Received: by 10.213.65.68 with SMTP id h4csp2144104imn; Sun, 8 Apr 2018 20:51:27 -0700 (PDT) X-Google-Smtp-Source: AIpwx4/5SZNqnqfgvdjeTVx88/DCpZvkPAawZb8Tr5jQPp+OPVua+iXUQOwFJiz/Eae1U4/kBEhg X-Received: by 10.99.119.9 with SMTP id s9mr23675765pgc.276.1523245886949; Sun, 08 Apr 2018 20:51:26 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1523245886; cv=none; d=google.com; s=arc-20160816; b=Y4zf62XoTwSbFNOQ9bJEd4iMdYQwf88DxFdFbjUrfPtlOtmERdW6oShKtUtxHmRB4W CkSiqM6KdKqLPofD5KySL4gUghgJsyrCvx3iQkV2Xb+RDn/btqLwYBhcMszCQKgyFqVv y2MJzI6UqSZz3uGX/SxxAg1QceTADpaLbmzbLgb4pgcDKuqaRE0Eb82TO6BkrcCnM1OE qw38MC77Z42dhY0wLrzt50Jxf408AIDMd9yIdGDEz7UkWV2VZzTUEWHpitfuW+/xMu1m Zf3tH6vG9bQtFLrQIKRSQlOvrg/+SAyzQ8fZH1Kj9jH3bIajEhx8JfEm4Fn5hxZhBJMl NVLg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=8qJChQNOr7zfAb5JSIZiK1DKyBWzwtbYCXB2Ys9j9jE=; b=vrngDfUSjcyBNLPIG+T8E8Mh6Amd2orpDhx7IcolBHD5ejFEa9HkKGXOhTwCU7B5dZ yVetmYPzMfas6NvLrxReD7gOty/nKib9iIVrOzCjL11kYtA9T3oo9qbJlquqeVLvuZuJ wVVoj2OTEK1NcZtmtbGHwMoE0smlZ9ILG/CZScF910EyHyVRwNgGhcP/G+JsU0ki+Bf3 kEFu4rwmo1GnF+DMLpRVJ7iFWQF6jevamleza6OW8EbN+8d585V3PHZlO2APO+DwqHtx vPY+Sdzqzk2L37UyXb2f+axzOL4CI/tF1ux8lrZl6QgukpCLuvLNhIX+FYd79pyLCTSv BBQw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=cAqVXUoV; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id 142si10493536pgg.29.2018.04.08.20.50.49; Sun, 08 Apr 2018 20:51:26 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=cAqVXUoV; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753536AbeDIDob (ORCPT + 99 others); Sun, 8 Apr 2018 23:44:31 -0400 Received: from mail-cys01nam02on0123.outbound.protection.outlook.com ([104.47.37.123]:10471 "EHLO NAM02-CY1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752944AbeDIAUW (ORCPT ); Sun, 8 Apr 2018 20:20:22 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=8qJChQNOr7zfAb5JSIZiK1DKyBWzwtbYCXB2Ys9j9jE=; b=cAqVXUoVbhP4AVyBa9Q3+4/gEHW7v2LTVvVAF7X+8/tPGiFbpmww4MiwYIbQHXtzQb2qiE0TSkRzyNrdGLO3Do34x28CS2yI4fYSSiJ0o2kNZx9z2fik1WGSVwtBEBvb6eC16UD7d8Y8+aOI8By3ejjkbagqefnv8KvYCwPVWew= Received: from DM5PR2101MB1032.namprd21.prod.outlook.com (52.132.128.13) by DM5PR2101MB1110.namprd21.prod.outlook.com (52.132.131.167) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.696.0; Mon, 9 Apr 2018 00:20:15 +0000 Received: from DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059]) by DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059%2]) with mapi id 15.20.0696.003; Mon, 9 Apr 2018 00:20:15 +0000 From: Sasha Levin To: "stable@vger.kernel.org" , "linux-kernel@vger.kernel.org" CC: Michal Hocko , Michal Hocko , "David S . Miller" , Andrew Morton , Pablo Neira Ayuso , Sasha Levin Subject: [PATCH AUTOSEL for 4.15 137/189] netfilter: x_tables: make allocation less aggressive Thread-Topic: [PATCH AUTOSEL for 4.15 137/189] netfilter: x_tables: make allocation less aggressive Thread-Index: AQHTz5hO6sFR++IwKEWANN1bk69UMw== Date: Mon, 9 Apr 2018 00:18:37 +0000 Message-ID: <20180409001637.162453-137-alexander.levin@microsoft.com> References: <20180409001637.162453-1-alexander.levin@microsoft.com> In-Reply-To: <20180409001637.162453-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;DM5PR2101MB1110;7:tFEgQ3/Re2qZRmX1pQKT+9zdxhzT9F2brpAlOI3EvfBafaFfFPZS0VrQo7R4qh1R5x8wcOkVvc0jKMDDnZ+x0v1IAgniskHKxzGvDiz8H01fR4lcgTCDjEnQ4ZV41C2/c6vX+aHrtOtJnk7f+RDeWPo2HqLcd1A9fFltVvTnTVAKVo012Y3Niekg0uwtBG5hEomOcVnA2zvCGeLC6TAiqditi1RMRRZDXkEJ6eZRdu4oL3kIA9AmjqJGIILnX3Zt;20:h/g5v9Zfd3GJGR3aChNV/lczhnzP/Yvr8U9HYy9bSAZ33Q+ufmUTb+x6dTH3SH84AdmCHlo0Stcd93ZbmUkTw09PODA2NX6z3+K1U+85de4/TPd4ZToeMoadIVWrKBQs3DeivcFU9/9C9Lja3MG+9USsoG9UtZh/xf6U4Y6LP7E= x-ms-office365-filtering-ht: Tenant X-MS-Office365-Filtering-Correlation-Id: a53906fb-2ff7-4b1d-7c2e-08d59dafab16 x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7193020);SRVR:DM5PR2101MB1110; x-ms-traffictypediagnostic: DM5PR2101MB1110: authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(89211679590171)(42068640409301); x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(8211001083)(61425038)(6040522)(2401047)(5005006)(8121501046)(93006095)(93001095)(3231221)(944501327)(52105095)(3002001)(10201501046)(6055026)(61426038)(61427038)(6041310)(20161123558120)(20161123562045)(20161123560045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(6072148)(201708071742011);SRVR:DM5PR2101MB1110;BCL:0;PCL:0;RULEID:;SRVR:DM5PR2101MB1110; x-forefront-prvs: 0637FCE711 x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(376002)(366004)(346002)(396003)(39380400002)(39860400002)(199004)(189003)(5660300001)(478600001)(86612001)(3846002)(6116002)(106356001)(6486002)(72206003)(25786009)(10290500003)(8936002)(6436002)(76176011)(2616005)(6506007)(2900100001)(97736004)(486006)(26005)(36756003)(10090500001)(81166006)(8676002)(81156014)(59450400001)(102836004)(2906002)(99286004)(11346002)(476003)(3660700001)(66066001)(6512007)(86362001)(6306002)(53936002)(966005)(105586002)(186003)(5250100002)(14454004)(22452003)(6666003)(2501003)(446003)(7736002)(316002)(1076002)(110136005)(3280700002)(54906003)(68736007)(107886003)(4326008)(305945005)(22906009)(217873001);DIR:OUT;SFP:1102;SCL:1;SRVR:DM5PR2101MB1110;H:DM5PR2101MB1032.namprd21.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;A:1;MX:1; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) x-microsoft-antispam-message-info: Y+sZFDBTjHcwxhbwQNbu+58y9i7lNHl/KeZbgxXfU+mMfXKOt6UVt4i7GukGBL9jrIEL+uu14rfd8L1grrK5zdXbMO8V8tlMwHK5GAIO8H2N1B1DUbQQLFQ6z1iwdyysABslz5oBSoRPPUZ32dKh6G4BKjb+Z2qiiySZDEGtYlin7AURahL+1dVmQyk7FRJrIi0zusmwJ+DIc8CmXQKGqO9cbwN+dwUIgm3fqDStttzEiyG2vWDTEHPhPZ7MwufPsAxDphXlFDRcvkOX0DPBG9nNc1hXsWXuo0zkgi8Qr4dl4dLpABKHRcVJQxkOP4InH+8cPercYMVBwi640g5jHsvFGz7q7AqC/aWM9n0bxBJlSwLyLoxbmoqu965G7edXn5nYTW/4dRHlXmkbM4nRhs7S3bE/MaOsCU2HNzVgLWU= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: a53906fb-2ff7-4b1d-7c2e-08d59dafab16 X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Apr 2018 00:18:37.7690 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR2101MB1110 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Michal Hocko [ Upstream commit 0537250fdc6c876ed4cbbe874c739aebef493ee2 ] syzbot has noticed that xt_alloc_table_info can allocate a lot of memory. This is an admin only interface but an admin in a namespace is sufficient as well. eacd86ca3b03 ("net/netfilter/x_tables.c: use kvmalloc() in xt_alloc_table_info()") has changed the opencoded kmalloc->vmalloc fallback into kvmalloc. It has dropped __GFP_NORETRY on the way because vmalloc has simply never fully supported __GFP_NORETRY semantic. This is still the case because e.g. page tables backing the vmalloc area are hardcoded GFP_KERNEL. Revert back to __GFP_NORETRY as a poors man defence against excessively large allocation request here. We will not rule out the OOM killer completely but __GFP_NORETRY should at least stop the large request in most cases. [akpm@linux-foundation.org: coding-style fixes] Fixes: eacd86ca3b03 ("net/netfilter/x_tables.c: use kvmalloc() in xt_alloc_= tableLink: http://lkml.kernel.org/r/20180130140104.GE21609@dhcp22.suse.cz Signed-off-by: Michal Hocko Acked-by: Florian Westphal Reviewed-by: Andrew Morton Cc: David S. Miller Signed-off-by: Andrew Morton Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/netfilter/x_tables.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/net/netfilter/x_tables.c b/net/netfilter/x_tables.c index d7070d18db20..d4442aa8fd54 100644 --- a/net/netfilter/x_tables.c +++ b/net/netfilter/x_tables.c @@ -1008,7 +1008,12 @@ struct xt_table_info *xt_alloc_table_info(unsigned i= nt size) if ((size >> PAGE_SHIFT) + 2 > totalram_pages) return NULL; =20 - info =3D kvmalloc(sz, GFP_KERNEL); + /* __GFP_NORETRY is not fully supported by kvmalloc but it should + * work reasonably well if sz is too large and bail out rather + * than shoot all processes down before realizing there is nothing + * more to reclaim. + */ + info =3D kvmalloc(sz, GFP_KERNEL | __GFP_NORETRY); if (!info) return NULL; =20 --=20 2.15.1