From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from LO0P265CU003.outbound.protection.outlook.com (mail-uksouthazon11022101.outbound.protection.outlook.com [52.101.96.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E0559372EFF for ; Sat, 8 Aug 2026 23:55:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.96.101 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786233335; cv=fail; b=Rp3cVERR1zuddrSzhPTqYw7FBgmvS3b1Fj8vMBUIlEcW+lFURICQ3td6C4B9VNcn8HI2PThjEs3PKFjGWAsTjAM0uq5pN3TvacrA9BWLTL/jrVupcCraUzOnSVy7oEei4UVj5mPHWd4arRkcrzhjB0J1wtV1Y4pZTab9Xnm1nU0= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786233335; c=relaxed/simple; bh=yQ3U8HDlR0Q2wR1wCvVkYNnP4YMBNysaGJy9VTZXFx0=; h=From:To:Cc:Subject:Date:Message-ID:Content-Type:MIME-Version; b=gDHbdDcjM8XPhART+0I6Gp4T1wTR+Aq3F6xpflXjuxoYI5BfTj8UnlGWbSMzavEtJfb43711L2pAan2AI2HNSQu23Z6Z+2vxCoqOLriRhU0VV4sukrEJEeeBAzPWxfadFfuUftZe7aQw5xCPxCp0JmzW03Sf4r+t8PJQmKI6EgA= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com; spf=pass smtp.mailfrom=atomlin.com; arc=fail smtp.client-ip=52.101.96.101 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=atomlin.com ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Td5008QZklQCIYhdT5hqwWG8+4n1IhXYeJZSbJSqUS0cabITVZdeFMOr8aRXQ1zAerijv+96sD1ctqKKgdWFo981Y8rXnXB4e5HNTr4aGOpZBtXVge2RlTKSrkeftZ235metbxQ0fns4qe0ZDJbpAr9aZfJZQiT8AJJvBj0oTlR9DiyUnK0nTOTYzVYJI+XKVcK1ZwqgIMmYgifwVrEMKYrHU196vx5Y9i6rJE4WX7oSB/Gj/NgbfpSTQthd1IDSSpn3X5lDDxnsWqafkclpVQGMa0QaXr6xvOjRLDcmywqCOt2WBt9XKhi0oomqs522lNZIIbM1/2DHreic4rgEUw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:MIME-Version; bh=nKZhCpXwkoGREyPcOzOOYA7xZ7uDXh05ryE1AxmQykk=; b=SZm5bS3beI0bFvki+e4+mVowE5cDQF4Ca5rMYCJqCdYUyMO5vKnsn4CgAy1cgaG3YSPB+xfjvpiWlLBLS/xPtGu9U8SPB55XRHjrQ1oGvJPEanbCqWo5A5zjAB5kaeOZ1KiZFtDfGu/nGNXqk/TYmJQ5VLnHABDbrZtJrsItvI6aI/hXrybnwnvubj2tALI0rs7nSWgf7ccRP14lUo35/JZmZpZPsr23CHUnxtHHqpN8YhFpbeFxsI2Z72FJ43DZdIrKUSnMLpU14ese1/nZiynRnkly3DvsSj9UIZv+xpQVz/9VFBs3uXSC+63tVI87foTQK0Yvr1YpDqUe6R9kZw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=atomlin.com; dmarc=pass action=none header.from=atomlin.com; dkim=pass header.d=atomlin.com; arc=none Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=atomlin.com; Received: from CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:183::5) by CW1P123MB8837.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:274::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.292.25; Sat, 8 Aug 2026 23:55:27 +0000 Received: from CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM ([fe80::cec4:77ab:262e:d230]) by CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM ([fe80::cec4:77ab:262e:d230%4]) with mapi id 15.21.0292.024; Sat, 8 Aug 2026 23:55:27 +0000 From: Aaron Tomlin To: mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org Cc: dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, zhanxusheng1024@gmail.com, neelx@suse.com, chjohnst@mail.com, mproche@mail.com, sean@ashe.io, steve@abita.co, linux-kernel@vger.kernel.org Subject: [PATCH v3 0/4] sched/debug: Introduce per-CPU debugfs files Date: Sat, 8 Aug 2026 19:55:18 -0400 Message-ID: <20260808235522.380038-1-atomlin@atomlin.com> X-Mailer: git-send-email 2.55.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: BN9PR03CA0880.namprd03.prod.outlook.com (2603:10b6:408:13c::15) To CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:183::5) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CWLP123MB6607:EE_|CW1P123MB8837:EE_ X-MS-Office365-Filtering-Correlation-Id: e8eca6a4-26db-4c02-7079-08def5a884dc X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|7416014|1800799024|366016|23010399003|6133799003|10067099003|56012099006|18002099003|3023799007; X-Microsoft-Antispam-Message-Info: qhy5+ICo5lbUTiG99RqApw1TkEyOmwydQJmF+1KWTOOJ7bvU1Zn4kMRBUF/5uPEvPx+DS/CX/UPCFzjwW72s1NLW8uqiRoz5lJYGN57igQsMvf0hC+YQgVk6OYB4G52HuNrPSGn0Y/SIuq6KSuBmsQqMC9C1bZN61kSewzpWAx05akUj2MHiK6YLLc+nwo4yWeZryg1oebvxeB5Nt3gp6wndKvBwjPx9tv1ezvnW91CGkqyJULQdC887p2DYprkmMKoxsXPj+lXIRBAkaGyhxFIKaR5SyVxMXIJtgQwahHsjEPgVtifJNP6tPszqisgml1zt7DGMHJkiuYIOK6DWxqEwv0HUQXqAV0w3C0aAE4C+dr949HSqOa8qLWUq3UPepyKnDIrQ/IfTm5f1mXNBEHB9vS2gZe8raVz5EghzWRCDdh/gXublC1GY2Cc5dva5qBr4PT/nTts7Zhd1PnnU4IERzetDeX9kA23ER7x/+K/AHMQdX2unHxvThQYCyTeDbp+uCtBbRWNsh+jl/a4YF3tkmPeHgbVolFyzUtHF5Y8qzoPzGjAFWCzOpVUViTZFPxrGCcHKT8pDYR/fa4Ajru9di6FFIEntIolcyranp4h2DraThhAjGkrNoNkFyNymr0CJOsuZsgpB20S3AGOBwFwkOQKNkky38vlphGp3JWA= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(7416014)(1800799024)(366016)(23010399003)(6133799003)(10067099003)(56012099006)(18002099003)(3023799007);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?j32GlfgrFfL9ax/JbozHgiR4T5MGUPIkywkHtHLtz+TngnvQECsiLs4hV5Qj?= =?us-ascii?Q?5VZrHIiw6PwZy1bQnPAaE44GcYpC66V54ncUZQlq54pN/Dk4PpnKrBcY+Uc+?= =?us-ascii?Q?kngMSBXFkVYFF0b1YaqDsYaee+tmM3Am9buirHqO0TozEUUYLDJE8ESrAjz3?= =?us-ascii?Q?hR61nEQFoZV3OYOgZAojQWY5YYm3FaOtDRQeGsKG1+GnTRU7Jm9CWN6J/BeS?= =?us-ascii?Q?YLZSAlR7Xa1aSNqMwwgDUBUmNglC6OEpZBrNIZufPg5n/uAn0trzfLl1192B?= =?us-ascii?Q?fNTI3zjfimZBfT7biY0ctrBRcH2T/NHSW7deY9hjT1lwe6Mq6xcdd1PCcA3k?= =?us-ascii?Q?tkVopVsJXIUxvGctlmn6xvE/A4D2896OBfvx55Oa71DsN2RFK2PW25uLDmeq?= =?us-ascii?Q?1K9YLCikV6+PIhw8uoqzAQZQqFcJCU2zYADDZHYKbZ28fyepkXB/cDvS/28v?= =?us-ascii?Q?+QbSyiie7bZnHmzOcysOAklACLneWxaiwRWgGR7k0Wn+0wldWHzbQaN7KsFc?= =?us-ascii?Q?S/9Msmh4i8DC99EHxAa3jU00yabbPQuCoHw1s3V6HXSWdtpF6GRPnYkVTn/o?= =?us-ascii?Q?FIdVix2I1vVsi8YvUKATE6G2OTuzDVkfjZwSCDuEN8PU44fC9Sq/Y+I5uB9M?= =?us-ascii?Q?HOJ3WBt9Xa4OXSVYsGR/j122isV+3f8fYam8+BhdKtt40mSdWkZFUaCAbBzl?= =?us-ascii?Q?u0PQDwPFzmKBIO01LJk+sjXzOo+Gy8HNzozhflXyKCoNpEjVjoNrq1QfVDCA?= =?us-ascii?Q?sAJZIsiopX+oQh6kVWLvUQds1VeL72uT+kHRei8RgDuAdiPSsIu9VWw8JTTj?= =?us-ascii?Q?2LpgOUVO8D8HnbupuE8Hk0911IaeW9Bjszhm+3hrYFCbnYEMSocEjJhteBHi?= =?us-ascii?Q?ivcQU+vv+C3wDeQSMvaXOAiKUF63SIWOPVrZZqkX/NiEf9ZZ9T11i8itH3kc?= =?us-ascii?Q?hv6ULnc3/HPDuWxDRYWNxgFGyF6pppjtCsQFULprQaie6fCZP7fKNADyrkWB?= =?us-ascii?Q?UDBsBr61Vtvr4bVkqFoddyZort2edfdkGvdHh/jWRh10x3P/n/JFhwoM+pua?= =?us-ascii?Q?nX6HQwPOeK3e+5ir8bQaUHJb+XyohA9HvAyb1uTtRsbqoxHMkQBMTx1opXcs?= =?us-ascii?Q?YtjcrfGTEdTNCf44O+M7I88RmKxANJcY2tILcHwjZ/GA6DOsYe1u2NvMCP2Q?= =?us-ascii?Q?1bB9gj7+3NyKcmdUU3803sefryhB4TOZ8JfP+LURIO7+UwPYgiOA/iVcbm4F?= =?us-ascii?Q?nHt7VKsf9cSLAeQReQSB4P3lXKYOOa/zbTl15l6DEnVlZ0spfxvcZchOC7rJ?= =?us-ascii?Q?ChuX/PhgNhlCz1kX2KXfsNDzUFQrCtrSBif9bgn+FwPjFQfmljI9OkrtD6WX?= =?us-ascii?Q?mt6Og73qxv15ajdXW5O7nyJWj2m3Wt0cUBsaedprKgUi+rXYDPWD1XfePMbD?= =?us-ascii?Q?jMKrtah+vy9e2tPciiWK38FKKX/ZR+WgAzYuuHkoJa8DUowv+SM29hM8wtm7?= =?us-ascii?Q?nVnRvDlVzzhzNrUXreBItreb3w25L21+LCxqi8ITK1OUSpgVEno7Tbmb3LQ6?= =?us-ascii?Q?YtTVDeXJ4/qw9CMuml8nxst4lj1C8eVcIhV7Ah5l42v08nDfrZJPc0kFm0hK?= =?us-ascii?Q?r20k7A77ySwLYI2VELElvZBI7xOydwlVCyD1+5V9hmbqMb5giiNo9sFdgjLq?= =?us-ascii?Q?HSFM0Ztqq5me2uplTkMZY03R40z04dB42uqEG6/QvPZTi4AhvkJCPUh8ri5a?= =?us-ascii?Q?bGM9nCjKTQ=3D=3D?= X-OriginatorOrg: atomlin.com X-MS-Exchange-CrossTenant-Network-Message-Id: e8eca6a4-26db-4c02-7079-08def5a884dc X-MS-Exchange-CrossTenant-AuthSource: CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 08 Aug 2026 23:55:26.9200 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: e6a32402-7d7b-4830-9a2b-76945bbbcb57 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: Ug1mPPS/xnOfjHGr0tE8YvXP2625F77nhCfNFMAtaFOTdjaCH8vxeXtHehQyKRS0DMWH9cWfoNQvC0879Rh1JQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: CW1P123MB8837 Hi Peter, Juri, Ingo, Vincent, This patch series addresses a few pre-existing memory safety and list traversal concurrency issues in scheduler debugfs handlers, and introduces per-CPU debugfs files under /sys/kernel/debug/sched/cpu/cpu/debug. Patch 1 fixes a potential use-after-free in print_cpu() where rq->curr is dereferenced locklessly to output the running task's PID. If the task exits concurrently and its reference count drops to zero, put_task_struct() schedules __put_task_struct_rcu_cb() via call_rcu(). Without holding an RCU read lock, an RCU grace period can elapse concurrently and free the task structure via free_task(), leading to a use-after-free race condition. This patch protects the rq->curr access using READ_ONCE() inside an RCU read-side critical section, delaying callback execution and guaranteeing memory safety. Patch 2 fixes a use-after-free in print_dl_rq() where cpu_rq(cpu)->rd is dereferenced locklessly to display deadline bandwidth statistics. During CPU hot-unplug or cgroup cpuset repartitioning events, partition_sched_domains() calls rq_attach_root() to detach the CPU from its root_domain and schedules free_rootdomain() via call_rcu(). Without an RCU read lock, an RCU grace period can resolve concurrently while debugfs reads the file, allowing free_rootdomain() to execute kfree() and causing a UAF when reading dl_bw->bw. This patch fetches rq->rd using READ_ONCE() inside an RCU read-side critical section to guarantee memory safety. Patch 3 fixes an RCU traversal violation in print_cfs_stats() where rq->leaf_cfs_rq_list is traversed locklessly using for_each_leaf_cfs_rq_safe(), which expands to list_for_each_entry_safe(). Although leaf_cfs_rq_list is modified using list_add_rcu(), list_for_each_entry_safe() lacks READ_ONCE(), allowing compiler instruction reordering or re-fetching that can cause readers to observe newly inserted cfs_rq nodes before their internal fields are fully visible. This patch introduces for_each_leaf_cfs_rq_rcu() using list_for_each_entry_rcu(). Patch 4 introduces per-CPU debugfs entries under /sys/kernel/debug/sched/cpu/, allowing targeted inspection of an individual CPU's runqueue on demand. If the target CPU is currently offline, reading its file returns -ENODEV. Changes since v2: - Protected lockless rq->curr dereferencing in print_cpu() with rcu_read_lock() and READ_ONCE() - Protected lockless rq->rd dereferencing in print_dl_rq() against CPU hot-unplug and cgroup cpuset repartitioning races - Introduced for_each_leaf_cfs_rq_rcu() using list_for_each_entry_rcu() for lockless leaf_cfs_rq_list iteration - Linked to v2: https://lore.kernel.org/lkml/20260728205238.18447-1-atomlin@atomlin.com/ Changes since v1: - Reframed commit message motivation around targeted interactive debugging on large SMP topologies (Peter Zijlstra and Zhan Xusheng) - Gated sched_debug_cpu_show() with a cpu_online(cpu) check returning -ENODEV when target CPU is offline (Zhan Xusheng) - Linked to v1: https://lore.kernel.org/lkml/20260728020309.6169-1-atomlin@atomlin.com/ Aaron Tomlin (4): sched/debug: Protect lockless rq->curr access in print_cpu() sched/debug: Protect lockless rq->rd access in print_dl_rq() sched/fair: Use list_for_each_entry_rcu() in print_cfs_stats() sched/debug: Introduce per-CPU debugfs files kernel/sched/debug.c | 60 +++++++++++++++++++++++++++++++++++++++++--- kernel/sched/fair.c | 11 ++++++-- 2 files changed, 65 insertions(+), 6 deletions(-) -- 2.55.0