From: Andrea Righi <arighi@nvidia.com>
To: Tejun Heo <tj@kernel.org>, David Vernet <void@manifault.com>,
Changwoo Min <changwoo@igalia.com>,
John Stultz <jstultz@google.com>
Cc: Ingo Molnar <mingo@redhat.com>,
Peter Zijlstra <peterz@infradead.org>,
Juri Lelli <juri.lelli@redhat.com>,
Vincent Guittot <vincent.guittot@linaro.org>,
Dietmar Eggemann <dietmar.eggemann@arm.com>,
Steven Rostedt <rostedt@goodmis.org>,
Ben Segall <bsegall@google.com>, Mel Gorman <mgorman@suse.de>,
Valentin Schneider <vschneid@redhat.com>,
K Prateek Nayak <kprateek.nayak@amd.com>,
Christian Loehle <christian.loehle@arm.com>,
David Dai <david.dai@linux.dev>, Koba Ko <kobak@nvidia.com>,
Aiqun Yu <aiqun.yu@oss.qualcomm.com>,
Shuah Khan <shuah@kernel.org>,
sched-ext@lists.linux.dev, linux-kernel@vger.kernel.org
Subject: [PATCH 08/12] sched_ext: Skip ops.runnable() when nested in SCX_CALL_OP_TASK
Date: Thu, 2 Jul 2026 19:09:24 +0200 [thread overview]
Message-ID: <20260702171909.1994478-9-arighi@nvidia.com> (raw)
In-Reply-To: <20260702171909.1994478-1-arighi@nvidia.com>
ops.running() can pull in enqueue_task_scx() -> ops.runnable() on the
same current task while kf_tasks[] save/restore is still insufficient
for every BPF/kfunc combination, leading to NULL dispatches and stack
corruption.
Track SCX_CALL_OP_TASK nesting in current->scx.kf_nest (incremented by
all SCX_CALL_OP_TASK* macros) and omit the ops.runnable() callback when
non-zero. The full enqueue path including ops.enqueue() still runs, only
the runnable hook is skipped in this case.
Signed-off-by: Andrea Righi <arighi@nvidia.com>
---
include/linux/sched/ext.h | 7 +++++++
kernel/sched/ext/ext.c | 3 ++-
kernel/sched/ext/internal.h | 6 ++++++
3 files changed, 15 insertions(+), 1 deletion(-)
diff --git a/include/linux/sched/ext.h b/include/linux/sched/ext.h
index e599bb86f8acd..a0c2077216094 100644
--- a/include/linux/sched/ext.h
+++ b/include/linux/sched/ext.h
@@ -201,6 +201,13 @@ struct sched_ext_entity {
s32 holding_cpu;
s32 selected_cpu;
struct task_struct *kf_tasks[2]; /* see SCX_CALL_OP_TASK() */
+ /*
+ * Nesting depth of SCX_CALL_OP_TASK() on this task as %current (e.g.
+ * during schedule() %current is still the previous task). Used to skip
+ * ops.runnable() when invoked from inside another task op such as
+ * ops.running() to avoid breaking BPF re-entrance guarantees.
+ */
+ u32 kf_nest;
struct list_head runnable_node; /* rq->scx.runnable_list */
unsigned long runnable_at;
diff --git a/kernel/sched/ext/ext.c b/kernel/sched/ext/ext.c
index 4cefe5acb36ff..c48d043dbe58f 100644
--- a/kernel/sched/ext/ext.c
+++ b/kernel/sched/ext/ext.c
@@ -1862,7 +1862,8 @@ static void enqueue_task_scx(struct rq *rq, struct task_struct *p, int core_enq_
rq->scx.nr_running++;
add_nr_running(rq, 1);
- if (SCX_HAS_OP(sch, runnable) && !task_on_rq_migrating(p))
+ if (SCX_HAS_OP(sch, runnable) && !task_on_rq_migrating(p) &&
+ !READ_ONCE(current->scx.kf_nest))
SCX_CALL_OP_TASK(sch, runnable, rq, p, enq_flags);
if (enq_flags & SCX_ENQ_WAKEUP)
diff --git a/kernel/sched/ext/internal.h b/kernel/sched/ext/internal.h
index 7d92826fc3a5f..1774e44aebcf7 100644
--- a/kernel/sched/ext/internal.h
+++ b/kernel/sched/ext/internal.h
@@ -1804,11 +1804,13 @@ do { \
struct task_struct *__scx_kf0_sv = current->scx.kf_tasks[0]; \
struct task_struct *__scx_kf1_sv = current->scx.kf_tasks[1]; \
\
+ current->scx.kf_nest++; \
current->scx.kf_tasks[0] = task; \
current->scx.kf_tasks[1] = NULL; \
SCX_CALL_OP((sch), op, locked_rq, task, ##args); \
current->scx.kf_tasks[0] = __scx_kf0_sv; \
current->scx.kf_tasks[1] = __scx_kf1_sv; \
+ current->scx.kf_nest--; \
} while (0)
#define SCX_CALL_OP_TASK_RET(sch, op, locked_rq, task, args...) \
@@ -1817,11 +1819,13 @@ do { \
struct task_struct *__scx_kf0_sv = current->scx.kf_tasks[0]; \
struct task_struct *__scx_kf1_sv = current->scx.kf_tasks[1]; \
\
+ current->scx.kf_nest++; \
current->scx.kf_tasks[0] = task; \
current->scx.kf_tasks[1] = NULL; \
__ret = SCX_CALL_OP_RET((sch), op, locked_rq, task, ##args); \
current->scx.kf_tasks[0] = __scx_kf0_sv; \
current->scx.kf_tasks[1] = __scx_kf1_sv; \
+ current->scx.kf_nest--; \
__ret; \
})
@@ -1831,11 +1835,13 @@ do { \
struct task_struct *__scx_kf0_sv = current->scx.kf_tasks[0]; \
struct task_struct *__scx_kf1_sv = current->scx.kf_tasks[1]; \
\
+ current->scx.kf_nest++; \
current->scx.kf_tasks[0] = task0; \
current->scx.kf_tasks[1] = task1; \
__ret = SCX_CALL_OP_RET((sch), op, locked_rq, task0, task1, ##args); \
current->scx.kf_tasks[0] = __scx_kf0_sv; \
current->scx.kf_tasks[1] = __scx_kf1_sv; \
+ current->scx.kf_nest--; \
__ret; \
})
--
2.55.0
next prev parent reply other threads:[~2026-07-02 17:20 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-02 17:09 [PATCHSET v2 sched_ext/for-7.3] sched: Make proxy execution compatible with sched_ext Andrea Righi
2026-07-02 17:09 ` [PATCH 01/12] sched/core: Skip migration disabled tasks in proxy execution Andrea Righi
2026-07-02 18:17 ` K Prateek Nayak
2026-07-02 18:37 ` Andrea Righi
2026-07-02 18:21 ` Peter Zijlstra
2026-07-02 18:34 ` Andrea Righi
2026-07-02 17:09 ` [PATCH 02/12] sched/core: Skip put_prev_task/set_next_task re-entry for sched_ext donors Andrea Righi
2026-07-02 18:24 ` Peter Zijlstra
2026-07-02 18:46 ` Andrea Righi
2026-07-02 17:09 ` [PATCH 03/12] sched_ext: Split curr|donor references properly Andrea Righi
2026-07-03 6:10 ` Aiqun(Maria) Yu
2026-07-03 8:37 ` Andrea Righi
2026-07-02 17:09 ` [PATCH 04/12] sched_ext: Avoid migrating blocked tasks with proxy execution Andrea Righi
2026-07-03 8:02 ` Aiqun(Maria) Yu
2026-07-03 20:05 ` Andrea Righi
2026-07-02 17:09 ` [PATCH 05/12] sched_ext: Fix TOCTOU race in consume_remote_task() Andrea Righi
2026-07-02 17:09 ` [PATCH 06/12] sched_ext: Fix ops.running/stopping() pairing for proxy-exec donors Andrea Righi
2026-07-02 17:09 ` [PATCH 07/12] sched_ext: Save/restore kf_tasks[] when task ops nest Andrea Righi
2026-07-02 17:09 ` Andrea Righi [this message]
2026-07-02 17:09 ` [PATCH 09/12] sched_ext: Delegate proxy donor admission to BPF schedulers Andrea Righi
2026-07-02 18:41 ` K Prateek Nayak
2026-07-02 19:10 ` Andrea Righi
2026-07-02 17:09 ` [PATCH 10/12] sched_ext: Add selftest for blocked donor admission Andrea Righi
2026-07-02 17:09 ` [PATCH 11/12] sched_ext: scx_qmap: Add proxy execution support Andrea Righi
2026-07-02 17:09 ` [PATCH 12/12] sched: Allow enabling proxy exec with sched_ext Andrea Righi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260702171909.1994478-9-arighi@nvidia.com \
--to=arighi@nvidia.com \
--cc=aiqun.yu@oss.qualcomm.com \
--cc=bsegall@google.com \
--cc=changwoo@igalia.com \
--cc=christian.loehle@arm.com \
--cc=david.dai@linux.dev \
--cc=dietmar.eggemann@arm.com \
--cc=jstultz@google.com \
--cc=juri.lelli@redhat.com \
--cc=kobak@nvidia.com \
--cc=kprateek.nayak@amd.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mgorman@suse.de \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=rostedt@goodmis.org \
--cc=sched-ext@lists.linux.dev \
--cc=shuah@kernel.org \
--cc=tj@kernel.org \
--cc=vincent.guittot@linaro.org \
--cc=void@manifault.com \
--cc=vschneid@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®