[RFC PATCH v1.2 10/19] mm/damon/core: validate params for probe hits weighted sum overflow

From: SJ Park

Date: Thu Jul 09 2026 - 10:19:09 EST


damon_probe_hits_wsum() could overflow in weird setups. Users could set
the weight unreasonably high. They could also set the aggregation
interval unreasonably high compared to the sampling interval. Such user
setup is unlikely. Even if such setup is used,
damon_has_probe_weights() always returns false, so the overflow cannot
happen. The function may be completed in future, though. Even if the
overflow happens, the consequence is degraded monitoring results for the
unreasonable setup. It is just a trivial user experience issue.

It is still better to be prevented unless the cost is expensive. Avoid
the overflow by adding the parameter validation in the core layer
parameters validation function.

Signed-off-by: SJ Park <sj@xxxxxxxxxx>
---
mm/damon/core.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)

diff --git a/mm/damon/core.c b/mm/damon/core.c
index 4f1425e56950b..b585e4bf035f1 100644
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -1335,6 +1335,9 @@ static void damos_set_filters_default_reject(struct damos *s)
static bool damon_valid_probe_params(struct damon_ctx *ctx)
{
unsigned long sample_interval;
+ unsigned char max_probe_hits;
+ struct damon_probe *probe;
+ unsigned int wsum, wsum_to_add;

if (!damon_has_probe_weights(ctx))
return true;
@@ -1342,6 +1345,18 @@ static bool damon_valid_probe_params(struct damon_ctx *ctx)
sample_interval = ctx->attrs.sample_interval ? : 1;
if (ctx->attrs.aggr_interval / sample_interval > U8_MAX)
return false;
+
+ /* invlaid if probe hits weighted sum can overflow */
+ max_probe_hits = damon_nr_samples_per_aggr(&ctx->attrs);
+ wsum = 0;
+ damon_for_each_probe(probe, ctx) {
+ if (probe->weight > UINT_MAX / max_probe_hits)
+ return false;
+ wsum_to_add = probe->weight * max_probe_hits;
+ if (UINT_MAX - wsum < wsum_to_add)
+ return false;
+ wsum += wsum_to_add;
+ }
return true;
}

--
2.47.3