]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
mm/damon/reclaim: skip damon_call() if ctx has not started
authorSJ Park <sj@kernel.org>
Mon, 3 Aug 2026 13:46:44 +0000 (06:46 -0700)
committerAndrew Morton <akpm@linux-foundation.org>
Wed, 5 Aug 2026 03:02:03 +0000 (20:02 -0700)
Patch series "mm/damon/{reclaim,lru_sort}: fix commit_inputs infinite
hang".

Writing 'Y' to commit_inputs parameters of DAMON_RECLAIM and
DAMON_LRU_SORT before the modules were ever turned on causes infinite
hang.  Fix those.

The issue was discovered [1] by Sashiko.

This patch (of 2):

DAMON_RECLAIM calls damon_call() for commit_inputs parameter user input if
the DAMON context is initialized.  The context could be initialized, but
not yet successfully started.  In the case, damon_call() could
indefinitely hang.  Read the comment on damon_call() for more detail.  Fix
the problem by memorizing if the DAMON context has ever successfully
started, and skip damon_call() if it has not.

This issue can easily be reproduced by writing Y to commit_inputs on a
system that DAMON_RECLAIM was not turned on before.

Link: https://lore.kernel.org/20260803134646.16640-1-sj@kernel.org
Link: https://lore.kernel.org/20260803134646.16640-2-sj@kernel.org
Link: https://lore.kernel.org/20260802173021.762-1-sj@kernel.org
Fixes: de3c60e1c831 ("mm/damon: add synchronous commit for commit_inputs")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Liew Rui Yan <aethernet65535@gmail.com>
Cc: <stable@vger.kernel.org> # 7.2.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
mm/damon/reclaim.c

index 11b70d0a9a6f0a364e3d2557d7bd5ad7fd26ccec..a1a65b1270c8dbe9ce96b6d5aaf7ecc92a70d96d 100644 (file)
@@ -276,6 +276,8 @@ static int damon_reclaim_commit_inputs_fn(void *arg)
        return damon_reclaim_apply_parameters();
 }
 
+static bool damon_reclaim_damon_has_started;
+
 static int damon_reclaim_commit_inputs_store(const char *val,
                                             const struct kernel_param *kp)
 {
@@ -296,11 +298,8 @@ static int damon_reclaim_commit_inputs_store(const char *val,
        if (!commit_inputs_request)
                return 0;
 
-       /*
-        * Skip damon_call() if ctx is not initialized to avoid
-        * NULL pointer dereference.
-        */
-       if (!ctx)
+       /* Skip damon_call() if ctx has not successfully started. */
+       if (!damon_reclaim_damon_has_started)
                return -EINVAL;
 
        err = damon_call(ctx, &control);
@@ -347,6 +346,8 @@ static int damon_reclaim_turn(bool on)
        err = damon_start(&ctx, 1, true);
        if (err)
                return err;
+       if (!damon_reclaim_damon_has_started)
+               damon_reclaim_damon_has_started = true;
        return damon_call(ctx, &call_control);
 }