Skip to content

allocations.ql: match kmalloc calls by attribute, not name#408

Open
artmetla wants to merge 1 commit into
masterfrom
allocations-update-for-6.X-kernels
Open

allocations.ql: match kmalloc calls by attribute, not name#408
artmetla wants to merge 1 commit into
masterfrom
allocations-update-for-6.X-kernels

Conversation

@artmetla

Copy link
Copy Markdown
Collaborator

Kernel's alloc-profiling rework renamed kmalloc/kzalloc/kvmalloc to *_noprof, breaking the name-based match. Identify calls via the __alloc_size attribute + gfp_t parameter instead, so the same query works on both old-name (e.g. 6.1) and *_noprof (6.12+) kernels, and survives future renames the same way.

Also:

  • Drop the isAffectedByMacro() filter on the size arg. Every *_noprof call is now macro-wrapped (alloc_hooks()), so this filter would exclude every row; it also excluded struct_size()/array_size() allocations even before the rework, which is the flexible-array pattern this query is meant to find.
  • Fix getStruct() producing duplicate rows when its two resolution branches (sizeof-based and pointer-cast fallback) both matched.

Kernel's alloc-profiling rework renamed kmalloc/kzalloc/kvmalloc to
*_noprof, breaking the name-based match. Identify calls via the
__alloc_size attribute + gfp_t parameter instead, so the same query
works on both old-name (e.g. 6.1) and *_noprof (6.12+) kernels, and
survives future renames the same way.

Also:
- Drop the isAffectedByMacro() filter on the size arg. Every *_noprof
  call is now macro-wrapped (alloc_hooks()), so this filter would
  exclude every row; it also excluded struct_size()/array_size()
  allocations even before the rework, which is the flexible-array
  pattern this query is meant to find.
- Fix getStruct() producing duplicate rows when its two resolution
  branches (sizeof-based and pointer-cast fallback) both matched.
@artmetla
artmetla requested a review from JordyZomer July 16, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant