From: sashiko-bot@kernel.org
To: "Ravi Jonnalagadda" <ravis.opensrc@gmail.com>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH v3 9/9] mm/damon/core: allow both primitives disabled when a perf probe is present
Date: Sat, 03 Oct 2026 21:20:49 +0000 [thread overview]
Message-ID: <20261003212050.213C61F0089B@smtp.kernel.org> (raw)
In-Reply-To: <20261003-damon-perf-rfc-v3-send-2026-10-03-v3-9-0f00417b41bc@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] mm: destructive silent clearing of PTE accessed bits
- [High] mm: uninitialized sampling_addr read leads to out-of-bounds PFN lookup
--
commit 73703d94b2ed32c7f44c1db6e359a4902509dc91
Author: Ravi Jonnalagadda <ravis.opensrc@gmail.com>
mm/damon/core: allow both primitives disabled when a perf probe is present
The sample control validation requires exactly one software access check
primitive, page_table or page_fault, to be enabled. A context carrying a
perf-event probe needs neither: the probe drives the access signal
through its report ring and the drain, so region access rates and ages
update with both primitives off.
> diff --git a/mm/damon/core.c b/mm/damon/core.c
> index c2c74d0daf957..04a1cccbc2f5d 100644
> --- a/mm/damon/core.c
> +++ b/mm/damon/core.c
[ ... ]
> @@ -2390,6 +2387,14 @@ static int __damon_commit_ctx(struct damon_ctx *dst, struct damon_ctx *src,
>
> if (!damon_valid_probe_params(src))
> return -EINVAL;
> + /*
> + * A probe-driven context needs no software primitive. Validate this
> + * before anything is committed to @dst, so a rejected configuration
> + * cannot leave a live commit with its PMU events already armed.
> + */
> + if (!damon_has_event_driven_probes(src) &&
> + damon_primitives_enabled_invalid(&src->sample_control.primitives_enabled))
> + return -EINVAL;
[Severity: High]
Does this short-circuiting unintentionally allow both primitives to be enabled
concurrently when a probe is present?
Because damon_primitives_enabled_invalid() checks if both are enabled or
both are disabled, bypassing it allows both configurations.
If both page_table and page_fault are enabled, does this permanently destroy
system-wide page access history and break LRU memory reclaim algorithms?
In kdamond_fn(), the page_fault primitive takes precedence during the check
phase:
mm/damon/core.c:kdamond_fn() {
...
if (ctx->sample_control.primitives_enabled.page_fault)
max_merge_score = kdamond_apply_zero_access_report(ctx);
else if (!access_check_disabled && ctx->ops.check_accesses)
max_merge_score = ctx->ops.check_accesses(ctx);
...
}
Because the 'else if' is skipped, the hardware PTE accessed bits cleared
earlier by ctx->ops.prepare_access_checks() are never read back.
[Severity: High]
Does this relaxation also introduce an uninitialized read that leads to an
out-of-bounds PFN lookup?
If a context is configured with both primitives disabled and an event-driven
probe with a weight of 0, damon_has_probe_weights(ctx) returns false, which
causes access_check_disabled to evaluate to false.
Because page_table is false, ctx->ops.prepare_access_checks() skips
initialization, leaving r->sampling_addr completely uninitialized.
Since both are disabled, kdamond_fn() forces the execution of the access check
primitive:
mm/damon/core.c:kdamond_fn() {
...
else if (!access_check_disabled && ctx->ops.check_accesses)
max_merge_score = ctx->ops.check_accesses(ctx);
...
}
This calculates a physical address from this garbage memory in
__damon_pa_check_access():
mm/damon/paddr.c:__damon_pa_check_access() {
...
phys_addr_t sampling_addr = damon_pa_phys_addr(
r->sampling_addr, addr_unit);
...
}
Can this lead to out-of-bounds PFN lookups, unpredictable behavior, and
potential kernel crashes or information leaks?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261003-damon-perf-rfc-v3-send-2026-10-03-v3-0-0f00417b41bc@gmail.com?part=9
prev parent reply other threads:[~2026-10-03 21:20 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 21:07 [RFC PATCH v3 0/9] mm/damon: hardware-sampled access reports Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 1/9] mm/damon/paddr: remove page_fault access check primitive Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 2/9] mm/damon/core: replace the access report buffer with per-context rings Ravi Jonnalagadda
2026-10-03 21:22 ` sashiko-bot
2026-10-04 8:30 ` Kunwu Chan
2026-10-05 9:09 ` Ravi Jonnalagadda
2026-10-04 9:10 ` Kunwu Chan
2026-10-05 9:11 ` Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 3/9] mm/damon: add perf-event overflow handler feeding the report ring Ravi Jonnalagadda
2026-10-03 21:22 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 4/9] mm/damon/ops-common: use probe-weighted score when probe weights are set Ravi Jonnalagadda
2026-10-03 21:15 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 5/9] mm/damon: add perf_event prep type, core lifecycle, and PMU arm/disarm Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 6/9] mm/damon/sysfs: expose perf_event prep attributes Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 7/9] mm/damon/tests/drain-kunit: kunit for report rings and ring drain Ravi Jonnalagadda
2026-10-03 21:17 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 8/9] mm/damon/core: cap the region merge threshold per target Ravi Jonnalagadda
2026-10-03 21:18 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 9/9] mm/damon/core: allow both primitives disabled when a perf probe is present Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003212050.213C61F0089B@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=damon@lists.linux.dev \
--cc=ravis.opensrc@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox