DAMON development mailing list
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ravi Jonnalagadda" <ravis.opensrc@gmail.com>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH v3 3/9] mm/damon: add perf-event overflow handler feeding the report ring
Date: Sat, 03 Oct 2026 21:22:31 +0000	[thread overview]
Message-ID: <20261003212231.7C0761F0089B@smtp.kernel.org> (raw)
In-Reply-To: <20261003-damon-perf-rfc-v3-send-2026-10-03-v3-3-0f00417b41bc@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] mm/damon: uninitialized memory read of data->data_src in damon_perf_overflow()
- [Medium] mm/damon: off-by-one bounds check artificially limits max probes
--

commit 96712c62a34715ea96102373f3c70dda9da07873
Author: Ravi Jonnalagadda <ravis.opensrc@gmail.com>

mm/damon: add perf-event overflow handler feeding the report ring

This commit adds a PMU-agnostic perf-event overflow handler that feeds access
reports into DAMON. It runs in NMI context and translates hardware overflow
samples into physical or virtual address reports using a per-CPU ring buffer.

> diff --git a/mm/damon/perf_source.c b/mm/damon/perf_source.c
> --- /dev/null
> +++ b/mm/damon/perf_source.c

[ ... ]

> +static void damon_perf_overflow(struct perf_event *perf_event,
> +				struct perf_sample_data *data,
> +				struct pt_regs *regs)
> +{

[ ... ]

> +	if (!report.paddr && !report.vaddr) {
> +		this_cpu_inc(damon_perf_samples_filtered);
> +		return;
> +	}
> +
> +	report.is_write = !!(data->data_src.mem_op & PERF_MEM_OP_STORE);

[Severity: High]
Is it safe to unconditionally read data->data_src.mem_op here?

The perf_sample_data structure is allocated on the stack by the PMU interrupt
handler and only partially initialized:

include/linux/perf_event.h:perf_sample_data_init() {
    ...
    data->sample_flags = PERF_SAMPLE_PERIOD;
    data->period = period;
    data->dyn_size = 0;
    ...
}

If the underlying PMU does not support data source tracking (i.e.
PERF_SAMPLE_DATA_SRC is not set in data->sample_flags), data->data_src will
contain uninitialized stack garbage.

Should this read be conditionally guarded by checking if data->sample_flags &
PERF_SAMPLE_DATA_SRC is set, to avoid feeding random access reports into
DAMON?

[ ... ]

> +int damon_perf_probe_setup(struct damon_ctx *ctx,
> +			   struct damon_probe *probe,
> +			   struct damon_perf_probe_event *event)
> +{

[ ... ]

> +	/* Compute probe_idx by walking ctx->probes list */
> +	damon_for_each_probe(p, ctx) {
> +		if (p == probe)
> +			break;
> +		idx++;
> +	}
> +	/*
> +	 * Probe indices are 1-based (0 is the zero-init sentinel).
> +	 * With DAMON_MAX_PROBES slots (0..DAMON_MAX_PROBES-1), valid probe
> +	 * indices are 1..DAMON_MAX_PROBES-1, so the 0-based list position
> +	 * must be < DAMON_MAX_PROBES-1.
> +	 */
> +	if (idx >= DAMON_MAX_PROBES - 1) {
> +		err = -ENOSPC;
> +		goto release_owner;
> +	}

[Severity: Medium]
Does this bounds check artificially limit the maximum number of allowed probes
by one?

The array has DAMON_MAX_PROBES elements, meaning a 1-based probe_idx can
safely be DAMON_MAX_PROBES (which translates to array index
DAMON_MAX_PROBES - 1). 

If a user attempts to configure exactly DAMON_MAX_PROBES probes, won't this
check prematurely return -ENOSPC and drop the final slot?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003-damon-perf-rfc-v3-send-2026-10-03-v3-0-0f00417b41bc@gmail.com?part=3

  reply	other threads:[~2026-10-03 21:22 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03 21:07 [RFC PATCH v3 0/9] mm/damon: hardware-sampled access reports Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 1/9] mm/damon/paddr: remove page_fault access check primitive Ravi Jonnalagadda
2026-10-03 21:20   ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 2/9] mm/damon/core: replace the access report buffer with per-context rings Ravi Jonnalagadda
2026-10-03 21:22   ` sashiko-bot
2026-10-04  8:30   ` Kunwu Chan
2026-10-05  9:09     ` Ravi Jonnalagadda
2026-10-04  9:10   ` Kunwu Chan
2026-10-05  9:11     ` Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 3/9] mm/damon: add perf-event overflow handler feeding the report ring Ravi Jonnalagadda
2026-10-03 21:22   ` sashiko-bot [this message]
2026-10-03 21:07 ` [RFC PATCH v3 4/9] mm/damon/ops-common: use probe-weighted score when probe weights are set Ravi Jonnalagadda
2026-10-03 21:15   ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 5/9] mm/damon: add perf_event prep type, core lifecycle, and PMU arm/disarm Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 6/9] mm/damon/sysfs: expose perf_event prep attributes Ravi Jonnalagadda
2026-10-03 21:20   ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 7/9] mm/damon/tests/drain-kunit: kunit for report rings and ring drain Ravi Jonnalagadda
2026-10-03 21:17   ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 8/9] mm/damon/core: cap the region merge threshold per target Ravi Jonnalagadda
2026-10-03 21:18   ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 9/9] mm/damon/core: allow both primitives disabled when a perf probe is present Ravi Jonnalagadda
2026-10-03 21:20   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003212231.7C0761F0089B@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=damon@lists.linux.dev \
    --cc=ravis.opensrc@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox