mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Tim Chen <tim.c.chen@linux.intel.com>
To: Zenghui Yu <zenghui.yu@linux.dev>
Cc: Peter Zijlstra <peterz@infradead.org>,
	Ingo Molnar <mingo@redhat.com>,
	K Prateek Nayak <kprateek.nayak@amd.com>,
	"Gautham R . Shenoy" <gautham.shenoy@amd.com>,
	Vincent Guittot	 <vincent.guittot@linaro.org>,
	Juri Lelli <juri.lelli@redhat.com>,
	Dietmar Eggemann <dietmar.eggemann@arm.com>,
	Steven Rostedt <rostedt@goodmis.org>,
	Ben Segall	 <bsegall@google.com>, Mel Gorman <mgorman@suse.de>,
	Valentin Schneider	 <vschneid@redhat.com>,
	Madadi Vineeth Reddy <vineethr@linux.ibm.com>,
	Hillf Danton <hdanton@sina.com>,
	Shrikanth Hegde <sshegde@linux.ibm.com>,
	Jianyong Wu	 <jianyong.wu@outlook.com>,
	Yangyu Chen <cyy@cyyself.name>,
	Tingyin Duan	 <tingyin.duan@gmail.com>,
	Vern Hao <vernhao@tencent.com>, Vern Hao	 <haoxing990@gmail.com>,
	Len Brown <len.brown@intel.com>, Aubrey Li	 <aubrey.li@intel.com>,
	Zhao Liu <zhao1.liu@intel.com>, Chen Yu	 <yu.chen.surf@gmail.com>,
	Chen Yu <yu.c.chen@intel.com>,
	Adam Li	 <adamli@os.amperecomputing.com>,
	Aaron Lu <ziqianlu@bytedance.com>,
	Tim Chen	 <tim.c.chen@intel.com>, Josh Don <joshdon@google.com>,
	Gavin Guo	 <gavinguo@igalia.com>,
	Qais Yousef <qyousef@layalina.io>,
	Libo Chen	 <libchen@purestorage.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [Patch v4 01/22] sched/cache: Introduce infrastructure for cache-aware load balancing
Date: Mon, 14 Sep 2026 16:12:46 -0700	[thread overview]
Message-ID: <eb77a9a6b27940f1ae9acc0b87f75f3b46f28a13.camel@linux.intel.com> (raw)
In-Reply-To: <343a7e07-7fad-4979-9c9b-82ec038c293c@linux.dev>

On Tue, 2026-09-15 at 01:50 +0800, Zenghui Yu wrote:
> 

[snip]

> I sporadically hit the SLUB "Poison overwritten" reports on the mm_struct
> cache while running mm-new:
> 
>  [Poison overwritten] 0xffff8001076ec8e8-0xffff8001076ec8eb @offset=51432. First byte 0xff instead of 0x6b
>  =============================================================================
>  BUG mm_struct (Tainted: G                 N ): Object corrupt
>  -----------------------------------------------------------------------------
> 
>  Allocated in copy_process+0x1e48/0x2078 age=2 cpu=7 pid=11866
>   copy_process+0x1e48/0x2078
>   kernel_clone+0xa4/0x498
>   __do_sys_clone+0x5c/0x88
>   __arm64_sys_clone+0x1c/0x28
>   invoke_syscall+0x54/0x110
>   el0_svc_common.constprop.0+0x40/0xe0
>   do_el0_svc+0x1c/0x28
>   el0_svc+0x54/0x424
>   el0t_64_sync_handler+0xa0/0xe4
>   el0t_64_sync+0x1b0/0x1b4
>  Freed in __mmdrop+0x108/0x180 age=2 cpu=3 pid=11955
>   kmem_cache_free+0x290/0x53c
>   __mmdrop+0x108/0x180
>   __mmput+0x150/0x154
>   mmput+0x50/0x5c
>   exec_mm_put_old+0x74/0x84
>   setup_new_exec+0x7c/0x90
>   load_elf_binary+0x4b0/0x1914
>   bprm_execve+0x300/0x83c
>   do_execveat_common+0x168/0x1cc
>   __arm64_sys_execve+0x44/0x68
>   invoke_syscall+0x54/0x110
>   el0_svc_common.constprop.0+0x40/0xe0
>   do_el0_svc+0x1c/0x28
>   el0_svc+0x54/0x424
>   el0t_64_sync_handler+0xa0/0xe4
>   el0t_64_sync+0x1b0/0x1b4
>  Slab 0xffffffbfc1076e00 objects=23 used=18 fp=0xffff8001076e2140 flags=0x13fffe0000000240(workingset|head|node=1|zone=0|lastcpupid=0x1ffff)
>  Object 0xffff8001076ec640 @offset=50752 fp=0xffff8001076e2140
> 
>  [...]
> 
> The corruption is always exactly 4 bytes (0xffffffff) with everything
> around still being intact poison.  The in-object offset (51432 - 50752 =
> 680) resolves to &mm->sc_stat.cpu, and 0xffffffff is just -1.  My AI model
> points me to this write in account_mm_sched():
> 
> 	if (READ_ONCE(mm->sc_stat.cpu) != -1)
> 		WRITE_ONCE(mm->sc_stat.cpu, -1);
> 
> and helps with analyzing and fixing the issue like below :-) .  Please have
> a look.
> 
> Thanks,
> Zenghui
> 
> ---8<---
> 
> From 992b515f18710e77308cf5f88943cc3ce918a525 Mon Sep 17 00:00:00 2001
> From: "Zenghui Yu (Huawei)" <zenghui.yu@linux.dev>
> Date: Mon, 14 Sep 2026 22:00:18 +0800
> Subject: [PATCH] sched/cache: Fix use-after-free of mm in account_mm_sched()

I think you have hit a similar use after free issue that was discussed in this
thread.
https://lore.kernel.org/lkml/apPb-Dr4nPYuHQOK@v4bel/

Can you try the last two patches in this 4 patch series
that address this issue in a comprehensive way
https://lore.kernel.org/lkml/cover.1789061845.git.tim.c.chen@linux.intel.com/

Thanks.

Tim

> 
> account_mm_sched() accounts runtime against rq->curr and dereferences its
> ->mm: it updates the percpu chunk mm->sc_stat.pcpu_sched and may write
> mm->sc_stat.cpu = -1.
> 
> update_se(), which samples rq->curr and calls account_mm_sched(), is not
> only called from local contexts (tick, context switch) but also through
> update_curr() from enqueue/dequeue paths, which frequently run on a remote
> CPU while holding this rq's lock (cross-CPU try_to_wake_up(), load
> balancing).
> 
> In those remote contexts rq->curr is a task concurrently running on its
> home CPU.  The rq lock guarantees that rq->curr's identity does not change,
> but it says nothing about the lifetime of rq->curr->mm: that task does not
> need the rq lock to execute execve or exit, and switches and drops its ->mm
> under task_lock() and mmput(), neither of which orders against the remote
> CPU.  A remote CPU can therefore sample a valid mm pointer right before it
> is freed and write to it afterwards, corrupting the freed mm_struct (and
> the pcpu_sched percpu chunk, which mm_destroy_sched() frees even earlier).
> 
> Observed with CONFIG_SLUB_DEBUG=y as a sporadic "Poison overwritten" report
> on the mm_struct cache, with the overwritten bytes resolving to
> &mm->sc_stat.cpu.
> 
> Only account the physically running task (p == current), whose ->mm cannot
> go away while it is the one executing this code.  Local tick, context
> switch and sched_ttwu_pending() paths are unaffected; updates skipped in
> remote contexts only cause minor under-accounting of the sc_stat runtime
> heuristics.
> 
> Fixes: df0d98475954 ("sched/cache: Introduce infrastructure for cache-aware load balancing")
> Assisted-by: GLM-5.3 OpenCode
> Signed-off-by: Zenghui Yu (Huawei) <zenghui.yu@linux.dev>
> ---
>  kernel/sched/fair.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
> index ade1eceb39b8..2bbf59370d23 100644
> --- a/kernel/sched/fair.c
> +++ b/kernel/sched/fair.c
> @@ -1731,6 +1731,9 @@ void account_mm_sched(struct rq *rq, struct task_struct *p, s64 delta_exec)
>  	int mm_sched_llc = -1;
>  	unsigned long epoch;
>  
> +	if (p != current)
> +		return;
> +
>  	if (!sched_cache_enabled())
>  		return;
>  

  reply	other threads:[~2026-09-14 23:12 UTC|newest]

Thread overview: 71+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-04-01 21:52 [Patch v4 00/22] Cache aware scheduling Tim Chen
2026-04-01 21:52 ` [Patch v4 01/22] sched/cache: Introduce infrastructure for cache-aware load balancing Tim Chen
2026-04-09 12:41   ` Peter Zijlstra
2026-04-09 19:21     ` Tim Chen
2026-04-09 23:00       ` Peter Zijlstra
2026-04-10  6:30         ` Chen, Yu C
2026-04-15  2:06   ` Vern Hao
2026-04-15  3:34     ` Chen, Yu C
2026-09-14 17:50   ` Zenghui Yu
2026-09-14 23:12     ` Tim Chen [this message]
2026-04-01 21:52 ` [Patch v4 02/22] sched/cache: Limit the scan number of CPUs when calculating task occupancy Tim Chen
2026-04-09 13:17   ` Luo Gengkun
2026-04-09 13:41     ` Peter Zijlstra
2026-04-10 10:12       ` Luo Gengkun
2026-04-10  7:29     ` Chen, Yu C
2026-04-10 10:20       ` Luo Gengkun
2026-04-10 17:12       ` Tim Chen
2026-04-10 17:27         ` Chen, Yu C
2026-04-13  7:23           ` [RFC PATCH] sched/fair: dynamically scale the period of cache work Jianyong Wu
2026-04-13  8:38             ` Chen, Yu C
2026-04-13 11:27               ` Jianyong Wu
2026-04-15  3:31                 ` Chen, Yu C
2026-04-16  3:39                   ` Jianyong Wu
2026-04-15 17:22             ` Tim Chen
2026-04-16  6:50               ` Jianyong Wu
2026-04-14 15:07           ` [PATCH v2] sched/cache: Reduce the overhead of task_cache_work by only scan the visisted cpus Luo Gengkun
2026-04-15  3:10             ` Chen, Yu C
2026-04-18  9:01               ` Luo Gengkun
2026-04-20  7:53                 ` Chen, Yu C
2026-04-23  8:54                   ` [PATCH v3] " Luo Gengkun
2026-04-01 21:52 ` [Patch v4 03/22] sched/cache: Record per LLC utilization to guide cache aware scheduling decisions Tim Chen
2026-04-01 21:52 ` [Patch v4 04/22] sched/cache: Introduce helper functions to enforce LLC migration policy Tim Chen
2026-04-01 21:52 ` [Patch v4 05/22] sched/cache: Make LLC id continuous Tim Chen
2026-04-01 21:52 ` [Patch v4 06/22] sched/cache: Assign preferred LLC ID to processes Tim Chen
2026-04-01 21:52 ` [Patch v4 07/22] sched/cache: Track LLC-preferred tasks per runqueue Tim Chen
2026-04-01 21:52 ` [Patch v4 08/22] sched/cache: Introduce per CPU's tasks LLC preference counter Tim Chen
2026-04-01 21:52 ` [Patch v4 09/22] sched/cache: Calculate the percpu sd task LLC preference Tim Chen
2026-04-01 21:52 ` [Patch v4 10/22] sched/cache: Count tasks prefering destination LLC in a sched group Tim Chen
2026-04-01 21:52 ` [Patch v4 11/22] sched/cache: Check local_group only once in update_sg_lb_stats() Tim Chen
2026-04-01 21:52 ` [Patch v4 12/22] sched/cache: Prioritize tasks preferring destination LLC during balancing Tim Chen
2026-04-01 21:52 ` [Patch v4 13/22] sched/cache: Add migrate_llc_task migration type for cache-aware balancing Tim Chen
2026-04-01 21:52 ` [Patch v4 14/22] sched/cache: Handle moving single tasks to/from their preferred LLC Tim Chen
2026-04-01 21:52 ` [Patch v4 15/22] sched/cache: Respect LLC preference in task migration and detach Tim Chen
2026-04-01 21:52 ` [Patch v4 16/22] sched/cache: Disable cache aware scheduling for processes with high thread counts Tim Chen
2026-04-09 12:43   ` Peter Zijlstra
2026-04-09 19:27     ` Tim Chen
2026-04-01 21:52 ` [Patch v4 17/22] sched/cache: Avoid cache-aware scheduling for memory-heavy processes Tim Chen
2026-04-09 12:46   ` Peter Zijlstra
2026-04-09 12:55     ` Peter Zijlstra
2026-04-10  8:59     ` Chen, Yu C
2026-04-10  9:20       ` Peter Zijlstra
2026-04-01 21:52 ` [Patch v4 18/22] sched/cache: Enable cache aware scheduling for multi LLCs NUMA node Tim Chen
2026-04-09 13:37   ` Peter Zijlstra
2026-04-09 19:39     ` Tim Chen
2026-04-01 21:52 ` [Patch v4 19/22] sched/cache: Allow the user space to turn on and off cache aware scheduling Tim Chen
2026-04-01 21:52 ` [Patch v4 20/22] sched/cache: Add user control to adjust the aggressiveness of cache-aware scheduling Tim Chen
2026-04-01 21:52 ` [Patch v4 21/22] -- DO NOT APPLY!!! -- sched/cache/debug: Display the per LLC occupancy for each process via proc fs Tim Chen
2026-04-01 21:52 ` [Patch v4 22/22] -- DO NOT APPLY!!! -- sched/cache/debug: Add ftrace to track the load balance statistics Tim Chen
2026-04-09 13:54 ` [Patch v4 00/22] Cache aware scheduling Peter Zijlstra
2026-04-09 20:02   ` Tim Chen
2026-04-14  3:20 ` Duan Tingyin
2026-04-15 17:35   ` Tim Chen
2026-04-16  0:27 ` Qais Yousef
2026-04-20  9:01   ` Chen, Yu C
2026-04-21  0:34     ` Qais Yousef
2026-04-21 20:57       ` Tim Chen
2026-04-23 15:06         ` Qais Yousef
2026-04-23 16:48           ` Chen, Yu C
2026-04-25  0:05             ` Qais Yousef
2026-04-23 17:17       ` Chen, Yu C
2026-04-25  0:14         ` Qais Yousef

