From nobody Thu Sep 24 21:47:03 2026 Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C08413B71C4 for ; Sun, 20 Sep 2026 12:24:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.140 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789907072; cv=none; b=coFpt4SEtq0Hqatyr4d98GjX4xD7f/Cc/gupKOey4N4dLA+5ea2jSnBVx9y8UvIpyghW8XGueX2jPLAtpxbB8ftdWK0InxA5RWZj4JxrC5dYKwNHry1eXNzUj0INT9q0+i3BzUsG811NdsIIrYuo86TBYdpIcetDWsKnLXcL4MU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789907072; c=relaxed/simple; bh=X9og+gkcKs3FqJesjCqjxPxucohjf/RASztug2OUqqE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UbpZDWNnp6w9hybfAknPTHaiwMuEDLqjgUTIW6Z9EbHAFDoC3+Sf6bTWKgVfF6SwYY4VoEvUQgVbz1yVG8yD2Ea1vyyaStMTMTVQKmaBBuHwh+GLrcitVuL5G/Lqp9ERCA43TcS9KTqeTSGt2Gp0egLNN1Fx1sEukdF3Zek0ahA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=kvv9xhdB; arc=none smtp.client-ip=74.125.227.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="kvv9xhdB" Received: by mail-pj2-f12.google.com with SMTP id 98e67ed59e1d1-398c066106cso1693170a91.1 for ; Sun, 20 Sep 2026 05:24:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789907060; x=1790511860; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ONHA4wMDILxcRZ+Lg+d1Nlct6hNZeNgcOdxBA0gn77s=; b=kvv9xhdBSn+K4HnJhB98/4alaFtUSKqDKoCdI5PO8XQPIs4o1wIyDSZtu2sy2KlSvM taTKtVLigaxWd4lALeCSo0uc6/Jn+BKA2MybQbvU1tLbYQexa+EMutIgPODL+RK3I/eK Onbm9IeJLdczIXm8em/cGP7BBTLGsZw4NdaY+ALlqAtl/risfK9X0c75HSlBYtNlJNFK 8D8jCLI9jbIRCs3dSLrnrR06HipRT220n1Anu5xdI9X8xo6FX5asj6NOxxXG/6jYflwg EhbL0hHDOtiqnGZ7sUuenZnpr2CT74IgeNqPx3B++NirXZ7WOgTOllbOZKZRiZuDo7s1 YCow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789907060; x=1790511860; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ONHA4wMDILxcRZ+Lg+d1Nlct6hNZeNgcOdxBA0gn77s=; b=TQ4cwNM1CXlbuMa7XQvEYIPUyxLIeNOV+k0Hvw21rx80gPjmDjWxg8m2Yrk/5KLsik T/3t4GR/WF2KqYfzGLPW2fnyTKNTCEOmouAHyPMz2+mm81Vgj0TqXo6M2pOw60f9Gaed tajAq49j3iAur2zB9ltf+txK7Q4gUBGylL3wmZfN8BeeVhCO4s1F9db4zZRVg+a+38CM /EHb/jjKu0m8zArZxZwq4WtVJCz+gu5lxqN6aun8s36tal4kxBR+3ZQVyKAVBd+nBVS5 9ALCvWAMuVCwJ3jgjJhHNpFy9WGlZan9U9CSWDhA9P3mW8Qk/k8iQ1KDQ2mdtf5rPk4k hArA== X-Forwarded-Encrypted: i=1; AKwUvBz9K1vyPhSY42JHJybcvo1WQ8OipfPdtFbiz9lDcfU7U+hanwgE4Bz+2VqEo6dAgfH/WC1sXx4WXD85Rxk=@vger.kernel.org X-Gm-Message-State: AFuF++l7u6jxV7PPEycT62YuBaeZ9j2WMqnNkyBDZiAtZeyL/UxwgNew +ciKK1GD9nwrbHHmO32PP7r2/1vFg1YFDBsXRvQ38JzU4PXYQybl6y0= X-Gm-Gg: AYBFou2qT9AU1PZhY2uWCSea6DcXLZXB5Z12CfX9yc/rc78ydVSX5TCn1UmrZ/zbIBg MPpCg7WgXq2jITt6ckubIQ6WseXjQx+T8NwK/0rym2nTQmqzslgWU+Q95Ta/qMKx/uB09B03YBl vmrIgdqrysvG6wiv/fJTIhV4rE9inZ6iHp/c1SZirqP2Q+azKu7xMp005MDFbr3CxGUHNalyjPI mhvCFFRvykeAmQdbQUojlF7+i2Q2a9Mw1tW7Jl7TiaapGABtdaVbdJVsgU3F80aQ72BAXZjsyFR cc4NwykGd3z4w/+BBR6LaHbYyCG/4C7VjOeI+tOR2P4Ki0h24kWgZQtWjhwqjXC6ef5S9cPD+ih iiyS4D7GqXp1P3qwiRFSe+SjRUAE0goM1Vd3U2kR2nybnHexzW01Hu4/a3Y0ITpF9zEDFYQpujS rdQTle50WV3bvWP5sqWNYmqFhlxHpgLRttV1/I2aVvM28+QNKjt93U4+Jqut39GD48nqESy/aDs iaVrlr40KwVv4YqVe16ADGpUZI= X-Received: by 2002:a17:90b:1dc7:b0:39e:6c68:1553 with SMTP id 98e67ed59e1d1-39e6c68331amr8421991a91.27.1789907059964; Sun, 20 Sep 2026 05:24:19 -0700 (PDT) Received: from ydg-Zenbook-14-UM3406GA ([2001:2d8:7f00:8c85:e0d6:4b87:c472:c9ae]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39e6cae997csm8753943a91.11.2026.09.20.05.24.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 20 Sep 2026 05:24:19 -0700 (PDT) From: Donggeun Yoo To: sj@kernel.org, akpm@linux-foundation.org Cc: damon@lists.linux.dev, linux-mm@kvack.org, linux-kernel@vger.kernel.org, donggeunyoo.kernel@gmail.com, stable@vger.kernel.org Subject: [PATCH v3 1/2] mm/damon/core: prevent size quota overflow in the temporal goal tuner Date: Sun, 20 Sep 2026 21:24:10 +0900 Message-ID: <20260920122411.610213-2-donggeunyoo.kernel@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260920122411.610213-1-donggeunyoo.kernel@gmail.com> References: <20260920122411.610213-1-donggeunyoo.kernel@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" damos_goal_tune_esz_bp_temporal() converts the scheme's size quota into basis points with "quota->esz_bp =3D quota->sz * 10000", both unsigned long, and damos_set_effective_quota() divides the result back by 10000. quotas/bytes is unbounded; bytes_store() hands it to kstrtoul() as is. On 32-bit the product wraps for any size quota above ULONG_MAX / 10000, that is 429496 bytes. It lands on exactly zero when the quota is a multiple of 256 MiB, which includes the 1 GiB that Documentation/admin-guide/mm/damon/usage.rst uses in its example, and a zero effective quota makes damos_quota_is_full() true on the first test of every charge window. The scheme then applies nothing while the goal is unachieved. Other wrapped values are simply wrong, and any product below 10000 divides to a zero effective quota too: 429497 gives 0, 500000 gives 70503. Triggering this needs a scheme with a quota goal, the temporal goal tuner, and a size quota above ULONG_MAX / 10000 -- 429496 bytes on 32-bit, 1844674407370955 on 64-bit -- so it is unlikely to be hit on a tested setup. Nothing is corrupted and nothing leaks. The scheme makes no progress for as long as the goal is unachieved, which is easy to notice, and writing a smaller size quota restores it. addr_unit does not cover this. It only scales the numbers a paddr context writes to quotas/bytes, so a large enough scaled value wraps just the same, and vaddr and fvaddr contexts take raw byte values. Bound the multiply. A size quota too large to convert now takes the same ULONG_MAX branch as a scheme with no size quota, so the effective quota becomes ULONG_MAX / 10000 instead of a wrapped value. Fixes: af738a6a00c1 ("mm/damon/core: introduce DAMOS_QUOTA_GOAL_TUNER_TEMPO= RAL") Cc: # 7.1.x Signed-off-by: Donggeun Yoo --- Measured on i386 under QEMU: one paddr context with a stat scheme, the temporal goal tuner, and one unachieved user_input goal. Each size is written to quotas/bytes and quotas/effective_bytes is read back after update_schemes_effective_quotas. quotas/bytes effective_bytes effective_bytes before after 4096 4096 4096 429496 429496 429496 429497 0 429496 268435456 0 429496 1073741824 0 429496 500000 70503 429496 4294967295 429495 429496 0 429496 429496 Everything the conversion can hold is unchanged, and 429496 is what the no-size-quota row already produced before the patch. mm/damon/core.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mm/damon/core.c b/mm/damon/core.c index 2258b72da7a78..16d4145379a2b 100644 --- a/mm/damon/core.c +++ b/mm/damon/core.c @@ -3274,7 +3274,7 @@ static void damos_goal_tune_esz_bp_temporal(struct da= mon_ctx *c, =20 if (score >=3D 10000) quota->esz_bp =3D 0; - else if (quota->sz) + else if (quota->sz && quota->sz <=3D ULONG_MAX / 10000) quota->esz_bp =3D quota->sz * 10000; else quota->esz_bp =3D ULONG_MAX; --=20 2.53.0 From nobody Thu Sep 24 21:47:03 2026 Received: from mail-pj2-f42.google.com (mail-pj2-f42.google.com [74.125.227.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA2863DDAFB for ; Sun, 20 Sep 2026 12:24:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789907088; cv=none; b=lFOkEdA3A64PMBydZtCV+l+Gw17M4+ElrPxO7RbRflDMe/3GHXo2GGChwtjmap4DX1thoKU0zyUkTm7f3Azc2tbp/xVAr4h26GJQ7XO0HizkdEYbFhe4uvT1z2cWxHj9TiMBSrgCQKuEtR3iY3zkgx/J19pXRvBi4CoH49+8PCU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789907088; c=relaxed/simple; bh=rmWR38P9oV+3YYhnLaf+Dq+xPZyqqx+mXZBXqMUox8U=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=I2PszaIKwR9pjuhNERIItP2+8GtZYsV/gegQWr8gXLHJwyQnVbGIFnKQ29SxCUGKTxx7mpegyVtnWng7hGQwM61BPN6tnA66E2GKpbV2WI5Zffpnhu1jsApwTbn7ZT5FeCkbyxgL1DbG2SjAKUkk/+zQewbkjdSxR+0EBpQeIh8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=llYkJpeP; arc=none smtp.client-ip=74.125.227.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="llYkJpeP" Received: by mail-pj2-f42.google.com with SMTP id 98e67ed59e1d1-398cb5615deso2536197a91.3 for ; Sun, 20 Sep 2026 05:24:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789907062; x=1790511862; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NtyjzrgYhOa3bpnnzl8J/NBn02c098QytsBeznFYa9A=; b=llYkJpePvS4ewE5aDOXji8GvTCarYPh/amN+6WC6/bSQpPb0YBTyrSQydROM9K6sD4 3YO6utO0zMLERCV2qkwm1IPxYkwkr/YAqD54MmWxXEAqRvlPUjiPX5Fj/9WP1qr6/R8M MOlGLi7vbRgaxSIWpvXWsxlQXr+HWVgwcIMpusueZarJltjC+dzLce1F5uNc8EYNRHmL N9NiQ917hoDpGqSAWjNeKI3cWJXsEAStlp7FRy544Tc/46GdPWsYd3tGl+vVWROjieNn X8YFeUyh89qP2s7cCe5lgOD41jJbjyEn4eHWYM9NzmyxYLv4D1VBgn/pPqFZ8BuyJTJ3 WjIA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789907062; x=1790511862; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=NtyjzrgYhOa3bpnnzl8J/NBn02c098QytsBeznFYa9A=; b=XDnWVG9/CN2dP6E439UOBZDEh+fXpNmZP+Roat0W2/kEgWi9PiVQjvRkN38hIr6KWl BYh44U0Sj9Q9rhTqadl9ZaPjc6auQDy+A8SeArf7YmuCF33wdRq1EAM1rfXm3zUTh1vZ cb1lYhynQND2GpGXTr2pMusSKBFTmfBcuUTBHqBJjl23oSMxl8TMC0nTziW2UqgpyNhK e1YmjeiOdemfcbnP6yNVyHIJP69zVpN8N7proT2pn5tKaaEVPdoIsPrHHmLtEkzt+vn4 +IWBuaKwS7/haLZThev6ga3Jcvu4YCYk7inuD+jPKS40g3oIKjOCn7id6ugb21gZOPW5 CrSQ== X-Forwarded-Encrypted: i=1; AKwUvBx1NxEkYkUowv0jRnpxS9Obj9G76YsdLAkukcSFotafU7yS2YnKIVqBbgShs9pMypFId+BxBT5XD27tfFg=@vger.kernel.org X-Gm-Message-State: AFuF++lHjPEXF4Q7V+/dwYI3DDM5HHy8ic+dS2gN1ArgXnp2V6Bjb0Mm 7AeDdBmZcaLz29IXtK93qN7lnyt/Z0VK/WAUiUNby7QiNTpaYamZiyU= X-Gm-Gg: AYBFou2lfAExDdRWxYxeSj72QOGEoVN4CT779Ke5rx/UTghBZDbfGu2g33Vkj8ZQVhV EK1TavWMMLWeWuTQntBnrXwgAlBhxl47Id/kQxMsL7BNwvaJKY1g0vOVKhzaK8tmVMxMiUs+bFA xy2D5uhvFEEE60YLegrVVWaPcni5j7NwqBKE2O27KAvFSUkGzZtFBce/824GRjvsjeZXRexhy+/ mQrwZHK3rDNaYfSMLKQyZUYrwl0pecSg14VPR7R9yrIASL32hZhwz7W/7vFCBZHRzWjVM6coUya eDvIXc9hqKfN3rB1DGsXi5a7i15MMGDO+QOG5C98zRor7KMaOtg8yvaGsjjCR+RbIxBCYGwao3A 9B5g2rkd0M1XXWj/iifZRvcYo2Ss0UFm4cO/+UoaQp+H+VUXoocuKS53RMsXjrJTjBKaYK4bKZB Uj4m8ryi5XATJOzw+whaJNsZyks6WvqaXyRlAIlEuxy4oLDdJGHs54qp32TRvFB0VNIcM81d92i sIB6lV/azDKWD0D1MmfP+GKR8U= X-Received: by 2002:a17:90b:3a81:b0:39e:6a82:afd9 with SMTP id 98e67ed59e1d1-39e6a82bbe2mr6880094a91.43.1789907062475; Sun, 20 Sep 2026 05:24:22 -0700 (PDT) Received: from ydg-Zenbook-14-UM3406GA ([2001:2d8:7f00:8c85:e0d6:4b87:c472:c9ae]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39e6cae997csm8753943a91.11.2026.09.20.05.24.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 20 Sep 2026 05:24:22 -0700 (PDT) From: Donggeun Yoo To: sj@kernel.org, akpm@linux-foundation.org Cc: damon@lists.linux.dev, linux-mm@kvack.org, linux-kernel@vger.kernel.org, donggeunyoo.kernel@gmail.com Subject: [PATCH v3 2/2] mm/damon/tests/core-kunit: test the temporal tuner's size quota conversion Date: Sun, 20 Sep 2026 21:24:11 +0900 Message-ID: <20260920122411.610213-3-donggeunyoo.kernel@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260920122411.610213-1-donggeunyoo.kernel@gmail.com> References: <20260920122411.610213-1-donggeunyoo.kernel@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" damos_goal_tune_esz_bp_temporal() encodes the size quota in basis points, so the conversion is exact only up to ULONG_MAX / 10000. Pin the three sizes around that boundary: the largest one that fits, the first one that does not, and ULONG_MAX. Signed-off-by: Donggeun Yoo Reviewed-by: SJ Park --- mm/damon/tests/core-kunit.h | 48 +++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) diff --git a/mm/damon/tests/core-kunit.h b/mm/damon/tests/core-kunit.h index 5ff0436c58441..a0604788bc638 100644 --- a/mm/damon/tests/core-kunit.h +++ b/mm/damon/tests/core-kunit.h @@ -1929,6 +1929,53 @@ static void damon_test_rand(struct kunit *test) } } =20 +static void damos_test_esz_goal_temporal(struct kunit *test) +{ + struct damos_access_pattern pattern =3D {}; + struct damos_watermarks wmarks =3D {}; + struct damos_quota quota =3D { + .goal_tuner =3D DAMOS_QUOTA_GOAL_TUNER_TEMPORAL, + }; + struct damos_quota_goal *goal; + struct damon_ctx *ctx; + struct damos *s; + + ctx =3D damon_new_ctx(); + KUNIT_ASSERT_NOT_NULL(test, ctx); + + s =3D damon_new_scheme(&pattern, DAMOS_STAT, 0, "a, &wmarks, + NUMA_NO_NODE); + if (!s) { + damon_destroy_ctx(ctx); + kunit_skip(test, "scheme alloc fail"); + } + damon_add_scheme(ctx, s); + + goal =3D damos_new_quota_goal(DAMOS_QUOTA_USER_INPUT, 10000); + if (!goal) { + damon_destroy_ctx(ctx); + kunit_skip(test, "quota goal alloc fail"); + } + goal->current_value =3D 0; + damos_add_quota_goal(&s->quota, goal); + + /* The largest size quota the basis-point conversion can hold. */ + s->quota.sz =3D ULONG_MAX / 10000; + damos_set_effective_quota(ctx, s); + KUNIT_EXPECT_EQ(test, s->quota.esz, ULONG_MAX / 10000); + + /* Any larger one saturates instead of wrapping. */ + s->quota.sz =3D ULONG_MAX / 10000 + 1; + damos_set_effective_quota(ctx, s); + KUNIT_EXPECT_EQ(test, s->quota.esz, ULONG_MAX / 10000); + + s->quota.sz =3D ULONG_MAX; + damos_set_effective_quota(ctx, s); + KUNIT_EXPECT_EQ(test, s->quota.esz, ULONG_MAX / 10000); + + damon_destroy_ctx(ctx); +} + static struct kunit_case damon_test_cases[] =3D { KUNIT_CASE(damon_test_target), KUNIT_CASE(damon_test_regions), @@ -1965,6 +2012,7 @@ static struct kunit_case damon_test_cases[] =3D { KUNIT_CASE(damon_test_is_last_region), KUNIT_CASE(damon_test_walk_control_obsolete), KUNIT_CASE(damon_test_rand), + KUNIT_CASE(damos_test_esz_goal_temporal), {}, }; =20 --=20 2.53.0