208U56MtSDuVUSobAZV/Q9p95hP0IfKK6SRWl63k67sxCvyDaFu+7n4KlJQMf 2ywL9NvB0t1M6Cm+lXAI+zlyaMYARBQy2ACz/5hySKoqJs2z4Wz2f77446NX2+iqi5tSGmPvYWJ QbZScUrg6M0h7M+JWO2vlmPDJv7oDyJ4/YInPONHtBs6uLbVHTed8+0+dP74Hnb5VjM2cTDHhau oTiGovN7+502yzhNSUwsLz4RiAOAJeNac27SwTM7Bo9lXAjCQ32/hos1XjZFh5TfIMi53gF4S6q 4SLHd30uMGfVWhH/cklNoqKieDbKG7+g9K3+Xxx7OWgDvPAkbCDDkYMs6fHNy5IOpIoaakYoU3p sv0XKKOLU1iietpss3k/WUDhAaIFh39d2wNr4A6xENwWK+hR/BOoL/hYGRBCZeLxzzLVExiVjdZ J4jQsDpstgfgi+dVXou4Eoe3NSDN64qOPXogyWKWwtVa0yjT6V7Q== X-Received: by 2002:a17:907:608b:b0:c16:73a0:c4ec with SMTP id a640c23a62f3a-c212a26d672mr1059757766b.18.1786970584755; Mon, 17 Aug 2026 05:43:04 -0700 (PDT) Received: from [127.0.0.1] ([2a09:bac6:3861:1e5a::306:a]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c217feb99d4sm52626266b.22.2026.08.17.05.43.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Aug 2026 05:43:04 -0700 (PDT) From: Caleb Kan Date: Mon, 17 Aug 2026 13:42:45 +0100 Subject: [PATCH RFC 5/9] kmsan: report trie-backed stack depot traces Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260817-stackdepot-trie-v1-5-53870ca1651b@cloudflare.com> References: <20260817-stackdepot-trie-v1-0-53870ca1651b@cloudflare.com> In-Reply-To: <20260817-stackdepot-trie-v1-0-53870ca1651b@cloudflare.com> To: Andrew Morton Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, kasan-dev@googlegroups.com, Vlastimil Babka , Alexander Potapenko , Marco Elver , Dmitry Vyukov , Andrey Konovalov , Oscar Salvador , Caleb Kan , kernel-team@cloudflare.com X-Mailer: b4 0.16.0 From: Caleb Kan KMSAN stores ordinary origin stacks and synthetic alloca and chain origins as persistent stack depot records. Once trie storage is enabled, these handles can be trie-backed, while kmsan_print_origin() still relies on the hash-only stack_depot_fetch() API. Use one KMSAN_STACK_DEPTH array to materialize each origin and chained stack in turn. Preserve the chain's head and next-origin handles before reusing the array for the chained stack. The array covers both the regular save limit and the smaller synthetic records. lib/stackdepot.c is uninstrumented, so stack_depot_fetch_into() unpoisons the successfully copied range before returning it to KMSAN. Remove the now-redundant explicit unpoisoning of chained entries. Origin depth and use-after-free metadata remain in the handle's extra bits and are unchanged. Update test_stackdepot_roundtrip() to use caller-owned storage while retaining its frame-count and kmsan_check_memory() checks. This verifies that the copy-out API returns initialized entries to instrumented callers. Signed-off-by: Caleb Kan --- mm/kmsan/kmsan_test.c | 4 ++-- mm/kmsan/report.c | 17 +++++++---------- 2 files changed, 9 insertions(+), 12 deletions(-) diff --git a/mm/kmsan/kmsan_test.c b/mm/kmsan/kmsan_test.c index 31f47cc4dab4..7c04e4b21873 100644 --- a/mm/kmsan/kmsan_test.c +++ b/mm/kmsan/kmsan_test.c @@ -669,7 +669,7 @@ static void test_long_origin_chain(struct kunit *test) */ static void test_stackdepot_roundtrip(struct kunit *test) { - unsigned long src_entries[16], *dst_entries; + unsigned long src_entries[16], dst_entries[16]; unsigned int src_nentries, dst_nentries; EXPECTATION_NO_REPORT(expect); depot_stack_handle_t handle; @@ -680,7 +680,7 @@ static void test_stackdepot_roundtrip(struct kunit *test) stack_trace_save(src_entries, ARRAY_SIZE(src_entries), 1); handle = stack_depot_save(src_entries, src_nentries, GFP_KERNEL); stack_depot_print(handle); - dst_nentries = stack_depot_fetch(handle, &dst_entries); + dst_nentries = stack_depot_fetch_into(handle, dst_entries, ARRAY_SIZE(dst_entries)); KUNIT_EXPECT_TRUE(test, src_nentries == dst_nentries); kmsan_check_memory((void *)dst_entries, diff --git a/mm/kmsan/report.c b/mm/kmsan/report.c index d6853ce08954..c20c24cffde5 100644 --- a/mm/kmsan/report.c +++ b/mm/kmsan/report.c @@ -85,7 +85,7 @@ static char *pretty_descr(char *descr) void kmsan_print_origin(depot_stack_handle_t origin) { - unsigned long *entries = NULL, *chained_entries = NULL; + unsigned long entries[KMSAN_STACK_DEPTH]; unsigned int nr_entries, chained_nr_entries, skipnr; void *pc1 = NULL, *pc2 = NULL; depot_stack_handle_t head; @@ -97,7 +97,8 @@ void kmsan_print_origin(depot_stack_handle_t origin) return; while (true) { - nr_entries = stack_depot_fetch(origin, &entries); + nr_entries = + stack_depot_fetch_into(origin, entries, ARRAY_SIZE(entries)); depth = kmsan_depth_from_eb(stack_depot_get_extra_bits(origin)); magic = nr_entries ? entries[0] : 0; if ((nr_entries == 4) && (magic == KMSAN_ALLOCA_MAGIC_ORIGIN)) { @@ -123,14 +124,10 @@ void kmsan_print_origin(depot_stack_handle_t origin) origin = entries[2]; pr_err("Uninit was stored to memory at:\n"); chained_nr_entries = - stack_depot_fetch(head, &chained_entries); - kmsan_internal_unpoison_memory( - chained_entries, - chained_nr_entries * sizeof(*chained_entries), - /*checked*/ false); - skipnr = get_stack_skipnr(chained_entries, - chained_nr_entries); - stack_trace_print(chained_entries + skipnr, + stack_depot_fetch_into(head, entries, + ARRAY_SIZE(entries)); + skipnr = get_stack_skipnr(entries, chained_nr_entries); + stack_trace_print(entries + skipnr, chained_nr_entries - skipnr, 0); pr_err("\n"); continue; -- Git-155)