1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
72
73#include <linux/init.h>
74#include <linux/kernel.h>
75#include <linux/list.h>
76#include <linux/sched/signal.h>
77#include <linux/sched/task.h>
78#include <linux/sched/task_stack.h>
79#include <linux/jiffies.h>
80#include <linux/delay.h>
81#include <linux/export.h>
82#include <linux/kthread.h>
83#include <linux/rbtree.h>
84#include <linux/fs.h>
85#include <linux/debugfs.h>
86#include <linux/seq_file.h>
87#include <linux/cpumask.h>
88#include <linux/spinlock.h>
89#include <linux/module.h>
90#include <linux/mutex.h>
91#include <linux/rcupdate.h>
92#include <linux/stacktrace.h>
93#include <linux/cache.h>
94#include <linux/percpu.h>
95#include <linux/memblock.h>
96#include <linux/pfn.h>
97#include <linux/mmzone.h>
98#include <linux/slab.h>
99#include <linux/thread_info.h>
100#include <linux/err.h>
101#include <linux/uaccess.h>
102#include <linux/string.h>
103#include <linux/nodemask.h>
104#include <linux/mm.h>
105#include <linux/workqueue.h>
106#include <linux/crc32.h>
107
108#include <asm/sections.h>
109#include <asm/processor.h>
110#include <linux/atomic.h>
111
112#include <linux/kasan.h>
113#include <linux/kmemleak.h>
114#include <linux/memory_hotplug.h>
115
116
117
118
119#define MAX_TRACE 16
120#define MSECS_MIN_AGE 5000
121#define SECS_FIRST_SCAN 60
122#define SECS_SCAN_WAIT 600
123#define MAX_SCAN_SIZE 4096
124
125#define BYTES_PER_POINTER sizeof(void *)
126
127
128#define gfp_kmemleak_mask(gfp) (((gfp) & (GFP_KERNEL | GFP_ATOMIC)) | \
129 __GFP_NORETRY | __GFP_NOMEMALLOC | \
130 __GFP_NOWARN | __GFP_NOFAIL)
131
132
133struct kmemleak_scan_area {
134 struct hlist_node node;
135 unsigned long start;
136 size_t size;
137};
138
139#define KMEMLEAK_GREY 0
140#define KMEMLEAK_BLACK -1
141
142
143
144
145
146
147
148
149
150struct kmemleak_object {
151 spinlock_t lock;
152 unsigned int flags;
153 struct list_head object_list;
154 struct list_head gray_list;
155 struct rb_node rb_node;
156 struct rcu_head rcu;
157
158 atomic_t use_count;
159 unsigned long pointer;
160 size_t size;
161
162 unsigned long excess_ref;
163
164 int min_count;
165
166 int count;
167
168 u32 checksum;
169
170 struct hlist_head area_list;
171 unsigned long trace[MAX_TRACE];
172 unsigned int trace_len;
173 unsigned long jiffies;
174 pid_t pid;
175 char comm[TASK_COMM_LEN];
176};
177
178
179#define OBJECT_ALLOCATED (1 << 0)
180
181#define OBJECT_REPORTED (1 << 1)
182
183#define OBJECT_NO_SCAN (1 << 2)
184
185#define HEX_PREFIX " "
186
187#define HEX_ROW_SIZE 16
188
189#define HEX_GROUP_SIZE 1
190
191#define HEX_ASCII 1
192
193#define HEX_MAX_LINES 2
194
195
196static LIST_HEAD(object_list);
197
198static LIST_HEAD(gray_list);
199
200static struct rb_root object_tree_root = RB_ROOT;
201
202static DEFINE_RWLOCK(kmemleak_lock);
203
204
205static struct kmem_cache *object_cache;
206static struct kmem_cache *scan_area_cache;
207
208
209static int kmemleak_enabled;
210
211static int kmemleak_free_enabled;
212
213static int kmemleak_initialized;
214
215static int kmemleak_early_log = 1;
216
217static int kmemleak_warning;
218
219static int kmemleak_error;
220
221
222static unsigned long min_addr = ULONG_MAX;
223static unsigned long max_addr;
224
225static struct task_struct *scan_thread;
226
227static unsigned long jiffies_min_age;
228static unsigned long jiffies_last_scan;
229
230static signed long jiffies_scan_wait;
231
232static int kmemleak_stack_scan = 1;
233
234static DEFINE_MUTEX(scan_mutex);
235
236static int kmemleak_skip_disable;
237
238static bool kmemleak_found_leaks;
239
240static bool kmemleak_verbose;
241module_param_named(verbose, kmemleak_verbose, bool, 0600);
242
243
244
245
246
247
248
249
250
251
252enum {
253 KMEMLEAK_ALLOC,
254 KMEMLEAK_ALLOC_PERCPU,
255 KMEMLEAK_FREE,
256 KMEMLEAK_FREE_PART,
257 KMEMLEAK_FREE_PERCPU,
258 KMEMLEAK_NOT_LEAK,
259 KMEMLEAK_IGNORE,
260 KMEMLEAK_SCAN_AREA,
261 KMEMLEAK_NO_SCAN,
262 KMEMLEAK_SET_EXCESS_REF
263};
264
265
266
267
268
269struct early_log {
270 int op_type;
271 int min_count;
272 const void *ptr;
273 union {
274 size_t size;
275 unsigned long excess_ref;
276 };
277 unsigned long trace[MAX_TRACE];
278 unsigned int trace_len;
279};
280
281
282static struct early_log
283 early_log[CONFIG_DEBUG_KMEMLEAK_EARLY_LOG_SIZE] __initdata;
284static int crt_early_log __initdata;
285
286static void kmemleak_disable(void);
287
288
289
290
291#define kmemleak_warn(x...) do { \
292 pr_warn(x); \
293 dump_stack(); \
294 kmemleak_warning = 1; \
295} while (0)
296
297
298
299
300
301
302#define kmemleak_stop(x...) do { \
303 kmemleak_warn(x); \
304 kmemleak_disable(); \
305} while (0)
306
307#define warn_or_seq_printf(seq, fmt, ...) do { \
308 if (seq) \
309 seq_printf(seq, fmt, ##__VA_ARGS__); \
310 else \
311 pr_warn(fmt, ##__VA_ARGS__); \
312} while (0)
313
314static void warn_or_seq_hex_dump(struct seq_file *seq, int prefix_type,
315 int rowsize, int groupsize, const void *buf,
316 size_t len, bool ascii)
317{
318 if (seq)
319 seq_hex_dump(seq, HEX_PREFIX, prefix_type, rowsize, groupsize,
320 buf, len, ascii);
321 else
322 print_hex_dump(KERN_WARNING, pr_fmt(HEX_PREFIX), prefix_type,
323 rowsize, groupsize, buf, len, ascii);
324}
325
326
327
328
329
330
331
332static void hex_dump_object(struct seq_file *seq,
333 struct kmemleak_object *object)
334{
335 const u8 *ptr = (const u8 *)object->pointer;
336 size_t len;
337
338
339 len = min_t(size_t, object->size, HEX_MAX_LINES * HEX_ROW_SIZE);
340
341 warn_or_seq_printf(seq, " hex dump (first %zu bytes):\n", len);
342 kasan_disable_current();
343 warn_or_seq_hex_dump(seq, DUMP_PREFIX_NONE, HEX_ROW_SIZE,
344 HEX_GROUP_SIZE, ptr, len, HEX_ASCII);
345 kasan_enable_current();
346}
347
348
349
350
351
352
353
354
355
356
357
358static bool color_white(const struct kmemleak_object *object)
359{
360 return object->count != KMEMLEAK_BLACK &&
361 object->count < object->min_count;
362}
363
364static bool color_gray(const struct kmemleak_object *object)
365{
366 return object->min_count != KMEMLEAK_BLACK &&
367 object->count >= object->min_count;
368}
369
370
371
372
373
374
375static bool unreferenced_object(struct kmemleak_object *object)
376{
377 return (color_white(object) && object->flags & OBJECT_ALLOCATED) &&
378 time_before_eq(object->jiffies + jiffies_min_age,
379 jiffies_last_scan);
380}
381
382
383
384
385
386static void print_unreferenced(struct seq_file *seq,
387 struct kmemleak_object *object)
388{
389 int i;
390 unsigned int msecs_age = jiffies_to_msecs(jiffies - object->jiffies);
391
392 warn_or_seq_printf(seq, "unreferenced object 0x%08lx (size %zu):\n",
393 object->pointer, object->size);
394 warn_or_seq_printf(seq, " comm \"%s\", pid %d, jiffies %lu (age %d.%03ds)\n",
395 object->comm, object->pid, object->jiffies,
396 msecs_age / 1000, msecs_age % 1000);
397 hex_dump_object(seq, object);
398 warn_or_seq_printf(seq, " backtrace:\n");
399
400 for (i = 0; i < object->trace_len; i++) {
401 void *ptr = (void *)object->trace[i];
402 warn_or_seq_printf(seq, " [<%p>] %pS\n", ptr, ptr);
403 }
404}
405
406
407
408
409
410
411static void dump_object_info(struct kmemleak_object *object)
412{
413 struct stack_trace trace;
414
415 trace.nr_entries = object->trace_len;
416 trace.entries = object->trace;
417
418 pr_notice("Object 0x%08lx (size %zu):\n",
419 object->pointer, object->size);
420 pr_notice(" comm \"%s\", pid %d, jiffies %lu\n",
421 object->comm, object->pid, object->jiffies);
422 pr_notice(" min_count = %d\n", object->min_count);
423 pr_notice(" count = %d\n", object->count);
424 pr_notice(" flags = 0x%x\n", object->flags);
425 pr_notice(" checksum = %u\n", object->checksum);
426 pr_notice(" backtrace:\n");
427 print_stack_trace(&trace, 4);
428}
429
430
431
432
433
434
435
436static struct kmemleak_object *lookup_object(unsigned long ptr, int alias)
437{
438 struct rb_node *rb = object_tree_root.rb_node;
439
440 while (rb) {
441 struct kmemleak_object *object =
442 rb_entry(rb, struct kmemleak_object, rb_node);
443 if (ptr < object->pointer)
444 rb = object->rb_node.rb_left;
445 else if (object->pointer + object->size <= ptr)
446 rb = object->rb_node.rb_right;
447 else if (object->pointer == ptr || alias)
448 return object;
449 else {
450 kmemleak_warn("Found object by alias at 0x%08lx\n",
451 ptr);
452 dump_object_info(object);
453 break;
454 }
455 }
456 return NULL;
457}
458
459
460
461
462
463
464
465static int get_object(struct kmemleak_object *object)
466{
467 return atomic_inc_not_zero(&object->use_count);
468}
469
470
471
472
473static void free_object_rcu(struct rcu_head *rcu)
474{
475 struct hlist_node *tmp;
476 struct kmemleak_scan_area *area;
477 struct kmemleak_object *object =
478 container_of(rcu, struct kmemleak_object, rcu);
479
480
481
482
483
484 hlist_for_each_entry_safe(area, tmp, &object->area_list, node) {
485 hlist_del(&area->node);
486 kmem_cache_free(scan_area_cache, area);
487 }
488 kmem_cache_free(object_cache, object);
489}
490
491
492
493
494
495
496
497
498static void put_object(struct kmemleak_object *object)
499{
500 if (!atomic_dec_and_test(&object->use_count))
501 return;
502
503
504 WARN_ON(object->flags & OBJECT_ALLOCATED);
505
506 call_rcu(&object->rcu, free_object_rcu);
507}
508
509
510
511
512static struct kmemleak_object *find_and_get_object(unsigned long ptr, int alias)
513{
514 unsigned long flags;
515 struct kmemleak_object *object;
516
517 rcu_read_lock();
518 read_lock_irqsave(&kmemleak_lock, flags);
519 object = lookup_object(ptr, alias);
520 read_unlock_irqrestore(&kmemleak_lock, flags);
521
522
523 if (object && !get_object(object))
524 object = NULL;
525 rcu_read_unlock();
526
527 return object;
528}
529
530
531
532
533
534
535static struct kmemleak_object *find_and_remove_object(unsigned long ptr, int alias)
536{
537 unsigned long flags;
538 struct kmemleak_object *object;
539
540 write_lock_irqsave(&kmemleak_lock, flags);
541 object = lookup_object(ptr, alias);
542 if (object) {
543 rb_erase(&object->rb_node, &object_tree_root);
544 list_del_rcu(&object->object_list);
545 }
546 write_unlock_irqrestore(&kmemleak_lock, flags);
547
548 return object;
549}
550
551
552
553
554static int __save_stack_trace(unsigned long *trace)
555{
556 struct stack_trace stack_trace;
557
558 stack_trace.max_entries = MAX_TRACE;
559 stack_trace.nr_entries = 0;
560 stack_trace.entries = trace;
561 stack_trace.skip = 2;
562 save_stack_trace(&stack_trace);
563
564 return stack_trace.nr_entries;
565}
566
567
568
569
570
571static struct kmemleak_object *create_object(unsigned long ptr, size_t size,
572 int min_count, gfp_t gfp)
573{
574 unsigned long flags;
575 struct kmemleak_object *object, *parent;
576 struct rb_node **link, *rb_parent;
577
578 object = kmem_cache_alloc(object_cache, gfp_kmemleak_mask(gfp));
579 if (!object) {
580 pr_warn("Cannot allocate a kmemleak_object structure\n");
581 kmemleak_disable();
582 return NULL;
583 }
584
585 INIT_LIST_HEAD(&object->object_list);
586 INIT_LIST_HEAD(&object->gray_list);
587 INIT_HLIST_HEAD(&object->area_list);
588 spin_lock_init(&object->lock);
589 atomic_set(&object->use_count, 1);
590 object->flags = OBJECT_ALLOCATED;
591 object->pointer = ptr;
592 object->size = size;
593 object->excess_ref = 0;
594 object->min_count = min_count;
595 object->count = 0;
596 object->jiffies = jiffies;
597 object->checksum = 0;
598
599
600 if (in_irq()) {
601 object->pid = 0;
602 strncpy(object->comm, "hardirq", sizeof(object->comm));
603 } else if (in_softirq()) {
604 object->pid = 0;
605 strncpy(object->comm, "softirq", sizeof(object->comm));
606 } else {
607 object->pid = current->pid;
608
609
610
611
612
613
614 strncpy(object->comm, current->comm, sizeof(object->comm));
615 }
616
617
618 object->trace_len = __save_stack_trace(object->trace);
619
620 write_lock_irqsave(&kmemleak_lock, flags);
621
622 min_addr = min(min_addr, ptr);
623 max_addr = max(max_addr, ptr + size);
624 link = &object_tree_root.rb_node;
625 rb_parent = NULL;
626 while (*link) {
627 rb_parent = *link;
628 parent = rb_entry(rb_parent, struct kmemleak_object, rb_node);
629 if (ptr + size <= parent->pointer)
630 link = &parent->rb_node.rb_left;
631 else if (parent->pointer + parent->size <= ptr)
632 link = &parent->rb_node.rb_right;
633 else {
634 kmemleak_stop("Cannot insert 0x%lx into the object search tree (overlaps existing)\n",
635 ptr);
636
637
638
639
640 dump_object_info(parent);
641 kmem_cache_free(object_cache, object);
642 object = NULL;
643 goto out;
644 }
645 }
646 rb_link_node(&object->rb_node, rb_parent, link);
647 rb_insert_color(&object->rb_node, &object_tree_root);
648
649 list_add_tail_rcu(&object->object_list, &object_list);
650out:
651 write_unlock_irqrestore(&kmemleak_lock, flags);
652 return object;
653}
654
655
656
657
658static void __delete_object(struct kmemleak_object *object)
659{
660 unsigned long flags;
661
662 WARN_ON(!(object->flags & OBJECT_ALLOCATED));
663 WARN_ON(atomic_read(&object->use_count) < 1);
664
665
666
667
668
669 spin_lock_irqsave(&object->lock, flags);
670 object->flags &= ~OBJECT_ALLOCATED;
671 spin_unlock_irqrestore(&object->lock, flags);
672 put_object(object);
673}
674
675
676
677
678
679static void delete_object_full(unsigned long ptr)
680{
681 struct kmemleak_object *object;
682
683 object = find_and_remove_object(ptr, 0);
684 if (!object) {
685#ifdef DEBUG
686 kmemleak_warn("Freeing unknown object at 0x%08lx\n",
687 ptr);
688#endif
689 return;
690 }
691 __delete_object(object);
692}
693
694
695
696
697
698
699static void delete_object_part(unsigned long ptr, size_t size)
700{
701 struct kmemleak_object *object;
702 unsigned long start, end;
703
704 object = find_and_remove_object(ptr, 1);
705 if (!object) {
706#ifdef DEBUG
707 kmemleak_warn("Partially freeing unknown object at 0x%08lx (size %zu)\n",
708 ptr, size);
709#endif
710 return;
711 }
712
713
714
715
716
717
718
719
720 start = object->pointer;
721 end = object->pointer + object->size;
722 if (ptr > start)
723 create_object(start, ptr - start, object->min_count,
724 GFP_KERNEL);
725 if (ptr + size < end)
726 create_object(ptr + size, end - ptr - size, object->min_count,
727 GFP_KERNEL);
728
729 __delete_object(object);
730}
731
732static void __paint_it(struct kmemleak_object *object, int color)
733{
734 object->min_count = color;
735 if (color == KMEMLEAK_BLACK)
736 object->flags |= OBJECT_NO_SCAN;
737}
738
739static void paint_it(struct kmemleak_object *object, int color)
740{
741 unsigned long flags;
742
743 spin_lock_irqsave(&object->lock, flags);
744 __paint_it(object, color);
745 spin_unlock_irqrestore(&object->lock, flags);
746}
747
748static void paint_ptr(unsigned long ptr, int color)
749{
750 struct kmemleak_object *object;
751
752 object = find_and_get_object(ptr, 0);
753 if (!object) {
754 kmemleak_warn("Trying to color unknown object at 0x%08lx as %s\n",
755 ptr,
756 (color == KMEMLEAK_GREY) ? "Grey" :
757 (color == KMEMLEAK_BLACK) ? "Black" : "Unknown");
758 return;
759 }
760 paint_it(object, color);
761 put_object(object);
762}
763
764
765
766
767
768static void make_gray_object(unsigned long ptr)
769{
770 paint_ptr(ptr, KMEMLEAK_GREY);
771}
772
773
774
775
776
777static void make_black_object(unsigned long ptr)
778{
779 paint_ptr(ptr, KMEMLEAK_BLACK);
780}
781
782
783
784
785
786static void add_scan_area(unsigned long ptr, size_t size, gfp_t gfp)
787{
788 unsigned long flags;
789 struct kmemleak_object *object;
790 struct kmemleak_scan_area *area;
791
792 object = find_and_get_object(ptr, 1);
793 if (!object) {
794 kmemleak_warn("Adding scan area to unknown object at 0x%08lx\n",
795 ptr);
796 return;
797 }
798
799 area = kmem_cache_alloc(scan_area_cache, gfp_kmemleak_mask(gfp));
800 if (!area) {
801 pr_warn("Cannot allocate a scan area\n");
802 goto out;
803 }
804
805 spin_lock_irqsave(&object->lock, flags);
806 if (size == SIZE_MAX) {
807 size = object->pointer + object->size - ptr;
808 } else if (ptr + size > object->pointer + object->size) {
809 kmemleak_warn("Scan area larger than object 0x%08lx\n", ptr);
810 dump_object_info(object);
811 kmem_cache_free(scan_area_cache, area);
812 goto out_unlock;
813 }
814
815 INIT_HLIST_NODE(&area->node);
816 area->start = ptr;
817 area->size = size;
818
819 hlist_add_head(&area->node, &object->area_list);
820out_unlock:
821 spin_unlock_irqrestore(&object->lock, flags);
822out:
823 put_object(object);
824}
825
826
827
828
829
830
831
832static void object_set_excess_ref(unsigned long ptr, unsigned long excess_ref)
833{
834 unsigned long flags;
835 struct kmemleak_object *object;
836
837 object = find_and_get_object(ptr, 0);
838 if (!object) {
839 kmemleak_warn("Setting excess_ref on unknown object at 0x%08lx\n",
840 ptr);
841 return;
842 }
843
844 spin_lock_irqsave(&object->lock, flags);
845 object->excess_ref = excess_ref;
846 spin_unlock_irqrestore(&object->lock, flags);
847 put_object(object);
848}
849
850
851
852
853
854
855static void object_no_scan(unsigned long ptr)
856{
857 unsigned long flags;
858 struct kmemleak_object *object;
859
860 object = find_and_get_object(ptr, 0);
861 if (!object) {
862 kmemleak_warn("Not scanning unknown object at 0x%08lx\n", ptr);
863 return;
864 }
865
866 spin_lock_irqsave(&object->lock, flags);
867 object->flags |= OBJECT_NO_SCAN;
868 spin_unlock_irqrestore(&object->lock, flags);
869 put_object(object);
870}
871
872
873
874
875
876static void __init log_early(int op_type, const void *ptr, size_t size,
877 int min_count)
878{
879 unsigned long flags;
880 struct early_log *log;
881
882 if (kmemleak_error) {
883
884 crt_early_log++;
885 return;
886 }
887
888 if (crt_early_log >= ARRAY_SIZE(early_log)) {
889 crt_early_log++;
890 kmemleak_disable();
891 return;
892 }
893
894
895
896
897
898 local_irq_save(flags);
899 log = &early_log[crt_early_log];
900 log->op_type = op_type;
901 log->ptr = ptr;
902 log->size = size;
903 log->min_count = min_count;
904 log->trace_len = __save_stack_trace(log->trace);
905 crt_early_log++;
906 local_irq_restore(flags);
907}
908
909
910
911
912static void early_alloc(struct early_log *log)
913{
914 struct kmemleak_object *object;
915 unsigned long flags;
916 int i;
917
918 if (!kmemleak_enabled || !log->ptr || IS_ERR(log->ptr))
919 return;
920
921
922
923
924 rcu_read_lock();
925 object = create_object((unsigned long)log->ptr, log->size,
926 log->min_count, GFP_ATOMIC);
927 if (!object)
928 goto out;
929 spin_lock_irqsave(&object->lock, flags);
930 for (i = 0; i < log->trace_len; i++)
931 object->trace[i] = log->trace[i];
932 object->trace_len = log->trace_len;
933 spin_unlock_irqrestore(&object->lock, flags);
934out:
935 rcu_read_unlock();
936}
937
938
939
940
941static void early_alloc_percpu(struct early_log *log)
942{
943 unsigned int cpu;
944 const void __percpu *ptr = log->ptr;
945
946 for_each_possible_cpu(cpu) {
947 log->ptr = per_cpu_ptr(ptr, cpu);
948 early_alloc(log);
949 }
950}
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966void __ref kmemleak_alloc(const void *ptr, size_t size, int min_count,
967 gfp_t gfp)
968{
969 pr_debug("%s(0x%p, %zu, %d)\n", __func__, ptr, size, min_count);
970
971 if (kmemleak_enabled && ptr && !IS_ERR(ptr))
972 create_object((unsigned long)ptr, size, min_count, gfp);
973 else if (kmemleak_early_log)
974 log_early(KMEMLEAK_ALLOC, ptr, size, min_count);
975}
976EXPORT_SYMBOL_GPL(kmemleak_alloc);
977
978
979
980
981
982
983
984
985
986
987void __ref kmemleak_alloc_percpu(const void __percpu *ptr, size_t size,
988 gfp_t gfp)
989{
990 unsigned int cpu;
991
992 pr_debug("%s(0x%p, %zu)\n", __func__, ptr, size);
993
994
995
996
997
998 if (kmemleak_enabled && ptr && !IS_ERR(ptr))
999 for_each_possible_cpu(cpu)
1000 create_object((unsigned long)per_cpu_ptr(ptr, cpu),
1001 size, 0, gfp);
1002 else if (kmemleak_early_log)
1003 log_early(KMEMLEAK_ALLOC_PERCPU, ptr, size, 0);
1004}
1005EXPORT_SYMBOL_GPL(kmemleak_alloc_percpu);
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
1016void __ref kmemleak_vmalloc(const struct vm_struct *area, size_t size, gfp_t gfp)
1017{
1018 pr_debug("%s(0x%p, %zu)\n", __func__, area, size);
1019
1020
1021
1022
1023
1024 if (kmemleak_enabled) {
1025 create_object((unsigned long)area->addr, size, 2, gfp);
1026 object_set_excess_ref((unsigned long)area,
1027 (unsigned long)area->addr);
1028 } else if (kmemleak_early_log) {
1029 log_early(KMEMLEAK_ALLOC, area->addr, size, 2);
1030
1031 log_early(KMEMLEAK_SET_EXCESS_REF,
1032 area, (unsigned long)area->addr, 0);
1033 }
1034}
1035EXPORT_SYMBOL_GPL(kmemleak_vmalloc);
1036
1037
1038
1039
1040
1041
1042
1043
1044void __ref kmemleak_free(const void *ptr)
1045{
1046 pr_debug("%s(0x%p)\n", __func__, ptr);
1047
1048 if (kmemleak_free_enabled && ptr && !IS_ERR(ptr))
1049 delete_object_full((unsigned long)ptr);
1050 else if (kmemleak_early_log)
1051 log_early(KMEMLEAK_FREE, ptr, 0, 0);
1052}
1053EXPORT_SYMBOL_GPL(kmemleak_free);
1054
1055
1056
1057
1058
1059
1060
1061
1062
1063
1064void __ref kmemleak_free_part(const void *ptr, size_t size)
1065{
1066 pr_debug("%s(0x%p)\n", __func__, ptr);
1067
1068 if (kmemleak_enabled && ptr && !IS_ERR(ptr))
1069 delete_object_part((unsigned long)ptr, size);
1070 else if (kmemleak_early_log)
1071 log_early(KMEMLEAK_FREE_PART, ptr, size, 0);
1072}
1073EXPORT_SYMBOL_GPL(kmemleak_free_part);
1074
1075
1076
1077
1078
1079
1080
1081
1082void __ref kmemleak_free_percpu(const void __percpu *ptr)
1083{
1084 unsigned int cpu;
1085
1086 pr_debug("%s(0x%p)\n", __func__, ptr);
1087
1088 if (kmemleak_free_enabled && ptr && !IS_ERR(ptr))
1089 for_each_possible_cpu(cpu)
1090 delete_object_full((unsigned long)per_cpu_ptr(ptr,
1091 cpu));
1092 else if (kmemleak_early_log)
1093 log_early(KMEMLEAK_FREE_PERCPU, ptr, 0, 0);
1094}
1095EXPORT_SYMBOL_GPL(kmemleak_free_percpu);
1096
1097
1098
1099
1100
1101
1102
