From: sashiko-bot@kernel.org
To: "SJ Park" <sj@kernel.org>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH v2 1/7] mm/damon/core: introduce damos_quota_goal->complement
Date: Sat, 19 Sep 2026 01:25:09 +0000 [thread overview]
Message-ID: <20260919012510.22CD61F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260919011359.88921-2-sj@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mm: Integer underflow in DAMOS_QUOTA_SOME_MEM_PSI_US complement calculation
--
commit f2de2d4493473c2c847f3ad213eaef640f0e1600
Author: SJ Park <sj@kernel.org>
mm/damon/core: introduce damos_quota_goal->complement
Introduce damos_quota_goal->complement for specifying whether to use a
complemented value of the given goal target metric. Add the field to
the data structure and implement essential core support. Handle the
flag in the quota goal commit and current quota goal metric value
retrieval.
> diff --git a/mm/damon/core.c b/mm/damon/core.c
> index 2258b72da7a78..9fd08cbfacd8c 100644
> --- a/mm/damon/core.c
> +++ b/mm/damon/core.c
[ ... ]
> @@ -3238,6 +3239,23 @@ static void damos_set_quota_goal_current_value(struct damon_ctx *c,
> default:
> break;
> }
> + if (!goal->complement)
> + return;
> +
> + /* updte current_value to complemented value */
> +
> + /* for user_input, users set complemented value on their own */
> + if (goal->metric == DAMOS_QUOTA_USER_INPUT)
> + return;
> + if (goal->metric == DAMOS_QUOTA_SOME_MEM_PSI_US) {
> + goal->current_value = s->quota.reset_interval * 1000 -
> + goal->current_value;
[Severity: High]
Does this unsigned subtraction underflow if goal->current_value exceeds
s->quota.reset_interval * 1000?
If goal->current_value exceeds the nominal reset interval, which can happen on
the first iteration when initialized to an arbitrarily large user-provided
target_value, or on subsequent iterations if kernel scheduling delays cause the
actual elapsed time between callbacks to exceed the nominal reset_interval,
this subtraction will underflow and produce a massive current_value near
ULONG_MAX.
This large value is then passed to damos_quota_score(), which computes a
normalized score that maxes out the feedback loop, forcing the tuned quota
limit to drop aggressively.
> + return;
> + }
> + if (goal->current_value < 10000)
> + goal->current_value = 10000 - goal->current_value;
> + else
> + goal->current_value = 0;
> }
>
> /* Return the highest score since it makes schemes least aggressive */
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260919011359.88921-1-sj@kernel.org?part=1
next prev parent reply other threads:[~2026-09-19 1:25 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-19 1:13 [RFC PATCH v2 0/7] mm/damon: introduce damos quota goal target metric complement flag SJ Park
2026-09-19 1:13 ` [RFC PATCH v2 1/7] mm/damon/core: introduce damos_quota_goal->complement SJ Park
2026-09-19 1:25 ` sashiko-bot [this message]
2026-09-19 1:27 ` SJ Park
2026-09-19 1:13 ` [RFC PATCH v2 2/7] mm/damon: add complement argument to damos_new_quota_goal() SJ Park
2026-09-19 1:23 ` sashiko-bot
2026-09-19 1:36 ` SJ Park
2026-09-19 1:13 ` [RFC PATCH v2 3/7] mm/damon/sysfs-schemes: support quota goal complement flag SJ Park
2026-09-19 1:26 ` sashiko-bot
2026-09-19 1:37 ` SJ Park
2026-09-19 1:13 ` [RFC PATCH v2 4/7] mm/damon/tests/core-kunit: test quota_goal->complement commit SJ Park
2026-09-19 1:17 ` sashiko-bot
2026-09-19 1:13 ` [RFC PATCH v2 5/7] Docs/mm/damon/design: document damos quota goal complement flag SJ Park
2026-09-19 1:16 ` sashiko-bot
2026-09-19 1:13 ` [RFC PATCH v2 6/7] Docs/admin-guide/mm/damon/usage: update for quota goal complement file SJ Park
2026-09-19 1:16 ` sashiko-bot
2026-09-19 1:13 ` [RFC PATCH v2 7/7] Docs/ABI/damon: update for quota goal metric complement sysfs file SJ Park
2026-09-19 1:23 ` sashiko-bot
2026-09-19 1:38 ` SJ Park
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260919012510.22CD61F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=damon@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox