From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from CWXP265CU008.outbound.protection.outlook.com (mail-ukwestazon11020133.outbound.protection.outlook.com [52.101.195.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B95E5481FA5 for ; Tue, 25 Aug 2026 14:14:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.195.133 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787667263; cv=fail; b=YQf5YVABZhnQkXQ+fFH3rzBdL6TGg01pqksgykS5NgK03YMsY1uLhtzhSmParOJrhjxQVEe2jvVVwUw/fGjItyIYgNf3Mq7ZV5/+oZ3ULnu/7EBtngFWmWCgFt48dhpPEeoz5oJYjL7ByA7BR0cLP8bXZNuZB6wgYhPzac1M1zc= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787667263; c=relaxed/simple; bh=YoRoAWjSTqJdkb+9fOKFlYllN2OWsXbi0+F1RjG7p14=; h=From:To:Cc:Subject:Date:Message-ID:Content-Type:MIME-Version; b=YfnaDAKz/aeNJUWYReNicQ+pg6dWX2kRQQ50iL3+XupBcDOAiSw+/I4Nvbh+pbkLxbyXdehngeNuGKy+uUl8Uo+tro0kqaTlpVz/5HCu4i0JHmV4aize5mvLRrPvctA3yv+YgnhGORNFc/XLDUmkxqu0g0YbUiL/RPGiqHrXLJ0= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com; spf=pass smtp.mailfrom=atomlin.com; arc=fail smtp.client-ip=52.101.195.133 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=atomlin.com ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=m+BKd/00UN1dghL8arL1ZfrXVkovPEEQD/HxCzchfmHLdQPdMVsdefnEF2dvL2AmFCOIlK3eik1E3ULM0iLoTpK8ZFVjSmEAPqNX7eHcQZSlvEvtKQ/pDPD+AnZqxyH2p+2l1/Wjv4mLcv7+R+ztyGxiZOdYLcMELldEPwdbFpNTmukDByRJcoUutkv66qgMwuP5jRKTrW95VdUDYCK1Ywj8d//OFR7fmQEFhnr4xZP0AxmQsZ5KT0zDN7L9/C7eWHdQ/kNsgK1q0/1m/KGyhiXywa/gelzBBC/w45Rthzt1s1Zo1nUWeFwtrnr/pMvWsTsy7OBjl1rTL8ZTE0io+Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:MIME-Version; bh=LAapIcxSXwZ4/mGgH3rh0TqUODaEAoO1O9KEGQkqvNY=; b=WXIhlGviU6XNdzuIFmd8mQEFwC5p5Jny3l/Tcv54Shf4Y7MqXM/9jv50paZBLFsiBpwi7CPjIv8NBHD6xaU4m2RmDiAi6xVt3PNZQiUbuUrKiDY86zB/68n3DlawQqkUnvQCUGGDiReHAdH0qN8Scqdx72f6XWoN5hIe8jAErj0J3k+4lDzI3sph7uO+jE3HXFzV8R1pZLkBbudnQ2IM2VDHwdFxmjChjEFuizGXcJ9FDcww4WEwn+QuiiqV6NYShKdtXRFJEQQyJ4ENZ5YWiBxIAwoLTQK/SnwMKy8TeCh/yotfKKhOLx0JhJ8hfqvGOI2bCxKKJChBF5EzNw90MQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=atomlin.com; dmarc=pass action=none header.from=atomlin.com; dkim=pass header.d=atomlin.com; arc=none Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=atomlin.com; Received: from CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:183::5) by CWYP123MB8971.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:286::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.6; Tue, 25 Aug 2026 14:14:15 +0000 Received: from CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM ([fe80::cec4:77ab:262e:d230]) by CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM ([fe80::cec4:77ab:262e:d230%4]) with mapi id 15.21.0339.012; Tue, 25 Aug 2026 14:14:14 +0000 From: Aaron Tomlin To: mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org Cc: dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, zhanxusheng1024@gmail.com, neelx@suse.com, atomlin@atomlin.com, chjohnst@mail.com, mproche@mail.com, sean@ashe.io, steve@abita.co, rishil1999@outlook.com, linux-kernel@vger.kernel.org Subject: [PATCH v5 0/6] sched/debug: Introduce per-CPU debugfs files Date: Tue, 25 Aug 2026 10:14:07 -0400 Message-ID: <20260825141413.868997-1-atomlin@atomlin.com> X-Mailer: git-send-email 2.55.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: LO4P265CA0311.GBRP265.PROD.OUTLOOK.COM (2603:10a6:600:391::16) To CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:183::5) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CWLP123MB6607:EE_|CWYP123MB8971:EE_ X-MS-Office365-Filtering-Correlation-Id: 67ce8064-006e-46f6-76e3-08df02b32486 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|7416014|376014|366016|1800799024|10067099003|6133799003|3023799007|18002099003|56012099006; X-Microsoft-Antispam-Message-Info: dzqf0pdfFv9fd2/VFb6rL6d2E9pSJu+rlzu2nZEBvIikW+ayfvqeRpr9IM7iUZMvlWK6UgM+wTQE2S61M2jKTm2WdxFJ1bX/lv8tY69obreTWFUlbIJqBcvZ9Khcec0VfC4sSh10qu3KrcimTrXW/S4jp3y3iNTXbN1EY5P6/cTReZIR9e6/7nMzhHDFxgjpX+U3231L8fHrhI4RvCd1bD7ZO+2iOmNqS5rCAxJU64XsT/LgSWv4sCOVkFkeEdSHnJDWUSWtcDqULE+Ymf9APZ/a3UWzOJ7zJs+1NkPjg+oLsI8tQec1dAEXDL/HFMddGrv1pY6Cg3OCjH43Wm1VKdV3nS7toZXTmuy0mnALxnI4PpaxZg/2FDy9v3TzyLfwBxxkipC8sSfDe2N/VWwDpFCc3/0WzCxwiUnvT/vlDUUvsKmnw9TXooxKyW55WB79pdFjtijfLBDGaf6Pmnqt1/BIomWpR/XqgdBUnDtk8fFyHEfRchez9P6zfkD3EzzzVPBnTgc6HimXlgUNyhp6efglm5m4rvKuOxk6y3W3oxtAe3nUfs8Js8MK65PxPvOGnwwfLfhIZ4viUuHcG3AEqurNRLBbwld+Dmknc4bcb22m4rVeYtA7tXTNIrXq+GTzY1KvN7ICFV5AQEBCV3qN87/irOEHpMSnUSFBvUOEWFE= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(7416014)(376014)(366016)(1800799024)(10067099003)(6133799003)(3023799007)(18002099003)(56012099006);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?W5iC4rBDKCTFALnwR4YiV2h93yTcWDQmes8X7uZlWVxs2NGJoGVylg3RmFxj?= =?us-ascii?Q?qETtR/cXwZI0fRtZA5TpeQP6mhEULO9aNg+YABWrxgCBJXlNDN1xwwiWeeGY?= =?us-ascii?Q?qh8H+GzPELDirgoxY8wVNgpP28YV3vAzcISF1sF3SedeYb4/W7Eq3ioZ6FEr?= =?us-ascii?Q?BNo5mUXvzp5G6Eih9YU5WjNWzLPzCo/oQ0yVEqz2FFVUnqgTwZu7Hxvg6mhN?= =?us-ascii?Q?wVaWtssYiASh+6v+C8HFp6uGaiNMfhv959EiJtvNzd86z7tj4WPFnNhHonEu?= =?us-ascii?Q?2bRsO8Y6rr4RUXyees8IdWX2UH54VlJDItxhcgwWuC9bb+yvVBIKQdRth85N?= =?us-ascii?Q?SV4ZG919GHQAJhARrqI6e97626Xd0faesAm0CBhTwWIfwmY2IXWmBpSYRBGJ?= =?us-ascii?Q?sZpTvY08yblKUE14i1egm5+7IplNcZGhqtAJN22sKCgDzfr4SbWepl/CWhAh?= =?us-ascii?Q?Et1RKSpny0rVSbreLI6Mpq4h92o7ZKCAso9crnqVYfq4v5mnWVyDAnS9TNyX?= =?us-ascii?Q?ydNDMpRsdmQItgxoAA2htbcl6KxiDqoUbHWkgAJ6NFQziPbQT/eTSAn+Tg1h?= =?us-ascii?Q?Pp1ajbrkxJ7+Ubcdb1rzoEy9XRRNUqdJ5mQfTAD0TITQQTm1FVrTkz1D9CEr?= =?us-ascii?Q?rRdwjXEp2iNw5umSUwN0TQHbF3+HW5aUrshZoPpg9nbiUvNTutkK25zLwMg0?= =?us-ascii?Q?dMrfL+gHoC6J0GOhqW3Dag9aCI9+eEgcGvJ2pRUxKBz1yqGBd76bZnlSjePW?= =?us-ascii?Q?CqDhBtP10fcGxgzk0bxFu5HD34ebSauGr2NvJI+WmVokgWEFabmeFISx6cWp?= =?us-ascii?Q?inSdViIRit39a89x1YqmqH0ldUgAkMAJBdSI3bG/dbSXCUA8V4wlMr+pPloS?= =?us-ascii?Q?sz4K52YYuMsDiYaFXvqxCCgPU5WtgSqIfo/Siy7Q/f8/athfasurYfZbelhZ?= =?us-ascii?Q?WMbb0igOhZO1BAh8UTDK34s4aZN5aFsv8IgMRSqMwpvlMmC22X5ImMBPbH72?= =?us-ascii?Q?a0ySh3IyHm1B/2pJC0JFEb2SNdznRWmvfVA36EpZQAlIpYKHtUfqlc2lwKo3?= =?us-ascii?Q?FjLpceH4fjOscBxqGVo5FcPXRnWil4FTI0d/lVBE+xNkRax50ihURt+UY++f?= =?us-ascii?Q?ACEBAW/X/x4NeHnmLSL4BkCIvdlsXHOsII2hYb++CknK9zPlNuF8BeKihxiy?= =?us-ascii?Q?P5xkRFMTfJRNhY8luba4EQXPGRz0oj/EO0YQRGMuTRAIiatW5uVvWPWzl72a?= =?us-ascii?Q?vOZ0ikHZXvQ3JuYbCLfVZ4eNyEI+ZuijkQBFD3dBZ4hvy+lLdqZZgbm27pB8?= =?us-ascii?Q?df+LJrkkaDGKvsHMnOzNenM7ZQGw31yEooezZ/D/dAbwBxHg6Gl7vMFs44Xr?= =?us-ascii?Q?JGZWrJNeM9DY+TcyiX6BCn2MZTYNSDyJuYv5357rtjZk0p6d5JKUxuojyMp0?= =?us-ascii?Q?QOrZxCeVsAgqo/6opsdTtk1BXZ/hmbGI+Q6DuDLQSHRGKnp1+fc4ahC8RgZ3?= =?us-ascii?Q?yVCHeM29nE5SF1aLMrpsgLC7zBIITuoeOwPDyMGGmUK14NuKBNCr46gRZJz4?= =?us-ascii?Q?e+vKu7nG46qQcUslGvm23dKmNsCYw9dL4c2hdWmano0MctNxFSqfRhbDcDOV?= =?us-ascii?Q?eJgPg7yP+yfKM4tLS17xQ9FeuaFhFDAMxxeSWq8btLvrrEB4DorGoL6H02lr?= =?us-ascii?Q?mt6SYQM5egtAvjw1/N7+GbKriqvqAH4QK6nvJHFgvuH+5ppz?= X-OriginatorOrg: atomlin.com X-MS-Exchange-CrossTenant-Network-Message-Id: 67ce8064-006e-46f6-76e3-08df02b32486 X-MS-Exchange-CrossTenant-AuthSource: CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Aug 2026 14:14:14.7193 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: e6a32402-7d7b-4830-9a2b-76945bbbcb57 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: HuczgdBc24SKeh2UyhFmHau61rYpR/fYtjIXIIeHs7MS56pyvn8+UPkuLRr1IGR7ledComRv33q0LZvT8RifiQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: CWYP123MB8971 Hi Peter, Juri, Ingo, Vincent, This patch series addresses a few pre-existing memory safety and list traversal concurrency issues in scheduler debugfs handlers, and introduces per-CPU debugfs files under /sys/kernel/debug/sched/cpu/cpu/debug. Patch 1 introduces a new prerequisite patch that annotates struct rq's rd (root_domain) pointer with __rcu in kernel/sched/sched.h and updates lockless readers across the core scheduler to use rcu_dereference(), ensuring Sparse compliance and proper memory barriers on weakly ordered architectures. Patch 2 fixes a use-after-free in print_dl_rq() where cpu_rq(cpu)->rd is dereferenced locklessly to display deadline bandwidth statistics. During CPU hot-unplug or cgroup cpuset repartitioning events, partition_sched_domains() calls rq_attach_root() to detach the CPU from its root_domain and schedules free_rootdomain() via call_rcu(). Without an RCU read lock, an RCU grace period can resolve concurrently while debugfs reads the file, allowing free_rootdomain() to execute kfree() and causing a UAF when reading dl_bw->bw. This patch adds rcu_assign_pointer() on the writer side in rq_attach_root() and uses guard(rcu)() with rcu_dereference() in print_dl_rq(). Patch 3 fixes a potential use-after-free in print_cpu() where rq->curr is dereferenced locklessly to output the running task's PID. If the task exits concurrently and its reference count drops to zero, put_task_struct() schedules __put_task_struct_rcu_cb() via call_rcu(). Without holding an RCU read lock, an RCU grace period can elapse concurrently and free the task structure via free_task(), leading to a use-after-free race condition. This patch protects rq->curr access using rcu_dereference() inside an RCU read-side critical section. Patch 4 fixes both a time-of-check to time-of-use race condition and a potential use-after-free in sched_show_numa(), where p->mm is checked locklessly and then passed to P(mm->numa_scan_seq). If the task exits concurrently via exit_mm(p), current->mm is set to NULL under task_lock(p) before mmput() is called to free the struct mm_struct. Wrapping the p->mm check and dereference in task_lock(p) eliminates both hazards. Patch 5 fixes an RCU traversal violation in print_cfs_stats() where rq->leaf_cfs_rq_list is traversed locklessly using for_each_leaf_cfs_rq_safe(), which expands to list_for_each_entry_safe(). Although leaf_cfs_rq_list is modified using list_add_rcu(), list_for_each_entry_safe() lacks READ_ONCE() and pre-fetches the next pointer without memory barriers. Furthermore, because cfs_rq nodes are re-linked on enqueue/dequeue without waiting for RCU grace periods, concurrent list churn can cause backward jumps or infinite loops. This patch introduces for_each_leaf_cfs_rq_rcu(), bounds traversal with a circuit-breaker ceiling, and emits an explicit truncation notice if the ceiling is reached. Patch 6 introduces per-CPU debugfs entries under /sys/kernel/debug/sched/cpu/cpu/debug, allowing targeted inspection of an individual CPU's runqueue on demand. If the target CPU is currently offline, reading its file returns -ENODEV. Changes since v4: - Added a new prerequisite patch to annotate struct rq's rd field with __rcu and updated lockless readers to use rcu_dereference()/rcu_dereference_sched() - Updated print_dl_rq() to use guard(rcu)() and rcu_dereference() on rq->rd (Daniel Vacek and K Prateek Nayak) - Replaced READ_ONCE(p->mm) with task_lock(p)/task_unlock(p) in sched_show_numa() to prevent use-after-free against concurrent exit_mm() and mmput() - Updated print_cfs_stats() to use guard(rcu)() - Increased SCHED_DEBUG_MAX_ITER from 1024 to 4096 and added an explicit truncation notice - Moved SEQ_printf() and SEQ_printf_task_group_path() to kernel/sched/sched.h, replaced strcpy() with strscpy(), and used IS_ENABLED(CONFIG_FAIR_GROUP_SCHED) with a typed static inline fallback stub - Corrected the "Fixes:" commit tag in Patch 5 to 039ae8bcf7a5 ("sched/fair: Fix O(nr_cgroups) in the load balancing path") - Linked to v4: https://lore.kernel.org/lkml/20260810015812.428999-1-atomlin@atomlin.com/ Changes since v3: - Updated Patch 1 to use rcu_dereference(rq->curr) instead of READ_ONCE() to preserve __rcu - Added missing writer-side RCU publication barrier (rcu_assign_pointer()) in rq_attach_root() for Patch 2 - Added Patch 3 to fix a TOCTOU condition in sched_show_numa() using READ_ONCE(p->mm) - Added a safety iteration ceiling in print_cfs_stats() for Patch 4 to prevent unbounded list iteration and RCU stalls under heavy leaf_cfs_rq_list churn - Linked to v3: https://lore.kernel.org/lkml/20260808235522.380038-1-atomlin@atomlin.com/ Changes since v2: - Protected lockless rq->curr dereferencing in print_cpu() with rcu_read_lock() and READ_ONCE() - Protected lockless rq->rd dereferencing in print_dl_rq() against CPU hot-unplug and cgroup cpuset repartitioning races - Introduced for_each_leaf_cfs_rq_rcu() using list_for_each_entry_rcu() for lockless leaf_cfs_rq_list iteration - Linked to v2: https://lore.kernel.org/lkml/20260728205238.18447-1-atomlin@atomlin.com/ Changes since v1: - Reframed commit message motivation around targeted interactive debugging on large SMP topologies (Peter Zijlstra and Zhan Xusheng) - Gated sched_debug_cpu_show() with a cpu_online(cpu) check returning -ENODEV when target CPU is offline (Zhan Xusheng) - Linked to v1: https://lore.kernel.org/lkml/20260728020309.6169-1-atomlin@atomlin.com/ Aaron Tomlin (6): sched: Annotate rq->rd with __rcu and update lockless readers sched/debug: Protect lockless rq->rd access in print_dl_rq() sched/debug: Protect lockless rq->curr access in print_cpu() sched/debug: Protect p->mm access in sched_show_numa() sched/fair: Use list_for_each_entry_rcu() in print_cfs_stats() sched/debug: Introduce per-CPU debugfs files kernel/sched/core.c | 16 ++++--- kernel/sched/deadline.c | 8 ++-- kernel/sched/debug.c | 92 ++++++++++++++++++++++++----------------- kernel/sched/fair.c | 62 +++++++++++++++++++-------- kernel/sched/sched.h | 53 +++++++++++++++++++++++- kernel/sched/topology.c | 2 +- 6 files changed, 165 insertions(+), 68 deletions(-) -- 2.55.0