From nobody Sat Jul 25 23:03:33 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 70430372075; Sat, 11 Jul 2026 18:04:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793061; cv=none; b=fMB2HKqzFtu1rRUArdtBKYv+Om88wQq1ZdFy3yGaNbhP9LB3vhz2I+55SRAjnm+XaiGgFQ/TU/4XMDdvgIifLHxNy8L5q3mRLQuWQFzwvhGvRsoCYEdVzmZTNOeF8q8EDIFEjWF58mAof5L7RRlZL9cCF2FkHPALKcrTFndDklw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793061; c=relaxed/simple; bh=uommVYjcgv1yUQymXHLWitvXUy8HlVyIq9wOy8obzmw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fDtAobO1eNQ9DG8kfQUbONZxhk53ObR7YbP2oUUaXcHjKACxq4a+QWzNv7+6sjAsHTrDUTpDJfrMA46Y+QVlJQmqpxxpmkgyM6uurEDLClsKWm3qXSEYMAVQwWZ+t3KaKqAuqoCzb87ZiUSSCh1e171ST2rAE2h0lJBHBfG2QoI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ZM7JMyvK; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ZM7JMyvK" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D3D021F000E9; Sat, 11 Jul 2026 18:04:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783793060; bh=Q9KjTQrAluw9j+QP6j3O8xbCeroVnCVq06v65dUktLw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ZM7JMyvKDar39MxAxv9gEXqrrpdcMhCd0EaxaHFtTiOxwPWfh9E8aGiJ/Zw1mE65n emJa9iHLBdDxaY3ZQwrs26X/ipMp+fiCY8QS9w56DtrrZVpFwjofAUN+FpytNFDXnp aGklVVK7h5VtCqPemCJ5Jxgp1ygBuhPifJhNsvkeERtbspZeclMmU5W4X+bdLREpIm KBAsjy6by68i1W6n5VtA1+8Y3eYoT8wmov3iLMtQX0pxutZo5+nTB8RAclaEsHZpK0 smYc+dxIOBy7zZOSiUNAwQLPQ+QmlH6kliZeYGU7XpMSvAs3Fw/AloPX8VwwjInK9a BVFTK/0Rdbbsg== From: SJ Park To: Cc: SJ Park , "# 6 . 10 . x" , Andrew Morton , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH 1/5] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Date: Sat, 11 Jul 2026 11:04:04 -0700 Message-ID: <20260711180409.82093-2-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260711180409.82093-1-sj@kernel.org> References: <20260711180409.82093-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Due to online parameter update like events, the number of DAMON regions could be higher than the user-set upper limit. kdamond_merge_regions() repeats merge regions until the number meets the limit, while doubling the merge threshold up to the theoretical maximum threshold. It is tried only up to the theoretical maximum threshold because even the aggressive merging can fail from reducing the number of regions under the user-defined upper limit. For example, there could be many user-defined non-contiguous regions that cannot be merged. The threshold based loop break condition is evaluated by comparing the threshold for the next merging try against the theoretical maximum threshold. If max_thres is larger than UINT_MAX / 2, doubling the threshold could make it overflow, and bypass the loop break condition. In the case, if the number of regions cannot be reduced under the upper limit like explained above, the loop will run infinitely. Prevent the case by doing the break condition check before doubling the threshold. Also, prevent the threshold exceeding the maximum threshold, as it could overflow and apply the wrong merge threshold. This issue is unlikely to occur in real world, since having the max_thres higher than UINT_MAX / 2 require unrealistically large aggregation intervals compared to the sampling interval. Also, it requires an unrealistically large number of uncontiguous regions setup. Nonetheless, the consequence is bad and the fix is simple. The issue was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260709145425.96247-1-sj@kernel.org Fixes: 310d6c15e910 ("mm/damon/core: merge regions aggressively when max_nr= _regions is unmet") Cc: # 6.10.x Signed-off-by: SJ Park --- mm/damon/core.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/mm/damon/core.c b/mm/damon/core.c index 6c4215cc809ec..603b102ff80f9 100644 --- a/mm/damon/core.c +++ b/mm/damon/core.c @@ -3372,7 +3372,7 @@ static void kdamond_merge_regions(struct damon_ctx *c= , unsigned int threshold, =20 max_thres =3D c->attrs.aggr_interval / (c->attrs.sample_interval ? c->attrs.sample_interval : 1); - do { + while (true) { nr_regions =3D 0; damon_for_each_target(t, c) { damon_merge_regions_of(t, threshold, sz_limit, c, @@ -3380,9 +3380,14 @@ static void kdamond_merge_regions(struct damon_ctx *= c, unsigned int threshold, nr_regions +=3D damon_nr_regions(t); } count_age =3D false; - threshold =3D max(1, threshold * 2); - } while (nr_regions > c->attrs.max_nr_regions && - threshold / 2 < max_thres); + if (nr_regions <=3D c->attrs.max_nr_regions || + max_thres <=3D threshold) + break; + if (threshold < max_thres / 2) + threshold =3D max(1, threshold * 2); + else + threshold =3D max_thres; + } } =20 #ifdef CONFIG_DAMON_DEBUG_SANITY --=20 2.47.3 From nobody Sat Jul 25 23:03:33 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BB8A23A9861; Sat, 11 Jul 2026 18:04:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793061; cv=none; b=QsNU+5Oq4MpNxnqaBDb2hUYMHHlVC4NS4RNS5o1k8DSi83SJlVi9LKgjE7wViVZkpmF+nu/+HZAnxWVoUTZKprhky42kpn1zZHq6+itJgi4J1xKhGHW+g7jSxxOULauXQlNU9revw3+RQ/eXyi/hXdkHp16/r3La/kf0ofH+TWc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793061; c=relaxed/simple; bh=/PEZNLM6W5X3AYEfC3MrlYbKHoYFP903LT2sqctGZic=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=hl+eyTqtJj7iLaLr+yWY5TsihIw/hglHHcV4ut9mBoE7deUHc+DJu4Ig9VdRskK8vjvixvv6O/R3RdAc/mJNS/900yy/bw6xZXi5luAVNXUi7tCZqZJopSCXoA6begU04qR48ry1qjvfxo/L8DAB1cFMV+03kIIqRNcj4jdViHI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=NlR9W1Qc; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="NlR9W1Qc" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3660C1F00A3D; Sat, 11 Jul 2026 18:04:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783793060; bh=pbj4M0PCAFhChb2r0bNN0cHfe6XonAYY07ZTVFUWh04=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=NlR9W1Qcz8xV7IqYh9TId8gWx/a84Z1oJt38FZGx/ZhwBtOZqmdUG6YY/SGybTLvO +QOkqHi6KptogQW+p04qBCVT9NPA0K6Jcq1iXiT7XsoVhiiDqhnqtGWkbzhczFVbTL nlilupHYRytu7Ms8aO7Ixi2kJgGhoKHLIheM+zE09nWqJRBSLcilBKDrHnmjKFkku8 zj/O+mYJl6D11ahUh871RSWcAMMERFrh0N+7s8K/CpCshntF3sgJM4eZxueJTlSkUM EAlEqDPphJYMdRFGCt4QJp1/v/tqqjByAck20wRZRkf90wzCGzY3eg2EpKraSriHWX Xf2nccWV8oHOQ== From: SJ Park To: Cc: SJ Park , "# 5 . 15 . x" , Andrew Morton , Brendan Higgins , David Gow , SeongJae Park , damon@lists.linux.dev, kunit-dev@googlegroups.com, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH 2/5] mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() Date: Sat, 11 Jul 2026 11:04:05 -0700 Message-ID: <20260711180409.82093-3-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260711180409.82093-1-sj@kernel.org> References: <20260711180409.82093-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" KUNIT_EXPECT_EQ() does not abort the execution of test code when the expectation is not met. But damon_test_merge_regions_of() code after its initial KUNIT_EXPECT_EQ() call assumes the expectation is met. It does a per-region test with a hard-coded number of regions that is correct only if the expectation was met. As a result, __nth_region_of() could return NULL, and the test code can dereference NULL pointers. Fix the issue by catching the expectation failure and skip the per-region tests. The user impact on realistic setups should be negligible, as it is a unit test. The issue was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260710144937.26981-1-sj@kernel.org Fixes: 17ccae8bb5c9 ("mm/damon: add kunit tests") Cc: # 5.15.x Signed-off-by: SJ Park --- mm/damon/tests/core-kunit.h | 3 +++ 1 file changed, 3 insertions(+) diff --git a/mm/damon/tests/core-kunit.h b/mm/damon/tests/core-kunit.h index 68d30648c612e..fb882a0602ff9 100644 --- a/mm/damon/tests/core-kunit.h +++ b/mm/damon/tests/core-kunit.h @@ -260,11 +260,14 @@ static void damon_test_merge_regions_of(struct kunit = *test) damon_merge_regions_of(t, 9, 9999, ctx, true); /* 0-112, 114-130, 130-156, 156-170, 170-230, 230-10170 */ KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 6u); + if (damon_nr_regions(t) !=3D 6) + goto out; for (i =3D 0; i < 6; i++) { r =3D __nth_region_of(t, i); KUNIT_EXPECT_EQ(test, r->ar.start, saddrs[i]); KUNIT_EXPECT_EQ(test, r->ar.end, eaddrs[i]); } +out: damon_free_target(t); damon_destroy_ctx(ctx); } --=20 2.47.3 From nobody Sat Jul 25 23:03:33 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 733583CF203; Sat, 11 Jul 2026 18:04:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793062; cv=none; b=cw9II16Aj4XWMVA8LwoAp+WjpqX/fJrzvrEwxZoxi6E7ZU9RdCgLhroiJQb1Pg+aTdM8O7IcYVj56Uyj6ZDj9YOxooxjR8Yx+2cferpznoUBPompF65sT74QIlF4MJA3ASPPyGluH6UuVpFYZ9NhfNfqvCzOfWUuvb3k8L6HmNU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793062; c=relaxed/simple; bh=eShbpgLz2NbIysbCSJJgbBQ51wiA+Nyw8yXGHdcRa9M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gqm+lOg8iXbjid43ww8iolL7+5i0Qg8wR0kPxmKMAZdxDErFrydb7zKenXsn2WqnggXmXzLL6UeQFYDxSMjMuFY4DdgL4MnxJ7huacWBiwAEmJHsm2rPD7TvAOk5myvBVeE6H501bGa7hF5OVfNrrZ3XGBIPJBa6+GfvB99TwDk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=op3h4Blz; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="op3h4Blz" Received: by smtp.kernel.org (Postfix) with ESMTPSA id BC5FC1F00A3E; Sat, 11 Jul 2026 18:04:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783793061; bh=Y5xW2GMWQ2fJulemhF10bJTV6JcOyhTF3brjsm/0yqc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=op3h4BlzzWxIRL9mMkFVjIL13nQaru6+YNQBVr6INCZjs+9GzxN/GXZHy5xhq8qb4 KmOGyQomZpWjvKKZICQR4wvSxurZaj9z4vJIF3lM7OSfHTEK+r1ReYAeCS9nkAvapC +aDBbobBMNq3Ctp/B98N41tFowCT/zJng8zVEH3CALzvf0DY3BDxL+SXsw2TlmVaA9 jfalGPF8MN0H5XO2B96UqZlTg+yvraVNioWHxDFHXApcS3c7f4ciur+GF2U+dGFPr+ ogxUThR+9T77WwaMkv3t7gkUSyOTDqQYGfUqhQ1f//1YcnzMREHk3PWV80X0RuWOQT ohQ7Aarudbv3g== From: SJ Park To: Cc: SJ Park , "# 5 . 15 . x" , Andrew Morton , Fernand Sieber , Leonard Foerster , SeongJae Park , Shakeel Butt , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH 3/5] mm/damon/vaddr: drop last same folio access check optimization Date: Sat, 11 Jul 2026 11:04:06 -0700 Message-ID: <20260711180409.82093-4-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260711180409.82093-1-sj@kernel.org> References: <20260711180409.82093-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The optimization can race when multiple kdamonds are running. Meanwhile, the impact of the optimization is quite doubtful. Just remove it. The user impact of the issue should be quite trivial. After all, the race can happen only when the user intentionally setup DAMON in the way. Even if it happens, it would be rare and only degrade the best-effort monitoring results. No critical