* [PATCH 6.6.y] mm/damon/core-kunit: handle region split failure in filter_out() [not found] <2026090831-operative-attribute-934e@gregkh> @ 2026-09-09 4:07 ` SJ Park 2026-09-09 4:14 ` sashiko-bot 2026-09-09 20:26 ` Sasha Levin 0 siblings, 2 replies; 3+ messages in thread From: SJ Park @ 2026-09-09 4:07 UTC (permalink / raw) To: stable; +Cc: damon, SJ Park, Brendan Higgins, Andrew Morton damos_test_filter_out() test checks if damos_filter_match() of an address filter splits the region as expected under a given condition. But, the test continued regardless of the split successes. As a result, the later part of the test could dereference invalid pointers that returned from damon_next_region(). Further, it could corrupt memory from damon_destroy_region(). The consequent user impact (memory corruption) is quite bad. The realistic user impact would be limited, though. It would affect only test run setups. Fix it by exiting early for the number of regions test failure. The issue was discovered [1] by Sashiko. Link: https://lore.kernel.org/20260718001442.87129-5-sj@kernel.org Link: https://lore.kernel.org/20260714142352.100478-1-sj@kernel.org [1] Fixes: 26713c890875 ("mm/damon/core-test: add a unit test for __damos_filter_out()") Signed-off-by: SJ Park <sj@kernel.org> Cc: Brendan Higgins <brendan.higgins@linux.dev> Cc: <stable@vger.kernel.org> # 6.6.x Signed-off-by: Andrew Morton <akpm@linux-foundation.org> (cherry picked from commit 3423fe70395210e2f0cd795270292f6a27cd57b5) Signed-off-by: SJ Park <sj@kernel.org> --- mm/damon/core-test.h | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/mm/damon/core-test.h b/mm/damon/core-test.h index a2aa410d6d0d0..853cb8902d5ef 100644 --- a/mm/damon/core-test.h +++ b/mm/damon/core-test.h @@ -497,6 +497,8 @@ static void damos_test_filter_out(struct kunit *test) KUNIT_EXPECT_EQ(test, r->ar.start, DAMON_MIN_REGION * 1); KUNIT_EXPECT_EQ(test, r->ar.end, DAMON_MIN_REGION * 2); KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2); + if (damon_nr_regions(t) != 2) + goto out; r2 = damon_next_region(r); KUNIT_EXPECT_EQ(test, r2->ar.start, DAMON_MIN_REGION * 2); KUNIT_EXPECT_EQ(test, r2->ar.end, DAMON_MIN_REGION * 4); @@ -510,11 +512,14 @@ static void damos_test_filter_out(struct kunit *test) KUNIT_EXPECT_EQ(test, r->ar.start, DAMON_MIN_REGION * 2); KUNIT_EXPECT_EQ(test, r->ar.end, DAMON_MIN_REGION * 6); KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2); + if (damon_nr_regions(t) != 2) + goto out; r2 = damon_next_region(r); KUNIT_EXPECT_EQ(test, r2->ar.start, DAMON_MIN_REGION * 6); KUNIT_EXPECT_EQ(test, r2->ar.end, DAMON_MIN_REGION * 8); damon_destroy_region(r2, t); +out: damon_free_target(t); damos_free_filter(f); } -- 2.47.3 ^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH 6.6.y] mm/damon/core-kunit: handle region split failure in filter_out() 2026-09-09 4:07 ` [PATCH 6.6.y] mm/damon/core-kunit: handle region split failure in filter_out() SJ Park @ 2026-09-09 4:14 ` sashiko-bot 2026-09-09 20:26 ` Sasha Levin 1 sibling, 0 replies; 3+ messages in thread From: sashiko-bot @ 2026-09-09 4:14 UTC (permalink / raw) To: SJ Park; +Cc: damon > damos_test_filter_out() test checks if damos_filter_match() of an address > filter splits the region as expected under a given condition. But, the > test continued regardless of the split successes. As a result, the later > part of the test could dereference invalid pointers that returned from > damon_next_region(). Further, it could corrupt memory from > damon_destroy_region(). > > The consequent user impact (memory corruption) is quite bad. The > realistic user impact would be limited, though. It would affect only test > run setups. > > Fix it by exiting early for the number of regions test failure. > > The issue was discovered [1] by Sashiko. > > Link: https://lore.kernel.org/20260718001442.87129-5-sj@kernel.org > Link: https://lore.kernel.org/20260714142352.100478-1-sj@kernel.org [1] > Fixes: 26713c890875 ("mm/damon/core-test: add a unit test for __damos_filter_out()") > Signed-off-by: SJ Park <sj@kernel.org> > Cc: Brendan Higgins <brendan.higgins@linux.dev> > Cc: <stable@vger.kernel.org> # 6.6.x > Signed-off-by: Andrew Morton <akpm@linux-foundation.org> > (cherry picked from commit 3423fe70395210e2f0cd795270292f6a27cd57b5) > Signed-off-by: SJ Park <sj@kernel.org> Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review · https://sashiko.dev/#/patchset/20260909040751.175004-1-sj@kernel.org?part=1 ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 6.6.y] mm/damon/core-kunit: handle region split failure in filter_out() 2026-09-09 4:07 ` [PATCH 6.6.y] mm/damon/core-kunit: handle region split failure in filter_out() SJ Park 2026-09-09 4:14 ` sashiko-bot @ 2026-09-09 20:26 ` Sasha Levin 1 sibling, 0 replies; 3+ messages in thread From: Sasha Levin @ 2026-09-09 20:26 UTC (permalink / raw) To: stable; +Cc: Sasha Levin, damon, SJ Park, Brendan Higgins, Andrew Morton > damos_test_filter_out() test checks if damos_filter_match() of an address > filter splits the region as expected under a given condition. But, the > test continued regardless of the split successes. Queued for 6.6, thanks. -- Thanks, Sasha ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-09 20:26 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <2026090831-operative-attribute-934e@gregkh>
2026-09-09 4:07 ` [PATCH 6.6.y] mm/damon/core-kunit: handle region split failure in filter_out() SJ Park
2026-09-09 4:14 ` sashiko-bot
2026-09-09 20:26 ` Sasha Levin
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for NNTP newsgroup(s).