The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH] mm/damon/core: handle zero intervals in damon_max_nr_accesses()
@ 2026-06-21 15:48 SeongJae Park
  2026-06-21 18:03 ` SeongJae Park
  0 siblings, 1 reply; 2+ messages in thread
From: SeongJae Park @ 2026-06-21 15:48 UTC (permalink / raw)
  To: Andrew Morton; +Cc: SeongJae Park, # 5 . 16 . x, damon, linux-kernel, linux-mm

damon_max_nr_accesses() causes a divide-by-zero if the sampling interval
is set to zero by the user.  If the aggregation interval is set to zero,
the function returns zero.  It is wrong, since the real maximum
nr_acceses in the setup should be one.  Worse yet, it can cause another
divide-by-zero from its caller, damon_hot_score(), since it uses
damon_max_nr_accesses() return value as a denominator.

Fix the problem by setting the denominator in the function as 1 when the
sampling interval is zero.  Also ensure the return value is always 1 or
greater.

The issue was discovered [1] by Sashiko.

[1] https://lore.kernel.org/20260619202459.145010-1-sj@kernel.org

Fixes: 198f0f4c58b9 ("mm/damon/vaddr,paddr: support pageout prioritization")
Cc: <stable@vger.kernel.org> # 5.16.x
Signed-off-by: SeongJae Park <sj@kernel.org>
---
Changes from RFC v1.1
- rfc v1.1: https://lore.kernel.org/20260620171413.89555-1-sj@kernel.org
- Wordsmith commit message.
- Drop RFC tag.
Changes from RFC v1
- rfc v1: https://lore.kernel.org/20260619205144.150664-1-sj@kernel.org
- Handle zero aggr_interval case.

 include/linux/damon.h | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/include/linux/damon.h b/include/linux/damon.h
index 64d75c78f4df4..02ac34537df9a 100644
--- a/include/linux/damon.h
+++ b/include/linux/damon.h
@@ -1066,9 +1066,13 @@ static inline bool damon_target_has_pid(const struct damon_ctx *ctx)
 
 static inline unsigned int damon_max_nr_accesses(const struct damon_attrs *attrs)
 {
-	/* {aggr,sample}_interval are unsigned long, hence could overflow */
-	return min(attrs->aggr_interval / attrs->sample_interval,
+	unsigned long sample_interval;
+	unsigned long max_nr_accesses;
+
+	sample_interval = attrs->sample_interval ? : 1;
+	max_nr_accesses = min(attrs->aggr_interval / sample_interval,
 			(unsigned long)UINT_MAX);
+	return max_nr_accesses ? : 1;
 }
 
 

base-commit: 7a58ae62cdf3c006a53b805bbb12079ab2621a07
-- 
2.47.3

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] mm/damon/core: handle zero intervals in damon_max_nr_accesses()
  2026-06-21 15:48 [PATCH] mm/damon/core: handle zero intervals in damon_max_nr_accesses() SeongJae Park
@ 2026-06-21 18:03 ` SeongJae Park
  0 siblings, 0 replies; 2+ messages in thread
From: SeongJae Park @ 2026-06-21 18:03 UTC (permalink / raw)
  To: SeongJae Park; +Cc: Andrew Morton, # 5 . 16 . x, damon, linux-kernel, linux-mm

On Sun, 21 Jun 2026 08:48:06 -0700 SeongJae Park <sj@kernel.org> wrote:

> damon_max_nr_accesses() causes a divide-by-zero if the sampling interval
> is set to zero by the user.  If the aggregation interval is set to zero,
> the function returns zero.  It is wrong, since the real maximum
> nr_acceses in the setup should be one.  Worse yet, it can cause another
> divide-by-zero from its caller, damon_hot_score(), since it uses
> damon_max_nr_accesses() return value as a denominator.
> 
> Fix the problem by setting the denominator in the function as 1 when the
> sampling interval is zero.  Also ensure the return value is always 1 or
> greater.
> 
> The issue was discovered [1] by Sashiko.
> 
> [1] https://lore.kernel.org/20260619202459.145010-1-sj@kernel.org
> 
> Fixes: 198f0f4c58b9 ("mm/damon/vaddr,paddr: support pageout prioritization")

Sashiko found [1] another bug that was introduced by another commit.  I will
repost this patch with a fix for the another bug.

[1] https://lore.kernel.org/20260621175849.91990-1-sj@kernel.org


Thanks,
SJ

[...]

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-06-21 18:04 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-21 15:48 [PATCH] mm/damon/core: handle zero intervals in damon_max_nr_accesses() SeongJae Park
2026-06-21 18:03 ` SeongJae Park

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox