* [PATCH 6.18.y] mm/damon/core-kunit: handle region split failure in filter_out()
[not found] <2026090830-think-magical-cf80@gregkh>
@ 2026-09-09 4:04 ` SJ Park
2026-09-09 4:15 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: SJ Park @ 2026-09-09 4:04 UTC (permalink / raw)
To: stable; +Cc: damon, SJ Park, Brendan Higgins, Andrew Morton
damos_test_filter_out() test checks if damos_filter_match() of an address
filter splits the region as expected under a given condition. But, the
test continued regardless of the split successes. As a result, the later
part of the test could dereference invalid pointers that returned from
damon_next_region(). Further, it could corrupt memory from
damon_destroy_region().
The consequent user impact (memory corruption) is quite bad. The
realistic user impact would be limited, though. It would affect only test
run setups.
Fix it by exiting early for the number of regions test failure.
The issue was discovered [1] by Sashiko.
Link: https://lore.kernel.org/20260718001442.87129-5-sj@kernel.org
Link: https://lore.kernel.org/20260714142352.100478-1-sj@kernel.org [1]
Fixes: 26713c890875 ("mm/damon/core-test: add a unit test for __damos_filter_out()")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 6.6.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
(cherry picked from commit 3423fe70395210e2f0cd795270292f6a27cd57b5)
---
mm/damon/tests/core-kunit.h | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/mm/damon/tests/core-kunit.h b/mm/damon/tests/core-kunit.h
index 6687778752728..801407b481cdc 100644
--- a/mm/damon/tests/core-kunit.h
+++ b/mm/damon/tests/core-kunit.h
@@ -588,6 +588,8 @@ static void damos_test_filter_out(struct kunit *test)
KUNIT_EXPECT_EQ(test, r->ar.start, DAMON_MIN_REGION * 1);
KUNIT_EXPECT_EQ(test, r->ar.end, DAMON_MIN_REGION * 2);
KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2);
+ if (damon_nr_regions(t) != 2)
+ goto out;
r2 = damon_next_region(r);
KUNIT_EXPECT_EQ(test, r2->ar.start, DAMON_MIN_REGION * 2);
KUNIT_EXPECT_EQ(test, r2->ar.end, DAMON_MIN_REGION * 4);
@@ -602,11 +604,14 @@ static void damos_test_filter_out(struct kunit *test)
KUNIT_EXPECT_EQ(test, r->ar.start, DAMON_MIN_REGION * 2);
KUNIT_EXPECT_EQ(test, r->ar.end, DAMON_MIN_REGION * 6);
KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2);
+ if (damon_nr_regions(t) != 2)
+ goto out;
r2 = damon_next_region(r);
KUNIT_EXPECT_EQ(test, r2->ar.start, DAMON_MIN_REGION * 6);
KUNIT_EXPECT_EQ(test, r2->ar.end, DAMON_MIN_REGION * 8);
damon_destroy_region(r2, t);
+out:
damon_free_target(t);
damos_free_filter(f);
}
--
2.47.3
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH 6.18.y] mm/damon/core-kunit: handle region split failure in filter_out()
2026-09-09 4:04 ` [PATCH 6.18.y] mm/damon/core-kunit: handle region split failure in filter_out() SJ Park
@ 2026-09-09 4:15 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-09 4:15 UTC (permalink / raw)
To: SJ Park; +Cc: damon
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The exact same missing check for region split failure exists in `damon_test_split_at()`, leading to an out-of-bounds read.
--
commit fd822a4546c77b8ec92e7e67206ab99aafb176a1
Author: SJ Park <sj@kernel.org>
Subject: mm/damon/core-kunit: handle region split failure in filter_out()
The damos_test_filter_out() test checks if damos_filter_match() splits a
region as expected, but continued regardless of split successes. As a
result, the later part of the test could dereference invalid pointers
returned from damon_next_region() or corrupt memory from
damon_destroy_region(). This commit fixes it by exiting early when the
region split fails.
Link: https://lore.kernel.org/20260718001442.87129-5-sj@kernel.org
Link: https://lore.kernel.org/20260714142352.100478-1-sj@kernel.org [1]
> diff --git a/mm/damon/tests/core-kunit.h b/mm/damon/tests/core-kunit.h
> index 6687778752728..801407b481cdc 100644
> --- a/mm/damon/tests/core-kunit.h
> +++ b/mm/damon/tests/core-kunit.h
> @@ -588,6 +588,8 @@ static void damos_test_filter_out(struct kunit *test)
> KUNIT_EXPECT_EQ(test, r->ar.start, DAMON_MIN_REGION * 1);
> KUNIT_EXPECT_EQ(test, r->ar.end, DAMON_MIN_REGION * 2);
> KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2);
> + if (damon_nr_regions(t) != 2)
> + goto out;
> r2 = damon_next_region(r);
[Severity: High]
This is a pre-existing issue, but since this patch fixes the missing split
verification here, should a similar check be added to damon_test_split_at() in
the same file?
In damon_test_split_at(), the code calls damon_split_region_at() and then
unconditionally accesses the next region:
damon_split_region_at(t, r, 25);
KUNIT_EXPECT_EQ(test, r->ar.start, 0ul);
KUNIT_EXPECT_EQ(test, r->ar.end, 25ul);
r_new = damon_next_region(r);
KUNIT_EXPECT_EQ(test, r_new->ar.start, 25ul);
If the split fails, r remains the only region in the list. Calling
damon_next_region(r) would then return an invalid pointer derived from the
list head. Dereferencing r_new->ar.start could cause an out-of-bounds read
and a potential kernel panic.
Does damon_test_split_at() need an early exit if the split fails to prevent
this memory corruption during testing?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260909040431.171803-1-sj@kernel.org?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-09 4:15 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <2026090830-think-magical-cf80@gregkh>
2026-09-09 4:04 ` [PATCH 6.18.y] mm/damon/core-kunit: handle region split failure in filter_out() SJ Park
2026-09-09 4:15 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox