Re: [PATCH v3 1/2] mm/page_counter: avoid integer overflow in effective_protection()
From: Johannes Weiner
Date: Thu Sep 03 2026 - 10:15:01 EST
On Thu, Sep 03, 2026 at 11:19:51AM +0800, Ridong Chen wrote:
> From: Ridong Chen <chenridong@xxxxxxxxxx>
>
> effective_protection() scales a parent's protection by a ratio of page
> counts, e.g. for recursive protection:
>
> (parent_effective - siblings_protected) * (usage - protected)
> / (parent_usage - siblings_protected)
>
> The multiply is done at unsigned long width before dividing. On systems
> with >= 16TB RAM the product can exceed 2^64 and wrap, giving a bogus
> protection value and silently breaking memory.min/low enforcement.
>
> Use mul_u64_u64_div_u64() to multiply in a 128-bit intermediate. Because
> usage and parent_usage are not read atomically (a child is charged
> before its parent), usage - protected can briefly exceed the divisor,
> making the quotient overflow 64 bits and trap (#DE on x86). Cap it so
> the ratio stays <= 1.
>
> Reported by the sashiko review tool [1].
>
> [1] https://sashiko.dev/#/patchset/20260826133054.88529-1-ridong.chen@xxxxxxxxx?part=1
>
> Fixes: bc50bcc6e00b ("mm: memcontrol: clean up and document effective low/min calculations")
> Fixes: 8a931f801340 ("mm: memcontrol: recursive memory.low protection")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: Claude:claude-opus-4-8
> Reviewed-by: Barry Song <baohua@xxxxxxxxxx>
> Signed-off-by: Ridong Chen <chenridong@xxxxxxxxxx>
> ---
> mm/page_counter.c | 19 +++++++++++++------
> 1 file changed, 13 insertions(+), 6 deletions(-)
>
> diff --git a/mm/page_counter.c b/mm/page_counter.c
> index 661e0f2a5127..e8bd512069c5 100644
> --- a/mm/page_counter.c
> +++ b/mm/page_counter.c
> @@ -8,6 +8,7 @@
> #include <linux/page_counter.h>
> #include <linux/atomic.h>
> #include <linux/kernel.h>
> +#include <linux/math64.h>
> #include <linux/string.h>
> #include <linux/sched.h>
> #include <linux/bug.h>
> @@ -356,7 +357,8 @@ static unsigned long effective_protection(unsigned long usage,
> * otherwise get a smaller chunk than what they claimed.
> */
> if (siblings_protected > parent_effective)
> - return protected * parent_effective / siblings_protected;
> + return mul_u64_u64_div_u64(protected, parent_effective,
> + siblings_protected);
>
> /*
> * Ok, utilized protection of all children is within what the
> @@ -397,13 +399,18 @@ static unsigned long effective_protection(unsigned long usage,
> if (parent_effective > siblings_protected &&
> parent_usage > siblings_protected &&
> usage > protected) {
> - unsigned long unclaimed;
> + unsigned long unclaimed = parent_effective - siblings_protected;
> + unsigned long unprotected = usage - protected;
> + unsigned long parent_unprotected = parent_usage - siblings_protected;
>
> - unclaimed = parent_effective - siblings_protected;
> - unclaimed *= usage - protected;
> - unclaimed /= parent_usage - siblings_protected;
> + /*
> + * The usages aren't read atomically, so a child can transiently
> + * appear to use more than its parent, making the ratio exceed 1
> + * and the quotient overflow 64 bits (#DE on x86). Cap it.
> + */
> + unprotected = min(unprotected, parent_unprotected);
Looks correct to me. But a few nits on readability, since this code
already is quite painfully complicated.
Please don't do math in the declaration block.
`unclaimed` made a bit more sense when it held *this group's* final
share of the unclaimed protection. As an intermediate, it's *the
parent's* unclaimed protection.
Put together, it should look something like this:
unsigned long parent_unclaimed, parent_unprotected, unprotected;
parent_unclaimed = parent_effective - siblings_protected;
parent_unprotected = parent_usage - siblings_protected;
unprotected = usage - protected;
/* overflow comment */
unprotected = min(usage - protected, parent_unprotected);
ep += mul_u64_u64_div_u64(parent_unclaimed, unprotected, parent_unprotected);
With that,
Reviewed-by: Johannes Weiner <hannes@xxxxxxxxxxx>