From: sashiko-bot@kernel.org
To: "Shubhang Kaushik (Ampere)" <sh@gentwo.org>
Cc: sched-ext@lists.linux.dev
Subject: Re: [PATCH v2] sched: Restart hrtick after same-task repicks
Date: Fri, 11 Sep 2026 22:42:30 +0000 [thread overview]
Message-ID: <20260911224230.A19611F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260911-sched-fair-hrtick-restart-v2-1-0d34db26ecd1@gentwo.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Restarting the SCHED_DEADLINE hrtick on same-task repick uses a stale `dl_se->runtime`, pushing the timer expiration into the future and allowing bandwidth overruns.
--
commit fe44140b6abb0653f45d8368ffe6e56a2831b43c
Author: Shubhang Kaushik (Ampere) <sh@gentwo.org>
sched: Restart hrtick after same-task repicks
This commit introduces explicit hrtick restarts for same-task repicks in both
fair and deadline scheduling classes. It adds a new SNT_REPICK type to bypass
normal transition work while still rearming the timer.
Link: https://lore.kernel.org/r/20260813-sched-fair-hrtick-restart-v1-1-4230d1e18fbb@gentwo.org
> diff --git a/kernel/sched/deadline.c b/kernel/sched/deadline.c
> index 0663c00c41c04..6c17563f42a1d 100644
> --- a/kernel/sched/deadline.c
> +++ b/kernel/sched/deadline.c
[ ... ]
> -static void set_next_task_dl(struct rq *rq, struct task_struct *p, bool first)
> +static void set_next_task_dl(struct rq *rq, struct task_struct *p, enum snt_e type)
> {
> struct sched_dl_entity *dl_se = &p->dl;
> struct dl_rq *dl_rq = &rq->dl;
>
> + if (type == SNT_REPICK)
> + goto repick;
> +
> p->se.exec_start = rq_clock_task(rq);
[ ... ]
> deadline_queue_push_tasks(rq);
>
> +repick:
> if (hrtick_enabled_dl(rq))
> start_hrtick_dl(rq, &p->dl);
> }
[Severity: High]
Does this code use a stale dl_se->runtime to arm the hrtick?
When a wake-up or other non-tick preemption check sets TIF_NEED_RESCHED
on a running SCHED_DEADLINE task without calling update_curr_dl(),
__schedule() might repick the same task (e.g., if the woken task was migrated
away before picking).
If that happens, put_prev_set_next_task() takes the SNT_REPICK path, which
skips put_prev_task():
kernel/sched/sched.h:put_prev_set_next_task() {
...
if (next == prev) {
next->sched_class->set_next_task(rq, next, SNT_REPICK);
return;
}
...
}
Because put_prev_task() is skipped, its embedded update_curr_dl() call is
also skipped. As a result, dl_se->runtime is not decremented for the time
executed since the last update.
When start_hrtick_dl() is then invoked from the repick label above, the new
hrtick is erroneously scheduled using the un-updated runtime.
Can this allow SCHED_DEADLINE tasks to exceed their configured bandwidth bounds
and starve other tasks?
> diff --git a/kernel/sched/sched.h b/kernel/sched/sched.h
> index e656c7059bf86..defcf7fd023fa 100644
> --- a/kernel/sched/sched.h
> +++ b/kernel/sched/sched.h
[ ... ]
> @@ -2802,11 +2808,13 @@ static inline void put_prev_set_next_task(struct rq *rq,
>
> __put_prev_set_next_dl_server(rq, prev, next);
>
> - if (next == prev)
> + if (next == prev) {
> + next->sched_class->set_next_task(rq, next, SNT_REPICK);
> return;
> + }
>
> prev->sched_class->put_prev_task(rq, prev, next);
> - next->sched_class->set_next_task(rq, next, true);
> + next->sched_class->set_next_task(rq, next, SNT_PICK);
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260911-sched-fair-hrtick-restart-v2-1-0d34db26ecd1@gentwo.org?part=1
next prev parent reply other threads:[~2026-09-11 22:42 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 22:08 [PATCH v2] sched: Restart hrtick after same-task repicks Shubhang Kaushik (Ampere)
2026-09-11 22:42 ` sashiko-bot [this message]
2026-09-11 23:31 ` Shubhang
2026-09-13 20:10 ` Shubhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911224230.A19611F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sched-ext@lists.linux.dev \
--cc=sh@gentwo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.