From: sashiko-bot@kernel.org
To: "Andrea Righi" <arighi@nvidia.com>
Cc: sched-ext@lists.linux.dev
Subject: Re: [PATCH 17/18] sched_ext: scx_qmap: Add proxy execution support
Date: Mon, 31 Aug 2026 18:33:56 +0000 [thread overview]
Message-ID: <20260831183356.6E92E1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831134338.1531664-18-arighi@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Missing bounds check on `cid` returned from `cmask_next_and_set_wrap()` due to a TOCTOU race with `qa.self_cids.mask` modifications.
--
commit 564b1258b3dc07e22341c55b61be164307b61870
Author: Andrea Righi <arighi@nvidia.com>
sched_ext: scx_qmap: Add proxy execution support
Add a -X option to opt scx_qmap into queueing mutex-blocked tasks for proxy
execution. When scx_qmap receives a blocked donor, it selects an eligible cid
and dispatches the donor to that local DSQ.
> diff --git a/tools/sched_ext/scx_qmap.bpf.c b/tools/sched_ext/scx_qmap.bpf.c
> index 5bb8b90a275a3..21f8a9be9650c 100644
> --- a/tools/sched_ext/scx_qmap.bpf.c
> +++ b/tools/sched_ext/scx_qmap.bpf.c
[ ... ]
> @@ -460,6 +464,53 @@ void BPF_STRUCT_OPS(qmap_enqueue, struct task_struct *p, u64 enq_flags)
[ ... ]
> + /*
> + * Insert a blocked mutex donor at the head of an eligible local DSQ with
> + * a fresh slice and %SCX_ENQ_PREEMPT, requesting an immediate reschedule.
> + * The test above guarantees that cpus_allowed intersects self_cids, but
> + * the donor's current cid may have been delegated to a child. Search the
> + * intersection starting at the current cid, preserving it when qmap still
> + * holds it and wrapping to another eligible self cid otherwise.
> + *
> + * A self cid may be held exclusively with SCX_CAP_ENQ or time-shared with
> + * only SCX_CAP_ENQ_IMMED. Add needs_immed() so either kind can accept the
> + * local insertion instead of rejecting and reenqueuing the donor for a
> + * capability miss. Once selected, the core proxy-exec path can run the
> + * mutex owner using the donor's scheduling context.
> + *
> + * This policy is intentionally unfair and can strongly prioritize tasks
> + * using contended mutexes; scx_qmap is a demonstration scheduler and
> + * this behavior makes proxy-exec support easy to observe.
> + */
> + if (enq_flags & SCX_ENQ_BLOCKED) {
> + cid = cmask_next_and_set_wrap(&taskc->cpus_allowed,
> + &qa.self_cids.mask,
> + scx_bpf_task_cid(p));
> + scx_bpf_dsq_insert(p, SCX_DSQ_LOCAL_ON | cid, slice_ns,
> + enq_flags | needs_immed(cid) | SCX_ENQ_PREEMPT);
> + return;
> + }
[Severity: High]
Does this code risk an out-of-bounds access if the intersection becomes
empty?
In qmap_enqueue(), there is an earlier check for
cmask_intersects(&taskc->cpus_allowed, &qa.self_cids.mask).
However, if apply_partition() modifies and zeroes qa.self_cids.mask
concurrently on another CPU after the check, the intersection might become
empty before cmask_next_and_set_wrap() executes.
If this happens, cmask_next_and_set_wrap() returns the out-of-bounds
sentinel scx_bpf_nr_cids().
This out-of-bounds cid is then used without a bounds check in:
scx_bpf_dsq_insert(p, SCX_DSQ_LOCAL_ON | cid, ...)
which can cause scx_cpu_valid() to fail and forcefully eject the BPF
scheduler. It could also lead to an out-of-bounds read in needs_immed(cid).
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260831134338.1531664-1-arighi@nvidia.com?part=17
next prev parent reply other threads:[~2026-08-31 18:33 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 13:42 [PATCHSET v13 sched_ext/for-7.4] sched: Make proxy execution compatible with sched_ext Andrea Righi
2026-08-31 13:42 ` [PATCH 01/18] sched/core: Drop mutex locks before proxy rescheduling Andrea Righi
2026-08-31 13:42 ` [PATCH 02/18] sched/core: Dequeue waking proxy donors before reset Andrea Righi
2026-09-01 5:24 ` K Prateek Nayak
2026-09-08 9:28 ` Andrea Righi
2026-08-31 13:42 ` [PATCH 03/18] sched: Make NOHZ CFS bandwidth checks follow proxy donor Andrea Righi
2026-09-10 9:54 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 04/18] sched/core: Avoid false migration warning for proxy donors Andrea Righi
2026-09-10 10:06 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 05/18] sched: Pass next class to sched_change_begin() Andrea Righi
2026-09-10 10:12 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 06/18] sched: Add helper to block retained proxy donors Andrea Righi
2026-08-31 13:42 ` [PATCH 07/18] sched: Add sched_ext hooks for proxy execution Andrea Righi
2026-09-10 10:38 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 08/18] sched: Introduce WF_ON_RQ wake flag Andrea Righi
2026-09-10 10:45 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 09/18] sched_ext: Block proxy donors across scheduler transitions Andrea Righi
2026-09-10 10:53 ` Peter Zijlstra
2026-09-10 11:41 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 10/18] sched_ext: Fix ops.running/stopping() pairing for proxy-exec donors Andrea Righi
2026-08-31 13:42 ` [PATCH 11/18] sched_ext: Move reject DSQ draining into core Andrea Righi
2026-08-31 13:42 ` [PATCH 12/18] sched_ext: Generalize the reject DSQ reenqueue path Andrea Righi
2026-09-03 22:39 ` Tejun Heo
2026-09-08 9:34 ` Andrea Righi
2026-08-31 13:42 ` [PATCH 13/18] sched_ext: Handle proxy-exec races in remote DSQ transfers Andrea Righi
2026-08-31 13:42 ` [PATCH 14/18] sched_ext: Split curr|donor references properly Andrea Righi
2026-08-31 17:49 ` sashiko-bot
2026-09-08 10:15 ` Andrea Righi
2026-09-10 11:47 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 15/18] sched_ext: Delegate proxy donor admission to BPF schedulers Andrea Righi
2026-08-31 18:08 ` sashiko-bot
2026-09-08 10:08 ` Andrea Righi
2026-09-10 13:39 ` Peter Zijlstra
2026-09-10 13:41 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 16/18] sched_ext: Add selftest for blocked donor admission Andrea Righi
2026-08-31 13:42 ` [PATCH 17/18] sched_ext: scx_qmap: Add proxy execution support Andrea Righi
2026-08-31 18:33 ` sashiko-bot [this message]
2026-09-01 7:52 ` Richard Cheng
2026-09-08 9:42 ` Andrea Righi
2026-08-31 13:42 ` [PATCH 18/18] sched: Allow enabling proxy exec with sched_ext Andrea Righi
2026-09-03 22:51 ` [PATCHSET v13 sched_ext/for-7.4] sched: Make proxy execution compatible " Tejun Heo
2026-09-08 8:02 ` Peter Zijlstra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831183356.6E92E1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=arighi@nvidia.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sched-ext@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.