aboutsummaryrefslogtreecommitdiffstats
path: root/mm
diff options
context:
space:
mode:
Diffstat (limited to 'mm')
-rw-r--r--mm/slub.c14
1 files changed, 13 insertions, 1 deletions
diff --git a/mm/slub.c b/mm/slub.c
index 8657ab838b8..97bb5b8d935 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -261,6 +261,18 @@ static inline void *get_freepointer(struct kmem_cache *s, void *object)
261 return *(void **)(object + s->offset); 261 return *(void **)(object + s->offset);
262} 262}
263 263
264static inline void *get_freepointer_safe(struct kmem_cache *s, void *object)
265{
266 void *p;
267
268#ifdef CONFIG_DEBUG_PAGEALLOC
269 probe_kernel_read(&p, (void **)(object + s->offset), sizeof(p));
270#else
271 p = get_freepointer(s, object);
272#endif
273 return p;
274}
275
264static inline void set_freepointer(struct kmem_cache *s, void *object, void *fp) 276static inline void set_freepointer(struct kmem_cache *s, void *object, void *fp)
265{ 277{
266 *(void **)(object + s->offset) = fp; 278 *(void **)(object + s->offset) = fp;
@@ -1933,7 +1945,7 @@ redo:
1933 if (unlikely(!this_cpu_cmpxchg_double( 1945 if (unlikely(!this_cpu_cmpxchg_double(
1934 s->cpu_slab->freelist, s->cpu_slab->tid, 1946 s->cpu_slab->freelist, s->cpu_slab->tid,
1935 object, tid, 1947 object, tid,
1936 get_freepointer(s, object), next_tid(tid)))) { 1948 get_freepointer_safe(s, object), next_tid(tid)))) {
1937 1949
1938 note_cmpxchg_failure("slab_alloc", s, tid); 1950 note_cmpxchg_failure("slab_alloc", s, tid);
1939 goto redo; 1951 goto redo;