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=eb77a9a6b27940f1ae9acc0b87f75f3b46f28a13.camel@linux.intel.com \
    --to=tim.c.chen@linux.intel.com \
    --cc=adamli@os.amperecomputing.com \
    --cc=aubrey.li@intel.com \
    --cc=bsegall@google.com \
    --cc=cyy@cyyself.name \
    --cc=dietmar.eggemann@arm.com \
    --cc=gautham.shenoy@amd.com \
    --cc=gavinguo@igalia.com \
    --cc=haoxing990@gmail.com \
    --cc=hdanton@sina.com \
    --cc=jianyong.wu@outlook.com \
    --cc=joshdon@google.com \
    --cc=juri.lelli@redhat.com \
    --cc=kprateek.nayak@amd.com \
    --cc=len.brown@intel.com \
    --cc=libchen@purestorage.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mgorman@suse.de \
    --cc=mingo@redhat.com \
    --cc=peterz@infradead.org \
    --cc=qyousef@layalina.io \
    --cc=rostedt@goodmis.org \
    --cc=sshegde@linux.ibm.com \
    --cc=tim.c.chen@intel.com \
    --cc=tingyin.duan@gmail.com \
    --cc=vernhao@tencent.com \
    --cc=vincent.guittot@linaro.org \
    --cc=vineethr@linux.ibm.com \
    --cc=vschneid@redhat.com \
    --cc=yu.c.chen@intel.com \
    --cc=yu.chen.surf@gmail.com \
    --cc=zenghui.yu@linux.dev \
    --cc=zhao1.liu@intel.com \
    --cc=ziqianlu@bytedance.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®