Re: [RFC PATCH 3/9] mm/damon/paddr: respect folio end for DAMOS_STAT

SJ Park <[email protected]> Sat, 1 Aug 2026 13:07:11 -0700
Newsgroups dev.linux.lists.damon
Message-ID <[email protected]>
On Sat, 01 Aug 2026 18:21:01 +0000 [email protected] wrote:

> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> 
> Pre-existing issues:
> - [High] Incomplete fix for large folio address iteration boundary bug.
> --
> 
> --- Patch [3]: [RFC PATCH 3/9] mm/damon/paddr: respect folio end for DAMOS_STAT ---
> commit b98d6f7836f4a90b6724f683127a934a339f77d5
> Author: SJ Park <[email protected]>
> 
> mm/damon/paddr: respect folio end for DAMOS_STAT
> 
> This commit fixes an issue in damon_pa_stat() where advancing the address
> by folio_size(folio) could skip subsequent folios if the start address
> is unaligned within a large folio. It corrects this by advancing the
> address to exactly the start address of the next folio.
> 
> > diff --git a/mm/damon/paddr.c b/mm/damon/paddr.c
> > index 5c6c3a597fd0b..2ab7b3842701e 100644
> > --- a/mm/damon/paddr.c
> > +++ b/mm/damon/paddr.c
> > @@ -379,7 +379,7 @@ static unsigned long damon_pa_stat(struct damon_region *r,
> >  
> >  		if (!damos_pa_filter_out(s, folio))
> >  			*sz_filter_passed += folio_size(folio) / addr_unit;
> > -		addr += folio_size(folio);
> > +		addr = PFN_PHYS(folio_pfn(folio)) + folio_size(folio);
> 
> [Severity: High]
> This is a pre-existing issue, but does this same bug exist in other DAMON
> operations that iterate over folios?
> 
> For example, looking at damon_pa_pageout():
> 
> mm/damon/paddr.c:damon_pa_pageout() {
>     ...
> 		else
> 			list_add(&folio->lru, &folio_list);
> put_folio:
> 		addr += folio_size(folio);
> 		folio_put(folio);
> 	}
>     ...
> }
> 
> It appears damon_pa_pageout(), damon_pa_de_activate(), and damon_pa_migrate()
> all still advance the address by folio_size(folio) instead of calculating the
> exact folio end.
> 
> Could these operations also overshoot subsequent memory and skip valid memory
> folios if the region starts unaligned inside a large folio?

A later patch of this series is fixinfg the bug.

> 
> >  		folio_put(folio);
> >  	}
> >  	s->last_applied = folio;
> 
> -- 
> Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=3


Thanks,
SJ