From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
To: sj@kernel.org, akpm@linux-foundation.org
Cc: damon@lists.linux.dev, linux-mm@kvack.org,
linux-kernel@vger.kernel.org, donggeunyoo.kernel@gmail.com,
stable@vger.kernel.org
Subject: [PATCH v1 1/2] mm/damon/core: prevent size quota overflow in the temporal goal tuner
Date: Sat, 19 Sep 2026 16:13:23 +0900 [thread overview]
Message-ID: <20260919071324.1583280-2-donggeunyoo.kernel@gmail.com> (raw)
In-Reply-To: <20260919071324.1583280-1-donggeunyoo.kernel@gmail.com>
damos_goal_tune_esz_bp_temporal() converts the scheme's size quota into
basis points with "quota->esz_bp = quota->sz * 10000", both unsigned long,
and damos_set_effective_quota() divides the result back by 10000.
quotas/bytes is unbounded; bytes_store() hands it to kstrtoul() as is.
On 32-bit the product wraps for any size quota above ULONG_MAX / 10000,
that is 429496 bytes. Documentation/admin-guide/mm/damon/usage.rst
instructs "echo $((1024*1024*1024)) > quotas/bytes", and 1 GiB * 10000 is
2500 * 2^32, so that documented value wraps to exactly zero; 256 MiB and
every multiple of it do the same. quota->esz then becomes zero while the
goal is not achieved, the trailing "if (quota->sz && quota->sz < esz)" can
only lower esz further, and damos_quota_is_full() is true on the first test
of every charge window, so the scheme applies nothing and the goal is never
approached. Other sizes are wrong without being zero: 500000 yields 70503.
Saturate to ULONG_MAX, which is what the same function already writes for a
scheme with no size quota. Widening esz_bp instead would reach the consist
tuner, which runs the same field through damon_feed_loop_next_input(),
unsigned long in and out; bounding the multiply keeps the change to this
branch. On 32-bit a large size quota then behaves like no size quota
rather than like a dead scheme.
Fixes: af738a6a00c1 ("mm/damon/core: introduce DAMOS_QUOTA_GOAL_TUNER_TEMPORAL")
Cc: <stable@vger.kernel.org> # 7.1.x
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
---
Measured on i386 under QEMU: one paddr context with a stat scheme, the
temporal goal tuner, and one unachieved user_input goal. Each size is
written to quotas/bytes, the kdamond is started, and
quotas/effective_bytes is read back after
update_schemes_effective_quotas.
quotas/bytes effective_bytes effective_bytes
before after
4096 4096 4096
429496 429496 429496
429497 0 429496
268435456 0 429496
1073741824 0 429496
500000 70503 429496
4294967295 429495 429496
0 429496 429496
Everything the conversion can hold is unchanged, and 429496 is what the
no-size-quota row already produced before the patch.
Patch 2 pins the same boundary at ULONG_MAX / 10000 and so runs on any
word size. Without this patch it fails on x86_64:
# damos_test_esz_goal_temporal: EXPECTATION FAILED at mm/damon/tests/core-kunit.h:1959
Expected s.quota.esz == max_sz, but
s.quota.esz == 0 (0x0)
max_sz == 1844674407370955 (0x68db8bac710cb)
mm/damon/core.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/mm/damon/core.c b/mm/damon/core.c
index 2258b72da7a7..5ec476cef4db 100644
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -3274,10 +3274,10 @@ static void damos_goal_tune_esz_bp_temporal(struct damon_ctx *c,
if (score >= 10000)
quota->esz_bp = 0;
- else if (quota->sz)
- quota->esz_bp = quota->sz * 10000;
- else
+ else if (!quota->sz || quota->sz > ULONG_MAX / 10000)
quota->esz_bp = ULONG_MAX;
+ else
+ quota->esz_bp = quota->sz * 10000;
}
/*
--
2.53.0
next prev parent reply other threads:[~2026-09-19 7:13 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-19 7:13 [PATCH 0/2] mm/damon: fix the temporal goal tuner's size quota conversion Donggeun Yoo
2026-09-19 7:13 ` Donggeun Yoo [this message]
2026-09-19 7:20 ` [PATCH v1 1/2] mm/damon/core: prevent size quota overflow in the temporal goal tuner sashiko-bot
2026-09-19 16:55 ` SJ Park
2026-09-20 2:37 ` Donggeun Yoo
2026-09-19 7:13 ` [PATCH v1 2/2] mm/damon/tests/core-kunit: test the temporal tuner's size quota conversion Donggeun Yoo
2026-09-19 7:20 ` sashiko-bot
2026-09-19 17:01 ` SJ Park
2026-09-20 2:37 ` Donggeun Yoo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260919071324.1583280-2-donggeunyoo.kernel@gmail.com \
--to=donggeunyoo.kernel@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=damon@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=sj@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.