From: Aaron Tomlin <atomlin@atomlin.com>
To: mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com,
vincent.guittot@linaro.org
Cc: dietmar.eggemann@arm.com, rostedt@goodmis.org,
bsegall@google.com, mgorman@suse.de, vschneid@redhat.com,
kprateek.nayak@amd.com, zhanxusheng1024@gmail.com,
neelx@suse.com, chjohnst@mail.com, mproche@mail.com,
sean@ashe.io, steve@abita.co, linux-kernel@vger.kernel.org
Subject: [PATCH v3 2/4] sched/debug: Protect lockless rq->rd access in print_dl_rq()
Date: Sat, 8 Aug 2026 19:55:20 -0400 [thread overview]
Message-ID: <20260808235522.380038-3-atomlin@atomlin.com> (raw)
In-Reply-To: <20260808235522.380038-1-atomlin@atomlin.com>
In print_dl_rq(), cpu_rq(cpu)->rd is dereferenced locklessly to display
deadline bandwidth statistics.
During CPU hot-unplug or cgroup cpuset repartitioning events,
partition_sched_domains() calls cpu_attach_domain(), which executes
rq_attach_root() to detach the CPU from its root_domain. When the
reference count of the detached root_domain drops to zero,
rq_attach_root() calls call_rcu(&old_rd->rcu, free_rootdomain) to
schedule memory teardown after an RCU grace period.
Because print_dl_rq() does not hold an RCU read lock while dereferencing
cpu_rq(cpu)->rd, an RCU grace period can elapse concurrently while
debugfs is reading the file. This allows free_rootdomain() to execute
kfree(old_rd), introducing a use-after-free race condition when
print_dl_rq() reads dl_bw->bw.
Fix this by fetching rq->rd using READ_ONCE() inside an RCU read-side
critical section. Holding the RCU read lock guarantees that the struct
root_domain memory remains valid while being accessed.
Fixes: 02968ccf7b80 ("sched: add /proc/sched_debug file")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Signed-off-by: Aaron Tomlin <atomlin@atomlin.com>
---
kernel/sched/debug.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/kernel/sched/debug.c b/kernel/sched/debug.c
index 78fc02d71710..e9d40a660346 100644
--- a/kernel/sched/debug.c
+++ b/kernel/sched/debug.c
@@ -1081,6 +1081,7 @@ void print_rt_rq(struct seq_file *m, int cpu, struct rt_rq *rt_rq)
void print_dl_rq(struct seq_file *m, int cpu, struct dl_rq *dl_rq)
{
struct dl_bw *dl_bw;
+ struct root_domain *rd;
SEQ_printf(m, "\n");
SEQ_printf(m, "dl_rq[%d]:\n", cpu);
@@ -1089,9 +1090,14 @@ void print_dl_rq(struct seq_file *m, int cpu, struct dl_rq *dl_rq)
SEQ_printf(m, " .%-30s: %lu\n", #x, (unsigned long)(dl_rq->x))
PU(dl_nr_running);
- dl_bw = &cpu_rq(cpu)->rd->dl_bw;
- SEQ_printf(m, " .%-30s: %lld\n", "dl_bw->bw", dl_bw->bw);
- SEQ_printf(m, " .%-30s: %lld\n", "dl_bw->total_bw", dl_bw->total_bw);
+ rcu_read_lock();
+ rd = READ_ONCE(cpu_rq(cpu)->rd);
+ if (rd) {
+ dl_bw = &rd->dl_bw;
+ SEQ_printf(m, " .%-30s: %lld\n", "dl_bw->bw", dl_bw->bw);
+ SEQ_printf(m, " .%-30s: %lld\n", "dl_bw->total_bw", dl_bw->total_bw);
+ }
+ rcu_read_unlock();
#undef PU
}
--
2.55.0
next prev parent reply other threads:[~2026-08-08 23:55 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-08 23:55 [PATCH v3 0/4] sched/debug: Introduce per-CPU debugfs files Aaron Tomlin
2026-08-08 23:55 ` [PATCH v3 1/4] sched/debug: Protect lockless rq->curr access in print_cpu() Aaron Tomlin
2026-08-08 23:55 ` Aaron Tomlin [this message]
2026-08-08 23:55 ` [PATCH v3 3/4] sched/fair: Use list_for_each_entry_rcu() in print_cfs_stats() Aaron Tomlin
2026-08-08 23:55 ` [PATCH v3 4/4] sched/debug: Introduce per-CPU debugfs files Aaron Tomlin
2026-08-10 3:17 ` [PATCH v3 0/4] " Aaron Tomlin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260808235522.380038-3-atomlin@atomlin.com \
--to=atomlin@atomlin.com \
--cc=bsegall@google.com \
--cc=chjohnst@mail.com \
--cc=dietmar.eggemann@arm.com \
--cc=juri.lelli@redhat.com \
--cc=kprateek.nayak@amd.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mgorman@suse.de \
--cc=mingo@redhat.com \
--cc=mproche@mail.com \
--cc=neelx@suse.com \
--cc=peterz@infradead.org \
--cc=rostedt@goodmis.org \
--cc=sean@ashe.io \
--cc=steve@abita.co \
--cc=vincent.guittot@linaro.org \
--cc=vschneid@redhat.com \
--cc=zhanxusheng1024@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.