From: sashiko-bot@kernel.org
To: "Ravi Jonnalagadda" <ravis.opensrc@gmail.com>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH v3 3/9] mm/damon: add perf-event overflow handler feeding the report ring
Date: Sat, 03 Oct 2026 21:22:31 +0000 [thread overview]
Message-ID: <20261003212231.7C0761F0089B@smtp.kernel.org> (raw)
In-Reply-To: <20261003-damon-perf-rfc-v3-send-2026-10-03-v3-3-0f00417b41bc@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] mm/damon: uninitialized memory read of data->data_src in damon_perf_overflow()
- [Medium] mm/damon: off-by-one bounds check artificially limits max probes
--
commit 96712c62a34715ea96102373f3c70dda9da07873
Author: Ravi Jonnalagadda <ravis.opensrc@gmail.com>
mm/damon: add perf-event overflow handler feeding the report ring
This commit adds a PMU-agnostic perf-event overflow handler that feeds access
reports into DAMON. It runs in NMI context and translates hardware overflow
samples into physical or virtual address reports using a per-CPU ring buffer.
> diff --git a/mm/damon/perf_source.c b/mm/damon/perf_source.c
> --- /dev/null
> +++ b/mm/damon/perf_source.c
[ ... ]
> +static void damon_perf_overflow(struct perf_event *perf_event,
> + struct perf_sample_data *data,
> + struct pt_regs *regs)
> +{
[ ... ]
> + if (!report.paddr && !report.vaddr) {
> + this_cpu_inc(damon_perf_samples_filtered);
> + return;
> + }
> +
> + report.is_write = !!(data->data_src.mem_op & PERF_MEM_OP_STORE);
[Severity: High]
Is it safe to unconditionally read data->data_src.mem_op here?
The perf_sample_data structure is allocated on the stack by the PMU interrupt
handler and only partially initialized:
include/linux/perf_event.h:perf_sample_data_init() {
...
data->sample_flags = PERF_SAMPLE_PERIOD;
data->period = period;
data->dyn_size = 0;
...
}
If the underlying PMU does not support data source tracking (i.e.
PERF_SAMPLE_DATA_SRC is not set in data->sample_flags), data->data_src will
contain uninitialized stack garbage.
Should this read be conditionally guarded by checking if data->sample_flags &
PERF_SAMPLE_DATA_SRC is set, to avoid feeding random access reports into
DAMON?
[ ... ]
> +int damon_perf_probe_setup(struct damon_ctx *ctx,
> + struct damon_probe *probe,
> + struct damon_perf_probe_event *event)
> +{
[ ... ]
> + /* Compute probe_idx by walking ctx->probes list */
> + damon_for_each_probe(p, ctx) {
> + if (p == probe)
> + break;
> + idx++;
> + }
> + /*
> + * Probe indices are 1-based (0 is the zero-init sentinel).
> + * With DAMON_MAX_PROBES slots (0..DAMON_MAX_PROBES-1), valid probe
> + * indices are 1..DAMON_MAX_PROBES-1, so the 0-based list position
> + * must be < DAMON_MAX_PROBES-1.
> + */
> + if (idx >= DAMON_MAX_PROBES - 1) {
> + err = -ENOSPC;
> + goto release_owner;
> + }
[Severity: Medium]
Does this bounds check artificially limit the maximum number of allowed probes
by one?
The array has DAMON_MAX_PROBES elements, meaning a 1-based probe_idx can
safely be DAMON_MAX_PROBES (which translates to array index
DAMON_MAX_PROBES - 1).
If a user attempts to configure exactly DAMON_MAX_PROBES probes, won't this
check prematurely return -ENOSPC and drop the final slot?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261003-damon-perf-rfc-v3-send-2026-10-03-v3-0-0f00417b41bc@gmail.com?part=3
next prev parent reply other threads:[~2026-10-03 21:22 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 21:07 [RFC PATCH v3 0/9] mm/damon: hardware-sampled access reports Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 1/9] mm/damon/paddr: remove page_fault access check primitive Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 2/9] mm/damon/core: replace the access report buffer with per-context rings Ravi Jonnalagadda
2026-10-03 21:22 ` sashiko-bot
2026-10-04 8:30 ` Kunwu Chan
2026-10-05 9:09 ` Ravi Jonnalagadda
2026-10-04 9:10 ` Kunwu Chan
2026-10-05 9:11 ` Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 3/9] mm/damon: add perf-event overflow handler feeding the report ring Ravi Jonnalagadda
2026-10-03 21:22 ` sashiko-bot [this message]
2026-10-03 21:07 ` [RFC PATCH v3 4/9] mm/damon/ops-common: use probe-weighted score when probe weights are set Ravi Jonnalagadda
2026-10-03 21:15 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 5/9] mm/damon: add perf_event prep type, core lifecycle, and PMU arm/disarm Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 6/9] mm/damon/sysfs: expose perf_event prep attributes Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 7/9] mm/damon/tests/drain-kunit: kunit for report rings and ring drain Ravi Jonnalagadda
2026-10-03 21:17 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 8/9] mm/damon/core: cap the region merge threshold per target Ravi Jonnalagadda
2026-10-03 21:18 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 9/9] mm/damon/core: allow both primitives disabled when a perf probe is present Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003212231.7C0761F0089B@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=damon@lists.linux.dev \
--cc=ravis.opensrc@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox