mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Andrea Righi <arighi@nvidia.com>
To: Tejun Heo <tj@kernel.org>, David Vernet <void@manifault.com>,
	Changwoo Min <changwoo@igalia.com>
Cc: Waiman Long <longman@redhat.com>,
	Ridong Chen <ridong.chen@linux.dev>,
	Johannes Weiner <hannes@cmpxchg.org>,
	Michal Koutny <mkoutny@suse.com>,
	sched-ext@lists.linux.dev, cgroups@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: [PATCH 1/3] cgroup/cpuset: Protect is_in_v2_mode() in cpuset_num_cpus()
Date: Tue, 29 Sep 2026 10:37:38 +0200	[thread overview]
Message-ID: <20260929084124.626693-2-arighi@nvidia.com> (raw)
In-Reply-To: <20260929084124.626693-1-arighi@nvidia.com>

cpuset_num_cpus() enters its RCU read-side section only after checking
is_in_v2_mode(). When cpuset is bound to a v1 hierarchy, is_in_v2_mode()
dereferences cpuset_cgrp_subsys.root, which is freed via kfree_rcu()
once that hierarchy is destroyed and cpuset is rebound to the default
hierarchy. A preemptible caller outside RCU can therefore read the flags
of a freed root.

The only current caller, fair's group share calculation, runs under the
rq lock with preemption disabled, so it can't hit this. However, the
helper already means to protect itself with RCU, and upcoming sched_ext
support exposes it to sleepable BPF programs.

Take the RCU read lock before is_in_v2_mode() so that the whole lookup
is protected regardless of the caller's context.

Signed-off-by: Andrea Righi <arighi@nvidia.com>
---
 kernel/cgroup/cpuset.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c
index d100634fa12b7..03fa9472c0893 100644
--- a/kernel/cgroup/cpuset.c
+++ b/kernel/cgroup/cpuset.c
@@ -4292,8 +4292,12 @@ int cpuset_num_cpus(struct cgroup *cgrp)
 	int nr = num_online_cpus();
 	struct cpuset *cs;
 
+	/*
+	 * is_in_v2_mode() dereferences cpuset's hierarchy root, which can be a
+	 * v1 root freed via kfree_rcu() on unmount.
+	 */
+	guard(rcu)();
 	if (is_in_v2_mode()) {
-		guard(rcu)();
 		cs = css_cs(cgroup_e_css(cgrp, &cpuset_cgrp_subsys));
 		if (cs)
 			nr = cpumask_weight(cs->effective_cpus);
-- 
2.55.0


  reply	other threads:[~2026-09-29  8:41 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  8:37 [PATCHSET sched_ext/for-7.4] sched_ext: Add scx_bpf_cgroup_nr_cpus() Andrea Righi
2026-09-29  8:37 ` Andrea Righi [this message]
2026-09-29 13:47   ` [PATCH 1/3] cgroup/cpuset: Protect is_in_v2_mode() in cpuset_num_cpus() Michal Koutný
2026-09-29 15:32     ` Waiman Long
2026-09-29 17:35       ` Andrea Righi
2026-09-29 18:10         ` Waiman Long
2026-09-29 19:08           ` Peter Zijlstra
2026-09-29  8:37 ` [PATCH 2/3] sched_ext: Introduce scx_bpf_cgroup_nr_cpus() Andrea Righi
2026-09-29  8:37 ` [PATCH 3/3] selftests/sched_ext: Test scx_bpf_cgroup_nr_cpus() Andrea Righi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929084124.626693-2-arighi@nvidia.com \
    --to=arighi@nvidia.com \
    --cc=cgroups@vger.kernel.org \
    --cc=changwoo@igalia.com \
    --cc=hannes@cmpxchg.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=longman@redhat.com \
    --cc=mkoutny@suse.com \
    --cc=ridong.chen@linux.dev \
    --cc=sched-ext@lists.linux.dev \
    --cc=tj@kernel.org \
    --cc=void@manifault.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®