From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 81ACB4C97 for ; Sun, 1 Mar 2026 05:48:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772344085; cv=none; b=J1aMVAW7B9OvH52q/PAdv2bHIyWEinGbXm94CIIo4UEPRjo6H3rl1ITGuX4tkeRsuG4JaIjeDvd0yFmV25OYKQw8UEgGJe2MrGJaTzhRXZmiv6U6D6AXEQbTCT/kDtwm2zjpdk86TfHJ23Yus2pM6B1ppCW0VmXBym81HTq2Z/o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772344085; c=relaxed/simple; bh=YVzdQWatupisD5/6zI1ple5bTlnh//OV1FXeFgLZYxI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=u1KVGPHHWlx4+JyOpodAwi39nNeJ634fX59toi2bwIPdzJCRc2WrM5SKbZz8Jj/Ii6wiHOslXGXqOMV8ZDrORmAGvHPfimCS/Twu3S3efibJ24yZR+S+Vj7gr7M/YUXPGxzb3eUIYrPNUHy5pwAczIC93ZHleWXD1W3J89MeQyY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SOyp4DQU; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SOyp4DQU" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-4837f27cf2dso29041675e9.2 for ; Sat, 28 Feb 2026 21:48:04 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1772344083; x=1772948883; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=WCm4b83PuYf6Kz8btQCPJzVgHYbi6fm8+OU5cku/I/8=; b=SOyp4DQU9Hez/WhnHcOzyJ1XlGmm9KmdbPeFW0O5sbMifDKEramGHLzFrlruuFQpIY s79vjUkPneLlTQIlZI8cXCDi1Di+ieDtxVwZT/oPnL3rPPPzqQR20klM39GnvYmJ85nG +r+MttaW5/gABYuVx/L2r91qw3XkTVe/V/wdTtapi9we3b1iQB3MxmqKqv1DoNionCjh xF4pKAHZcAxjvh/DPZZx1WGmMQMQr4xPNfUZzxMLLPgkipafWnm37f4fYOGZojNBXhTz Q7ip0oJIih5zvLexjPYjutb4AbqskoXBjTfrE2BOmsUNZBWFYnrhjls/IsQroK2xlPNl gW2w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772344083; x=1772948883; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=WCm4b83PuYf6Kz8btQCPJzVgHYbi6fm8+OU5cku/I/8=; b=GTD1RRiCqAn18++PzWT+WU4+p5ecdnZEXiTpkDUjOgpJk2HHFWGBbF/8TVjx8U9Nfz o/PPPTBqo6xe7L78SsbDymIFq38FZGa+7zyAidahE9lQA7qrtpvEEf0FrLmiCCgneeAN emp6Rg+JsDGtdg7hQpNZMzFOg/YbRvD4xbd0tO0sl9P2i/GXJrADtq0n3402o8DtCgvP 7xMn8trr6tnTlNZb1LgiRei4zNyYbSy9PBy5yx81OIzeWYuVy8e8JQxEnQNmQdg7+OBF yr+ISoMZhWCqygwcjeOe3GFkGNtPutxrMWOCryPYcRse9wGrK15lvQkz0cRs/foo3T9b TrIw== X-Gm-Message-State: AOJu0YwtLFfDiHT9SnFbaf9clQH5Qh3vITRSXCOj7aMnPD6M/D4OuJ1E UUkuALkyNu4C4UnJPVNSyUCLqrbiDbXsAZD+o8U7z9pwrMyTbeVcbFJv58EXZ0a5 X-Gm-Gg: ATEYQzxVexEDaMMShuz1uwmr3YR6gHAnKDydwq32jJLK8F6UZfrX+N4TZb0CXZHiDVa DRFAQqtPKDRagoFoBiaoACMASlHapjN4UepOeb2RtyUyYA3mVywNtw2CS+jhqOdobkkkGwU4owY p0+w6/KtgBzo5ZZX+WZ/UqusWWmKeHAozJIQZZgvsDBgc21KPvSqiUTbyLgX4wfx2L56C54S4Oc fnOcv7h+HaRYkymiC8DxcEK2yRjV2EC+/ssIMC2JkFoqmU/t7BmaL9Dg+FvlgA6ZPha/Y0Q1/qz HvIqH73OiFDzUebPGtidUyGvFgj47+yVs0BnT7YaBR/9dTz4TIZw/llzhuKPVkr8aYxhkU6mroP YgglPonK3haE9NqvuFudAafCTGBjqjQ3PCQtYogFKpe+cL6sY9ZswoA0ZREa91pHzhR/FBHq5a6 zeLWgoBRWMMy/UwEJM2txLzhJ+35KheMc5kr9B7RAwvb2GCVk9rK6W0Cwj1xXtyEnPeL57xbKdx DkWB0OMTlHV/ifNy49B X-Received: by 2002:a05:600c:1c28:b0:471:14af:c715 with SMTP id 5b1f17b1804b1-483c9bc5643mr144065295e9.3.1772344082404; Sat, 28 Feb 2026 21:48:02 -0800 (PST) Received: from rozandragon.chello.ie (188-141-5-72.dynamic.upc.ie. [188.141.5.72]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-439b55df68dsm349785f8f.26.2026.02.28.21.48.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 28 Feb 2026 21:48:01 -0800 (PST) From: David Carlier To: Tejun Heo , David Vernet Cc: linux-kernel@vger.kernel.org, David Carlier Subject: [PATCH] tools/sched_ext: scx_simple/scx_cpu0: fix potential stack overflow from VLA in read_stats Date: Sun, 1 Mar 2026 05:47:56 +0000 Message-ID: <20260301054756.237229-1-devnexen@gmail.com> X-Mailer: git-send-email 2.51.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit read_stats() in both scx_simple and scx_cpu0 had a VLA allocating 2 * nr_cpus * 8 bytes on the stack, risking stack overflow on large CPU counts. Apply the same fix as commit cabd76bbc036 ("tools/sched_ext: scx_flatcg: fix potential stack overflow from VLA in fcg_read_stats"): use a single heap allocation, reuse it across all stat indices, and free it at the end. Signed-off-by: David Carlier --- tools/sched_ext/scx_cpu0.c | 12 +++++++++--- tools/sched_ext/scx_simple.c | 12 +++++++++--- 2 files changed, 18 insertions(+), 6 deletions(-) diff --git a/tools/sched_ext/scx_cpu0.c b/tools/sched_ext/scx_cpu0.c index a6fba9978b9c..0b412d2eb3f0 100644 --- a/tools/sched_ext/scx_cpu0.c +++ b/tools/sched_ext/scx_cpu0.c @@ -41,21 +41,27 @@ static void read_stats(struct scx_cpu0 *skel, __u64 *stats) { int nr_cpus = libbpf_num_possible_cpus(); assert(nr_cpus > 0); - __u64 cnts[2][nr_cpus]; + __u64 *cnts; __u32 idx; + cnts = calloc(nr_cpus, sizeof(__u64)); + if (!cnts) + return; + memset(stats, 0, sizeof(stats[0]) * 2); for (idx = 0; idx < 2; idx++) { int ret, cpu; ret = bpf_map_lookup_elem(bpf_map__fd(skel->maps.stats), - &idx, cnts[idx]); + &idx, cnts); if (ret < 0) continue; for (cpu = 0; cpu < nr_cpus; cpu++) - stats[idx] += cnts[idx][cpu]; + stats[idx] += cnts[cpu]; } + + free(cnts); } int main(int argc, char **argv) diff --git a/tools/sched_ext/scx_simple.c b/tools/sched_ext/scx_simple.c index c3b48611712b..b6ef4cca425a 100644 --- a/tools/sched_ext/scx_simple.c +++ b/tools/sched_ext/scx_simple.c @@ -43,21 +43,27 @@ static void read_stats(struct scx_simple *skel, __u64 *stats) { int nr_cpus = libbpf_num_possible_cpus(); assert(nr_cpus > 0); - __u64 cnts[2][nr_cpus]; + __u64 *cnts; __u32 idx; + cnts = calloc(nr_cpus, sizeof(__u64)); + if (!cnts) + return; + memset(stats, 0, sizeof(stats[0]) * 2); for (idx = 0; idx < 2; idx++) { int ret, cpu; ret = bpf_map_lookup_elem(bpf_map__fd(skel->maps.stats), - &idx, cnts[idx]); + &idx, cnts); if (ret < 0) continue; for (cpu = 0; cpu < nr_cpus; cpu++) - stats[idx] += cnts[idx][cpu]; + stats[idx] += cnts[cpu]; } + + free(cnts); } int main(int argc, char **argv) -- 2.51.0