1103
1104void __ref kmemleak_update_trace(const void *ptr)
1105{
1106 struct kmemleak_object *object;
1107 unsigned long flags;
1108
1109 pr_debug("%s(0x%p)\n", __func__, ptr);
1110
1111 if (!kmemleak_enabled || IS_ERR_OR_NULL(ptr))
1112 return;
1113
1114 object = find_and_get_object((unsigned long)ptr, 1);
1115 if (!object) {
1116#ifdef DEBUG
1117 kmemleak_warn("Updating stack trace for unknown object at %p\n",
1118 ptr);
1119#endif
1120 return;
1121 }
1122
1123 spin_lock_irqsave(&object->lock, flags);
1124 object->trace_len = __save_stack_trace(object->trace);
1125 spin_unlock_irqrestore(&object->lock, flags);
1126
1127 put_object(object);
1128}
1129EXPORT_SYMBOL(kmemleak_update_trace);
1130
1131
1132
1133
1134
1135
1136
1137
1138void __ref kmemleak_not_leak(const void *ptr)
1139{
1140 pr_debug("%s(0x%p)\n", __func__, ptr);
1141
1142 if (kmemleak_enabled && ptr && !IS_ERR(ptr))
1143 make_gray_object((unsigned long)ptr);
1144 else if (kmemleak_early_log)
1145 log_early(KMEMLEAK_NOT_LEAK, ptr, 0, 0);
1146}
1147EXPORT_SYMBOL(kmemleak_not_leak);
1148
1149
1150
1151
1152
1153
1154
1155
1156
1157
1158void __ref kmemleak_ignore(const void *ptr)
1159{
1160 pr_debug("%s(0x%p)\n", __func__, ptr);
1161
1162 if (kmemleak_enabled && ptr && !IS_ERR(ptr))
1163 make_black_object((unsigned long)ptr);
1164 else if (kmemleak_early_log)
1165 log_early(KMEMLEAK_IGNORE, ptr, 0, 0);
1166}
1167EXPORT_SYMBOL(kmemleak_ignore);
1168
1169
1170
1171
1172
1173
1174
1175
1176
1177
1178
1179
1180void __ref kmemleak_scan_area(const void *ptr, size_t size, gfp_t gfp)
1181{
1182 pr_debug("%s(0x%p)\n", __func__, ptr);
1183
1184 if (kmemleak_enabled && ptr && size && !IS_ERR(ptr))
1185 add_scan_area((unsigned long)ptr, size, gfp);
1186 else if (kmemleak_early_log)
1187 log_early(KMEMLEAK_SCAN_AREA, ptr, size, 0);
1188}
1189EXPORT_SYMBOL(kmemleak_scan_area);
1190
1191
1192
1193
1194
1195
1196
1197
1198
1199
1200void __ref kmemleak_no_scan(const void *ptr)
1201{
1202 pr_debug("%s(0x%p)\n", __func__, ptr);
1203
1204 if (kmemleak_enabled && ptr && !IS_ERR(ptr))
1205 object_no_scan((unsigned long)ptr);
1206 else if (kmemleak_early_log)
1207 log_early(KMEMLEAK_NO_SCAN, ptr, 0, 0);
1208}
1209EXPORT_SYMBOL(kmemleak_no_scan);
1210
1211
1212
1213
1214
1215
1216
1217
1218
1219
1220void __ref kmemleak_alloc_phys(phys_addr_t phys, size_t size, int min_count,
1221 gfp_t gfp)
1222{
1223 if (!IS_ENABLED(CONFIG_HIGHMEM) || PHYS_PFN(phys) < max_low_pfn)
1224 kmemleak_alloc(__va(phys), size, min_count, gfp);
1225}
1226EXPORT_SYMBOL(kmemleak_alloc_phys);
1227
1228
1229
1230
1231
1232
1233
1234
1235void __ref kmemleak_free_part_phys(phys_addr_t phys, size_t size)
1236{
1237 if (!IS_ENABLED(CONFIG_HIGHMEM) || PHYS_PFN(phys) < max_low_pfn)
1238 kmemleak_free_part(__va(phys), size);
1239}
1240EXPORT_SYMBOL(kmemleak_free_part_phys);
1241
1242
1243
1244
1245
1246
1247void __ref kmemleak_not_leak_phys(phys_addr_t phys)
1248{
1249 if (!IS_ENABLED(CONFIG_HIGHMEM) || PHYS_PFN(phys) < max_low_pfn)
1250 kmemleak_not_leak(__va(phys));
1251}
1252EXPORT_SYMBOL(kmemleak_not_leak_phys);
1253
1254
1255
1256
1257
1258
1259void __ref kmemleak_ignore_phys(phys_addr_t phys)
1260{
1261 if (!IS_ENABLED(CONFIG_HIGHMEM) || PHYS_PFN(phys) < max_low_pfn)
1262 kmemleak_ignore(__va(phys));
1263}
1264EXPORT_SYMBOL(kmemleak_ignore_phys);
1265
1266
1267
1268
1269static bool update_checksum(struct kmemleak_object *object)
1270{
1271 u32 old_csum = object->checksum;
1272
1273 kasan_disable_current();
1274 object->checksum = crc32(0, (void *)object->pointer, object->size);
1275 kasan_enable_current();
1276
1277 return object->checksum != old_csum;
1278}
1279
1280
1281
1282
1283static void update_refs(struct kmemleak_object *object)
1284{
1285 if (!color_white(object)) {
1286
1287 return;
1288 }
1289
1290
1291
1292
1293
1294
1295
1296 object->count++;
1297 if (color_gray(object)) {
1298
1299 WARN_ON(!get_object(object));
1300 list_add_tail(&object->gray_list, &gray_list);
1301 }
1302}
1303
1304
1305
1306
1307
1308static int scan_should_stop(void)
1309{
1310 if (!kmemleak_enabled)
1311 return 1;
1312
1313
1314
1315
1316
1317 if (current->mm)
1318 return signal_pending(current);
1319 else
1320 return kthread_should_stop();
1321
1322 return 0;
1323}
1324
1325
1326
1327
1328
1329static void scan_block(void *_start, void *_end,
1330 struct kmemleak_object *scanned)
1331{
1332 unsigned long *ptr;
1333 unsigned long *start = PTR_ALIGN(_start, BYTES_PER_POINTER);
1334 unsigned long *end = _end - (BYTES_PER_POINTER - 1);
1335 unsigned long flags;
1336
1337 read_lock_irqsave(&kmemleak_lock, flags);
1338 for (ptr = start; ptr < end; ptr++) {
1339 struct kmemleak_object *object;
1340 unsigned long pointer;
1341 unsigned long excess_ref;
1342
1343 if (scan_should_stop())
1344 break;
1345
1346 kasan_disable_current();
1347 pointer = *ptr;
1348 kasan_enable_current();
1349
1350 if (pointer < min_addr || pointer >= max_addr)
1351 continue;
1352
1353
1354
1355
1356
1357
1358
1359 object = lookup_object(pointer, 1);
1360 if (!object)
1361 continue;
1362 if (object == scanned)
1363
1364 continue;
1365
1366
1367
1368
1369
1370
1371 spin_lock_nested(&object->lock, SINGLE_DEPTH_NESTING);
1372
1373 if (color_gray(object)) {
1374 excess_ref = object->excess_ref;
1375
1376 } else {
1377 excess_ref = 0;
1378 update_refs(object);
1379 }
1380 spin_unlock(&object->lock);
1381
1382 if (excess_ref) {
1383 object = lookup_object(excess_ref, 0);
1384 if (!object)
