* [PATCH 6.12.y] mm/damon/paddr: drop last same folio access check reuse optimization
[not found] <2026090852-morally-preview-efa5@gregkh>
@ 2026-09-09 5:36 ` SJ Park
2026-09-09 5:48 ` sashiko-bot
2026-09-09 20:26 ` Sasha Levin
0 siblings, 2 replies; 3+ messages in thread
From: SJ Park @ 2026-09-09 5:36 UTC (permalink / raw)
To: stable; +Cc: damon, SJ Park, Andrew Morton
It can race when multiple kdamonds are being used. The problem from the
race is doubtful, but the gain from the optimization is also doubtful.
Simply drop the optimization in favor of code simplicity.
The user impact is doubtfully trivial. After all, this kind of
interference can happen only by intentional user setup. Even if it
happens, it will be rare, and the consequence is degradation of the
best-effort monitoring results. No critical consequences like kernel
panic or memory corruption happen.
The race was discovered [1] by Sashiko.
Link: https://lore.kernel.org/20260715031002.108504-5-sj@kernel.org
Link: https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org [1]
Fixes: a28397beb55b ("mm/damon: implement primitives for physical address space monitoring")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 5.16.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
(cherry picked from commit f23f0aa62b2f32c2b12f95959fc4603ef81678b2)
Signed-off-by: SJ Park <sj@kernel.org>
---
mm/damon/paddr.c | 20 ++++----------------
1 file changed, 4 insertions(+), 16 deletions(-)
diff --git a/mm/damon/paddr.c b/mm/damon/paddr.c
index d4a4d51750f5f..a6b1de97b1e8a 100644
--- a/mm/damon/paddr.c
+++ b/mm/damon/paddr.c
@@ -148,7 +148,7 @@ static bool damon_folio_young(struct folio *folio)
return accessed;
}
-static bool damon_pa_young(unsigned long paddr, unsigned long *folio_sz)
+static bool damon_pa_young(unsigned long paddr)
{
struct folio *folio = damon_get_folio(PHYS_PFN(paddr));
bool accessed;
@@ -157,7 +157,6 @@ static bool damon_pa_young(unsigned long paddr, unsigned long *folio_sz)
return false;
accessed = damon_folio_young(folio);
- *folio_sz = folio_size(folio);
folio_put(folio);
return accessed;
}
@@ -165,21 +164,10 @@ static bool damon_pa_young(unsigned long paddr, unsigned long *folio_sz)
static void __damon_pa_check_access(struct damon_region *r,
struct damon_attrs *attrs)
{
- static unsigned long last_addr;
- static unsigned long last_folio_sz = PAGE_SIZE;
- static bool last_accessed;
-
- /* If the region is in the last checked page, reuse the result */
- if (ALIGN_DOWN(last_addr, last_folio_sz) ==
- ALIGN_DOWN(r->sampling_addr, last_folio_sz)) {
- damon_update_region_access_rate(r, last_accessed, attrs);
- return;
- }
-
- last_accessed = damon_pa_young(r->sampling_addr, &last_folio_sz);
- damon_update_region_access_rate(r, last_accessed, attrs);
+ bool accessed;
- last_addr = r->sampling_addr;
+ accessed = damon_pa_young(r->sampling_addr);
+ damon_update_region_access_rate(r, accessed, attrs);
}
static unsigned int damon_pa_check_accesses(struct damon_ctx *ctx)
--
2.47.3
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH 6.12.y] mm/damon/paddr: drop last same folio access check reuse optimization
2026-09-09 5:36 ` [PATCH 6.12.y] mm/damon/paddr: drop last same folio access check reuse optimization SJ Park
@ 2026-09-09 5:48 ` sashiko-bot
2026-09-09 20:26 ` Sasha Levin
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-09 5:48 UTC (permalink / raw)
To: SJ Park; +Cc: damon
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but it is a pre-existing TOCTOU race in `damon_folio_young` where an anonymous folio can be converted to a KSM folio after lockless checks, leading to `rmap_walk_ksm` being called without the folio lock.
--
commit fca283b4eb28ba2daec6fc0d0f8aed873b1ec9ca
Author: SJ Park <sj@kernel.org>
mm/damon/paddr: drop last same folio access check reuse optimization
This commit removes a race-prone optimization in damon's physical address
monitoring that attempted to reuse access check results for the same folio.
The optimization provided doubtful benefits while introducing potential races
when multiple kdamonds run.
Link: https://lore.kernel.org/20260715031002.108504-5-sj@kernel.org
Link: https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org [1]
> diff --git a/mm/damon/paddr.c b/mm/damon/paddr.c
> index d4a4d51750f5f..a6b1de97b1e8a 100644
> --- a/mm/damon/paddr.c
> +++ b/mm/damon/paddr.c
[ ... ]
> @@ -157,7 +157,6 @@ static bool damon_pa_young(unsigned long paddr, unsigned long *folio_sz)
> return false;
>
> accessed = damon_folio_young(folio);
[Severity: High]
This is a pre-existing issue, but is there a time-of-check to time-of-use
race in damon_folio_young() when handling anonymous folios?
When damon_pa_check_access() calls damon_pa_young(), it takes a speculative
reference to the folio and calls damon_folio_young(). Inside
damon_folio_young(), the need for a lock is determined locklessly:
damon_folio_young() {
need_lock = !folio_test_anon(folio) || folio_test_ksm(folio);
if (need_lock && !folio_trylock(folio))
return false;
rmap_walk(folio, &rwc);
}
If the ksm daemon is concurrently processing an anonymous folio, could the
lockless check evaluate to false just before the ksm daemon updates
the folio with the ksm flag?
If that sequence occurs, damon_folio_young() would skip acquiring the
folio lock and call rmap_walk(). The rmap_walk() function would then
re-evaluate the ksm flag, see it is set, and call rmap_walk_ksm() without
holding the required folio lock.
Could this lead to a panic or data corruption when walking the ksm stable
tree locklessly?
> - *folio_sz = folio_size(folio);
> folio_put(folio);
> return accessed;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260909053646.245843-1-sj@kernel.org?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 6.12.y] mm/damon/paddr: drop last same folio access check reuse optimization
2026-09-09 5:36 ` [PATCH 6.12.y] mm/damon/paddr: drop last same folio access check reuse optimization SJ Park
2026-09-09 5:48 ` sashiko-bot
@ 2026-09-09 20:26 ` Sasha Levin
1 sibling, 0 replies; 3+ messages in thread
From: Sasha Levin @ 2026-09-09 20:26 UTC (permalink / raw)
To: stable; +Cc: Sasha Levin, damon, SJ Park, Andrew Morton
> It can race when multiple kdamonds are being used. The problem from the
> race is doubtful, but the gain from the optimization is also doubtful.
> Simply drop the optimization in favor of code simplicity.
Queued for 6.12, thanks.
--
Thanks,
Sasha
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-09 20:26 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <2026090852-morally-preview-efa5@gregkh>
2026-09-09 5:36 ` [PATCH 6.12.y] mm/damon/paddr: drop last same folio access check reuse optimization SJ Park
2026-09-09 5:48 ` sashiko-bot
2026-09-09 20:26 ` Sasha Levin
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.