From: Tim Chen <tim.c.chen@linux.intel.com>
To: Zenghui Yu <zenghui.yu@linux.dev>
Cc: Peter Zijlstra <peterz@infradead.org>,
Ingo Molnar <mingo@redhat.com>,
K Prateek Nayak <kprateek.nayak@amd.com>,
"Gautham R . Shenoy" <gautham.shenoy@amd.com>,
Vincent Guittot <vincent.guittot@linaro.org>,
Juri Lelli <juri.lelli@redhat.com>,
Dietmar Eggemann <dietmar.eggemann@arm.com>,
Steven Rostedt <rostedt@goodmis.org>,
Ben Segall <bsegall@google.com>, Mel Gorman <mgorman@suse.de>,
Valentin Schneider <vschneid@redhat.com>,
Madadi Vineeth Reddy <vineethr@linux.ibm.com>,
Hillf Danton <hdanton@sina.com>,
Shrikanth Hegde <sshegde@linux.ibm.com>,
Jianyong Wu <jianyong.wu@outlook.com>,
Yangyu Chen <cyy@cyyself.name>,
Tingyin Duan <tingyin.duan@gmail.com>,
Vern Hao <vernhao@tencent.com>, Vern Hao <haoxing990@gmail.com>,
Len Brown <len.brown@intel.com>, Aubrey Li <aubrey.li@intel.com>,
Zhao Liu <zhao1.liu@intel.com>, Chen Yu <yu.chen.surf@gmail.com>,
Chen Yu <yu.c.chen@intel.com>,
Adam Li <adamli@os.amperecomputing.com>,
Aaron Lu <ziqianlu@bytedance.com>,
Tim Chen <tim.c.chen@intel.com>, Josh Don <joshdon@google.com>,
Gavin Guo <gavinguo@igalia.com>,
Qais Yousef <qyousef@layalina.io>,
Libo Chen <libchen@purestorage.com>,
linux-kernel@vger.kernel.org
Subject: Re: [Patch v4 01/22] sched/cache: Introduce infrastructure for cache-aware load balancing
Date: Mon, 14 Sep 2026 16:12:46 -0700 [thread overview]
Message-ID: <eb77a9a6b27940f1ae9acc0b87f75f3b46f28a13.camel@linux.intel.com> (raw)
In-Reply-To: <343a7e07-7fad-4979-9c9b-82ec038c293c@linux.dev>
On Tue, 2026-09-15 at 01:50 +0800, Zenghui Yu wrote:
>
[snip]
> I sporadically hit the SLUB "Poison overwritten" reports on the mm_struct
> cache while running mm-new:
>
> [Poison overwritten] 0xffff8001076ec8e8-0xffff8001076ec8eb @offset=51432. First byte 0xff instead of 0x6b
> =============================================================================
> BUG mm_struct (Tainted: G N ): Object corrupt
> -----------------------------------------------------------------------------
>
> Allocated in copy_process+0x1e48/0x2078 age=2 cpu=7 pid=11866
> copy_process+0x1e48/0x2078
> kernel_clone+0xa4/0x498
> __do_sys_clone+0x5c/0x88
> __arm64_sys_clone+0x1c/0x28
> invoke_syscall+0x54/0x110
> el0_svc_common.constprop.0+0x40/0xe0
> do_el0_svc+0x1c/0x28
> el0_svc+0x54/0x424
> el0t_64_sync_handler+0xa0/0xe4
> el0t_64_sync+0x1b0/0x1b4
> Freed in __mmdrop+0x108/0x180 age=2 cpu=3 pid=11955
> kmem_cache_free+0x290/0x53c
> __mmdrop+0x108/0x180
> __mmput+0x150/0x154
> mmput+0x50/0x5c
> exec_mm_put_old+0x74/0x84
> setup_new_exec+0x7c/0x90
> load_elf_binary+0x4b0/0x1914
> bprm_execve+0x300/0x83c
> do_execveat_common+0x168/0x1cc
> __arm64_sys_execve+0x44/0x68
> invoke_syscall+0x54/0x110
> el0_svc_common.constprop.0+0x40/0xe0
> do_el0_svc+0x1c/0x28
> el0_svc+0x54/0x424
> el0t_64_sync_handler+0xa0/0xe4
> el0t_64_sync+0x1b0/0x1b4
> Slab 0xffffffbfc1076e00 objects=23 used=18 fp=0xffff8001076e2140 flags=0x13fffe0000000240(workingset|head|node=1|zone=0|lastcpupid=0x1ffff)
> Object 0xffff8001076ec640 @offset=50752 fp=0xffff8001076e2140
>
> [...]
>
> The corruption is always exactly 4 bytes (0xffffffff) with everything
> around still being intact poison. The in-object offset (51432 - 50752 =
> 680) resolves to &mm->sc_stat.cpu, and 0xffffffff is just -1. My AI model
> points me to this write in account_mm_sched():
>
> if (READ_ONCE(mm->sc_stat.cpu) != -1)
> WRITE_ONCE(mm->sc_stat.cpu, -1);
>
> and helps with analyzing and fixing the issue like below :-) . Please have
> a look.
>
> Thanks,
> Zenghui
>
> ---8<---
>
> From 992b515f18710e77308cf5f88943cc3ce918a525 Mon Sep 17 00:00:00 2001
> From: "Zenghui Yu (Huawei)" <zenghui.yu@linux.dev>
> Date: Mon, 14 Sep 2026 22:00:18 +0800
> Subject: [PATCH] sched/cache: Fix use-after-free of mm in account_mm_sched()
I think you have hit a similar use after free issue that was discussed in this
thread.
https://lore.kernel.org/lkml/apPb-Dr4nPYuHQOK@v4bel/
Can you try the last two patches in this 4 patch series
that address this issue in a comprehensive way
https://lore.kernel.org/lkml/cover.1789061845.git.tim.c.chen@linux.intel.com/
Thanks.
Tim
>
> account_mm_sched() accounts runtime against rq->curr and dereferences its
> ->mm: it updates the percpu chunk mm->sc_stat.pcpu_sched and may write
> mm->sc_stat.cpu = -1.
>
> update_se(), which samples rq->curr and calls account_mm_sched(), is not
> only called from local contexts (tick, context switch) but also through
> update_curr() from enqueue/dequeue paths, which frequently run on a remote
> CPU while holding this rq's lock (cross-CPU try_to_wake_up(), load
> balancing).
>
> In those remote contexts rq->curr is a task concurrently running on its
> home CPU. The rq lock guarantees that rq->curr's identity does not change,
> but it says nothing about the lifetime of rq->curr->mm: that task does not
> need the rq lock to execute execve or exit, and switches and drops its ->mm
> under task_lock() and mmput(), neither of which orders against the remote
> CPU. A remote CPU can therefore sample a valid mm pointer right before it
> is freed and write to it afterwards, corrupting the freed mm_struct (and
> the pcpu_sched percpu chunk, which mm_destroy_sched() frees even earlier).
>
> Observed with CONFIG_SLUB_DEBUG=y as a sporadic "Poison overwritten" report
> on the mm_struct cache, with the overwritten bytes resolving to
> &mm->sc_stat.cpu.
>
> Only account the physically running task (p == current), whose ->mm cannot
> go away while it is the one executing this code. Local tick, context
> switch and sched_ttwu_pending() paths are unaffected; updates skipped in
> remote contexts only cause minor under-accounting of the sc_stat runtime
> heuristics.
