From: sashiko-bot@kernel.org
To: "Ravi Jonnalagadda" <ravis.opensrc@gmail.com>
Cc: damon@lists.linux.dev
Subject: Re: [RFC PATCH v3 2/9] mm/damon/core: replace the access report buffer with per-context rings
Date: Sat, 03 Oct 2026 21:22:31 +0000 [thread overview]
Message-ID: <20261003212232.303EB1F0089C@smtp.kernel.org> (raw)
In-Reply-To: <20261003-damon-perf-rfc-v3-send-2026-10-03-v3-2-0f00417b41bc@gmail.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] mm: Off-by-one error drops valid reports for the maximum probe index
- [High] mm: Preempt-unsafe this_cpu_inc() usage in preemptible kthread context
- [Low] mm: Spurious target-lookup allocation failure warning when targets are zero
--
commit 8fff2ca2d88fc496c6ec48a611f9bfdad8cf1ae4
Author: Ravi Jonnalagadda <ravis.opensrc@gmail.com>
mm/damon/core: replace the access report buffer with per-context rings
This commit replaces the global access report buffer with per-context, per-CPU
SPSC rings for NMI-safe access reporting. It updates the kdamond drain logic
to process these rings using a binary search over a per-target region snapshot.
> diff --git a/mm/damon/core.c b/mm/damon/core.c
> index 886e068e78447..4fd1db12bc49b 100644
> --- a/mm/damon/core.c
> +++ b/mm/damon/core.c
[ ... ]
> +static void __kdamond_drain_ring(struct damon_ctx *ctx,
> + struct damon_target_lookup *tbl,
> + struct damon_report_ring __percpu *ring_pcpu,
> + cpumask_t *pending)
> +{
[ ... ]
> + while (tail != head) {
> + unsigned long stale_before;
> + int pidx;
> +
> + entry = &ring->entries[tail];
> + /*
> + * Use sample_interval (not aggr_interval) as the
> + * staleness window: entries older than one sample
> + * interval are from a previous monitoring tick and
> + * should not inflate the current aggregation window.
> + */
> + stale_before = jiffies -
> + usecs_to_jiffies(ctx->attrs.sample_interval);
> + if (time_before(entry->report_jiffies, stale_before)) {
> + this_cpu_inc(damon_samples_stale_drained);
[Severity: High]
Does this code trigger a BUG: using this_cpu_inc() in preemptible context
warning? __kdamond_drain_ring() runs in the kdamond kernel thread, which is a
fully preemptible context, but this_cpu_inc() is preempt-unsafe without
explicitly disabling preemption.
> + goto next;
> + }
> + pidx = entry->probe_idx;
> + /*
> + * Every entry in this ring is a perf-event report
> + * (probe_idx >= 1); damon_report_access() drops any
> + * DAMON_PROBE_IDX_NONE report before it reaches a ring.
> + * Reject only out-of-range indices (>= DAMON_MAX_PROBES)
> + * and, defensively, any non-positive value.
> + */
> + if (pidx <= 0 || pidx >= DAMON_MAX_PROBES)
[Severity: High]
Does this bounds check inadvertently discard reports for the 4th configured
probe? The probe_idx is 1-based, meaning valid indices range from 1 to
DAMON_MAX_PROBES (4). However, checking pidx >= DAMON_MAX_PROBES drops the
report if pidx == 4.
> + goto next;
> +
[ ... ]
> +static void kdamond_check_reported_accesses(struct damon_ctx *ctx)
> +{
> + struct damon_target_lookup *tbl;
> + unsigned int nr_targets = 0;
> +
> + /*
> + * Build the sorted region snapshot once for this drain. If the alloc
> + * fails, skip the drain this tick rather than falling back to a linear
> + * scan (a missed tick self-heals; a linear scan does not).
> + */
> + tbl = damon_build_target_lookup(ctx, &nr_targets);
> + if (!tbl) {
> + pr_warn_ratelimited(
> + "damon: target-lookup alloc failed; ring drain skipped this tick\n");
[Severity: Low]
Can this spam the kernel log with spurious warnings when 0 targets are
configured?
If a DAMON context is started with 0 targets, damon_build_target_lookup() sets
nr_targets to 0 and correctly returns NULL if the lookup buffer was never
previously allocated. This code misinterprets the NULL as an allocation failure.
> + return;
> + }
> +
> + if (damon_drains_ring_perf(ctx))
> + __kdamond_drain_ring(ctx, tbl, ctx->perf_rings,
> + &ctx->perf_pending);
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261003-damon-perf-rfc-v3-send-2026-10-03-v3-0-0f00417b41bc@gmail.com?part=2
next prev parent reply other threads:[~2026-10-03 21:22 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 21:07 [RFC PATCH v3 0/9] mm/damon: hardware-sampled access reports Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 1/9] mm/damon/paddr: remove page_fault access check primitive Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 2/9] mm/damon/core: replace the access report buffer with per-context rings Ravi Jonnalagadda
2026-10-03 21:22 ` sashiko-bot [this message]
2026-10-04 8:30 ` Kunwu Chan
2026-10-05 9:09 ` Ravi Jonnalagadda
2026-10-04 9:10 ` Kunwu Chan
2026-10-05 9:11 ` Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 3/9] mm/damon: add perf-event overflow handler feeding the report ring Ravi Jonnalagadda
2026-10-03 21:22 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 4/9] mm/damon/ops-common: use probe-weighted score when probe weights are set Ravi Jonnalagadda
2026-10-03 21:15 ` sashiko-bot
2026-10-03 21:07 ` [RFC PATCH v3 5/9] mm/damon: add perf_event prep type, core lifecycle, and PMU arm/disarm Ravi Jonnalagadda
2026-10-03 21:07 ` [RFC PATCH v3 6/9] mm/damon/sysfs: expose perf_event prep attributes Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 7/9] mm/damon/tests/drain-kunit: kunit for report rings and ring drain Ravi Jonnalagadda
2026-10-03 21:17 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 8/9] mm/damon/core: cap the region merge threshold per target Ravi Jonnalagadda
2026-10-03 21:18 ` sashiko-bot
2026-10-03 21:08 ` [RFC PATCH v3 9/9] mm/damon/core: allow both primitives disabled when a perf probe is present Ravi Jonnalagadda
2026-10-03 21:20 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003212232.303EB1F0089C@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=damon@lists.linux.dev \
--cc=ravis.opensrc@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox