From: sashiko-bot@kernel.org
To: "SeongJae Park" <sj@kernel.org>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH 05/13] mm/damon/sysfs-schemes: use damon_nr_accesses_mvsum() for damo regions
Date: Fri, 19 Jun 2026 19:47:50 +0000 [thread overview]
Message-ID: <20260619194750.B30821F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260619193415.73833-6-sj@kernel.org>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Calling `damon_nr_accesses_mvsum()` triggers a division by zero kernel panic when `aggr_interval` and `sample_interval` are configured to 0.
- [Medium] Integer overflow in `damon_nr_accesses_mvsum()` on 32-bit architectures when `window_len` is large.
--
commit 66c2d8d0e11cf5ef0032d41b0f9dcf8d2fd41a3b
Author: SeongJae Park <sj@kernel.org>
mm/damon/sysfs-schemes: use damon_nr_accesses_mvsum() for damo regions
This commit updates the DAMON sysfs interface to use
damon_nr_accesses_mvsum() for scheme-tried regions instead of reading
nr_accesses_bp directly.
> diff --git a/mm/damon/sysfs-schemes.c b/mm/damon/sysfs-schemes.c
> index 329cfd0bbe9f3..e648b0f809332 100644
> --- a/mm/damon/sysfs-schemes.c
> +++ b/mm/damon/sysfs-schemes.c
> @@ -159,7 +159,7 @@ struct damon_sysfs_scheme_region {
> };
>
> static struct damon_sysfs_scheme_region *damon_sysfs_scheme_region_alloc(
> - struct damon_region *region)
> + struct damon_region *region, struct damon_ctx *ctx)
> {
> struct damon_sysfs_scheme_region *sysfs_region = kmalloc_obj(*sysfs_region);
>
> @@ -167,7 +167,7 @@ static struct damon_sysfs_scheme_region *damon_sysfs_scheme_region_alloc(
> return NULL;
> sysfs_region->kobj = (struct kobject){};
> sysfs_region->ar = region->ar;
> - sysfs_region->nr_accesses = region->nr_accesses_bp / 10000;
> + sysfs_region->nr_accesses = damon_nr_accesses_mvsum(region, ctx);
[Severity: High]
Could this new call trigger a divide-by-zero kernel panic?
If a user configures both aggr_interval and sample_interval to 0 via the
DAMON sysfs interface, damon_set_attrs() accepts these values. During the
calculation of the moving sum in damon_nr_accesses_mvsum(), window_len
evaluates to 0:
mm/damon/core.c:damon_nr_accesses_mvsum() {
sample_interval = ctx->attrs.sample_interval ? : 1;
window_len = ctx->attrs.aggr_interval / sample_interval;
...
left_window_bp = mult_frac(left_window, 10000, window_len);
...
}
Since window_len becomes 0/1 = 0, the subsequent call to mult_frac()
performs a division by window_len, which would crash the system.
[Severity: Medium]
Also, does this calculation cause an integer overflow on 32-bit architectures?
The mult_frac macro expands to (rem * 10000) / window_len. On 32-bit
systems where unsigned long is 32 bits, if the aggregation interval is large
and sample interval is small, window_len can exceed 429,496.
As rem approaches window_len, the intermediate multiplication (rem * 10000)
exceeds ULONG_MAX and wraps around, corrupting the moving sum access
statistics.
> sysfs_region->age = region->age;
> sysfs_region->probes = NULL;
> INIT_LIST_HEAD(&sysfs_region->list);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260619193415.73833-1-sj@kernel.org?part=5
next prev parent reply other threads:[~2026-06-19 19:47 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-19 19:33 [RFC PATCH 00/13] mm/damon: optimize out nr_accesses_bp SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 01/13] mm/damon: introduce damon_nr_accesses_mvsum() SeongJae Park
2026-06-19 19:44 ` sashiko-bot
2026-06-19 19:52 ` SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 02/13] mm/damon/tests/core-kunit: test damon_mvsum() SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 03/13] mm/damon/core: use damon_nr_accesses_mvsum() in __damos_valid_target() SeongJae Park
2026-06-19 19:49 ` sashiko-bot
2026-06-19 19:33 ` [RFC PATCH 04/13] mm/damon/core: use damon_nr_accesses_mvsum() for damos region tracing SeongJae Park
2026-06-19 19:51 ` sashiko-bot
2026-06-19 20:17 ` SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 05/13] mm/damon/sysfs-schemes: use damon_nr_accesses_mvsum() for damo regions SeongJae Park
2026-06-19 19:47 ` sashiko-bot [this message]
2026-06-19 19:55 ` SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 06/13] mm/damon/core: remove damon_warn_fix_nr_accesses_corruption() SeongJae Park
2026-06-19 19:47 ` sashiko-bot
2026-06-19 19:56 ` SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 07/13] mm/damon/core: remove damon_verify_reset_aggregated() SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 08/13] mm/damon/core: remove damon_verify_merge_regions_of() SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 09/13] mm/damon/tests/core-kunit: remove nr_accesses_bp setup and tests SeongJae Park
2026-06-19 19:52 ` sashiko-bot
2026-06-19 20:24 ` SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 10/13] selftests/damon/drgn_dump_damon_status: do not dump nr_accesses_bp SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 11/13] mm/damon/core: remove nr_accesses_bp setups and updates SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 12/13] mm/damon/core: remove damon_moving_sum() and its unit test SeongJae Park
2026-06-19 19:33 ` [RFC PATCH 13/13] mm/damon: remove damon_region->nr_accesses_bp SeongJae Park
2026-06-19 19:49 ` sashiko-bot
2026-06-19 20:36 ` SeongJae Park
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260619194750.B30821F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=damon@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.