All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tejun Heo <tj@kernel.org>
To: Tao Cui <cui.tao@linux.dev>
Cc: Tao Cui <cuitao@kylinos.cn>,
	void@manifault.com, arighi@nvidia.com, changwoo@igalia.com,
	sched-ext@lists.linux.dev, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] sched_ext: don't rehome a dead task in scx_cgroup_task_migrated
Date: Fri, 14 Aug 2026 09:04:18 -1000	[thread overview]
Message-ID: <71d1c173b538ca29d783232d89464d7a@kernel.org> (raw)
In-Reply-To: <20260811103122.357067-1-cui.tao@linux.dev>

Hello,

On Tue, Aug 11, 2026 at 06:31:22PM +0800, Tao Cui wrote:
> A task can exit between cgroup migration commit and the MIGRATED callback:
> sched_ext_dead() marks it SCX_TASK_DEAD before cgroup_task_dead() removes it
> from the migration list, so scx_cgroup_task_migrated() can pick up a dead
> task and call scx_rehome_task(), which re-enables it and leaks the BPF
> scheduler's per-task resources. The other scx_rehome_task() callers already
> check for this; do the same here.

I don't think this window exists. SCX_TASK_DEAD is set only by
sched_ext_dead() from finish_task_switch(), which a task reaches only
after exit_signals(), and exit_signals() sets PF_EXITING inside
cgroup_threadgroup_change_begin(). The MIGRATED notifiers run inside
cgroup_migrate_execute() with the same rwsem write-held through
cgroup_attach_lock(), so no task in the set can enter the exit path
until the migration is done. Tasks which were already exiting are
filtered out by the PF_EXITING test in cgroup_migrate_add_task().

The DEAD tests you referenced are in scx_task_iter walks which run
without the threadgroup rwsem, where dying tasks can actually show up.

Did you try to reproduce the leak? When code review turns up a
suspected bug, it's a good idea to reproduce it first to verify the
assumptions before writing a fix.

Thanks.

--
tejun

  reply	other threads:[~2026-08-14 19:04 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-11 10:31 [PATCH] sched_ext: don't rehome a dead task in scx_cgroup_task_migrated Tao Cui
2026-08-14 19:04 ` Tejun Heo [this message]
2026-08-15  3:31   ` Tao Cui

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=71d1c173b538ca29d783232d89464d7a@kernel.org \
    --to=tj@kernel.org \
    --cc=arighi@nvidia.com \
    --cc=changwoo@igalia.com \
    --cc=cui.tao@linux.dev \
    --cc=cuitao@kylinos.cn \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sched-ext@lists.linux.dev \
    --cc=void@manifault.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.