1385 continue;
1386 if (object == scanned)
1387
1388 continue;
1389 spin_lock_nested(&object->lock, SINGLE_DEPTH_NESTING);
1390 update_refs(object);
1391 spin_unlock(&object->lock);
1392 }
1393 }
1394 read_unlock_irqrestore(&kmemleak_lock, flags);
1395}
1396
1397
1398
1399
1400static void scan_large_block(void *start, void *end)
1401{
1402 void *next;
1403
1404 while (start < end) {
1405 next = min(start + MAX_SCAN_SIZE, end);
1406 scan_block(start, next, NULL);
1407 start = next;
1408 cond_resched();
1409 }
1410}
1411
1412
1413
1414
1415
1416static void scan_object(struct kmemleak_object *object)
1417{
1418 struct kmemleak_scan_area *area;
1419 unsigned long flags;
1420
1421
1422
1423
1424
1425 spin_lock_irqsave(&object->lock, flags);
1426 if (object->flags & OBJECT_NO_SCAN)
1427 goto out;
1428 if (!(object->flags & OBJECT_ALLOCATED))
1429
1430 goto out;
1431 if (hlist_empty(&object->area_list)) {
1432 void *start = (void *)object->pointer;
1433 void *end = (void *)(object->pointer + object->size);
1434 void *next;
1435
1436 do {
1437 next = min(start + MAX_SCAN_SIZE, end);
1438 scan_block(start, next, object);
1439
1440 start = next;
1441 if (start >= end)
1442 break;
1443
1444 spin_unlock_irqrestore(&object->lock, flags);
1445 cond_resched();
1446 spin_lock_irqsave(&object->lock, flags);
1447 } while (object->flags & OBJECT_ALLOCATED);
1448 } else
1449 hlist_for_each_entry(area, &object->area_list, node)
1450 scan_block((void *)area->start,
1451 (void *)(area->start + area->size),
1452 object);
1453out:
1454 spin_unlock_irqrestore(&object->lock, flags);
1455}
1456
1457
1458
1459
1460
1461static void scan_gray_list(void)
1462{
1463 struct kmemleak_object *object, *tmp;
1464
1465
1466
1467
1468
1469
1470 object = list_entry(gray_list.next, typeof(*object), gray_list);
1471 while (&object->gray_list != &gray_list) {
1472 cond_resched();
1473
1474
1475 if (!scan_should_stop())
1476 scan_object(object);
1477
1478 tmp = list_entry(object->gray_list.next, typeof(*object),
1479 gray_list);
1480
1481
1482 list_del(&object->gray_list);
1483 put_object(object);
1484
1485 object = tmp;
1486 }
1487 WARN_ON(!list_empty(&gray_list));
1488}
1489
1490
1491
1492
1493
1494
1495static void kmemleak_scan(void)
1496{
1497 unsigned long flags;
1498 struct kmemleak_object *object;
1499 int i;
1500 int new_leaks = 0;
1501
1502 jiffies_last_scan = jiffies;
1503
1504
1505 rcu_read_lock();
1506 list_for_each_entry_rcu(object, &object_list, object_list) {
1507 spin_lock_irqsave(&object->lock, flags);
1508#ifdef DEBUG
1509
1510
1511
1512
1513 if (atomic_read(&object->use_count) > 1) {
1514 pr_debug("object->use_count = %d\n",
1515 atomic_read(&object->use_count));
1516 dump_object_info(object);
1517 }
1518#endif
1519
1520 object->count = 0;
1521 if (color_gray(object) && get_object(object))
1522 list_add_tail(&object->gray_list, &gray_list);
1523
1524 spin_unlock_irqrestore(&object->lock, flags);
1525 }
1526 rcu_read_unlock();
1527
1528
1529 scan_large_block(_sdata, _edata);
1530 scan_large_block(__bss_start, __bss_stop);
1531 scan_large_block(__start_ro_after_init, __end_ro_after_init);
1532
1533#ifdef CONFIG_SMP
1534
1535 for_each_possible_cpu(i)
1536 scan_large_block(__per_cpu_start + per_cpu_offset(i),
1537 __per_cpu_end + per_cpu_offset(i));
1538#endif
1539
1540
1541
1542
1543 get_online_mems();
1544 for_each_online_node(i) {
1545 unsigned long start_pfn = node_start_pfn(i);
1546 unsigned long end_pfn = node_end_pfn(i);
1547 unsigned long pfn;
1548
1549 for (pfn = start_pfn; pfn < end_pfn; pfn++) {
1550 struct page *page;
1551
1552 if (!pfn_valid(pfn))
1553 continue;
1554 page = pfn_to_page(pfn);
1555
1556 if (page_count(page) == 0)
1557 continue;
1558 scan_block(page, page + 1, NULL);
1559 if (!(pfn & 63))
1560 cond_resched();
1561 }
1562 }
1563 put_online_mems();
1564
1565
1566
1567
1568 if (kmemleak_stack_scan) {
1569 struct task_struct *p, *g;
1570
1571 read_lock(&tasklist_lock);
1572 do_each_thread(g, p) {
1573 void *stack = try_get_task_stack(p);
1574 if (stack) {
1575 scan_block(stack, stack + THREAD_SIZE, NULL);
1576 put_task_stack(p);
1577 }
1578 } while_each_thread(g, p);
1579 read_unlock(&tasklist_lock);
1580 }
1581
1582
1583
1584
1585
1586 scan_gray_list();
1587
1588
1589
1590
1591
1592 rcu_read_lock();
1593 list_for_each_entry_rcu(object, &object_list, object_list) {
1594 spin_lock_irqsave(&object->lock, flags);
1595 if (color_white(object) && (object->flags & OBJECT_ALLOCATED)
1596 && update_checksum(object) && get_object(object)) {
1597
1598 object->count = object->min_count;
1599 list_add_tail(&object->gray_list, &gray_list);
1600 }
1601 spin_unlock_irqrestore(&object->lock, flags);
1602 }
1603 rcu_read_unlock();
1604
1605
1606
1607
1608 scan_gray_list();
1609
1610
1611
1612
1613 if (scan_should_stop())
1614 return;
1615
1616
1617
1618
1619 rcu_read_lock();
1620 list_for_each_entry_rcu(object, &object_list, object_list) {
1621 spin_lock_irqsave(&object->lock, flags);
1622 if (unreferenced_object(object) &&
1623 !(object->flags & OBJECT_REPORTED)) {
1624 object->flags |= OBJECT_REPORTED;
1625
1626 if (kmemleak_verbose)
1627 print_unreferenced(NULL, object);
1628
1629 new_leaks++;
1630 }
1631 spin_unlock_irqrestore(&object->lock, flags);
1632 }
1633 rcu_read_unlock();
1634
1635 if (new_leaks) {
1636 kmemleak_found_leaks = true;
1637
1638 pr_info("%d new suspected memory leaks (see /sys/kernel/debug/kmemleak)\n",
1639 new_leaks);
1640 }
1641
1642}
1643
1644
1645
1646
1647
1648static int kmemleak_scan_thread(void *arg)
1649{
1650 static int first_run = 1;
1651
1652 pr_info("Automatic memory scanning thread started\n");
1653 set_user_nice(current, 10);
1654
1655
1656
1657
1658 if (first_run) {
1659 signed long timeout = msecs_to_jiffies(SECS_FIRST_SCAN * 1000);
1660 first_run = 0;
1661 while (timeout && !kthread_should_stop())
1662 timeout = schedule_timeout_interruptible(timeout);
1663 }
1664
1665 while (!kthread_should_stop()) {
1666 signed long timeout = jiffies_scan_wait;
1667
1668 mutex_lock(&scan_mutex);
1669 kmemleak_scan();
1670 mutex_unlock(&scan_mutex);
1671
1672
1673 while (timeout && !kthread_should_stop())
1674 timeout = schedule_timeout_interruptible(timeout);
1675 }
1676
1677 pr_info("Automatic memory scanning thread ended\n");
1678
1679 return 0;
1680}
1681
1682
1683
1684
1685
1686static void start_scan_thread(void)
1687{
1688 if (scan_thread)
1689 return;
1690 scan_thread = kthread_run(kmemleak_scan_thread, NULL, "kmemleak");
1691 if (IS_ERR(scan_thread)) {
1692 pr_warn("Failed to create the scan thread\n");
1693 scan_thread = NULL;
1694 }
1695}
1696
1697
1698
1699
1700static void stop_scan_thread(void)
1701{
1702 if (scan_thread) {
1703 kthread_stop(scan_thread);
1704 scan_thread = NULL;
1705 }
1706}
1707
1708
1709
1710
1711
1712
1713static void *kmemleak_seq_start(struct seq_file *seq, loff_t *pos)
1714{
1715 struct kmemleak_object *object;
1716 loff_t n = *pos;
1717 int err;
1718
1719 err = mutex_lock_interruptible(&scan_mutex);
1720 if (err < 0)
1721 return ERR_PTR(err);
1722
1723 rcu_read_lock();
1724 list_for_each_entry_rcu(object, &object_list, object_list) {
1725 if (n-- > 0)
1726 continue;
1727 if (get_object(object))
1728 goto out;
1729 }
1730 object = NULL;
1731out:
1732 return object;
1733}
1734
1735
1736
1737
1738
1739static void *kmemleak_seq_next(struct seq_file *seq, void *v, loff_t *pos)
1740{
1741 struct kmemleak_object *prev_obj = v;
1742 struct kmemleak_object *next_obj = NULL;
1743 struct kmemleak_object *obj = prev_obj;
1744
1745 ++(*pos);
1746
1747 list_for_each_entry_continue_rcu(obj, &object_list, object_list) {
1748 if (get_object(obj)) {
1749 next_obj = obj;
1750 break;
1751 }
1752 }
1753
1754 put_object(prev_obj);
1755 return next_obj;
1756}
1757
1758
1759
1760
1761static void kmemleak_seq_stop(struct seq_file *seq, void *v)
1762{
1763 if (!IS_ERR(v)) {
1764
1765
1766
1767
1768 rcu_read_unlock();
1769 mutex_unlock(&scan_mutex);
1770 if (v)
1771 put_object(v);
1772 }
1773}
1774
1775
1776
1777
1778static int kmemleak_seq_show(struct seq_file *seq, void *v)
1779{
1780 struct kmemleak_object *object = v;
1781 unsigned long flags;
1782
1783 spin_lock_irqsave(&object->lock, flags);
1784 if ((object->flags & OBJECT_REPORTED) && unreferenced_object(object))
1785 print_unreferenced(seq, object);
1786 spin_unlock_irqrestore(&object->lock, flags);
1787 return 0;
1788}
1789
1790static const struct seq_operations kmemleak_seq_ops = {
1791 .start = kmemleak_seq_start,
1792 .next = kmemleak_seq_next,
1793 .stop = kmemleak_seq_stop,
1794 .show = kmemleak_seq_show,
1795};
1796
1797static int kmemleak_open(struct inode *inode, struct file *file)
1798{
1799 return seq_open(file, &kmemleak_seq_ops);
1800}
1801
1802static int dump_str_object_info(const char *str)
1803{
1804 unsigned long flags;
1805 struct kmemleak_object *object;
1806 unsigned long addr;
1807
1808 if (kstrtoul(str, 0, &addr))
1809 return -EINVAL;
1810 object = find_and_get_object(addr, 0);
1811 if (!object) {
1812 pr_info("Unknown object at 0x%08lx\n", addr);
1813 return -EINVAL;
1814 }
1815
1816 spin_lock_irqsave(&object->lock, flags);
1817 dump_object_info(object);
1818 spin_unlock_irqrestore(&object->lock, flags);
1819
1820 put_object(object);
1821 return 0;
1822}
1823
1824
1825
1826
1827
1828
1829
1830static void kmemleak_clear(void)
1831{
1832 struct kmemleak_object *object;
1833 unsigned long flags;
1834
1835 rcu_read_lock();
1836 list_for_each_entry_rcu(object, &object_list, object_list) {
1837 spin_lock_irqsave(&object->lock, flags);
1838 if ((object->flags & OBJECT_REPORTED) &&
1839 unreferenced_object(object))
1840 __paint_it(object, KMEMLEAK_GREY);
1841 spin_unlock_irqrestore(&object->lock, flags);
1842 }
1843 rcu_read_unlock();
1844
1845 kmemleak_found_leaks = false;
1846}
1847
1848static void __kmemleak_do_cleanup(void);
1849
1850
1851
1852
1853
1854
1855
1856
1857
1858
1859
1860
1861
1862
1863
1864
1865
1866static ssize_t kmemleak_write(struct file *file, const char __user *user_buf,
1867 size_t size, loff_t *ppos)
1868{
1869 char buf[64];
1870 int buf_size;
1871 int ret;
1872
1873 buf_size = min(size, (sizeof(buf) - 1));
1874 if (strncpy_from_user(buf, user_buf, buf_size) < 0)
1875 return -EFAULT;
1876 buf[buf_size] = 0;
1877
1878 ret = mutex_lock_interruptible(&scan_mutex);
1879 if (ret < 0)
1880 return ret;
1881
1882 if (strncmp(buf, "clear", 5) == 0) {
1883 if (kmemleak_enabled)
1884 kmemleak_clear();
1885 else
1886 __kmemleak_do_cleanup();
1887 goto out;
1888 }
1889
1890 if (!kmemleak_enabled) {
1891 ret = -EBUSY;
1892 goto out;
1893 }
1894
1895 if (strncmp(buf, "off", 3) == 0)
1896 kmemleak_disable();
1897 else if (strncmp(buf, "stack=on", 8) == 0)
1898 kmemleak_stack_scan = 1;
1899 else if (strncmp(buf, "stack=off", 9) == 0)
1900 kmemleak_stack_scan = 0;
1901 else if (strncmp(buf, "scan=on", 7) == 0)
1902 start_scan_thread();
1903 else if (strncmp(buf, "scan=off", 8) == 0)
1904 stop_scan_thread();
1905 else if (strncmp(buf, "scan=", 5) == 0) {
1906 unsigned long secs;
1907
1908 ret = kstrtoul(buf + 5, 0, &secs);
1909 if (ret < 0)
1910 goto out;
1911 stop_scan_thread();
1912 if (secs) {
1913 jiffies_scan_wait = msecs_to_jiffies(secs * 1000);
1914 start_scan_thread();
1915 }
1916 } else if (strncmp(buf, "scan", 4) == 0)
1917 kmemleak_scan();
1918 else if (strncmp(buf, "dump=", 5) == 0)
1919 ret = dump_str_object_info(buf + 5);
1920 else
1921 ret = -EINVAL;
1922
1923out:
1924 mutex_unlock(&scan_mutex);
1925 if (ret < 0)
1926 return ret;
1927
1928
1929 *ppos += size;
1930 return size;
1931}
1932
1933static const struct file_operations kmemleak_fops = {
1934 .owner = THIS_MODULE,
1935 .open = kmemleak_open,
1936 .read = seq_read,
1937 .write = kmemleak_write,
1938 .llseek = seq_lseek,
1939 .release = seq_release,
1940};
1941
1942static void __kmemleak_do_cleanup(void)
1943{
1944 struct kmemleak_object *object;
1945
1946 rcu_read_lock();
1947 list_for_each_entry_rcu(object, &object_list, object_list)
1948 delete_object_full(object->pointer);
1949 rcu_read_unlock();
1950}
1951
1952
1953
1954
1955
1956
1957static void kmemleak_do_cleanup(struct work_struct *work)
1958{
1959 stop_scan_thread();
1960
1961 mutex_lock(&scan_mutex);
1962
1963
1964
1965
1966
1967
1968 kmemleak_free_enabled = 0;
1969 mutex_unlock(&scan_mutex);
1970
1971 if (!kmemleak_found_leaks)
1972 __kmemleak_do_cleanup();
1973 else
1974 pr_info("Kmemleak disabled without freeing internal data. Reclaim the memory with \"echo clear > /sys/kernel/debug/kmemleak\".\n");
1975}
1976
1977static DECLARE_WORK(cleanup_work, kmemleak_do_cleanup);
1978
1979
1980
1981
1982
1983static void kmemleak_disable(void)
1984{
1985
1986 if (cmpxchg(&kmemleak_error, 0, 1))
1987 return;
1988
1989
1990 kmemleak_enabled = 0;
1991
1992
1993 if (kmemleak_initialized)
1994 schedule_work(&cleanup_work);
1995 else
1996 kmemleak_free_enabled = 0;
1997
1998 pr_info("Kernel memory leak detector disabled\n");
1999}
2000
2001
2002
2003
2004static int __init kmemleak_boot_config(char *str)
2005{
2006 if (!str)
2007 return -EINVAL;
2008 if (strcmp(str, "off") == 0)
2009 kmemleak_disable();
2010 else if (strcmp(str, "on") == 0)
2011 kmemleak_skip_disable = 1;
2012 else
2013 return -EINVAL;
2014 return 0;
2015}
2016early_param("kmemleak", kmemleak_boot_config);
2017
2018static void __init print_log_trace(struct early_log *log)
2019{
2020 struct stack_trace trace;
2021
2022 trace.nr_entries = log->trace_len;
2023 trace.entries = log->trace;
2024
2025 pr_notice("Early log backtrace:\n");
2026 print_stack_trace(&trace, 2);
2027}
2028
2029
2030
2031
2032void __init kmemleak_init(void)
2033{
2034 int i;
2035 unsigned long flags;
2036
2037#ifdef CONFIG_DEBUG_KMEMLEAK_DEFAULT_OFF
2038 if (!kmemleak_skip_disable) {
2039 kmemleak_early_log = 0;
2040 kmemleak_disable();
2041 return;
2042 }
2043#endif
2044
2045 jiffies_min_age = msecs_to_jiffies(MSECS_MIN_AGE);
2046 jiffies_scan_wait = msecs_to_jiffies(SECS_SCAN_WAIT * 1000);
2047
2048 object_cache = KMEM_CACHE(kmemleak_object, SLAB_NOLEAKTRACE);
2049 scan_area_cache = KMEM_CACHE(kmemleak_scan_area, SLAB_NOLEAKTRACE);
2050
2051 if (crt_early_log > ARRAY_SIZE(early_log))
2052 pr_warn("Early log buffer exceeded (%d), please increase DEBUG_KMEMLEAK_EARLY_LOG_SIZE\n",
2053 crt_early_log);
2054
2055
2056 local_irq_save(flags);
2057 kmemleak_early_log = 0;
2058 if (kmemleak_error) {
2059 local_irq_restore(flags);
2060 return;
2061 } else {
2062 kmemleak_enabled = 1;
2063 kmemleak_free_enabled = 1;
2064 }
2065 local_irq_restore(flags);
2066
2067
2068
2069
2070
2071
2072 for (i = 0; i < crt_early_log; i++) {
2073 struct early_log *log = &early_log[i];
2074
2075 switch (log->op_type) {
2076 case KMEMLEAK_ALLOC:
2077 early_alloc(log);
2078 break;
2079 case KMEMLEAK_ALLOC_PERCPU:
2080 early_alloc_percpu(log);
2081 break;
2082 case KMEMLEAK_FREE:
2083 kmemleak_free(log->ptr);
2084 break;
2085 case KMEMLEAK_FREE_PART:
2086 kmemleak_free_part(log->ptr, log->size);
2087 break;
2088 case KMEMLEAK_FREE_PERCPU:
2089 kmemleak_free_percpu(log->ptr);
2090 break;
2091 case KMEMLEAK_NOT_LEAK:
2092 kmemleak_not_leak(log->ptr);
2093 break;
2094 case KMEMLEAK_IGNORE:
2095 kmemleak_ignore(log->ptr);
2096 break;
2097 case KMEMLEAK_SCAN_AREA:
2098 kmemleak_scan_area(log->ptr, log->size, GFP_KERNEL);
2099 break;
2100 case KMEMLEAK_NO_SCAN:
2101 kmemleak_no_scan(log->ptr);
2102 break;
2103 case KMEMLEAK_SET_EXCESS_REF:
2104 object_set_excess_ref((unsigned long)log->ptr,
2105 log->excess_ref);
2106 break;
2107 default:
2108 kmemleak_warn("Unknown early log operation: %d\n",
2109 log->op_type);
2110 }
2111
2112 if (kmemleak_warning) {
2113 print_log_trace(log);
2114 kmemleak_warning = 0;
2115 }
2116 }
2117}
2118
2119
2120
2121
2122static int __init kmemleak_late_init(void)
2123{
2124 struct dentry *dentry;
2125
2126 kmemleak_initialized = 1;
2127
2128 dentry = debugfs_create_file("kmemleak", 0644, NULL, NULL,
2129 &kmemleak_fops);
2130 if (!dentry)
2131 pr_warn("Failed to create the debugfs kmemleak file\n");
2132
2133 if (kmemleak_error) {
2134
2135
2136
2137
2138
2139
2140 schedule_work(&cleanup_work);
2141 return -ENOMEM;
2142 }
2143
2144 mutex_lock(&scan_mutex);
2145 start_scan_thread();
2146 mutex_unlock(&scan_mutex);
2147
2148 pr_info("Kernel memory leak detector initialized\n");
2149
2150 return 0;
2151}
2152late_initcall(kmemleak_late_init);
2153