Received: by 10.213.65.68 with SMTP id h4csp2121256imn; Sun, 8 Apr 2018 20:13:46 -0700 (PDT) X-Google-Smtp-Source: AIpwx4/1WuGhzffNLqqw3lc0JEBIVZvw+/YaLrVu7zSAsd2oMF5eEV19/a6wfvwoVthxhDwD2Rbf X-Received: by 10.98.152.217 with SMTP id d86mr5504052pfk.18.1523243626261; Sun, 08 Apr 2018 20:13:46 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1523243626; cv=none; d=google.com; s=arc-20160816; b=MAIfo1pgfVukjdF3SJGt9GanvCK2/kQTGmjhOwidcFLYJuB2ftfaQEISmBrzEJuxsR qfK1PeWJUT6nqmH72X6jCUdn4ZbfdZqiE+Be9Z7kt77BD1pDX70KADjl65KvA1grV7eQ P3jCJb2tm9LREQFqviH2KZs4nzpv5t9H4ERrBw9sVLvfqPsCmOJEzLn1ZtvEKNthqruQ C08dmUgGFQ4SHWp1VODJCrY5gFvlOPfdexbED+u0bhEz9ZkCFq2kbnA02ml7LpCKbShU gCcw0YakPGjFQP4aUo5s8jSMW4a5ixCx6SqyR1gzuZ5r2EPJCGKF7yLec497rJyX3wOx N7bA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=kGE917cMCO5VRNrgeKAYUWWWKodQ8UVoLLYwsyFhJLo=; b=htDWamTIeOWixfCiE0J4T0L9N8pj3Ls8HjA+ijoqg504aKI60fC7MxauIswoq/Nyo2 ec5epiH/08TyUabzqIvxfA25HerjK4P3XAeznJnvDtXzGdODATotGpqHARoCcDo7tUnc nD6e3gDJ0rBieRodcF6hBmRKWOEHp4vZSSYnqpS95WdjNqKyrs0ZI8oMOh1bJvv34fFh aHMW0hPzOHc7cLGseDuK6zJfmNQ2WFuxyK0lJAG7VNGeneYVv5DgknLbr8YIJQleGFIh J/Nc20z0b0+PWQ3yoij1HfRZnn+T7Ibr+h6jMpNlAAsqowSi0R2oEt8XR2z4aWWmn5HC KLtg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=cCSAP2Zx; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id p4si8922586pgc.66.2018.04.08.20.13.09; Sun, 08 Apr 2018 20:13:46 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=cCSAP2Zx; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752460AbeDIDCu (ORCPT + 99 others); Sun, 8 Apr 2018 23:02:50 -0400 Received: from mail-sn1nam02on0138.outbound.protection.outlook.com ([104.47.36.138]:39392 "EHLO NAM02-SN1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1754319AbeDIAZX (ORCPT ); Sun, 8 Apr 2018 20:25:23 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=kGE917cMCO5VRNrgeKAYUWWWKodQ8UVoLLYwsyFhJLo=; b=cCSAP2ZxtIiQJll3tzpGTPpfGNG1htyVLdkcDcYYDf6hb9WbmkxbZ1dq5QlKSfjozfipT+SCZfoxo2sWNwCJLKcXK9XQAgxmPd29fXOQqJR8IjG5M7nSfr/pq4kCgfj1Y5mi2RXsm9uBkn9lO053uzieispk0xhYex+pF85WbsY= Received: from DM5PR2101MB1032.namprd21.prod.outlook.com (52.132.128.13) by DM5PR2101MB0983.namprd21.prod.outlook.com (52.132.133.29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.696.0; Mon, 9 Apr 2018 00:25:21 +0000 Received: from DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059]) by DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059%2]) with mapi id 15.20.0696.003; Mon, 9 Apr 2018 00:25:21 +0000 From: Sasha Levin To: "stable@vger.kernel.org" , "linux-kernel@vger.kernel.org" CC: Michal Hocko , Michal Hocko , "David S . Miller" , Andrew Morton , Pablo Neira Ayuso , Sasha Levin Subject: [PATCH AUTOSEL for 4.14 114/161] netfilter: x_tables: make allocation less aggressive Thread-Topic: [PATCH AUTOSEL for 4.14 114/161] netfilter: x_tables: make allocation less aggressive Thread-Index: AQHTz5iygJuu0aDbmkS9msG/Ufx9xA== Date: Mon, 9 Apr 2018 00:21:26 +0000 Message-ID: <20180409001936.162706-114-alexander.levin@microsoft.com> References: <20180409001936.162706-1-alexander.levin@microsoft.com> In-Reply-To: <20180409001936.162706-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;DM5PR2101MB0983;7:Wt7pwG5K0fpFJPLmDI2AJUlwP5ycllIxKQ5zxS9WxH2vdadeLZU8IW23E188lXv6VdV/tQxmHTKs92O1G0OmlF9R4dI3QtQXpgqCZf4S1MIFqjV8Z+q99azlIuWRxm3pF1Y6kMIZP3YT7ajxSBiMPQ+liVsCTGjRKo0j3c4O0M9EZa8gpLCajbZAFFJSkQN49RR1RBqLf2PjdThoiV9QcXz1bq6709hMQOJYdwz9NzhjZUS2b0/WksUcYdhDLTJy;20:ciPUZXDkvVx6cekjslpTL/5LCiboJt+bFyawS7OtY01CkycFwAC2rTpG7gAtBMmu1jjvIvFQYli72ge9RExzM0A2uY+0g5gLKMMWFKmEP+FQzOcktJNOJAGBUz2uDfOzPSCS6ojIs+Zi3armFR7HWpQtdMBfYrOKg4pkJUMVDmM= x-ms-office365-filtering-ht: Tenant X-MS-Office365-Filtering-Correlation-Id: e00a39e0-6645-48bc-9ac2-08d59db0612b x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7193020);SRVR:DM5PR2101MB0983; x-ms-traffictypediagnostic: DM5PR2101MB0983: authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(89211679590171)(42068640409301); x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(8211001083)(61425038)(6040522)(2401047)(8121501046)(5005006)(93006095)(93001095)(3231221)(944501327)(52105095)(3002001)(10201501046)(6055026)(61426038)(61427038)(6041310)(20161123562045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123558120)(20161123564045)(20161123560045)(6072148)(201708071742011);SRVR:DM5PR2101MB0983;BCL:0;PCL:0;RULEID:;SRVR:DM5PR2101MB0983; x-forefront-prvs: 0637FCE711 x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(396003)(39860400002)(346002)(376002)(39380400002)(366004)(199004)(189003)(478600001)(59450400001)(72206003)(10290500003)(3846002)(102836004)(6506007)(6116002)(25786009)(6436002)(66066001)(99286004)(54906003)(86612001)(105586002)(53936002)(76176011)(316002)(486006)(7736002)(22452003)(3660700001)(86362001)(97736004)(106356001)(8936002)(110136005)(5660300001)(11346002)(446003)(81166006)(81156014)(2906002)(8676002)(2900100001)(1076002)(476003)(2616005)(10090500001)(6486002)(107886003)(36756003)(4326008)(966005)(2501003)(68736007)(186003)(305945005)(3280700002)(5250100002)(6306002)(6512007)(26005)(14454004)(22906009)(217873001);DIR:OUT;SFP:1102;SCL:1;SRVR:DM5PR2101MB0983;H:DM5PR2101MB1032.namprd21.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;A:1;MX:1; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) x-microsoft-antispam-message-info: +Z8MXBMcRmRMGA36NXwIefognt1++ZD7xVxYsYcmUJvSGhtwCqLNKUhhGGKS2yLSYjNxZWRP4k5pZ4EIxDZNSfpozMMWQhNhTQ3V3O7aHkSG/+DLDTTkDHVXsyRE/Hbx1/jFodcP1qxq+Fa0p4D79z8XLg6m1yhwZIjJujSMMTVtWJ5GQG4xpxPIcRJbS0bUDV6lVC2IBEOJvbT/jAGgwGCTU7qTNH/B8ziyBCKdKny6xYZTXFwUAck/T6VSwre+B7g1r/3FN8DVZo4kFTKyNk0ReUtIKMPhvLbnuITSYPioEzz8zgCXtWeik1q2mPyhyTiVnWNJEM62HbDS13UDupGyzA1QV0W+kW8rD7QpMWT3Pp/tcliOnjfoQsQBjtGVPBhIYl9Cn0kzLBsoP8iTnM9beHAHPuvSgh8LQilTiNE= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: e00a39e0-6645-48bc-9ac2-08d59db0612b X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Apr 2018 00:21:26.1749 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR2101MB0983 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Michal Hocko [ Upstream commit 0537250fdc6c876ed4cbbe874c739aebef493ee2 ] syzbot has noticed that xt_alloc_table_info can allocate a lot of memory. This is an admin only interface but an admin in a namespace is sufficient as well. eacd86ca3b03 ("net/netfilter/x_tables.c: use kvmalloc() in xt_alloc_table_info()") has changed the opencoded kmalloc->vmalloc fallback into kvmalloc. It has dropped __GFP_NORETRY on the way because vmalloc has simply never fully supported __GFP_NORETRY semantic. This is still the case because e.g. page tables backing the vmalloc area are hardcoded GFP_KERNEL. Revert back to __GFP_NORETRY as a poors man defence against excessively large allocation request here. We will not rule out the OOM killer completely but __GFP_NORETRY should at least stop the large request in most cases. [akpm@linux-foundation.org: coding-style fixes] Fixes: eacd86ca3b03 ("net/netfilter/x_tables.c: use kvmalloc() in xt_alloc_= tableLink: http://lkml.kernel.org/r/20180130140104.GE21609@dhcp22.suse.cz Signed-off-by: Michal Hocko Acked-by: Florian Westphal Reviewed-by: Andrew Morton Cc: David S. Miller Signed-off-by: Andrew Morton Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/netfilter/x_tables.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/net/netfilter/x_tables.c b/net/netfilter/x_tables.c index 60c92158a2cd..8a4947ff2ebf 100644 --- a/net/netfilter/x_tables.c +++ b/net/netfilter/x_tables.c @@ -1008,7 +1008,12 @@ struct xt_table_info *xt_alloc_table_info(unsigned i= nt size) if ((size >> PAGE_SHIFT) + 2 > totalram_pages) return NULL; =20 - info =3D kvmalloc(sz, GFP_KERNEL); + /* __GFP_NORETRY is not fully supported by kvmalloc but it should + * work reasonably well if sz is too large and bail out rather + * than shoot all processes down before realizing there is nothing + * more to reclaim. + */ + info =3D kvmalloc(sz, GFP_KERNEL | __GFP_NORETRY); if (!info) return NULL; =20 --=20 2.15.1