From nobody Sat Jul 25 22:31:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5932A261B8A; Sun, 12 Jul 2026 17:03:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875820; cv=none; b=O8f3R8Zg/XGXO/IW0R2/LJshbLwed+bnI4dI6Ng55aQfDjOiGS//Xc/bOWiRvUpvJpIL55ZRUYKLlRrpjcB4V28+s7/Hl1pTTajNUtNsECR/jXdvkFpN05r660k/0Xj5CrXRwU91hd/Z6E8yDYKPb1fUxnUAyBfC2l/caqU7Vaw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875820; c=relaxed/simple; bh=UvG3w3Q38JCvdgaSsgN+1fOmYYd1A7xQdvoEpH7rRxM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=LIBogW3vLA0sduXA9gHurt3Zfy//T9hlV2oZ85KfHP7Lnv/mN+eWkdszydqC161CpcFuhR7aScyW/GPen3/3lKa1l373UGnZQ+x23dzOsIJxmO5oijv86BPiIh64P7ZNd+waU+OU0oacYthIuNAITEANdg4aZdCPrw3svtxiK1U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=GX/i+5+c; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="GX/i+5+c" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E5E4E1F00A3D; Sun, 12 Jul 2026 17:03:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783875819; bh=yFIQucAr4vFmOrW82XY64T561EcF6nkSnWV7DSiSLJg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GX/i+5+coUrveNcvaY0xrsZhuVmtLA73CcoyMgGHIOeUe/2ZqEWjBRanPSO0/jWo3 hZXs98sRQ5y6Z/l7LJLzomKm6ll1TUyBUHzWgkM7q14s2RJ6TOP8Q4EBEL8cb44sya 5oDv87oF7WZfwYblAmUApiym4/OeEpy2nrZwVTmJz97NhAF2m7f3AoEvMRKJf87btW APaptSK4lju2hZNVR2ZfI55SEZ+I7PAGQa4GUS0kiEAifPyUG0gfYefAUsPXNuG5S+ bwIjD6aaNbxBciAczMQ3Uz2wEIn01AmfPXvPT21LRmBoXnc/2Tkv530H41GKV3lo2n FdNYfWLdVvtbg== From: SJ Park To: Cc: SJ Park , stable@vger.kernel.org, Andrew Morton , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH v1.1 1/5] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Date: Sun, 12 Jul 2026 10:03:23 -0700 Message-ID: <20260712170328.91144-2-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260712170328.91144-1-sj@kernel.org> References: <20260712170328.91144-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Due to online parameter update like events, the number of DAMON regions could be higher than the user-set upper limit. kdamond_merge_regions() repeats merge regions until the number meets the limit, while doubling the merge threshold up to the theoretical maximum threshold. It is tried only up to the theoretical maximum threshold because even the aggressive merging can fail from reducing the number of regions under the user-defined upper limit. For example, there could be many user-defined non-contiguous regions that cannot be merged. The threshold based loop break condition is evaluated by comparing the threshold for the next merging try against the theoretical maximum threshold. If max_thres is larger than UINT_MAX / 2, doubling the threshold could make it overflow, and bypass the loop break condition. In the case, if the number of regions cannot be reduced under the upper limit like explained above, the loop will run infinitely. Prevent the case by doing the break condition check before doubling the threshold. Also, prevent the threshold exceeding the maximum threshold, as it could overflow and apply the wrong merge threshold. This issue is unlikely to occur in real world, since having the max_thres higher than UINT_MAX / 2 require unrealistically large aggregation intervals compared to the sampling interval. Also, it requires an unrealistically large number of uncontiguous regions setup. Nonetheless, the consequence is bad and the fix is simple. The issue was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260709145425.96247-1-sj@kernel.org Fixes: 310d6c15e910 ("mm/damon/core: merge regions aggressively when max_nr= _regions is unmet") Cc: # 6.10.x Signed-off-by: SJ Park --- mm/damon/core.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/mm/damon/core.c b/mm/damon/core.c index 806a67d02a6e9..f3b6a46fdaabd 100644 --- a/mm/damon/core.c +++ b/mm/damon/core.c @@ -3369,15 +3369,20 @@ static void kdamond_merge_regions(struct damon_ctx = *c, unsigned int threshold, =20 max_thres =3D c->attrs.aggr_interval / (c->attrs.sample_interval ? c->attrs.sample_interval : 1); - do { + while (true) { nr_regions =3D 0; damon_for_each_target(t, c) { damon_merge_regions_of(t, threshold, sz_limit, c); nr_regions +=3D damon_nr_regions(t); } - threshold =3D max(1, threshold * 2); - } while (nr_regions > c->attrs.max_nr_regions && - threshold / 2 < max_thres); + if (nr_regions <=3D c->attrs.max_nr_regions || + max_thres <=3D threshold) + break; + if (threshold < max_thres / 2) + threshold =3D max(1, threshold * 2); + else + threshold =3D max_thres; + } } =20 #ifdef CONFIG_DAMON_DEBUG_SANITY --=20 2.47.3 From nobody Sat Jul 25 22:31:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 40E9F340410; Sun, 12 Jul 2026 17:03:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875821; cv=none; b=p3gatf67QZGQbozk+xMMcbHn0dSZldLWaruzCmRcww3ons7yfqjVJ5eJLr7AtO7cxO0v2pUYNQDEwSanL1E/NogkBTlXRgayMjbfD2iXE8fvzo0N29J8C8YEX7YuD9lV3437AhIIJ2xHoF/aKEoFDzrw6CuXnPkeBxIbuhERBPQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875821; c=relaxed/simple; bh=2YTUi5fssLwguc0tdmj+L1Qs0tTe4BqhfdbB6oOiClA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CzE3/MA1h92WFN8hYJL8LglyNkrt16HBgnYdbauyUC/b352wkcoZmczHO4shXqw5y8EHR1E4VnTEFMx8+PdQdM7SPAepcxx/dIJsNvukDnqysYkX9LPoA0oDlf4Iub+MO3URuwASzcOjQp/o3EV5tiGW7UCf8hz4A1AYIs5T8ro= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=mjT+7kGG; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="mjT+7kGG" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4FC761F00A3E; Sun, 12 Jul 2026 17:03:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783875819; bh=SKLq7ZuoHq2BFm176pu4DfNEYfPU8F0EbpgzHa8ZXlA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=mjT+7kGGAZYWj8JiuahXfYm2MBh7kCuE9DE+qZXwgVLnf66mD8V7l5743EVqT/ZB+ px2Kktm5XGebVXuPIEqzhuGDyAxeou/Yg5M3DlHa+j3Fh1/kpD0DD6txtSqp5RfQ/y lcFGHl2+XcewCNUxbjxgMnH9R0lVWko4XgbBORuqZ8AbCbSt3DFRDv8l8RRKBcrZQu 7eMhcaAEkzAYqX+zbo0qSI7Cf9AVEST+FwnpkEYdutt7uaJ2VpVjONtoiPhR2ZeCgT yXnTXCwj6RviPh1VazChP3DAGy28Q8nkBEV+kuYR+vDUeAfMfNytJrGMvgT14wTs20 D6KhmXJ2YEGMQ== From: SJ Park To: Cc: SJ Park , stable@vger.kernel.org, Andrew Morton , Brendan Higgins , David Gow , SeongJae Park , damon@lists.linux.dev, kunit-dev@googlegroups.com, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH v1.1 2/5] mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() Date: Sun, 12 Jul 2026 10:03:24 -0700 Message-ID: <20260712170328.91144-3-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260712170328.91144-1-sj@kernel.org> References: <20260712170328.91144-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" KUNIT_EXPECT_EQ() does not abort the execution of test code when the expectation is not met. But damon_test_merge_regions_of() code after its initial KUNIT_EXPECT_EQ() call assumes the expectation is met. It does a per-region test with a hard-coded number of regions that is correct only if the expectation was met. As a result, __nth_region_of() could return NULL, and the test code can dereference NULL pointers. Fix the issue by catching the expectation failure and skip the per-region tests. The user impact on realistic setups should be negligible, as it is a unit test. The issue was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260710144937.26981-1-sj@kernel.org Fixes: 17ccae8bb5c9 ("mm/damon: add kunit tests") Cc: # 5.15.x Signed-off-by: SJ Park --- mm/damon/tests/core-kunit.h | 3 +++ 1 file changed, 3 insertions(+) diff --git a/mm/damon/tests/core-kunit.h b/mm/damon/tests/core-kunit.h index 6ad73559dd8ea..a99363720e677 100644 --- a/mm/damon/tests/core-kunit.h +++ b/mm/damon/tests/core-kunit.h @@ -260,11 +260,14 @@ static void damon_test_merge_regions_of(struct kunit = *test) damon_merge_regions_of(t, 9, 9999, ctx); /* 0-112, 114-130, 130-156, 156-170, 170-230, 230-10170 */ KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 6u); + if (damon_nr_regions(t) !=3D 6) + goto out; for (i =3D 0; i < 6; i++) { r =3D __nth_region_of(t, i); KUNIT_EXPECT_EQ(test, r->ar.start, saddrs[i]); KUNIT_EXPECT_EQ(test, r->ar.end, eaddrs[i]); } +out: damon_free_target(t); damon_destroy_ctx(ctx); } --=20 2.47.3 From nobody Sat Jul 25 22:31:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BDE3036654C; Sun, 12 Jul 2026 17:03:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875821; cv=none; b=bOzG1tWYqY9uFOIS/4QXZsi1OOoK7PrNX9Euxm5x5DXqqbWI3+rWAy3TsaWtxN3ML+natsZmZMRM4JidoyJlCWSaHKZR5n5iLqIZ1s5Wefu9OoHCNzoe46iYX6aMdlf3Hjg+6SP4d2rhimd+94yyZMVlstEewylwnc1renxmUII= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875821; c=relaxed/simple; bh=eShbpgLz2NbIysbCSJJgbBQ51wiA+Nyw8yXGHdcRa9M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ozWUKkYdNAUyoVryMg47q2W4B5o+WsGxx64OdXoEQlShgGtvDXMF3EBjGJrdykvlQyGq8K/LCHtbpb+X9q9YK2jsIWvpZRPHLmi6huR9VV7tw73ogRWoNEpqDHOc2pMWhRxlm8e9whog+8lL37YfcXMG1x98LJlxOCobCRrjI18= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=K3VaMGI4; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="K3VaMGI4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 27A9E1F00A3F; Sun, 12 Jul 2026 17:03:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783875820; bh=Y5xW2GMWQ2fJulemhF10bJTV6JcOyhTF3brjsm/0yqc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=K3VaMGI4TyeJ5+PzRVirqrge5WUaVVa53j+QN2P8SmdEFEg3xutS40c25/o97BgMc kwp4o55qHO37t7Y/5bbHjb59fckHhRZOeMgJNz5lg/p4g0aLsNCACTXULm30U0Bs0z WCITAbrq1ea8ZvsV3Jy8LmpHm6DLsgcJGcWnGF5aNiOC79Cy9DO/Da78+OW6lDmJtr xhBqrgx4PXiwc+xDv+XVflDcf2xu0epXhNUJUP6FAWJxN/fOIdpanW9LyjcCr3IOL7 G8ZNRGVaZVvst5/xV0xuJr+iQ2vtHw+cHldCtB5jaK79QYutZydKFlnudYlwZzBQQ9 Uy7UtpgsLq1uw== From: SJ Park To: Cc: SJ Park , stable@vger.kernel.org, Andrew Morton , Fernand Sieber , Leonard Foerster , SeongJae Park , Shakeel Butt , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH v1.1 3/5] mm/damon/vaddr: drop last same folio access check optimization Date: Sun, 12 Jul 2026 10:03:25 -0700 Message-ID: <20260712170328.91144-4-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260712170328.91144-1-sj@kernel.org> References: <20260712170328.91144-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The optimization can race when multiple kdamonds are running. Meanwhile, the impact of the optimization is quite doubtful. Just remove it. The user impact of the issue should be quite trivial. After all, the race can happen only when the user intentionally setup DAMON in the way. Even if it happens, it would be rare and only degrade the best-effort monitoring results. No critical consequences like kernel panic or memory corruption happen. The race possibility was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org Fixes: 3f49584b262c ("mm/damon: implement primitives for the virtual memory= address spaces") Cc: # 5.15.x Signed-off-by: SJ Park --- mm/damon/vaddr.c | 26 ++++---------------------- 1 file changed, 4 insertions(+), 22 deletions(-) diff --git a/mm/damon/vaddr.c b/mm/damon/vaddr.c index d10b8042adb5b..16fe210d2042a 100644 --- a/mm/damon/vaddr.c +++ b/mm/damon/vaddr.c @@ -383,8 +383,6 @@ static void damon_va_prepare_access_checks(struct damon= _ctx *ctx) } =20 struct damon_young_walk_private { - /* size of the folio for the access checked virtual memory address */ - unsigned long *folio_sz; bool young; }; =20 @@ -411,7 +409,6 @@ static int damon_young_pmd_entry(pmd_t *pmd, unsigned l= ong addr, mmu_notifier_test_young(walk->mm, addr)) priv->young =3D true; - *priv->folio_sz =3D HPAGE_PMD_SIZE; huge_out: spin_unlock(ptl); return 0; @@ -430,7 +427,6 @@ static int damon_young_pmd_entry(pmd_t *pmd, unsigned l= ong addr, if (pte_young(ptent) || !folio_test_idle(folio) || mmu_notifier_test_young(walk->mm, addr)) priv->young =3D true; - *priv->folio_sz =3D folio_size(folio); out: pte_unmap_unlock(pte, ptl); return 0; @@ -458,7 +454,6 @@ static int damon_young_hugetlb_entry(pte_t *pte, unsign= ed long hmask, if (pte_young(entry) || !folio_test_idle(folio) || mmu_notifier_test_young(walk->mm, addr)) priv->young =3D true; - *priv->folio_sz =3D huge_page_size(h); =20 folio_put(folio); =20 @@ -470,11 +465,9 @@ static int damon_young_hugetlb_entry(pte_t *pte, unsig= ned long hmask, #define damon_young_hugetlb_entry NULL #endif /* CONFIG_HUGETLB_PAGE */ =20 -static bool damon_va_young(struct mm_struct *mm, unsigned long addr, - unsigned long *folio_sz) +static bool damon_va_young(struct mm_struct *mm, unsigned long addr) { struct damon_young_walk_private arg =3D { - .folio_sz =3D folio_sz, .young =3D false, }; =20 @@ -496,26 +489,15 @@ static bool damon_va_young(struct mm_struct *mm, unsi= gned long addr, static void __damon_va_check_access(struct mm_struct *mm, struct damon_region *r, bool same_target) { - static unsigned long last_addr; - static unsigned long last_folio_sz =3D PAGE_SIZE; - static bool last_accessed; + bool accessed; =20 if (!mm) { damon_update_region_access_rate(r, false); return; } =20 - /* If the region is in the last checked page, reuse the result */ - if (same_target && (ALIGN_DOWN(last_addr, last_folio_sz) =3D=3D - ALIGN_DOWN(r->sampling_addr, last_folio_sz))) { - damon_update_region_access_rate(r, last_accessed); - return; - } - - last_accessed =3D damon_va_young(mm, r->sampling_addr, &last_folio_sz); - damon_update_region_access_rate(r, last_accessed); - - last_addr =3D r->sampling_addr; + accessed =3D damon_va_young(mm, r->sampling_addr); + damon_update_region_access_rate(r, accessed); } =20 static unsigned int damon_va_check_accesses(struct damon_ctx *ctx) --=20 2.47.3 From nobody Sat Jul 25 22:31:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 758B3367B9C; Sun, 12 Jul 2026 17:03:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875822; cv=none; b=KVZFXrIKQ9EFHvsFKIJoGk1eZ2+/vsrsKFy9QN5V6Qn9elAuPdekgJbdRvga5PbsIaEASIqLyDH7P05AkhlfRJNRp7a82SwHTuQjgfMknWN9ohNAIv5rwyiEB/cD9RMz2/xGqNaN7xHJ0ZG8k6Y5j0J57mui06Aun0/h8PMRB6U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875822; c=relaxed/simple; bh=5ScejZ7WR20mP7M32rQjyj8bSoc3hvLkckL0qcqy7ww=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JQhuChmFDXN+OiSNPCzW4E5IHo7E6NVqEXqauCaSTtBhYMR0473PyVjzuw2GPJhKtJz9KEr38vtPQxHixrwPamLMYmFV+F9GfVVFIdsh74tHCsM6aXAZYrXJVP5wPe5Lsc5/vSfrArvGAmThxQzzGcfljTwVo7Br7Ux0PT7RbOs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=EJ5SwUQU; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="EJ5SwUQU" Received: by smtp.kernel.org (Postfix) with ESMTPSA id DFCA91F000E9; Sun, 12 Jul 2026 17:03:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783875821; bh=MTFa+hpzXfcfyF1zP3rvNz2Fhu2Cffg36gE6sioOaYQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=EJ5SwUQUrhliTXVTQ0gJzeD61a0JDOTHv2z0xzqoAS/iIA7hQdL75F85oFu1rSFjh AYPVpug0uM99scxME/UG9d4esLNmi8/IoZ5S6F2kNJpXfQS7w5LXdpbTnyGIVnuJlM +bRgjKl1KHMomWUhzJRwLtgez/wsaYpw2gppJS2HUB1M1jjEQ6jWDLA8/balgdk8A4 rEXdxh4mvVJRGXDjRKrBWnOVKAay8Qjez3OnN8Xjklw0Ytkj3wPkaR0452C7oymyj9 dBKoZ93RLxUnM7QwPhpx9jXI9Qg+fBEdHHQdAf9P7ve8UARAmyblwkp7IETnAt3h33 BAZoFhohdXLHw== From: SJ Park To: Cc: SJ Park , stable@vger.kernel.org, Andrew Morton , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH v1.1 4/5] mm/damon/paddr: drop last same folio access check reuse optimization Date: Sun, 12 Jul 2026 10:03:26 -0700 Message-ID: <20260712170328.91144-5-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260712170328.91144-1-sj@kernel.org> References: <20260712170328.91144-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" It can race when multiple kdamonds are being used. The problem from the race is doubtful, but the gain from the optimization is also doubtful. Simply drop the optimization in favor of code simplicity. The user impact is doubtfully trivial. After all, this kind of interference can happen only by intentional user setup. Even if it happens, it will be rare, and the consequence is degradation of the best-effort monitoring results. No critical consequences like kernel panic or memory corruption happen. The race was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org Fixes: a28397beb55b ("mm/damon: implement primitives for physical address s= pace monitoring") Cc: # 5.16.x Signed-off-by: SJ Park --- mm/damon/paddr.c | 20 ++++---------------- 1 file changed, 4 insertions(+), 16 deletions(-) diff --git a/mm/damon/paddr.c b/mm/damon/paddr.c index b85f88a7a38f4..e4f98d67461f5 100644 --- a/mm/damon/paddr.c +++ b/mm/damon/paddr.c @@ -65,7 +65,7 @@ static void damon_pa_prepare_access_checks(struct damon_c= tx *ctx) } } =20 -static bool damon_pa_young(phys_addr_t paddr, unsigned long *folio_sz) +static bool damon_pa_young(phys_addr_t paddr) { struct folio *folio =3D damon_get_folio(PHYS_PFN(paddr)); bool accessed; @@ -74,7 +74,6 @@ static bool damon_pa_young(phys_addr_t paddr, unsigned lo= ng *folio_sz) return false; =20 accessed =3D damon_folio_young(folio); - *folio_sz =3D folio_size(folio); folio_put(folio); return accessed; } @@ -82,23 +81,12 @@ static bool damon_pa_young(phys_addr_t paddr, unsigned = long *folio_sz) static void __damon_pa_check_access(struct damon_region *r, unsigned long addr_unit) { - static phys_addr_t last_addr; - static unsigned long last_folio_sz =3D PAGE_SIZE; - static bool last_accessed; + bool accessed; phys_addr_t sampling_addr =3D damon_pa_phys_addr( r->sampling_addr, addr_unit); =20 - /* If the region is in the last checked page, reuse the result */ - if (ALIGN_DOWN(last_addr, last_folio_sz) =3D=3D - ALIGN_DOWN(sampling_addr, last_folio_sz)) { - damon_update_region_access_rate(r, last_accessed); - return; - } - - last_accessed =3D damon_pa_young(sampling_addr, &last_folio_sz); - damon_update_region_access_rate(r, last_accessed); - - last_addr =3D sampling_addr; + accessed =3D damon_pa_young(sampling_addr); + damon_update_region_access_rate(r, accessed); } =20 static unsigned int damon_pa_check_accesses(struct damon_ctx *ctx) --=20 2.47.3 From nobody Sat Jul 25 22:31:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C9DC1368293; Sun, 12 Jul 2026 17:03:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875823; cv=none; b=nwMFDvPrbQFQ1wZrqq7E/OEiGaU9/1+fIezlSGLH2I/T6fT5pJZ3MWrWgUTdvQpPVSVP8lA3dc3chg9T28DA+GpxpjS8D3jCVSd4obTEwQF2nbxkTRtpldmzNmC4o42ZvhfDmzd91OQoskqkWgyZDb8ESjmk6KPqbf07D07b6rI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783875823; c=relaxed/simple; bh=nt1m4yOHpUkfhmuPI5sfQNBML1ejUt2LDcM7VHyWuzk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GtN5cBFsbZRgCVAbMjHx/zwPSYJ6HPt+V/Y3RrEyyZlYLM5adzGq0qiHmSkN6HAWQHFB67w7Mh1uxO2KmtpHGByFnCcTUk1ZO6qtnJelEHuwX2HtaF2tgQ1Co0xNlQygvipvy66y8R+8IPP187rkIsCg80im9XGaBLLYY6buFKQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=jqnAdXsz; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="jqnAdXsz" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 53A4D1F00A3D; Sun, 12 Jul 2026 17:03:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783875821; bh=hhmDCI+ot7IL3VsT3pLzYBJmbk4njLZd345nGTc/fNs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jqnAdXszxWlkiGPhG+kdzDqhjT1jdYqU0Tnu/kSJ3AMyLxt5ZpLy6QMxsZmv3a5np N8uVClMafeRShHx+Rw7BP9jddNRBrX9cBzjseNGnUi/MihUGK3Ybddi98rHiCHQXjb geQFfvghXDWU/d4XOctmwpMMxEhwPMmJ7cRocPSE64rgpaUdzqbfxeECokC1ZlazMQ bqpm69Gpg0v4AhyX/xxiJ9RNhhppw32Fb+lEvftBArHE3Xi5Hoys88Q/1gnahxHqE6 xv2Yv81igcLUYxhiVAlzno6vOk+XCuzG9SNEw6NqV/wGiKiNXkWhQ/CeYPCjPFwavb 4rA9AUj3dsOVQ== From: SJ Park To: Cc: SJ Park , Andrew Morton , damon@lists.linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org Subject: [RFC PATCH v1.1 5/5] mm/damon/sysfs: read ops_id only once Date: Sun, 12 Jul 2026 10:03:27 -0700 Message-ID: <20260712170328.91144-6-sj@kernel.org> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260712170328.91144-1-sj@kernel.org> References: <20260712170328.91144-1-sj@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" damon_sysfs_apply_inputs() reads ops_id twice. It could race with ops_id_store(). As a result, the min_region_sz could wrongly be set up. Read it once. The user impact is trivial. Sane users ain't update the parameter in parallel. Even if it happens, only monitoring itself runs differently than expected. No critical consequences like kernel panic or memory corruption happen. The issue was discovered [1] by Sashiko. [1] https://lore.kernel.org/20260703172417.95426-1-sj@kernel.org Signed-off-by: SJ Park --- mm/damon/sysfs.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/mm/damon/sysfs.c b/mm/damon/sysfs.c index b5fe036f78015..60a1a9e4ada34 100644 --- a/mm/damon/sysfs.c +++ b/mm/damon/sysfs.c @@ -2094,14 +2094,16 @@ static inline bool damon_sysfs_kdamond_running( static int damon_sysfs_apply_inputs(struct damon_ctx *ctx, struct damon_sysfs_context *sys_ctx) { + enum damon_ops_id ops_id; int err; =20 - err =3D damon_select_ops(ctx, sys_ctx->ops_id); + ops_id =3D READ_ONCE(sys_ctx->ops_id); + err =3D damon_select_ops(ctx, ops_id); if (err) return err; ctx->addr_unit =3D sys_ctx->addr_unit; /* addr_unit is respected by only DAMON_OPS_PADDR */ - if (sys_ctx->ops_id =3D=3D DAMON_OPS_PADDR) + if (ops_id =3D=3D DAMON_OPS_PADDR) ctx->min_region_sz =3D max( DAMON_MIN_REGION_SZ / sys_ctx->addr_unit, 1); ctx->pause =3D sys_ctx->pause; --=20 2.47.3