DAMON development mailing list
 help / color / mirror / Atom feed
From: SeongJae Park <sj@kernel.org>
To: sashiko-bot@kernel.org
Cc: SeongJae Park <sj@kernel.org>, damon@lists.linux.dev
Subject: Re: [RFC PATCH v3 05/28] mm/damon/core: introduce damon_region->probe_hits
Date: Sat, 16 May 2026 14:26:34 -0700	[thread overview]
Message-ID: <20260516212634.2945-1-sj@kernel.org> (raw)
In-Reply-To: <20260516185436.1ECEFC19425@smtp.kernel.org>

On Sat, 16 May 2026 18:54:35 +0000 sashiko-bot@kernel.org wrote:

> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
> - [High] Data type overflow of `probe_hits` array due to 8-bit `unsigned char` limit.
> - [High] Integer overflow in `probe_hits` weighted average calculation on 32-bit systems.
> --
> 
> commit b34f3f1254d83e9491235fb4e8e097729be04e60
> Author: SeongJae Park <sj@kernel.org>
> 
> mm/damon/core: introduce damon_region->probe_hits
> 
> This commit adds a probe_hits array to the damon_region structure to track
> the number of positive samples per region for each probe. It limits the
> number of probes to a fixed maximum for a simpler implementation.
> 
> > diff --git a/include/linux/damon.h b/include/linux/damon.h
> > index 32005b8b1f8cd..9e70239e5305f 100644
> > --- a/include/linux/damon.h
> > +++ b/include/linux/damon.h
> [ ... ]
> > @@ -80,6 +83,7 @@ struct damon_region {
> >  	unsigned long sampling_addr;
> >  	unsigned int nr_accesses;
> >  	unsigned int nr_accesses_bp;
> > +	unsigned char probe_hits[DAMON_MAX_PROBES];
> 
> Does probe_hits need a wider type to prevent wrapping around?
> 
> Since the number of samples in an aggregation interval is determined by
> aggr_interval / sample_interval, user-configurable values could cause the
> sample count to exceed the 8-bit limit of unsigned char (255). This might
> lead to silently wrapped monitoring statistics.

Yes, but such configurations may be rare, so no blocker.
For more details, please read my previous reply [1] for same question.

> 
> >  	struct list_head list;
> >  
> >  	unsigned int age;
> [ ... ]
> > diff --git a/mm/damon/core.c b/mm/damon/core.c
> > index 15f2795a1156f..e5667660b4cd9 100644
> > --- a/mm/damon/core.c
> > +++ b/mm/damon/core.c
> [ ... ]
> > @@ -2754,12 +2757,17 @@ static void damon_merge_two_regions(struct damon_target *t,
> >  		struct damon_region *l, struct damon_region *r)
> >  {
> >  	unsigned long sz_l = damon_sz_region(l), sz_r = damon_sz_region(r);
> > +	int i;
> >  
> >  	l->nr_accesses = (l->nr_accesses * sz_l + r->nr_accesses * sz_r) /
> >  			(sz_l + sz_r);
> >  	l->nr_accesses_bp = l->nr_accesses * 10000;
> >  	l->age = (l->age * sz_l + r->age * sz_r) / (sz_l + sz_r);
> >  	l->ar.end = r->ar.end;
> > +	/* todo: do this for only installed probes */
> > +	for (i = 0; i < DAMON_MAX_PROBES; i++)
> > +		l->probe_hits[i] = (l->probe_hits[i] * sz_l + r->probe_hits[i]
> > +				* sz_r) / (sz_l + sz_r);
> 
> Could this weighted average calculation overflow on 32-bit architectures?
> 
> Both sz_l and sz_r are unsigned long, which is 32 bits on 32-bit systems.
> If a region size is large (e.g., > 16.8MB) and probe_hits is up to 255,
> multiplying them can exceed the 32-bit limit and wrap around, corrupting
> the monitoring statistics.
> 
> It appears the nr_accesses calculation just above this has the exact same
> flaw, and this patch propagates it to the new probe_hits array.

On 32bit systems, users could use the addr_unit to avoid this kind of issues.
So no blocker.

[1] https://lore.kernel.org/20260516003559.141476-1-sj@kernel.org


Thanks,
SJ

[...]

  reply	other threads:[~2026-05-16 21:27 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-16 18:36 [RFC PATCH v3 00/28] mm/damon: introduce data attributes monitoring SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 01/28] mm/damon/core: introduce struct damon_probe SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 02/28] mm/damon/core: embed damon_probe objects in damon_ctx SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 03/28] mm/damon/core: introduce damon_filter SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 04/28] mm/damon/core: commit probes SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 05/28] mm/damon/core: introduce damon_region->probe_hits SeongJae Park
2026-05-16 18:54   ` sashiko-bot
2026-05-16 21:26     ` SeongJae Park [this message]
2026-05-16 18:36 ` [RFC PATCH v3 06/28] mm/damon/core: introduce damon_ops->apply_probes SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 07/28] mm/damon/core: do data attributes monitoring SeongJae Park
2026-05-16 19:00   ` sashiko-bot
2026-05-16 21:33     ` SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 08/28] mm/damon/paddr: support " SeongJae Park
2026-05-16 19:05   ` sashiko-bot
2026-05-16 21:46     ` SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 09/28] mm/damon/sysfs: implement probes dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 10/28] mm/damon/sysfs: implement probe dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 11/28] mm/damon/sysfs: implement filters directory SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 12/28] mm/damon/sysfs: implement filter dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 13/28] mm/damon/sysfs: implement filter dir files SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 14/28] mm/damon/sysfs: setup probes on DAMON core API parameters SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 15/28] mm/damon/sysfs-schemes: implement tried_regions/<r>/probes/ SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 16/28] mm/damon/sysfs-schemes: implement probe dir SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 17/28] mm/damon/sysfs-schemes: implement probe/hits file SeongJae Park
2026-05-16 18:36 ` [RFC PATCH v3 18/28] mm/damon: trace probe_hits SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 19/28] selftests/damon/sysfs.sh: test probes dir SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 20/28] Docs/mm/damon/design: document data attributes monitoring SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 21/28] Docs/admin-guide/mm/damon/usage: " SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 22/28] mm/damon/core: introduce DAMON_FILTER_TYPE_MEMCG SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 23/28] mm/damon/paddr: support DAMON_FILTER_TYPE_MEMCG SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 24/28] mm/damon/sysfs: add filters/<F>/path file SeongJae Park
2026-05-16 19:29   ` sashiko-bot
2026-05-16 21:51     ` SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 25/28] mm/damon/sysfs-schemes: move memcg_path_to_id() to sysfs-common SeongJae Park
2026-05-16 19:16   ` sashiko-bot
2026-05-16 21:54     ` SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 26/28] mm/damon/sysfs: setup damon_filter->memcg_id from path SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 27/28] Docs/mm/damon/design: update for memcg damon filter SeongJae Park
2026-05-16 18:37 ` [RFC PATCH v3 28/28] Docs/admin-guide/mm/damon/usage: " SeongJae Park
2026-05-16 19:09   ` sashiko-bot
2026-05-16 21:57     ` SeongJae Park
2026-05-16 18:50 ` [RFC PATCH v3 00/28] mm/damon: introduce data attributes monitoring SeongJae Park
2026-05-16 22:03 ` SeongJae Park

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260516212634.2945-1-sj@kernel.org \
    --to=sj@kernel.org \
    --cc=damon@lists.linux.dev \
    --cc=sashiko-bot@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox