DAMON development mailing list
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ravi Jonnalagadda" <ravis.opensrc@gmail.com>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH v3 9/9] mm/damon/core: allow both primitives disabled when a perf probe is present
Date: Sat, 03 Oct 2026 21:20:49 +0000	[thread overview]
Message-ID: <20261003212050.213C61F0089B@smtp.kernel.org> (raw)
In-Reply-To: <20261003-damon-perf-rfc-v3-send-2026-10-03-v3-9-0f00417b41bc@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] mm: destructive silent clearing of PTE accessed bits
- [High] mm: uninitialized sampling_addr read leads to out-of-bounds PFN lookup
--

commit 73703d94b2ed32c7f44c1db6e359a4902509dc91
Author: Ravi Jonnalagadda <ravis.opensrc@gmail.com>

mm/damon/core: allow both primitives disabled when a perf probe is present

The sample control validation requires exactly one software access check
primitive, page_table or page_fault, to be enabled.  A context carrying a
perf-event probe needs neither: the probe drives the access signal
through its report ring and the drain, so region access rates and ages
update with both primitives off.

> diff --git a/mm/damon/core.c b/mm/damon/core.c
> index c2c74d0daf957..04a1cccbc2f5d 100644
> --- a/mm/damon/core.c
> +++ b/mm/damon/core.c

[ ... ]

> @@ -2390,6 +2387,14 @@ static int __damon_commit_ctx(struct damon_ctx *dst, struct damon_ctx *src,
>  
>  	if (!damon_valid_probe_params(src))
>  		return -EINVAL;
> +	/*
> +	 * A probe-driven context needs no software primitive.  Validate this
> +	 * before anything is committed to @dst, so a rejected configuration
> +	 * cannot leave a live commit with its PMU events already armed.
> +	 */
> +	if (!damon_has_event_driven_probes(src) &&
> +	    damon_primitives_enabled_invalid(&src->sample_control.primitives_enabled))
> +		return -EINVAL;

[Severity: High]
Does this short-circuiting unintentionally allow both primitives to be enabled
concurrently when a probe is present?

Because damon_primitives_enabled_invalid() checks if both are enabled or
both are disabled, bypassing it allows both configurations.

If both page_table and page_fault are enabled, does this permanently destroy
system-wide page access history and break LRU memory reclaim algorithms?

In kdamond_fn(), the page_fault primitive takes precedence during the check
phase:

mm/damon/core.c:kdamond_fn() {
    ...
		if (ctx->sample_control.primitives_enabled.page_fault)
			max_merge_score = kdamond_apply_zero_access_report(ctx);
		else if (!access_check_disabled && ctx->ops.check_accesses)
			max_merge_score = ctx->ops.check_accesses(ctx);
    ...
}

Because the 'else if' is skipped, the hardware PTE accessed bits cleared
earlier by ctx->ops.prepare_access_checks() are never read back.

[Severity: High]
Does this relaxation also introduce an uninitialized read that leads to an
out-of-bounds PFN lookup?

If a context is configured with both primitives disabled and an event-driven
probe with a weight of 0, damon_has_probe_weights(ctx) returns false, which
causes access_check_disabled to evaluate to false.

Because page_table is false, ctx->ops.prepare_access_checks() skips
initialization, leaving r->sampling_addr completely uninitialized.

Since both are disabled, kdamond_fn() forces the execution of the access check
primitive:

mm/damon/core.c:kdamond_fn() {
    ...
		else if (!access_check_disabled && ctx->ops.check_accesses)
			max_merge_score = ctx->ops.check_accesses(ctx);
    ...
}

This calculates a physical address from this garbage memory in
__damon_pa_check_access():

mm/damon/paddr.c:__damon_pa_check_access() {
    ...
	phys_addr_t sampling_addr = damon_pa_phys_addr(
			r->sampling_addr, addr_unit);
    ...
}

Can this lead to out-of-bounds PFN lookups, unpredictable behavior, and
potential kernel crashes or information leaks?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003-damon-perf-rfc-v3-send-2026-10-03-v3-0-0f00417b41bc@gmail.com?part=9

      reply	other threads:[~2026-10-03 21:20 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03 21:07 [RFC PATCH v3 0/9] mm/damon: hardware-sampled access reports Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 1/9] mm/damon/paddr: remove page_fault access check primitive Ravi Jonnalagadda
2026-10-03 21:20   ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 2/9] mm/damon/core: replace the access report buffer with per-context rings Ravi Jonnalagadda
2026-10-03 21:22   ` sashiko-bot
2026-10-04  8:30   ` Kunwu Chan
2026-10-05  9:09     ` Ravi Jonnalagadda
2026-10-04  9:10   ` Kunwu Chan
2026-10-05  9:11     ` Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 3/9] mm/damon: add perf-event overflow handler feeding the report ring Ravi Jonnalagadda
2026-10-03 21:22   ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 4/9] mm/damon/ops-common: use probe-weighted score when probe weights are set Ravi Jonnalagadda
2026-10-03 21:15   ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 5/9] mm/damon: add perf_event prep type, core lifecycle, and PMU arm/disarm Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 6/9] mm/damon/sysfs: expose perf_event prep attributes Ravi Jonnalagadda
2026-10-03 21:20   ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 7/9] mm/damon/tests/drain-kunit: kunit for report rings and ring drain Ravi Jonnalagadda
2026-10-03 21:17   ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 8/9] mm/damon/core: cap the region merge threshold per target Ravi Jonnalagadda
2026-10-03 21:18   ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 9/9] mm/damon/core: allow both primitives disabled when a perf probe is present Ravi Jonnalagadda
2026-10-03 21:20   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003212050.213C61F0089B@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=damon@lists.linux.dev \
    --cc=ravis.opensrc@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox