From 387dbb9a9976eb22ed92e879193fe8d739032b0b Mon Sep 17 00:00:00 2001 From: Neill Kapron Date: Sat, 26 Jul 2025 14:57:33 +0000 Subject: [PATCH 1/5] ANDROID: bpf: do not fail to load if log is full Upstream commit 973c7a0d8a38 ("bpf: fix precision backtracking instruction iteration") slightly changes the logic in the verifier which results in the verifier log growing. This results in the log being too small when loading the filterPowerSupplyEvents BPF program in Android, and therefore causing the program loading to fail. Because this program is labeled 'critical', a load failure forces a boot loop. This BPF program exists on the vendor partition, and therefore we must maintain the GRF/ treble boundary and modify the kernel logic. The kernel's bpf log logic is refactored in the 6.4 kernel and acknowledges the shortcomings of the existing approach which causes the program load to fail. Instead of backporting the significant changes, this change simply ignores the fact that the log is full. For more information see commit 121664093803 ("bpf: Switch BPF verifier log to be a rotating log by default") Bug: 432207940 Bug: 433641053 Test: verify pixel 6 boots on a 5.10 kernel including commit 973c7a0d8a38 Change-Id: I35c3d2074dd9b39e44bfdbaf66fa56ec917df0a6 Signed-off-by: Neill Kapron Signed-off-by: Greg Kroah-Hartman --- kernel/bpf/verifier.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c index 013b9062c47c..da2f54b02d81 100644 --- a/kernel/bpf/verifier.c +++ b/kernel/bpf/verifier.c @@ -9685,8 +9685,14 @@ skip_full_check: env->verification_time = ktime_get_ns() - start_time; print_verification_stats(env); - if (log->level && bpf_verifier_log_full(log)) - ret = -ENOSPC; + // ANDROID: Do not fail to load if log buffer passed in from userspace + // is too small. The bpf log logic is refactored in the 6.4 kernel + // acknowledging the shortcomings of this approch. Instead of backporting + // the significant changes, simply ignore the fact that the log is full. + // For more information see commit 121664093803: bpf: Switch BPF verifier + // log to be a rotating log by default + //if (log->level && bpf_verifier_log_full(log)) + // ret = -ENOSPC; if (log->level && !log->ubuf) { ret = -EFAULT; goto err_release_maps; From 1e81917710748fcdc199df9978acde95d045753d Mon Sep 17 00:00:00 2001 From: Lion Ackermann Date: Mon, 30 Jun 2025 15:27:30 +0200 Subject: [PATCH 2/5] UPSTREAM: net/sched: Always pass notifications when child class becomes empty [ Upstream commit 103406b38c600fec1fe375a77b27d87e314aea09 ] Certain classful qdiscs may invoke their classes' dequeue handler on an enqueue operation. This may unexpectedly empty the child qdisc and thus make an in-flight class passive via qlen_notify(). Most qdiscs do not expect such behaviour at this point in time and may re-activate the class eventually anyways which will lead to a use-after-free. The referenced fix commit attempted to fix this behavior for the HFSC case by moving the backlog accounting around, though this turned out to be incomplete since the parent's parent may run into the issue too. The following reproducer demonstrates this use-after-free: tc qdisc add dev lo root handle 1: drr tc filter add dev lo parent 1: basic classid 1:1 tc class add dev lo parent 1: classid 1:1 drr tc qdisc add dev lo parent 1:1 handle 2: hfsc def 1 tc class add dev lo parent 2: classid 2:1 hfsc rt m1 8 d 1 m2 0 tc qdisc add dev lo parent 2:1 handle 3: netem tc qdisc add dev lo parent 3:1 handle 4: blackhole echo 1 | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888 tc class delete dev lo classid 1:1 echo 1 | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888 Since backlog accounting issues leading to a use-after-frees on stale class pointers is a recurring pattern at this point, this patch takes a different approach. Instead of trying to fix the accounting, the patch ensures that qdisc_tree_reduce_backlog always calls qlen_notify when the child qdisc is empty. This solves the problem because deletion of qdiscs always involves a call to qdisc_reset() and / or qdisc_purge_queue() which ultimately resets its qlen to 0 thus causing the following qdisc_tree_reduce_backlog() to report to the parent. Note that this may call qlen_notify on passive classes multiple times. This is not a problem after the recent patch series that made all the classful qdiscs qlen_notify() handlers idempotent. Bug: 431676976 Fixes: 3f981138109f ("sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()") Signed-off-by: Lion Ackermann Reviewed-by: Jamal Hadi Salim Acked-by: Cong Wang Acked-by: Jamal Hadi Salim Link: https://patch.msgid.link/d912cbd7-193b-4269-9857-525bee8bbb6a@gmail.com Signed-off-by: Jakub Kicinski Signed-off-by: Sasha Levin (cherry picked from commit e9921b57dca05ac5f4fa1fa8e993d4f0ee52e2b7) Signed-off-by: Lee Jones Change-Id: I2eb242c0279efc5c5e31e63f7fb12a3f4d5f3e1d --- net/sched/sch_api.c | 19 +++++-------------- 1 file changed, 5 insertions(+), 14 deletions(-) diff --git a/net/sched/sch_api.c b/net/sched/sch_api.c index 60c8b81a22dc..fe3808cc6eb8 100644 --- a/net/sched/sch_api.c +++ b/net/sched/sch_api.c @@ -758,15 +758,12 @@ static u32 qdisc_alloc_handle(struct net_device *dev) void qdisc_tree_reduce_backlog(struct Qdisc *sch, int n, int len) { - bool qdisc_is_offloaded = sch->flags & TCQ_F_OFFLOADED; const struct Qdisc_class_ops *cops; unsigned long cl; u32 parentid; bool notify; int drops; - if (n == 0 && len == 0) - return; drops = max_t(int, n, 0); rcu_read_lock(); while ((parentid = sch->parent)) { @@ -775,17 +772,8 @@ void qdisc_tree_reduce_backlog(struct Qdisc *sch, int n, int len) if (sch->flags & TCQ_F_NOPARENT) break; - /* Notify parent qdisc only if child qdisc becomes empty. - * - * If child was empty even before update then backlog - * counter is screwed and we skip notification because - * parent class is already passive. - * - * If the original child was offloaded then it is allowed - * to be seem as empty, so the parent is notified anyway. - */ - notify = !sch->q.qlen && !WARN_ON_ONCE(!n && - !qdisc_is_offloaded); + /* Notify parent qdisc only if child qdisc becomes empty. */ + notify = !sch->q.qlen; /* TODO: perform the search on a per txq basis */ sch = qdisc_lookup(qdisc_dev(sch), TC_H_MAJ(parentid)); if (sch == NULL) { @@ -794,6 +782,9 @@ void qdisc_tree_reduce_backlog(struct Qdisc *sch, int n, int len) } cops = sch->ops->cl_ops; if (notify && cops->qlen_notify) { + /* Note that qlen_notify must be idempotent as it may get called + * multiple times. + */ cl = cops->find(sch, parentid); cops->qlen_notify(sch, cl); } From 7802e7ac1645bcb0c8bcf8f4b79d6fae282d0e21 Mon Sep 17 00:00:00 2001 From: Joann Liu Date: Mon, 11 Aug 2025 15:22:13 +0800 Subject: [PATCH 3/5] ANDROID: GKI: update Trimble symbol list Update symbol for cdc_mbim and qcserial Leaf changes summary: 8 artifacts changed Changed leaf types summary: 0 leaf type changed Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 8 Added functions Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable 8 Added functions: [A] 'function int cdc_ncm_bind_common(usbnet*, usb_interface*, u8, int)' [A] 'function int cdc_ncm_change_mtu(net_device*, int)' [A] 'function sk_buff* cdc_ncm_fill_tx_frame(usbnet*, sk_buff*, __le32)' [A] 'function int cdc_ncm_rx_verify_ndp16(sk_buff*, int)' [A] 'function int cdc_ncm_rx_verify_nth16(cdc_ncm_ctx*, sk_buff*)' [A] 'function u8 cdc_ncm_select_altsetting(usb_interface*)' [A] 'function void cdc_ncm_unbind(usbnet*, usb_interface*)' [A] 'function void usb_disable_autosuspend(usb_device*)' Bug: 437733089 Change-Id: I8b5b287ffdd4bfd914cff1308487c10556a28433 Signed-off-by: Joann Liu --- android/abi_gki_aarch64.xml | 2028 ++++++++++++++++++------------- android/abi_gki_aarch64_trimble | 9 + 2 files changed, 1180 insertions(+), 857 deletions(-) diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml index fbb064dbdcb5..2cd5baedb02c 100644 --- a/android/abi_gki_aarch64.xml +++ b/android/abi_gki_aarch64.xml @@ -550,6 +550,13 @@ + + + + + + + @@ -4434,6 +4441,7 @@ + @@ -6856,7 +6864,17 @@ - + + + + + + + + + + + @@ -23638,7 +23656,7 @@ - + @@ -25922,7 +25940,7 @@ - + @@ -25942,7 +25960,7 @@ - + @@ -27799,12 +27817,12 @@ - + - + - + @@ -28682,7 +28700,7 @@ - + @@ -30163,7 +30181,7 @@ - + @@ -32099,7 +32117,7 @@ - + @@ -32562,7 +32580,7 @@ - + @@ -36692,6 +36710,7 @@ + @@ -59164,7 +59183,7 @@ - + @@ -78784,69 +78803,69 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -78866,9 +78885,9 @@ - + - + @@ -78879,50 +78898,50 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -79222,11 +79241,11 @@ - + - + @@ -79234,14 +79253,14 @@ - + - + - + @@ -89734,102 +89753,102 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -89847,264 +89866,264 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -90120,68 +90139,68 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -91242,7 +91261,7 @@ - + @@ -92535,7 +92554,7 @@ - + @@ -92952,71 +92971,71 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -93210,41 +93229,41 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -93295,7 +93314,7 @@ - + @@ -93303,77 +93322,77 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -93419,12 +93438,12 @@ - + - + - + @@ -94031,7 +94050,7 @@ - + @@ -94039,18 +94058,18 @@ - + - + - + - + - + @@ -94088,105 +94107,105 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -94273,13 +94292,13 @@ - - + + - + - + @@ -94293,82 +94312,82 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -94426,75 +94445,75 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -94663,18 +94682,18 @@ - + - + - + - + - + @@ -94800,69 +94819,69 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -95396,445 +95415,445 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -95855,567 +95874,567 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -98372,7 +98391,7 @@ - + @@ -98660,107 +98679,107 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -101085,11 +101104,11 @@ - - - - - + + + + + @@ -103249,7 +103268,7 @@ - + @@ -103368,7 +103387,7 @@ - + @@ -103670,7 +103689,7 @@ - + @@ -103681,7 +103700,7 @@ - + @@ -104411,11 +104430,292 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -106148,12 +106448,12 @@ - + - + - + @@ -112904,8 +113204,8 @@ - - + + @@ -113009,9 +113309,9 @@ - - - + + + @@ -118474,8 +118774,8 @@ - - + + @@ -121677,22 +121977,6 @@ - - - - - - - - - - - - - - - - @@ -121766,6 +122050,14 @@ + + + + + + + + @@ -121774,6 +122066,14 @@ + + + + + + + + @@ -122079,7 +122379,7 @@ - + @@ -122135,7 +122435,7 @@ - + @@ -129406,6 +129706,10 @@ + + + + @@ -130459,9 +130763,9 @@ - - - + + + @@ -142076,7 +142380,7 @@ - + @@ -144863,7 +145167,17 @@ - + + + + + + + + + + + @@ -159540,10 +159854,10 @@ - - - - + + + + @@ -159568,14 +159882,14 @@ - - + + - - - - + + + + @@ -159804,9 +160118,9 @@ - - - + + + @@ -166288,7 +166602,7 @@ - + @@ -166296,7 +166610,7 @@ - + @@ -166318,7 +166632,7 @@ - + @@ -166338,7 +166652,7 @@ - + @@ -167949,10 +168263,10 @@ - - - - + + + + @@ -174771,7 +175085,7 @@ - + @@ -179569,7 +179883,7 @@ - + @@ -179598,7 +179912,7 @@ - + @@ -180190,7 +180504,7 @@ - + @@ -181150,7 +181464,7 @@ - + diff --git a/android/abi_gki_aarch64_trimble b/android/abi_gki_aarch64_trimble index ea31389df078..be102c6c79c1 100644 --- a/android/abi_gki_aarch64_trimble +++ b/android/abi_gki_aarch64_trimble @@ -1,6 +1,15 @@ [abi_symbol_list] # required by cdc_mbim.ko in6_dev_finish_destroy + cdc_ncm_select_altsetting + cdc_ncm_bind_common + cdc_ncm_unbind + cdc_ncm_change_mtu + cdc_ncm_rx_verify_nth16 + cdc_ncm_rx_verify_ndp16 + cdc_ncm_fill_tx_frame # required by qmi_wwan.ko netdev_stats_to_stats64 netdev_upper_get_next_dev_rcu +# required by qcserial + usb_disable_autosuspend From 2f1e2df209f16a352b0ca1b4585421ea0a92161c Mon Sep 17 00:00:00 2001 From: Kalesh Singh Date: Wed, 9 Apr 2025 22:52:18 -0700 Subject: [PATCH 4/5] ANDROID: 16K: Don't copy data vma for maps/smaps output Remove get_data_vma() which made a copy of the original VMA containing padding and modified vm_end to exclude the trailing padding (if any). Avoid this copy to avoid races due to stale data relating to vma->vm_file. Instead use VMA_PAD_START(vma) directly to get the correct end excluding padding if any. Add additional check to verify the padding VMA is as expected and also check for allocation failure of the pad VMA. ELFs with padding can be loaded from tmpfs. For simplicity swapped out shmem accounting in smaps, skips the fast path for read only files and walks the page table with the range adjusted for padding. Example output: ===== Maps ===== 7ff6306c2000-7ff6306c3000 r--p 00000000 fe:09 1912 /system/lib64/bootstrap/libdl.so 7ff6306c3000-7ff6306c6000 ---p 00000000 00:00 0 [page size compat] 7ff6306c6000-7ff6306c7000 r-xp 00004000 fe:09 1912 /system/lib64/bootstrap/libdl.so 7ff6306c7000-7ff6306ca000 ---p 00000000 00:00 0 [page size compat] 7ff6306ca000-7ff6306cb000 r--p 00008000 fe:09 1912 /system/lib64/bootstrap/libdl.so ===== Smaps ===== 7ff6306c2000-7ff6306c3000 r--p 00000000 fe:09 1912 /system/lib64/bootstrap/libdl.so Size: 4 kB KernelPageSize: 4 kB MMUPageSize: 4 kB Rss: 4 kB Pss: 0 kB Pss_Dirty: 0 kB Shared_Clean: 4 kB Shared_Dirty: 0 kB Private_Clean: 0 kB Private_Dirty: 0 kB Referenced: 4 kB Anonymous: 0 kB KSM: 0 kB LazyFree: 0 kB AnonHugePages: 0 kB ShmemPmdMapped: 0 kB FilePmdMapped: 0 kB Shared_Hugetlb: 0 kB Private_Hugetlb: 0 kB Swap: 0 kB SwapPss: 0 kB Locked: 0 kB THPeligible: 0 VmFlags: rd mr mw me ?? 7ff6306c3000-7ff6306c6000 ---p 00000000 00:00 0 [page size compat] Size: 12 kB KernelPageSize: 4 kB MMUPageSize: 4 kB Rss: 0 kB Pss: 0 kB Pss_Dirty: 0 kB Shared_Clean: 0 kB Shared_Dirty: 0 kB Private_Clean: 0 kB Private_Dirty: 0 kB Referenced: 0 kB Anonymous: 0 kB KSM: 0 kB LazyFree: 0 kB AnonHugePages: 0 kB ShmemPmdMapped: 0 kB FilePmdMapped: 0 kB Shared_Hugetlb: 0 kB Private_Hugetlb: 0 kB Swap: 0 kB SwapPss: 0 kB Locked: 0 kB THPeligible: 0 VmFlags: mr mw me 7ff6306c6000-7ff6306c7000 r-xp 00004000 fe:09 1912 /system/lib64/bootstrap/libdl.so Size: 4 kB KernelPageSize: 4 kB MMUPageSize: 4 kB Rss: 4 kB Pss: 0 kB Pss_Dirty: 0 kB Shared_Clean: 4 kB Shared_Dirty: 0 kB Private_Clean: 0 kB Private_Dirty: 0 kB Referenced: 4 kB Anonymous: 0 kB KSM: 0 kB LazyFree: 0 kB AnonHugePages: 0 kB ShmemPmdMapped: 0 kB FilePmdMapped: 0 kB Shared_Hugetlb: 0 kB Private_Hugetlb: 0 kB Swap: 0 kB SwapPss: 0 kB Locked: 0 kB THPeligible: 0 VmFlags: rd ex mr mw me ?? 7ff6306c7000-7ff6306ca000 ---p 00000000 00:00 0 [page size compat] Size: 12 kB KernelPageSize: 4 kB MMUPageSize: 4 kB Rss: 0 kB Pss: 0 kB Pss_Dirty: 0 kB Shared_Clean: 0 kB Shared_Dirty: 0 kB Private_Clean: 0 kB Private_Dirty: 0 kB Referenced: 0 kB Anonymous: 0 kB KSM: 0 kB LazyFree: 0 kB AnonHugePages: 0 kB ShmemPmdMapped: 0 kB FilePmdMapped: 0 kB Shared_Hugetlb: 0 kB Private_Hugetlb: 0 kB Swap: 0 kB SwapPss: 0 kB Locked: 0 kB THPeligible: 0 VmFlags: mr mw me 7ff6306ca000-7ff6306cb000 r--p 00008000 fe:09 1912 /system/lib64/bootstrap/libdl.so Size: 4 kB KernelPageSize: 4 kB MMUPageSize: 4 kB Rss: 4 kB Pss: 4 kB Pss_Dirty: 4 kB Shared_Clean: 0 kB Shared_Dirty: 0 kB Private_Clean: 0 kB Private_Dirty: 4 kB Referenced: 4 kB Anonymous: 4 kB KSM: 0 kB LazyFree: 0 kB AnonHugePages: 0 kB ShmemPmdMapped: 0 kB FilePmdMapped: 0 kB Shared_Hugetlb: 0 kB Private_Hugetlb: 0 kB Swap: 0 kB SwapPss: 0 kB Locked: 0 kB THPeligible: 0 VmFlags: rd mr mw me ac Bug: 427145188 Bug: 409239984 Change-Id: Ic54e89571276db62ffc01681e7ca8986bb1ca7c4 Signed-off-by: Kalesh Singh --- fs/proc/task_mmu.c | 33 ++++++++++++++--------- include/linux/pgsize_migration.h | 16 ----------- mm/pgsize_migration.c | 46 +++++++++++++------------------- 3 files changed, 40 insertions(+), 55 deletions(-) diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c index 1afd67def3c1..fa54b36c8aeb 100644 --- a/fs/proc/task_mmu.c +++ b/fs/proc/task_mmu.c @@ -367,7 +367,7 @@ show_map_vma(struct seq_file *m, struct vm_area_struct *vma) } start = vma->vm_start; - end = vma->vm_end; + end = VMA_PAD_START(vma); show_vma_header_prefix(m, start, end, flags, pgoff, dev, ino); /* @@ -420,13 +420,12 @@ done: static int show_map(struct seq_file *m, void *v) { - struct vm_area_struct *pad_vma = get_pad_vma(v); - struct vm_area_struct *vma = get_data_vma(v); + struct vm_area_struct *vma = v; if (vma_pages(vma)) show_map_vma(m, vma); - show_map_pad_vma(vma, pad_vma, m, show_map_vma, false); + show_map_pad_vma(vma, m, show_map_vma, false); m_cache_vma(m, v); return 0; @@ -813,6 +812,8 @@ static const struct mm_walk_ops smaps_shmem_walk_ops = { static void smap_gather_stats(struct vm_area_struct *vma, struct mem_size_stats *mss) { + unsigned long end = VMA_PAD_START(vma); + #ifdef CONFIG_SHMEM /* In case of smaps_rollup, reset the value from previous vma */ mss->check_shmem_swap = false; @@ -829,18 +830,27 @@ static void smap_gather_stats(struct vm_area_struct *vma, */ unsigned long shmem_swapped = shmem_swap_usage(vma); - if (!shmem_swapped || (vma->vm_flags & VM_SHARED) || - !(vma->vm_flags & VM_WRITE)) { + if ((!shmem_swapped || (vma->vm_flags & VM_SHARED) || + !(vma->vm_flags & VM_WRITE)) && + /* + * Only if we don't have padding can we use the fast path + * shmem_inode_info->swapped for shmem_swapped. + * + * Else we'll walk the page table to calculate + * shmem_swapped, (excluding the padding region). + */ + end == vma->vm_end) { mss->swap += shmem_swapped; } else { mss->check_shmem_swap = true; - walk_page_vma(vma, &smaps_shmem_walk_ops, mss); + walk_page_range(vma->vm_mm, vma->vm_start, end, + &smaps_shmem_walk_ops, mss); return; } } #endif /* mmap_sem is held in m_start */ - walk_page_vma(vma, &smaps_walk_ops, mss); + walk_page_range(vma->vm_mm, vma->vm_start, end, &smaps_walk_ops, mss); } #define SEQ_PUT_DEC(str, val) \ @@ -901,7 +911,7 @@ static void show_smap_vma(struct seq_file *m, void *v) seq_putc(m, '\n'); } - SEQ_PUT_DEC("Size: ", vma->vm_end - vma->vm_start); + SEQ_PUT_DEC("Size: ", VMA_PAD_START(vma) - vma->vm_start); SEQ_PUT_DEC(" kB\nKernelPageSize: ", vma_kernel_pagesize(vma)); SEQ_PUT_DEC(" kB\nMMUPageSize: ", vma_mmu_pagesize(vma)); seq_puts(m, " kB\n"); @@ -918,13 +928,12 @@ static void show_smap_vma(struct seq_file *m, void *v) static int show_smap(struct seq_file *m, void *v) { - struct vm_area_struct *pad_vma = get_pad_vma(v); - struct vm_area_struct *vma = get_data_vma(v); + struct vm_area_struct *vma = v; if (vma_pages(vma)) show_smap_vma(m, vma); - show_map_pad_vma(vma, pad_vma, m, show_smap_vma, true); + show_map_pad_vma(vma, m, show_smap_vma, true); m_cache_vma(m, v); return 0; diff --git a/include/linux/pgsize_migration.h b/include/linux/pgsize_migration.h index 48672dbc84e9..359c1807ff1d 100644 --- a/include/linux/pgsize_migration.h +++ b/include/linux/pgsize_migration.h @@ -26,12 +26,7 @@ extern unsigned long vma_pad_pages(struct vm_area_struct *vma); extern void madvise_vma_pad_pages(struct vm_area_struct *vma, unsigned long start, unsigned long end); -extern struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma); - -extern struct vm_area_struct *get_data_vma(struct vm_area_struct *vma); - extern void show_map_pad_vma(struct vm_area_struct *vma, - struct vm_area_struct *pad, struct seq_file *m, void *func, bool smaps); extern void split_pad_vma(struct vm_area_struct *vma, struct vm_area_struct *new, @@ -57,18 +52,7 @@ static inline void madvise_vma_pad_pages(struct vm_area_struct *vma, { } -static inline struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma) -{ - return NULL; -} - -static inline struct vm_area_struct *get_data_vma(struct vm_area_struct *vma) -{ - return vma; -} - static inline void show_map_pad_vma(struct vm_area_struct *vma, - struct vm_area_struct *pad, struct seq_file *m, void *func, bool smaps) { } diff --git a/mm/pgsize_migration.c b/mm/pgsize_migration.c index ad9e638ab3b6..f80a40faa605 100644 --- a/mm/pgsize_migration.c +++ b/mm/pgsize_migration.c @@ -258,10 +258,10 @@ static const struct vm_operations_struct pad_vma_ops = { }; /* - * Returns a new VMA representing the padding in @vma, if no padding - * in @vma returns NULL. + * Returns a new VMA representing the padding in @vma; + * returns NULL if no padding in @vma or allocation failed. */ -struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma) +static struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma) { struct vm_area_struct *pad; @@ -269,6 +269,10 @@ struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma) return NULL; pad = kzalloc(sizeof(struct vm_area_struct), GFP_KERNEL); + if (!pad) { + pr_warn("Page size migration: Failed to allocate padding VMA"); + return NULL; + } *pad = *vma; @@ -290,34 +294,14 @@ struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma) return pad; } -/* - * Returns a new VMA exclusing the padding from @vma; if no padding in - * @vma returns @vma. - */ -struct vm_area_struct *get_data_vma(struct vm_area_struct *vma) -{ - struct vm_area_struct *data; - - if (!is_pgsize_migration_enabled() || !(vma->vm_flags & VM_PAD_MASK)) - return vma; - - data = kzalloc(sizeof(struct vm_area_struct), GFP_KERNEL); - - *data = *vma; - - /* Adjust the end to the start of the padding section */ - data->vm_end = VMA_PAD_START(data); - - return data; -} - /* * Calls the show_pad_vma_fn on the @pad VMA, and frees the copies of @vma * and @pad. */ -void show_map_pad_vma(struct vm_area_struct *vma, struct vm_area_struct *pad, - struct seq_file *m, void *func, bool smaps) +void show_map_pad_vma(struct vm_area_struct *vma, struct seq_file *m, + void *func, bool smaps) { + struct vm_area_struct *pad = get_pad_vma(vma); if (!pad) return; @@ -333,13 +317,21 @@ void show_map_pad_vma(struct vm_area_struct *vma, struct vm_area_struct *pad, */ BUG_ON(!vma); + /* The pad VMA should be anonymous. */ + BUG_ON(pad->vm_file); + + /* The pad VMA should be PROT_NONE. */ + BUG_ON(pad->vm_flags & (VM_READ|VM_WRITE|VM_EXEC)); + + /* The pad VMA itself cannot have padding; infinite recursion */ + BUG_ON(pad->vm_flags & VM_PAD_MASK); + if (smaps) ((show_pad_smaps_fn)func)(m, pad); else ((show_pad_maps_fn)func)(m, pad); kfree(pad); - kfree(vma); } /* From e4601d0bb216a56336728892a74ca28f26967193 Mon Sep 17 00:00:00 2001 From: Kalesh Singh Date: Thu, 17 Jul 2025 16:55:48 -0700 Subject: [PATCH 5/5] ANDROID: 16K: Allocate pad vma on the stack Now that the padding VMA is only used in show_map_pad_vma(), initialize the padding VMA struct on the stack. This is a nice clean up and avoid having to deal with dynamic allocation failure. Bug: 440210631 Bug: 432564748 Change-Id: I168cda6cdb98423a40bb691b687c0f99bd160db6 Signed-off-by: Kalesh Singh --- mm/pgsize_migration.c | 52 +++++++++++-------------------------------- 1 file changed, 13 insertions(+), 39 deletions(-) diff --git a/mm/pgsize_migration.c b/mm/pgsize_migration.c index f80a40faa605..15b053184b21 100644 --- a/mm/pgsize_migration.c +++ b/mm/pgsize_migration.c @@ -258,23 +258,11 @@ static const struct vm_operations_struct pad_vma_ops = { }; /* - * Returns a new VMA representing the padding in @vma; - * returns NULL if no padding in @vma or allocation failed. + * Initialize @pad VMA fields with information from the original @vma. */ -static struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma) +static void init_pad_vma(struct vm_area_struct *vma, struct vm_area_struct *pad) { - struct vm_area_struct *pad; - - if (!is_pgsize_migration_enabled() || !(vma->vm_flags & VM_PAD_MASK)) - return NULL; - - pad = kzalloc(sizeof(struct vm_area_struct), GFP_KERNEL); - if (!pad) { - pr_warn("Page size migration: Failed to allocate padding VMA"); - return NULL; - } - - *pad = *vma; + memcpy(pad, vma, sizeof(struct vm_area_struct)); /* Remove file */ pad->vm_file = NULL; @@ -290,48 +278,34 @@ static struct vm_area_struct *get_pad_vma(struct vm_area_struct *vma) /* Remove padding bits */ pad->vm_flags &= ~VM_PAD_MASK; - - return pad; } /* - * Calls the show_pad_vma_fn on the @pad VMA, and frees the copies of @vma - * and @pad. + * Calls the show_pad_vma_fn on the @pad VMA. */ void show_map_pad_vma(struct vm_area_struct *vma, struct seq_file *m, void *func, bool smaps) { - struct vm_area_struct *pad = get_pad_vma(vma); - if (!pad) + struct vm_area_struct pad; + + if (!is_pgsize_migration_enabled() || !(vma->vm_flags & VM_PAD_MASK)) return; - /* - * This cannot happen. If @pad vma was allocated the corresponding - * @vma should have the VM_PAD_MASK bit(s) set. - */ - BUG_ON(!(vma->vm_flags & VM_PAD_MASK)); - - /* - * This cannot happen. @pad is a section of the original VMA. - * Therefore @vma cannot be null if @pad is not null. - */ - BUG_ON(!vma); + init_pad_vma(vma, &pad); /* The pad VMA should be anonymous. */ - BUG_ON(pad->vm_file); + BUG_ON(pad.vm_file); /* The pad VMA should be PROT_NONE. */ - BUG_ON(pad->vm_flags & (VM_READ|VM_WRITE|VM_EXEC)); + BUG_ON(pad.vm_flags & (VM_READ|VM_WRITE|VM_EXEC)); /* The pad VMA itself cannot have padding; infinite recursion */ - BUG_ON(pad->vm_flags & VM_PAD_MASK); + BUG_ON(pad.vm_flags & VM_PAD_MASK); if (smaps) - ((show_pad_smaps_fn)func)(m, pad); + ((show_pad_smaps_fn)func)(m, &pad); else - ((show_pad_maps_fn)func)(m, pad); - - kfree(pad); + ((show_pad_maps_fn)func)(m, &pad); } /*