consequences like kernel panic or memory corruption happen. The race possibility was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org Fixes: 3f49584b262c ("mm/damon: implement primitives for the virtual memory= address spaces") Cc: # 5.15.x Signed-off-by: SJ Park --- mm/damon/vaddr.c | 26 ++++---------------------- 1 file changed, 4 insertions(+), 22 deletions(-) diff --git a/mm/damon/vaddr.c b/mm/damon/vaddr.c index d10b8042adb5b..16fe210d2042a 100644 --- a/mm/damon/vaddr.c +++ b/mm/damon/vaddr.c @@ -383,8 +383,6 @@ static void damon_va_prepare_access_checks(struct damon= _ctx *ctx) } =20 struct damon_young_walk_private { - /* size of the folio for the access checked virtual memory address */ - unsigned long *folio_sz; bool young; }; =20 @@ -411,7 +409,6 @@ static int damon_young_pmd_entry(pmd_t *pmd, unsigned l= ong addr, mmu_notifier_test_young(walk->mm, addr)) priv->young =3D true; - *priv->folio_sz =3D HPAGE_PMD_SIZE; huge_out: spin_unlock(ptl); return 0; @@ -430,7 +427,6 @@ static int damon_young_pmd_entry(pmd_t *pmd, unsigned l= ong addr, if (pte_young(ptent) || !folio_test_idle(folio) || mmu_notifier_test_young(walk->mm, addr)) priv->young =3D true; - *priv->folio_sz =3D folio_size(folio); out: pte_unmap_unlock(pte, ptl); return 0; @@ -458,7 +454,6 @@ static int damon_young_hugetlb_entry(pte_t *pte, unsign= ed long hmask, if (pte_young(entry) || !folio_test_idle(folio) || mmu_notifier_test_young(walk->mm, addr)) priv->young =3D true; - *priv->folio_sz =3D huge_page_size(h); =20 folio_put(folio); =20 @@ -470,11 +465,9 @@ static int damon_young_hugetlb_entry(pte_t *pte, unsig= ned long hmask, #define damon_young_hugetlb_entry NULL #endif /* CONFIG_HUGETLB_PAGE */ =20 -static bool damon_va_young(struct mm_struct *mm, unsigned long addr, - unsigned long *folio_sz) +static bool damon_va_young(struct mm_struct *mm, unsigned long addr) { struct damon_young_walk_private arg =3D { - .folio_sz =3D folio_sz, .young =3D false, }; =20 @@ -496,26 +489,15 @@ static bool damon_va_young(struct mm_struct *mm, unsi= gned long addr, static void __damon_va_check_access(struct mm_struct *mm, struct damon_region *r, bool same_target) { - static unsigned long last_addr; - static unsigned long last_folio_sz =3D PAGE_SIZE; - static bool last_accessed; + bool accessed; =20 if (!mm) { damon_update_region_access_rate(r, false); return; } =20 - /* If the region is in the last checked page, reuse the result */ - if (same_target && (ALIGN_DOWN(last_addr, last_folio_sz) =3D=3D - ALIGN_DOWN(r->sampling_addr, last_folio_sz))) { - damon_update_region_access_rate(r, last_accessed); - return; - } - - last_accessed =3D damon_va_young(mm, r->sampling_addr, &last_folio_sz); - damon_update_region_access_rate(r, last_accessed); - - last_addr =3D r->sampling_addr; + accessed =3D damon_va_young(mm, r->sampling_addr); + damon_update_region_access_rate(r, accessed); } =20 static unsigned int damon_va_check_accesses(struct damon_ctx *ctx) --=20 2.47.3 From nobody Sat Jul 25 23:03:33 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8BEC83CF210; Sat, 11 Jul 2026 18:04:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793062; cv=none; b=PmGSHd4lcCSWXukQDLxZDokPB2/5O6xPf6XUENyCZstl89zs/vj8zajV8F3iwgYnze7qVzSMKdbQ+y/xQT2Gy1UFVBkk8huJn3+qovvb8uEUbKI27YErTk/tqlbfzg0SmaiuIuGAOwrSkKTfdMo4fgBJRhdYQlRinAB8qpJrg54= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793062; c=relaxed/simple; bh=5ScejZ7WR20mP7M32rQjyj8bSoc3hvLkckL0qcqy7ww=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HQTIpp2ZqMqdgOq2JD/6Y5VjyWzj4LpHC5MTmX434b78olBVf4DTR7K2rfdnAfLmSfORxWfWsy2PjZ4WINkFeoX0UzXa/cIs7ANkKA0nmaIR4CjYi/FAc+R3S1LbE3gT2TktF6Wt7DWGT0nUWqh7FBZxxxDDpn5aZJ2teSfWNS0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=MulPV6Al; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="MulPV6Al" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 40E7F1F00A3F; Sat, 11 Jul 2026 18:04:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783793061; bh=MTFa+hpzXfcfyF1zP3rvNz2Fhu2Cffg36gE6sioOaYQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MulPV6Al7PdRkuMvExn0i9dIE8w1T9TdjXcHiU7mSLmr/ml12UAOwG/CZB/qATXyf md+aw7JdFjco/wyrSPmUgbVnYVIWdagWPMgaEfYZH7g00f7zpaGKkeqC0yN5cBsRPy gyiux1YnfWFwgb27qLWugO7JiIiU1fafzNMWASxfjhqEibw1QHZ0Y852PNflQhjisA SizWI8fULFQ71nSX7XRNxjg5h6laM3HKdaG9E/i4esoKomDjNXO8/7KP2qAutjSFZx 64lvCUtBI4imnyFEDZUkaGEGvdN+oPYnCL3wVMgmxqeiRhPXxWmFw8SilDe3O2WfBn eKOttvdn0SAOQ== From: SJ Park To: Cc: SJ Park , "# 5 . 16 . x" , Andrew Morton , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH 4/5] mm/damon/paddr: drop last same folio access check reuse optimization Date: Sat, 11 Jul 2026 11:04:07 -0700 Message-ID: <20260711180409.82093-5-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260711180409.82093-1-sj@kernel.org> References: <20260711180409.82093-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" It can race when multiple kdamonds are being used. The problem from the race is doubtful, but the gain from the optimization is also doubtful. Simply drop the optimization in favor of code simplicity. The user impact is doubtfully trivial. After all, this kind of interference can happen only by intentional user setup. Even if it happens, it will be rare, and the consequence is degradation of the best-effort monitoring results. No critical consequences like kernel panic or memory corruption happen. The race was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org Fixes: a28397beb55b ("mm/damon: implement primitives for physical address s= pace monitoring") Cc: # 5.16.x Signed-off-by: SJ Park --- mm/damon/paddr.c | 20 ++++---------------- 1 file changed, 4 insertions(+), 16 deletions(-) diff --git a/mm/damon/paddr.c b/mm/damon/paddr.c index b85f88a7a38f4..e4f98d67461f5 100644 --- a/mm/damon/paddr.c +++ b/mm/damon/paddr.c @@ -65,7 +65,7 @@ static void damon_pa_prepare_access_checks(struct damon_c= tx *ctx) } } =20 -static bool damon_pa_young(phys_addr_t paddr, unsigned long *folio_sz) +static bool damon_pa_young(phys_addr_t paddr) { struct folio *folio =3D damon_get_folio(PHYS_PFN(paddr)); bool accessed; @@ -74,7 +74,6 @@ static bool damon_pa_young(phys_addr_t paddr, unsigned lo= ng *folio_sz) return false; =20 accessed =3D damon_folio_young(folio); - *folio_sz =3D folio_size(folio); folio_put(folio); return accessed; } @@ -82,23 +81,12 @@ static bool damon_pa_young(phys_addr_t paddr, unsigned = long *folio_sz) static void __damon_pa_check_access(struct damon_region *r, unsigned long addr_unit) { - static phys_addr_t last_addr; - static unsigned long last_folio_sz =3D PAGE_SIZE; - static bool last_accessed; + bool accessed; phys_addr_t sampling_addr =3D damon_pa_phys_addr( r->sampling_addr, addr_unit); =20 - /* If the region is in the last checked page, reuse the result */ - if (ALIGN_DOWN(last_addr, last_folio_sz) =3D=3D - ALIGN_DOWN(sampling_addr, last_folio_sz)) { - damon_update_region_access_rate(r, last_accessed); - return; - } - - last_accessed =3D damon_pa_young(sampling_addr, &last_folio_sz); - damon_update_region_access_rate(r, last_accessed); - - last_addr =3D sampling_addr; + accessed =3D damon_pa_young(sampling_addr); + damon_update_region_access_rate(r, accessed); } =20 static unsigned int damon_pa_check_accesses(struct damon_ctx *ctx) --=20 2.47.3 From nobody Sat Jul 25 23:03:33 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DCE663CF96B; Sat, 11 Jul 2026 18:04:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793063; cv=none; b=P1Vj7zWBAHqOnvmPh2UV8X7nvL52yofGjZWrbIZj9S44PO+AHnw34yDJVVyw4Qsx5ieoW91XoVACYE62n/uzZb8L9Y6drAfBitzfoWVtp5A/FqLIoo16oDj7FiFIojY7/2m2litYW1F40olLkeiWNx2rpiR0IEk0LFCfl5TRElI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783793063; c=relaxed/simple; bh=nt1m4yOHpUkfhmuPI5sfQNBML1ejUt2LDcM7VHyWuzk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=LK9dJtV2sBa4SB8IFdEy4P/US8IFZVXx1ip5Mtzn5G7Sh7Y1SPf5pJzpSlI1X5KOzshSd6fza2f5xcL0uncusPmM4EwaW3Gl7gFmqvUJXup6iVtTMCEkc4Uc+z4uDipEbOGD/OAXG9I/FMgCsFvZq1Ll2/JYYRvig8Mf7/d9ors= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=eq8LOAv3; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="eq8LOAv3" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 999F91F00A3A; Sat, 11 Jul 2026 18:04:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783793061; bh=hhmDCI+ot7IL3VsT3pLzYBJmbk4njLZd345nGTc/fNs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=eq8LOAv38/JT//HvNVNFuX9mQYVns/QjBaRg4lFD6H13iiyHwdAqqGAHzowFBfpYp TQ845vSB2U/vzHnithCWeTxZHU2L4LlQ+w4ohRPsP+z26/uQkgXKJqxWwF7prLpa7F v8OfWijkA7lDe0BKpuxMaLmjq7HPpxf92RN3DuqjlxcCn3NT+Gu63ScjWp2C/hdYEC BJjrA9WqF1RvbnR5DP1QYEhLqbnKaftOrbc1Bb/x/+npMXPDZCH0OFnE1Yr2GL2PBB Dz3LKLleFAI+dUaGDHW7S0oF1Y/p+03h9hzlCS7svr+6fURFqcY4prI2uxh8l5Thdc Ihs5v09i67MxA== From: SJ Park To: Cc: SJ Park , Andrew Morton , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH 5/5] mm/damon/sysfs: read ops_id only once Date: Sat, 11 Jul 2026 11:04:08 -0700 Message-ID: <20260711180409.82093-6-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260711180409.82093-1-sj@kernel.org> References: <20260711180409.82093-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" damon_sysfs_apply_inputs() reads ops_id twice. It could race with ops_id_store(). As a result, the min_region_sz could wrongly be set up. Read it once. The user impact is trivial. Sane users ain't update the parameter in parallel. Even if it happens, only monitoring itself runs differently than expected. No critical consequences like kernel panic or memory corruption happen. The issue was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260703172417.95426-1-sj@kernel.org Signed-off-by: SJ Park --- mm/damon/sysfs.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/mm/damon/sysfs.c b/mm/damon/sysfs.c index b5fe036f78015..60a1a9e4ada34 100644 --- a/mm/damon/sysfs.c +++ b/mm/damon/sysfs.c @@ -2094,14 +2094,16 @@ static inline bool damon_sysfs_kdamond_running( static int damon_sysfs_apply_inputs(struct damon_ctx *ctx, struct damon_sysfs_context *sys_ctx) { + enum damon_ops_id ops_id; int err; =20 - err =3D damon_select_ops(ctx, sys_ctx->ops_id); + ops_id =3D READ_ONCE(sys_ctx->ops_id); + err =3D damon_select_ops(ctx, ops_id); if (err) return err; ctx->addr_unit =3D sys_ctx->addr_unit; /* addr_unit is respected by only DAMON_OPS_PADDR */ - if (sys_ctx->ops_id =3D=3D DAMON_OPS_PADDR) + if (ops_id =3D=3D DAMON_OPS_PADDR) ctx->min_region_sz =3D max( DAMON_MIN_REGION_SZ / sys_ctx->addr_unit, 1); ctx->pause =3D sys_ctx->pause; --=20 2.47.3