From: SJ Park <sj@kernel.org>
To: SJ Park <sj@kernel.org>
Cc: sashiko-bot@kernel.org, damon@lists.linux.dev
Subject: Re: [RFC PATCH v1.1 1/8] mm/damon/core: safely validate src on damon_commit_ctx()
Date: Tue, 22 Sep 2026 05:27:10 -0700 [thread overview]
Message-ID: <20260922122711.2449-1-sj@kernel.org> (raw)
In-Reply-To: <20260702213558.96934-1-sj@kernel.org>
On Thu, 2 Jul 2026 14:35:58 -0700 SJ Park <sj@kernel.org> wrote:
> On Thu, 02 Jul 2026 21:21:42 +0000 sashiko-bot@kernel.org wrote:
[...]
> > [Severity: High]
> > This is a pre-existing issue, but does this unintentionally corrupt the running
> > quota state?
> >
> > When __damon_commit_ctx() is called with the running context (dst) as the
> > source, it copies the schemes via damon_commit_schemes(), which calls
> > damon_new_scheme() and passes a pointer to the active scheme's quota:
> >
> > mm/damon/core.c:damon_commit_schemes() {
> > ...
> > new_scheme = damon_new_scheme(&src_scheme->pattern,
> > src_scheme->action,
> > src_scheme->apply_interval_us,
> > &src_scheme->quota, &src_scheme->wmarks,
> > NUMA_NO_NODE);
> > ...
> > }
> >
> > damon_new_scheme() then calls damos_quota_init() on that provided quota
> > pointer:
> >
> > mm/damon/core.c:damon_new_scheme() {
> > ...
> > scheme->quota = *(damos_quota_init(quota));
> > ...
> > }
> >
> > damos_quota_init() zeroes out the fields in-place:
> >
> > mm/damon/core.c:damos_quota_init() {
> > ...
> > quota->esz = 0;
> > quota->total_charged_sz = 0;
> > ...
> > }
> >
> > This mutates the running scheme's quota state, which would make the quota
> > effectively "full" mid-interval and prevent the scheme from applying its
> > actions until the next reset interval.
>
> That doesn't matter because it is only testing purpose scheme, not the schemes
> of the running context.
>
> >
> > Since this patch moves this test context logic into the core
> > damon_commit_ctx(), doesn't this expose all API users like damon_reclaim
> > and damon_lru_sort to this state corruption when parameters are committed?
>
> So, no problem.
I was misunderstanding Sashiko's point. Karl is thankfully working [1] on
fixing this.
[1] https://lore.kernel.org/20260921003047.12041-2-kmehltretter@gmail.com
Thanks,
SJ
[...]
next prev parent reply other threads:[~2026-09-22 12:27 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-02 21:05 [RFC PATCH v1.1 0/8] mm/damon: validate all parameters in the core SJ Park
2026-07-02 21:05 ` [RFC PATCH v1.1 1/8] mm/damon/core: safely validate src on damon_commit_ctx() SJ Park
2026-07-02 21:21 ` sashiko-bot
2026-07-02 21:35 ` SJ Park
2026-09-22 12:27 ` SJ Park [this message]
2026-07-02 21:05 ` [RFC PATCH v1.1 2/8] mm/damon/core: do parameter testing commit on damon_start() SJ Park
2026-07-02 21:05 ` [RFC PATCH v1.1 3/8] mm/damon/sysfs: remove duplicated commit input validity check SJ Park
2026-07-02 21:05 ` [RFC PATCH v1.1 4/8] mm/damon/reclaim: remove duplicated min_region_sz power of 2 check SJ Park
2026-07-02 21:05 ` [RFC PATCH v1.1 5/8] mm/damon/lru_sort: remove duplicated min_region_sz power_of_2() check SJ Park
2026-07-02 21:20 ` sashiko-bot
2026-07-02 21:44 ` SJ Park
2026-07-02 21:05 ` [RFC PATCH v1.1 6/8] mm/damon: document region size validation in damon_set_regions() SJ Park
2026-07-02 21:19 ` sashiko-bot
2026-07-02 21:48 ` SJ Park
2026-07-02 21:05 ` [RFC PATCH v1.1 7/8] mm/damon/core: remove start, end check in damon_set_region_system_rams() SJ Park
2026-07-02 21:16 ` sashiko-bot
2026-07-02 21:50 ` SJ Park
2026-07-02 21:05 ` [RFC PATCH v1.1 8/8] mm/damon/sysfs: remove region size validation SJ Park
2026-07-02 21:15 ` sashiko-bot
2026-07-02 21:53 ` SJ Park
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922122711.2449-1-sj@kernel.org \
--to=sj@kernel.org \
--cc=damon@lists.linux.dev \
--cc=sashiko-bot@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox