From: sashiko-bot@kernel.org
To: "SJ Park" <sj@kernel.org>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH 3/9] mm/damon/paddr: respect folio end for DAMOS_STAT
Date: Sat, 01 Aug 2026 18:21:01 +0000 [thread overview]
Message-ID: <20260801182102.70BB91F00AC4@smtp.kernel.org> (raw)
In-Reply-To: <20260801173554.94710-4-sj@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Incomplete fix for large folio address iteration boundary bug.
--
--- Patch [3]: [RFC PATCH 3/9] mm/damon/paddr: respect folio end for DAMOS_STAT ---
commit b98d6f7836f4a90b6724f683127a934a339f77d5
Author: SJ Park <sj@kernel.org>
mm/damon/paddr: respect folio end for DAMOS_STAT
This commit fixes an issue in damon_pa_stat() where advancing the address
by folio_size(folio) could skip subsequent folios if the start address
is unaligned within a large folio. It corrects this by advancing the
address to exactly the start address of the next folio.
> diff --git a/mm/damon/paddr.c b/mm/damon/paddr.c
> index 5c6c3a597fd0b..2ab7b3842701e 100644
> --- a/mm/damon/paddr.c
> +++ b/mm/damon/paddr.c
> @@ -379,7 +379,7 @@ static unsigned long damon_pa_stat(struct damon_region *r,
>
> if (!damos_pa_filter_out(s, folio))
> *sz_filter_passed += folio_size(folio) / addr_unit;
> - addr += folio_size(folio);
> + addr = PFN_PHYS(folio_pfn(folio)) + folio_size(folio);
[Severity: High]
This is a pre-existing issue, but does this same bug exist in other DAMON
operations that iterate over folios?
For example, looking at damon_pa_pageout():
mm/damon/paddr.c:damon_pa_pageout() {
...
else
list_add(&folio->lru, &folio_list);
put_folio:
addr += folio_size(folio);
folio_put(folio);
}
...
}
It appears damon_pa_pageout(), damon_pa_de_activate(), and damon_pa_migrate()
all still advance the address by folio_size(folio) instead of calculating the
exact folio end.
Could these operations also overshoot subsequent memory and skip valid memory
folios if the region starts unaligned inside a large folio?
> folio_put(folio);
> }
> s->last_applied = folio;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260801173554.94710-1-sj@kernel.org?part=3
next prev parent reply other threads:[~2026-08-01 18:21 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-01 17:35 [RFC PATCH 0/9] mm/damon: fix DAMOS bugs in core, paddr and vaddr SJ Park
2026-08-01 17:35 ` [RFC PATCH 1/9] mm/damon/core: skip applying scheme if region split for quota fails SJ Park
2026-08-01 17:53 ` sashiko-bot
2026-08-01 20:01 ` SJ Park
2026-08-01 20:31 ` SJ Park
2026-08-01 17:35 ` [RFC PATCH 2/9] mm/damon/core: initialize damos_quota_goal->last_psi_total SJ Park
2026-08-01 17:35 ` [RFC PATCH 3/9] mm/damon/paddr: respect folio end for DAMOS_STAT SJ Park
2026-08-01 18:21 ` sashiko-bot [this message]
2026-08-01 20:07 ` SJ Park
2026-08-01 17:35 ` [RFC PATCH 4/9] mm/damon/paddr: respect folio end for DAMOS actions except STAT SJ Park
2026-08-01 17:35 ` [RFC PATCH 5/9] mm/damon/vaddr: respect folio end for DAMOS_STAT SJ Park
2026-08-01 18:50 ` sashiko-bot
2026-08-01 20:12 ` SJ Park
2026-08-01 17:35 ` [RFC PATCH 6/9] mm/damon/vaddr: respect folio end for DAMOS_MIGRATE_{HOT,COLD} SJ Park
2026-08-01 17:35 ` [RFC PATCH 7/9] mm/damon/core: handle extreme memory state in damon_get_node_mem_bp() SJ Park
2026-08-01 19:11 ` sashiko-bot
2026-08-01 20:18 ` SJ Park
2026-08-01 17:35 ` [RFC PATCH 8/9] mm/damon/core: handle extreme memory state in get_node_memcg_used_bp() SJ Park
2026-08-01 19:31 ` sashiko-bot
2026-08-01 20:26 ` SJ Park
2026-08-01 17:35 ` [RFC PATCH 9/9] mm/damon/core: handle extreme memory state in get_in_active_mem_bp() SJ Park
2026-08-01 19:39 ` sashiko-bot
2026-08-01 20:29 ` SJ Park
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260801182102.70BB91F00AC4@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=damon@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.