>
> Fixes: df0d98475954 ("sched/cache: Introduce infrastructure for cache-aware load balancing")
> Assisted-by: GLM-5.3 OpenCode
> Signed-off-by: Zenghui Yu (Huawei) <zenghui.yu@linux.dev>
> ---
> kernel/sched/fair.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
> index ade1eceb39b8..2bbf59370d23 100644
> --- a/kernel/sched/fair.c
> +++ b/kernel/sched/fair.c
> @@ -1731,6 +1731,9 @@ void account_mm_sched(struct rq *rq, struct task_struct *p, s64 delta_exec)
> int mm_sched_llc = -1;
> unsigned long epoch;
>
> + if (p != current)
> + return;
> +
> if (!sched_cache_enabled())
> return;
>
next prev parent reply other threads:[~2026-09-14 23:12 UTC|newest]
Thread overview: 71+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-01 21:52 [Patch v4 00/22] Cache aware scheduling Tim Chen
2026-04-01 21:52 ` [Patch v4 01/22] sched/cache: Introduce infrastructure for cache-aware load balancing Tim Chen
2026-04-09 12:41 ` Peter Zijlstra
2026-04-09 19:21 ` Tim Chen
2026-04-09 23:00 ` Peter Zijlstra
2026-04-10 6:30 ` Chen, Yu C
2026-04-15 2:06 ` Vern Hao
2026-04-15 3:34 ` Chen, Yu C
2026-09-14 17:50 ` Zenghui Yu
2026-09-14 23:12 ` Tim Chen [this message]
2026-04-01 21:52 ` [Patch v4 02/22] sched/cache: Limit the scan number of CPUs when calculating task occupancy Tim Chen
2026-04-09 13:17 ` Luo Gengkun
2026-04-09 13:41 ` Peter Zijlstra
2026-04-10 10:12 ` Luo Gengkun
2026-04-10 7:29 ` Chen, Yu C
2026-04-10 10:20 ` Luo Gengkun
2026-04-10 17:12 ` Tim Chen
2026-04-10 17:27 ` Chen, Yu C
2026-04-13 7:23 ` [RFC PATCH] sched/fair: dynamically scale the period of cache work Jianyong Wu
2026-04-13 8:38 ` Chen, Yu C
2026-04-13 11:27 ` Jianyong Wu
2026-04-15 3:31 ` Chen, Yu C
2026-04-16 3:39 ` Jianyong Wu
2026-04-15 17:22 ` Tim Chen
2026-04-16 6:50 ` Jianyong Wu
2026-04-14 15:07 ` [PATCH v2] sched/cache: Reduce the overhead of task_cache_work by only scan the visisted cpus Luo Gengkun
2026-04-15 3:10 ` Chen, Yu C
2026-04-18 9:01 ` Luo Gengkun
2026-04-20 7:53 ` Chen, Yu C
2026-04-23 8:54 ` [PATCH v3] " Luo Gengkun
2026-04-01 21:52 ` [Patch v4 03/22] sched/cache: Record per LLC utilization to guide cache aware scheduling decisions Tim Chen
2026-04-01 21:52 ` [Patch v4 04/22] sched/cache: Introduce helper functions to enforce LLC migration policy Tim Chen
2026-04-01 21:52 ` [Patch v4 05/22] sched/cache: Make LLC id continuous Tim Chen
2026-04-01 21:52 ` [Patch v4 06/22] sched/cache: Assign preferred LLC ID to processes Tim Chen
2026-04-01 21:52 ` [Patch v4 07/22] sched/cache: Track LLC-preferred tasks per runqueue Tim Chen
2026-04-01 21:52 ` [Patch v4 08/22] sched/cache: Introduce per CPU's tasks LLC preference counter Tim Chen
2026-04-01 21:52 ` [Patch v4 09/22] sched/cache: Calculate the percpu sd task LLC preference Tim Chen
2026-04-01 21:52 ` [Patch v4 10/22] sched/cache: Count tasks prefering destination LLC in a sched group Tim Chen
2026-04-01 21:52 ` [Patch v4 11/22] sched/cache: Check local_group only once in update_sg_lb_stats() Tim Chen
2026-04-01 21:52 ` [Patch v4 12/22] sched/cache: Prioritize tasks preferring destination LLC during balancing Tim Chen
2026-04-01 21:52 ` [Patch v4 13/22] sched/cache: Add migrate_llc_task migration type for cache-aware balancing Tim Chen
2026-04-01 21:52 ` [Patch v4 14/22] sched/cache: Handle moving single tasks to/from their preferred LLC Tim Chen
2026-04-01 21:52 ` [Patch v4 15/22] sched/cache: Respect LLC preference in task migration and detach Tim Chen
2026-04-01 21:52 ` [Patch v4 16/22] sched/cache: Disable cache aware scheduling for processes with high thread counts Tim Chen
2026-04-09 12:43 ` Peter Zijlstra
2026-04-09 19:27 ` Tim Chen
2026-04-01 21:52 ` [Patch v4 17/22] sched/cache: Avoid cache-aware scheduling for memory-heavy processes Tim Chen
2026-04-09 12:46 ` Peter Zijlstra
2026-04-09 12:55 ` Peter Zijlstra
2026-04-10 8:59 ` Chen, Yu C
2026-04-10 9:20 ` Peter Zijlstra
2026-04-01 21:52 ` [Patch v4 18/22] sched/cache: Enable cache aware scheduling for multi LLCs NUMA node Tim Chen
2026-04-09 13:37 ` Peter Zijlstra
2026-04-09 19:39 ` Tim Chen
2026-04-01 21:52 ` [Patch v4 19/22] sched/cache: Allow the user space to turn on and off cache aware scheduling Tim Chen
2026-04-01 21:52 ` [Patch v4 20/22] sched/cache: Add user control to adjust the aggressiveness of cache-aware scheduling Tim Chen
2026-04-01 21:52 ` [Patch v4 21/22] -- DO NOT APPLY!!! -- sched/cache/debug: Display the per LLC occupancy for each process via proc fs Tim Chen
2026-04-01 21:52 ` [Patch v4 22/22] -- DO NOT APPLY!!! -- sched/cache/debug: Add ftrace to track the load balance statistics Tim Chen
2026-04-09 13:54 ` [Patch v4 00/22] Cache aware scheduling Peter Zijlstra
2026-04-09 20:02 ` Tim Chen
2026-04-14 3:20 ` Duan Tingyin
2026-04-15 17:35 ` Tim Chen
2026-04-16 0:27 ` Qais Yousef
2026-04-20 9:01 ` Chen, Yu C
2026-04-21 0:34 ` Qais Yousef
2026-04-21 20:57 ` Tim Chen
2026-04-23 15:06 ` Qais Yousef
2026-04-23 16:48 ` Chen, Yu C
2026-04-25 0:05 ` Qais Yousef
2026-04-23 17:17 ` Chen, Yu C
2026-04-25 0:14 ` Qais Yousef
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=eb77a9a6b27940f1ae9acc0b87f75f3b46f28a13.camel@linux.intel.com \
--to=tim.c.chen@linux.intel.com \
--cc=adamli@os.amperecomputing.com \
--cc=aubrey.li@intel.com \
--cc=bsegall@google.com \
--cc=cyy@cyyself.name \
--cc=dietmar.eggemann@arm.com \
--cc=gautham.shenoy@amd.com \
--cc=gavinguo@igalia.com \
--cc=haoxing990@gmail.com \
--cc=hdanton@sina.com \
--cc=jianyong.wu@outlook.com \
--cc=joshdon@google.com \
--cc=juri.lelli@redhat.com \
--cc=kprateek.nayak@amd.com \
--cc=len.brown@intel.com \
--cc=libchen@purestorage.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mgorman@suse.de \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=qyousef@layalina.io \
--cc=rostedt@goodmis.org \
--cc=sshegde@linux.ibm.com \
--cc=tim.c.chen@intel.com \
--cc=tingyin.duan@gmail.com \
--cc=vernhao@tencent.com \
--cc=vincent.guittot@linaro.org \
--cc=vineethr@linux.ibm.com \
--cc=vschneid@redhat.com \
--cc=yu.c.chen@intel.com \
--cc=yu.chen.surf@gmail.com \
--cc=zenghui.yu@linux.dev \
--cc=zhao1.liu@intel.com \
--cc=ziqianlu@bytedance.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®