DAMON development mailing list
 help / color / mirror / Atom feed
* [PATCH v2] mm/damon/core: fix false positive in
@ 2026-09-02  8:18 Liew Rui Yan
  2026-09-02  8:29 ` sashiko-bot
  2026-09-02  9:02 ` Liew Rui Yan
  0 siblings, 2 replies; 3+ messages in thread
From: Liew Rui Yan @ 2026-09-02  8:18 UTC (permalink / raw)
  To: SJ Park; +Cc: Andrew Morton, damon, linux-mm, linux-kernel, Liew Rui Yan,
	stable

When setting goal_tuner to 'temporal', if the goal is achieved,
quota->esz_bp will be set to zero.  In this case, damos_quota_is_full()
will always return true, even if no regions have been tried to apply at
all.  This causes qt_exceeds to increase unexpectedly.

Fix it by:

- Returning false in damos_quota_is_full() when quota->charged_sz is
  zero.
- Adding an early exit in damon_do_apply_schemes() for schemes with zero
  esz.

Fixes: c7ec7d5f6b3d ("mm/damon/core: handle <min_region_sz remaining quota as empty")
Cc: <stable@vger.kernel.org> # v7.2.x
Signed-off-by: Liew Rui Yan <aethernet65535@gmail.com>
---

Changes from v1:
- v1: https://lore.kernel.org/damon/20260901105925.106186-1-aethernet65535@gmail.com
- Changed the check in damos_quota_is_full() from '!quota->esz' to
  '!quota->charged_sz', because the former is an upper bound, while the
  latter represents the actual quota usage.
- Added an early exit in damon_do_apply_schemes() to prevent a scheme
  with zero esz from being evaluated by damos_quota_is_full().
- Changed patch title, original title: always return false when esz is
  zero

---
 mm/damon/core.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/mm/damon/core.c b/mm/damon/core.c
index 8e3ded1a2cf6..de78ad56c8b3 100644
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -2560,6 +2560,8 @@ static bool damos_quota_is_full(struct damos_quota *quota,
 {
 	if (!damos_quota_is_set(quota))
 		return false;
+	if (!quota->charged_sz)
+		return false;
 	if (quota->charged_sz >= quota->esz)
 		return true;
 	/*
@@ -2666,6 +2668,9 @@ static void damon_do_apply_schemes(struct damon_ctx *c,
 		if (!s->wmarks.activated)
 			continue;
 
+		if (!quota->esz)
+			continue;
+
 		/* Check the quota */
 		if (damos_quota_is_full(quota, c->min_region_sz))
 			continue;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH v2] mm/damon/core: fix false positive in
  2026-09-02  8:18 [PATCH v2] mm/damon/core: fix false positive in Liew Rui Yan
@ 2026-09-02  8:29 ` sashiko-bot
  2026-09-02  9:02 ` Liew Rui Yan
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-02  8:29 UTC (permalink / raw)
  To: Liew Rui Yan; +Cc: damon

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The newly added early exit `if (!quota->esz)` in `damon_do_apply_schemes()` unintentionally skips and completely breaks all DAMOS schemes that do not have quotas configured.
- [Medium] The new condition `if (!quota->charged_sz)` in `damos_quota_is_full()` incorrectly skips quota exhaustion checks when a configured quota is smaller than `min_region_sz`, violating per-region quota semantics and leading to statistic inflation and wasted CPU cycles.
--

commit b189466ffcadd150b11edbb63a99f1fb0477b8b5
Author: Liew Rui Yan <aethernet65535@gmail.com>

mm/damon/core: fix false positive in

This commit aims to fix a false positive in damos_quota_is_full() when
goal_tuner is 'temporal' and the goal is achieved, causing quota->esz_bp
to drop to zero. It adds checks for zero charged_sz and zero esz to
prevent unexpectedly increasing qt_exceeds.

> diff --git a/mm/damon/core.c b/mm/damon/core.c
> index df22621765911..f8c784df24600 100644
> --- a/mm/damon/core.c
> +++ b/mm/damon/core.c
> @@ -2655,6 +2655,8 @@ static bool damos_quota_is_full(struct damos_quota *quota,
>  {
>  	if (!damos_quota_is_set(quota))
>  		return false;
> +	if (!quota->charged_sz)
> +		return false;

[Severity: Medium]
Does this unconditionally bypass the remaining quota check when no regions
have been charged yet?

If a DAMOS scheme is evaluated with an effective quota (quota->esz) that
is greater than 0 but strictly less than c->min_region_sz, returning false
here skips the final check in this function:

	return quota->esz - quota->charged_sz < min_region_sz;

Could this cause the scheme to continue evaluating all targets and regions,
only to calculate a zero size later in damos_apply_scheme() due to
insufficient quota? This would artificially inflate s->stat.nr_tried for
every region while wasting CPU cycles applying zero bytes.

>  	if (quota->charged_sz >= quota->esz)
>  		return true;

[ ... ]

> @@ -2750,6 +2752,9 @@ static void damon_do_apply_schemes(struct damon_ctx *c,
>  		if (!s->wmarks.activated)
>  			continue;
>  
> +		if (!quota->esz)
> +			continue;
> +

[Severity: High]
Will this newly added check completely skip valid DAMOS schemes that simply
do not have quotas configured?

When a user creates a scheme without quota limits (ms == 0, sz == 0, and
no goals), damos_quota_init() initializes quota->esz to 0. Since
damos_adjust_quota() leaves esz unmodified for un-set quotas, esz remains 0.

Because this check happens before damos_quota_is_full() (which normally
handles non-quota schemes safely by returning false via damos_quota_is_set()),
won't this cause damon_do_apply_schemes() to unconditionally skip all
schemes that lack a quota?

>  		/* Check the quota */
>  		if (damos_quota_is_full(quota, c->min_region_sz))
>  			continue;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260902081825.18931-1-aethernet65535@gmail.com?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH v2] mm/damon/core: fix false positive in
  2026-09-02  8:18 [PATCH v2] mm/damon/core: fix false positive in Liew Rui Yan
  2026-09-02  8:29 ` sashiko-bot
@ 2026-09-02  9:02 ` Liew Rui Yan
  1 sibling, 0 replies; 3+ messages in thread
From: Liew Rui Yan @ 2026-09-02  9:02 UTC (permalink / raw)
  To: aethernet65535; +Cc: akpm, damon, linux-kernel, linux-mm, sj, stable

On Wed, 02 Sep 2026 16:18:25 +0800 Liew Rui Yan <aethernet65535@gmail.com> wrote:

> When setting goal_tuner to 'temporal', if the goal is achieved,
> quota->esz_bp will be set to zero.  In this case, damos_quota_is_full()
> will always return true, even if no regions have been tried to apply at
> all.  This causes qt_exceeds to increase unexpectedly.
> 
> Fix it by:
> 
> - Returning false in damos_quota_is_full() when quota->charged_sz is
>   zero.
> - Adding an early exit in damon_do_apply_schemes() for schemes with zero
>   esz.
> 
> Fixes: c7ec7d5f6b3d ("mm/damon/core: handle <min_region_sz remaining quota as empty")
> Cc: <stable@vger.kernel.org> # v7.2.x
> Signed-off-by: Liew Rui Yan <aethernet65535@gmail.com>
> ---
> 
> Changes from v1:
> - v1: https://lore.kernel.org/damon/20260901105925.106186-1-aethernet65535@gmail.com
> - Changed the check in damos_quota_is_full() from '!quota->esz' to
>   '!quota->charged_sz', because the former is an upper bound, while the
>   latter represents the actual quota usage.
> - Added an early exit in damon_do_apply_schemes() to prevent a scheme
>   with zero esz from being evaluated by damos_quota_is_full().
> - Changed patch title, original title: always return false when esz is
>   zero
> 
> ---
>  mm/damon/core.c | 5 +++++
>  1 file changed, 5 insertions(+)
> 
> diff --git a/mm/damon/core.c b/mm/damon/core.c
> index 8e3ded1a2cf6..de78ad56c8b3 100644
> --- a/mm/damon/core.c
> +++ b/mm/damon/core.c
> @@ -2560,6 +2560,8 @@ static bool damos_quota_is_full(struct damos_quota *quota,
>  {
>  	if (!damos_quota_is_set(quota))
>  		return false;
> +	if (!quota->charged_sz)
> +		return false;
>  	if (quota->charged_sz >= quota->esz)
>  		return true;
>  	/*
> @@ -2666,6 +2668,9 @@ static void damon_do_apply_schemes(struct damon_ctx *c,
>  		if (!s->wmarks.activated)
>  			continue;
>  
> +		if (!quota->esz)
> +			continue;
> +
>  		/* Check the quota */
>  		if (damos_quota_is_full(quota, c->min_region_sz))
>  			continue;
> -- 
> 2.55.0
> 
> 

Please ignore this patch.  The title was truncated, so I've reposted it.
If Sashiko provides a report in this thread that differs from the
reposted version, I'll forward it as well.

Best regards,
Rui Yan

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-02  9:02 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02  8:18 [PATCH v2] mm/damon/core: fix false positive in Liew Rui Yan
2026-09-02  8:29 ` sashiko-bot
2026-09-02  9:02 ` Liew Rui Yan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox