From: sashiko-bot@kernel.org
To: "SeongJae Park" <sj@kernel.org>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH v3 05/28] mm/damon/core: introduce damon_region->probe_hits
Date: Sat, 16 May 2026 18:54:35 +0000 [thread overview]
Message-ID: <20260516185436.1ECEFC19425@smtp.kernel.org> (raw)
In-Reply-To: <20260516183712.81393-6-sj@kernel.org>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Data type overflow of `probe_hits` array due to 8-bit `unsigned char` limit.
- [High] Integer overflow in `probe_hits` weighted average calculation on 32-bit systems.
--
commit b34f3f1254d83e9491235fb4e8e097729be04e60
Author: SeongJae Park <sj@kernel.org>
mm/damon/core: introduce damon_region->probe_hits
This commit adds a probe_hits array to the damon_region structure to track
the number of positive samples per region for each probe. It limits the
number of probes to a fixed maximum for a simpler implementation.
> diff --git a/include/linux/damon.h b/include/linux/damon.h
> index 32005b8b1f8cd..9e70239e5305f 100644
> --- a/include/linux/damon.h
> +++ b/include/linux/damon.h
[ ... ]
> @@ -80,6 +83,7 @@ struct damon_region {
> unsigned long sampling_addr;
> unsigned int nr_accesses;
> unsigned int nr_accesses_bp;
> + unsigned char probe_hits[DAMON_MAX_PROBES];
Does probe_hits need a wider type to prevent wrapping around?
Since the number of samples in an aggregation interval is determined by
aggr_interval / sample_interval, user-configurable values could cause the
sample count to exceed the 8-bit limit of unsigned char (255). This might
lead to silently wrapped monitoring statistics.
> struct list_head list;
>
> unsigned int age;
[ ... ]
> diff --git a/mm/damon/core.c b/mm/damon/core.c
> index 15f2795a1156f..e5667660b4cd9 100644
> --- a/mm/damon/core.c
> +++ b/mm/damon/core.c
[ ... ]
> @@ -2754,12 +2757,17 @@ static void damon_merge_two_regions(struct damon_target *t,
> struct damon_region *l, struct damon_region *r)
> {
> unsigned long sz_l = damon_sz_region(l), sz_r = damon_sz_region(r);
> + int i;
>
> l->nr_accesses = (l->nr_accesses * sz_l + r->nr_accesses * sz_r) /
> (sz_l + sz_r);
> l->nr_accesses_bp = l->nr_accesses * 10000;
> l->age = (l->age * sz_l + r->age * sz_r) / (sz_l + sz_r);
> l->ar.end = r->ar.end;
> + /* todo: do this for only installed probes */
> + for (i = 0; i < DAMON_MAX_PROBES; i++)
> + l->probe_hits[i] = (l->probe_hits[i] * sz_l + r->probe_hits[i]
> + * sz_r) / (sz_l + sz_r);
Could this weighted average calculation overflow on 32-bit architectures?
Both sz_l and sz_r are unsigned long, which is 32 bits on 32-bit systems.
If a region size is large (e.g., > 16.8MB) and probe_hits is up to 255,
multiplying them can exceed the 32-bit limit and wrap around, corrupting
the monitoring statistics.
It appears the nr_accesses calculation just above this has the exact same
flaw, and this patch propagates it to the new probe_hits array.
> damon_verify_merge_two_regions(l, r);
> damon_destroy_region(r, t);
> }
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260516183712.81393-1-sj@kernel.org?part=5
next prev parent reply other threads:[~2026-05-16 18:54 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-16 18:36 [RFC PATCH v3 00/28] mm/damon: introduce data attributes monitoring SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 01/28] mm/damon/core: introduce struct damon_probe SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 02/28] mm/damon/core: embed damon_probe objects in damon_ctx SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 03/28] mm/damon/core: introduce damon_filter SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 04/28] mm/damon/core: commit probes SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 05/28] mm/damon/core: introduce damon_region->probe_hits SeongJae Park
2026-05-16 18:54 ` sashiko-bot [this message]
2026-05-16 21:26 ` SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 06/28] mm/damon/core: introduce damon_ops->apply_probes SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 07/28] mm/damon/core: do data attributes monitoring SeongJae Park
2026-05-16 19:00 ` sashiko-bot
2026-05-16 21:33 ` SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 08/28] mm/damon/paddr: support " SeongJae Park
2026-05-16 19:05 ` sashiko-bot
2026-05-16 21:46 ` SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 09/28] mm/damon/sysfs: implement probes dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 10/28] mm/damon/sysfs: implement probe dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 11/28] mm/damon/sysfs: implement filters directory SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 12/28] mm/damon/sysfs: implement filter dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 13/28] mm/damon/sysfs: implement filter dir files SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 14/28] mm/damon/sysfs: setup probes on DAMON core API parameters SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 15/28] mm/damon/sysfs-schemes: implement tried_regions/<r>/probes/ SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 16/28] mm/damon/sysfs-schemes: implement probe dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 17/28] mm/damon/sysfs-schemes: implement probe/hits file SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 18/28] mm/damon: trace probe_hits SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 19/28] selftests/damon/sysfs.sh: test probes dir SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 20/28] Docs/mm/damon/design: document data attributes monitoring SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 21/28] Docs/admin-guide/mm/damon/usage: " SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 22/28] mm/damon/core: introduce DAMON_FILTER_TYPE_MEMCG SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 23/28] mm/damon/paddr: support DAMON_FILTER_TYPE_MEMCG SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 24/28] mm/damon/sysfs: add filters/<F>/path file SeongJae Park
2026-05-16 19:29 ` sashiko-bot
2026-05-16 21:51 ` SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 25/28] mm/damon/sysfs-schemes: move memcg_path_to_id() to sysfs-common SeongJae Park
2026-05-16 19:16 ` sashiko-bot
2026-05-16 21:54 ` SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 26/28] mm/damon/sysfs: setup damon_filter->memcg_id from path SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 27/28] Docs/mm/damon/design: update for memcg damon filter SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 28/28] Docs/admin-guide/mm/damon/usage: " SeongJae Park
2026-05-16 19:09 ` sashiko-bot
2026-05-16 21:57 ` SeongJae Park
2026-05-16 18:50 ` [RFC PATCH v3 00/28] mm/damon: introduce data attributes monitoring SeongJae Park
2026-05-16 22:03 ` SeongJae Park
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260516185436.1ECEFC19425@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=damon@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox