Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Kernel Memory Management

ASecurity

Use when using kmalloc, vmalloc, or the page allocator, sizing kmalloc allocations, working with SLUB or the buddy allocator, or debugging memory zones and kernel OOM.

54 stars
0 votes
0 copies
0 views
Added 9/20/2026
ai-agentsbashnodeawsdebuggingbackend

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/20/2026

$npx -y skills add OutlineDriven/outline-driven-development --skill kernel-memory-management --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Kernel Memory Management?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Kernel Memory Management
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/outlinedriven-kernel-memory-management-outline-driven-development/badge)](https://www.skillsdirectory.com/skills/outlinedriven-kernel-memory-management-outline-driven-development)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: kernel-memory-management
description: 'Use when using kmalloc, vmalloc, or the page allocator, sizing kmalloc allocations, working with SLUB or the buddy allocator, or debugging memory zones and kernel OOM.'
---

# Kernel memory management

## Contract

| Field | Bound contract |
|---|---|
| Trigger | Allocating kernel memory in a driver or subsystem: `kmalloc` versus `vmalloc`, GFP flags, the buddy allocator, SLUB caches, DMA-coherent buffers, or OOM and slab corruption debugging. |
| Authority | Read-only. Writes nothing. Chat output only. No remote mutation. |
| Side effect | Returns allocation choices and debug commands. No source files are modified. |
| Done | The allocator choice per allocation site, the GFP flag per context, and a debug path for any reported memory symptom are delivered. |

## Inputs

1. Allocation sites (required): each buffer with its size, lifetime, and the context that allocates it.
2. Hardware requirement (optional): which buffers feed a DMA device, and the device's addressing limits.
3. Failure report (optional): OOM kills, slab corruption reports, or allocation failures under load.

## Procedure

1. Pick the allocator per site from the contiguity and size facts.

   ```
   Physically contiguous needed (device DMA)?
   ├── Yes: dma_alloc_coherent() or the CMA pool
   └── No
       ├── Small buffer: kmalloc / kzalloc
       ├── Large buffer, virtual contiguity is enough: vmalloc / vzalloc
       └── Whole pages with manual layout: alloc_pages() / __free_pages()
   ```

   `kmalloc` returns physically contiguous memory from SLUB caches; above the largest cache the call falls back to the page allocator, which still yields contiguous pages up to the allocator's order limit. Check the real limits per architecture and page size in `include/linux/slab.h` (`KMALLOC_MAX_CACHE_SIZE`, `KMALLOC_MAX_SIZE`) instead of quoting a fixed byte ceiling. `vmalloc` gets virtual contiguity from scattered pages and must not back device DMA without `dma_map_*`. Done when: every site names its allocator and the reason.
2. Match the GFP flag to the context.

   | GFP flag | Context |
   |---|---|
   | `GFP_KERNEL` | Process context, may sleep |
   | `GFP_ATOMIC` | IRQ or spinlock held; draws from smaller reserves |
   | `GFP_DMA` | Legacy 32-bit devices limited to the DMA zone |

   Done when: no sleeping allocation can run in an atomic context, and atomic allocations are small and rare.
3. Inspect SLUB state when allocation behavior needs evidence.

   ```bash
   cat /proc/slabinfo           # per-cache counts; root-readable
   cat /sys/kernel/slab/kmalloc-1k/object_size
   ```

   SLUB is the only in-tree SLAB allocator since kernel 6.12 removed the legacy SLAB backend; the kernel floor here (LTS 6.18, mainline 7.2) has no SLAB. Done when: the cache sizes behind a hot allocation path are known from the running system.
4. Use the page allocator for page-granular structures.

   ```c
   struct page *page = alloc_pages(GFP_KERNEL, order);
   void *addr = page_address(page);
   __free_pages(page, order);
   ```

   An `order` of n allocates 2^n pages. Zone selection (`ZONE_DMA`, `ZONE_NORMAL`, `ZONE_MOVABLE`) lives in `include/linux/mmzone.h`. Done when: the order and the free call match the allocation.
5. Handle NUMA deliberately on multi-node systems. `kmalloc` already prefers the local node; bind hot per-node structures with `alloc_pages_node()`. In user space, control placement with `numactl` or `mbind` for HPC paths. Done when: per-node placement is stated for each latency-critical buffer.
6. Debug the reported symptom from evidence.

   ```bash
   cat /proc/meminfo
   cat /proc/slabinfo
   dmesg | grep -i oom
   ```

   For use-after-free and corruption hunts, build with `CONFIG_SLUB_DEBUG` and `CONFIG_KASAN`. Route deeper work: `virtual-memory-paging-and-tlb` for paging mechanics, `mmio-and-bit-manipulation` for register-level access around mapped buffers, `dma-baremetal` for bare-metal DMA setup. Done when: the symptom maps to one row of the failure table.

## Failure and recovery

| Symptom | Cause | Recovery |
|---|---|---|
| Large `kmalloc` fails | Above the allocator's contiguous limit | Move to `vmalloc`, or redesign around pages; check `KMALLOC_MAX_SIZE`. |
| Device reads garbage from a buffer | `vmalloc` memory handed to DMA | Allocate with `dma_alloc_coherent`, or map with `dma_map_*`. |
| OOM killer fires | Unbounded cache growth | Cap pool sizes; use a shrinker. |
| Slab corruption report | Use-after-free or double free | Enable KASAN; audit `kfree` pairing. |
| Sleep warning under load | `GFP_KERNEL` in atomic context | Switch that site to `GFP_ATOMIC` or defer the work. |

## Output

The allocator choice with reasons per site; the GFP flag per context; the SLUB inspection evidence; the page-allocation orders; the NUMA placement plan; the debug transcript for the reported symptom; the routing to related skills.

Attribution

OutlineDrivenOutlineDriven
View sourceSee grades on GitHubMore from OutlineDriven →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →