[PATCH 6.1.y 6.6.y] netfilter: nft_set_pipapo: account mapping table allocation

Karl Mehltretter <[email protected]>
Newsgroups gmane.linux.kernel.stable,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network,gmane.linux.kernel
Message-ID <[email protected]>
[ Upstream commit 69e687cea79fc99a17dfb0116c8644b9391b915e ]

The pipapo set backend data structure is one of the ruleset objects
that upstream changed to use GFP_KERNEL_ACCOUNT for memory accounting.

The 6.1.y and 6.6.y adaptations changed the other pipapo allocations,
but omitted the mapping table allocation in pipapo_realloc_mt() because
that helper does not exist in these branches.  The equivalent allocation
is in pipapo_resize() and still uses GFP_KERNEL, so the persistent mapping
table is not charged to the allocating memory cgroup.

Update this allocation to use GFP_KERNEL_ACCOUNT.

Fixes: a0bb39980635 ("netfilter: nf_tables: missing objects with no memcg accounting")
Fixes: 1c4f72fa9699 ("netfilter: nf_tables: missing objects with no memcg accounting")
Signed-off-by: Karl Mehltretter <[email protected]>
---
This patch is based on 6.6.155 and applies unchanged to the tested 6.1.y
tip.  The test configurations and full serial logs are retained in the
audit dossier.

A/B tests with a 32,768-element two-field concatenation set left two
262,144-byte mapping tables.  The fixed kernels charged approximately
512 KiB more kernel memory to the child cgroup:
  6.1.186: +524,288 bytes
  6.6.155: +516,096 bytes

The two-page difference on 6.6.y is within memory.stat measurement
variation.  Ruleset loading and element lookup succeeded before and after
the change on both branches.

Tested on:
  6.1.y d64a499eea6b62b5121beceed9e8a1f57b00d863 (Linux 6.1.186)
  6.6.y a4a971135a2ff64382ae4235b3ae60503bb1036a (Linux 6.6.155)

 net/netfilter/nft_set_pipapo.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/netfilter/nft_set_pipapo.c b/net/netfilter/nft_set_pipapo.c
index 7c8d28a031ad5..8ba76eea3eb18 100644
--- a/net/netfilter/nft_set_pipapo.c
+++ b/net/netfilter/nft_set_pipapo.c
@@ -705,7 +705,7 @@ static int pipapo_resize(struct nft_pipapo_field *f, int old_rules, int rules)
 		return -ENOMEM;
 	}
 
-	new_mt = kvmalloc(rules * sizeof(*new_mt), GFP_KERNEL);
+	new_mt = kvmalloc(rules * sizeof(*new_mt), GFP_KERNEL_ACCOUNT);
 	if (!new_mt) {
 		kvfree(new_lt);
 		return -ENOMEM;
-- 
2.39.5 (Apple Git-154)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.