3/5

slab: handle ERR_PTR values in kfree and hardened usercopy

Passing an ERR_PTR to kfree() currently reaches virt_to_page() and may fault. Warn and return instead, leaving the bad caller visible without using the pointer as allocator metadata. Also reject ERR_