From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from CY3PR05CU001.outbound.protection.outlook.com (mail-westcentralusazon11013043.outbound.protection.outlook.com [40.93.201.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DB7C52D5416 for ; Tue, 30 Dec 2025 09:53:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.93.201.43 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767088393; cv=fail; b=Krk0TmCmYKF/UVJDWL0D85Nch9eAiiHDZXs/jFPxW4muKlRi0Djha4rWsfKHwUpDvc8BnNYBe/saenlz+UN8WvsztNXhshqqd6jAlwiu6C+7Z1zAxNNdqU7MYQxLR+VIOF7ffSktWmKiKYvCoDMPg0VIDVqcO2wYjvFoy+bYdGs= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767088393; c=relaxed/simple; bh=UfUloaIkW62SmvaH02KkiNKjjk3+KDQaqRRB2Tc0cO0=; h=Message-ID:Date:MIME-Version:Subject:From:To:CC:References: In-Reply-To:Content-Type; b=YaRrLJ2XdEI2tq0N/x8MwmLKVuzTBLirxOkAPy4i24IzV5uuF2c28/lTfm7lGsxnzi/KSGnoPrEfa9dRFtqdEofI8eHSledCbvU0jiUm4DhY7leIGMZaEDDHz/Gl3eEqcXbBLVaYMTH5gsAGEb1314bTZPTDbrtH+GWUB0qaRfI= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=GKM04itE; arc=fail smtp.client-ip=40.93.201.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="GKM04itE" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=VdinH1r2NxEEeIbSIU3Xh6cjVzykYx9sNBlV2Y9+lb0SD951wCpkpWpRxjA/TU3/qJePPKIpqV8BNbmfYDigFyahhrX7brWRuoKO7GEOgDA10b5r/6heuRHaNNQinPGTDvzoKfUc+CLc1WNjqdlFJ9NOOTuub27hH76eeN7NjhD5UChXxpptl6BNvxM0Rq5vmpmHIDfqDsGDEpwqr1MU37fx6Y7ISStAoopHar6ySKrgTbONc12BgBKDztjWQ2TaKXwjHP3k1RLUMuXiO3vz/rnW8Sla/eiWm3jGy49LfnOZvoE9CASU/w2heKGEnslAbxRYV3m6+J3HPbCT0cQjZQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Ozmkf6nNNrzrzEc2LVvA9a6reioZ3w7osoHqV4Br2LA=; b=wLS+5O8wgqkHQtkWaqxpcLX19RYGwAei9poG8eq6HXUQa2bX/tdQFqL9UitAUqtjlCJuays5tMWMRw5If4OrHr+3xo8lWaE/8V90GmR81m2b6GlfEUPbySspgTxxh5Wwi8F0Bvt3omtEP0Zu11Z+U/RO0M0f8QXn6E6MGn1t6OJtnSTowxdFXJ49oKnMtHdI2HlqDsE+ogkviFfzdtEFWMFBMQfTKwsk6r2RpQEhX+jKHZy+VQ+KCGLp4XDPdesIoJVs515MVHPX6Nf5UhQzf1yYwZixWoH5Um2MgWrixm8oFlZB4AM+IVfnSKzcRxVImqKn0ynv9Z7mbpjEy99wnA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=google.com smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Ozmkf6nNNrzrzEc2LVvA9a6reioZ3w7osoHqV4Br2LA=; b=GKM04itET5c4QRlN+C8fiYfJQzSN1cadhhNM4c81Jja7mCLfuVzC2ajs3creXpblRQ9xWByU5BVHZWlm6D0Rp21wILE1vx99myjlSlZswbjJWGii0kdvGSZVUjfDAG7wg8uBpCGpToMMvKQ2THDZITW0peMT/S2Nw4+K+tNjrlo= Received: from BYAPR05CA0106.namprd05.prod.outlook.com (2603:10b6:a03:e0::47) by SJ2PR12MB9087.namprd12.prod.outlook.com (2603:10b6:a03:562::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9478.4; Tue, 30 Dec 2025 09:53:03 +0000 Received: from SJ5PEPF000001EB.namprd05.prod.outlook.com (2603:10b6:a03:e0:cafe::75) by BYAPR05CA0106.outlook.office365.com (2603:10b6:a03:e0::47) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.9478.4 via Frontend Transport; Tue, 30 Dec 2025 09:52:58 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=satlexmb08.amd.com; pr=C Received: from satlexmb08.amd.com (165.204.84.17) by SJ5PEPF000001EB.mail.protection.outlook.com (10.167.242.199) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9478.4 via Frontend Transport; Tue, 30 Dec 2025 09:53:02 +0000 Received: from satlexmb08.amd.com (10.181.42.217) by satlexmb08.amd.com (10.181.42.217) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.17; Tue, 30 Dec 2025 03:53:01 -0600 Received: from [10.136.45.77] (10.180.168.240) by satlexmb08.amd.com (10.181.42.217) with Microsoft SMTP Server id 15.2.2562.17 via Frontend Transport; Tue, 30 Dec 2025 03:52:54 -0600 Message-ID: <91206b32-ac57-461c-ad0b-4b771448559d@amd.com> Date: Tue, 30 Dec 2025 15:22:48 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v24 08/11] sched: Avoid donor->sched_class->yield_task() null traversal From: K Prateek Nayak To: John Stultz , LKML CC: Joel Fernandes , Qais Yousef , Ingo Molnar , Peter Zijlstra , Juri Lelli , Vincent Guittot , Dietmar Eggemann , Valentin Schneider , Steven Rostedt , Ben Segall , Zimuzo Ezeozue , Mel Gorman , Will Deacon , Waiman Long , Boqun Feng , "Paul E. McKenney" , Metin Kaya , Xuewen Yan , Thomas Gleixner , Daniel Lezcano , Suleiman Souhlal , kuyo chang , hupu , References: <20251124223111.3616950-1-jstultz@google.com> <20251124223111.3616950-9-jstultz@google.com> Content-Language: en-US In-Reply-To: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8bit X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: SJ5PEPF000001EB:EE_|SJ2PR12MB9087:EE_ X-MS-Office365-Filtering-Correlation-Id: 6df4b35e-6c5c-4a47-6308-08de47893927 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|82310400026|376014|7416014|36860700013|1800799024; X-Microsoft-Antispam-Message-Info: =?utf-8?B?b3hHR25CN25iMzNVeHNRNEZhL05xZGN1RXp4YVZ6WjExTGJjQURwWHlPSk1i?= =?utf-8?B?UEYzNVRjU0JTT01HS3VjT1FTVnkvWFBwQjQ4YnFyUzNWRGtERkhxdEY0UDc0?= =?utf-8?B?cUJzYjA3TDc5NW9ZSkFZVkdYOHVCL08zemdzdERzTk51VDBIcm0yZXphLzRV?= =?utf-8?B?N08yWmU2b0FvZ3JOSmhEK3VlZjRudzBTWko1cFdsQmcxRmVORmxmSkJQZ0Jp?= =?utf-8?B?aHk0cmtTS2pUUnBwVEQzTGZYSGhhTndZTjAraTdlYW1sV3cvc0o3Z0tZVTZp?= =?utf-8?B?elVaWHhHbWlldGhtMzVhVXg3VHR6RzA3RmdrZy85S25NQlU2b2xkcDVwUS9H?= =?utf-8?B?TytqNmp0VXNYaDdGaU13U2xiM0dENmMyWGY0Z3V1WHVrVHFRMW05QnIyWmZM?= =?utf-8?B?aC80NGZTQ2JYOG9qUSttaWRraFlCTEVPdC9mdG80RDZBbkZ0ekxZR2E3c2Yw?= =?utf-8?B?UTlHdGFZbkg5Sk03amlXVHFUQ2tGdk12dFJnbHZITzBuZkdRdVpGcVBiNzNN?= =?utf-8?B?ZXpiSDRmaU9oSHdxbUlNa3ZOT3Y4TWhhcDBJamRLTkhGVFl3KzcxNVB2a0NT?= =?utf-8?B?NlFBMERDbGNEazFMMlBWckpZbVo5ajR6MysxZDdWeFlsSVBNS2xLalI2SThl?= =?utf-8?B?WWZQZWUwRFZoK1pOQ2dwTEwrWUxmZEVsenB4TDZ6NThYSGowSFpjaG1CQUU0?= =?utf-8?B?bWs5cGExbzFpdVFTZFQ5emJ0YUJzbXcyWVBZbjJxZE9lOTVGRjJVTjZBL0tR?= =?utf-8?B?TEdhTXRJQk5YVCtQME16a051enBYY1ozcVdyczRBWnAyTVN6Rm9WWXpTMlBh?= =?utf-8?B?SHoydFRjSFI2QXlBRGxUejVUTUFYZlBNUGxHamhFWXhkNlA3MlpNM0MwV3Nq?= =?utf-8?B?S1M1bkkwT2RRV1BpNjdjOFRDVmZjVDRWQXRuUmxMOU0rMExmK3NaMUxCeFVK?= =?utf-8?B?bFp5Qkl5czQ1U20xdmRwUFhQRlB4YWpsVjJma3dGTnJ1cUphMiszbjMxY2dG?= =?utf-8?B?ZFJmUVFVOFFGRjBMTTdRSEJQL1FQSkM2YVJrQlRqQXBFbmZkWnF4dkdCS3pK?= =?utf-8?B?TE9jaXNnODZLUitkOERIZXZLZDgzclJGbFRYRkhRUEVzcHVkckJXbHhyajF3?= =?utf-8?B?VFYwL1I5Sm1lYi85UjNqR3E4MWEwV3c1R29aK202WEhTTTkzQjF6bFFLK2xh?= =?utf-8?B?alhlaHFIeHd5WXpLODdpQXpoYjRsT05ldVBHZkZmd0dIQ29LSlNiMUdudVQ4?= =?utf-8?B?clEweWRnd2lOK3Fab0lGY0J5ZnRQUDkvc1ZjQ3VsRk9ZZFNpU0hsRC9heXdZ?= =?utf-8?B?bWhDa2JobytiZnc2WTZqMzM0YzJrNUZaSVBaU09VeU0zV0txbXlITlU1UFds?= =?utf-8?B?WVhkVEloQzNRZ0IwYUJKcUwxb3Q0VU5RUDRXQVU5bzRPb28rcTFPUC9reWd0?= =?utf-8?B?VnhsYTBBdXRmQTZHa1Rvc1MrcWZUTzNxeERBT0tscTJkYVZaVUlUUWtDeldu?= =?utf-8?B?Rm9MSjVVUUNNdmhQNnMyenh2Qjd2ZFlOZjhpdnVpWHcxTTRNUU1iOTJENHky?= =?utf-8?B?SFcvOXJyazVCblQ0OXJmMks5dHlxdkNoanluVFpnZ3V1OSs2MjUvakR3QUU4?= =?utf-8?B?ZHZGMTRUdW9Jdy9paGtldmdRU0lyR1dpTjg5QitETFVXd09zZG1PUVM1RXhu?= =?utf-8?B?ZjlIcU9PUlVJQVk4TkJuVzNFUHhobFlYRHR1Y3lIb1F3Q3FJUUdaTlIwMjQr?= =?utf-8?B?RDZURVdiVXNkbDJONzlwcnExRlQxNDA0MndaRks2WDlGb2V2ZlJSRVREdDlQ?= =?utf-8?B?aGVQS0RCYkI0UERVaCs3d2FPUDhIa3oyV2xXa1c1THZEdGxOSnBVTERXMEpK?= =?utf-8?B?YVh0R0N5QmtoK1RPQ2lDYURZeVhyNjJNb1NBcDVaUmJreWpWSENGMjhmMGdk?= =?utf-8?B?M2trQnk4UTVCcStINVhUaHVaQXUzN2QrSmVVRGxuNkVFYTVYWEVpYjBXaE5s?= =?utf-8?B?QVBYQWRuN1lTclFIQTh4SGpLeXdHWTNTZ0YzNmpUbkVsWGQzYS8yYWFHZHZh?= =?utf-8?B?TzU0TWNlbVdKVE82T0dnaVNxeC9Ocjh6YXRjclZJaXlLRnlmRTk3dEtzWUo4?= =?utf-8?Q?m1fA=3D?= X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb08.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230040)(82310400026)(376014)(7416014)(36860700013)(1800799024);DIR:OUT;SFP:1101; X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Dec 2025 09:53:02.7436 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 6df4b35e-6c5c-4a47-6308-08de47893927 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[satlexmb08.amd.com] X-MS-Exchange-CrossTenant-AuthSource: SJ5PEPF000001EB.namprd05.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ2PR12MB9087 Hello John, On 12/30/2025 11:31 AM, K Prateek Nayak wrote: > On 11/25/2025 4:01 AM, John Stultz wrote: >> With proxy-exec once we do return migration from ttwu(), if a >> task is proxying for a waiting donor, and the donor is woken up, >> we switch the rq->donor to point to idle briefly until we can >> re-enter __schedule(). >> >> However, if a task that was acting as a proxy calls into >> yield() right after the donor is switched to idle, it may >> trip a null pointer traversal, because the idle task doesn't >> have a yield_task() pointer. > > I thought that was a transient state that should not be observed by the > running task. > > Since NEED_RESCHED is retained, we'll just go though another pass of > __schedule() loop and the task should not observe rq->donor as idle in > do_sched_yield() as only the current task can yield on the local CPU. > > Do we have a splat that suggests this happens? So I think I found my answer (at least one of them): find_proxy_task() /* case DEACTIVATE_DONOR */ proxy_deactivate(rq, donor) proxy_resched_idle(rq); /* Switched donor to rq->idle. */ try_to_block_task(rq, donor, &state, true) if (signal_pending_state(task_state, donor)) WRITE_ONCE(p->__state, TASK_RUNNING) return false; /* Blocking fails. */ /* If deactivate fails, force return */ p = donor; return p next = p; /* Donor is rq->idle. */ This should be illegal and I think we should either force a "pick_again" if proxy_deactivate() fails (can it get stuck on an infinite loop?) or we should fix the donor relation before running "p". We can also push the proxy_resched_idle() into try_to_block_task() and only do it once we are past all the early returns and if task_current_donor(rq, p). ... and as I write this I realize we can have this via proxy_needs_return() so I guess we need this patch after all and proxy_needs_return() should do resched_curr() for that case too so we can re-evaluate the donor context on the CPU where we are stealing away the donor from. Quick question: Can we avoid that proxy_resched_idle() in proxy_needs_return() by retaining PROXY_WAKING and letting proxy_force_return() handle donor's migration too? (Seems to survive the same set of challenges I've been putting my suggestions through) diff --git a/kernel/sched/core.c b/kernel/sched/core.c index 700fd08b2392..e01a61f1955e 100644 --- a/kernel/sched/core.c +++ b/kernel/sched/core.c @@ -3720,6 +3720,12 @@ static inline bool proxy_needs_return(struct rq *rq, struct task_struct *p) if (!sched_proxy_exec()) return false; + /* For current, and donor, let proxy_force_return() handle return. */ + if (task_current(rq, p) || task_current_donor(rq, p)) { + resched_curr(rq); + return false; + } + guard(raw_spinlock)(&p->blocked_lock); /* If task isn't PROXY_WAKING, we don't need to do return migration */ @@ -3728,20 +3734,12 @@ static inline bool proxy_needs_return(struct rq *rq, struct task_struct *p) __clear_task_blocked_on(p, PROXY_WAKING); - /* If already current, don't need to return migrate */ - if (task_current(rq, p)) - return false; - /* If wake_cpu is targeting this cpu, don't bother return migrating */ if (p->wake_cpu == cpu_of(rq)) { resched_curr(rq); return false; } - /* If we're return migrating the rq->donor, switch it out for idle */ - if (task_current_donor(rq, p)) - proxy_resched_idle(rq); - /* (ab)Use DEQUEUE_SPECIAL to ensure task is always blocked here. */ block_task(rq, p, DEQUEUE_NOCLOCK | DEQUEUE_SPECIAL); return true; --- I think you'll have a note somewhere that says why this is an absolutely terrible idea :-) -- Thanks and Regards, Prateek “Program testing can be used to show the presence of bugs, but never to show their absence!” ― Edsger W. Dijkstra