From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from LO2P265CU024.outbound.protection.outlook.com (mail-uksouthazon11021120.outbound.protection.outlook.com [52.101.95.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E990D312836 for ; Mon, 10 Aug 2026 01:58:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.95.120 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786327103; cv=fail; b=Al/9P66rsOK+C19nlSPotN3todR4TlpwmZNO9et+aRvULwYRjr3OXetrvwkHYvv4dvBBdMCFLoH1P4l0LF+G7IgW5+3L4sXKNIKW+9P0/RmSuDjkEg3NLIEIVdVVmC/dqPPF2hblz6TpZ7pHRlrMfUkU2zu6tCapZ9ANh+u0FUs= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786327103; c=relaxed/simple; bh=T83D94OThmP4Y0G4r107KIIhngjsCb0j43CUp+ZhkOM=; h=From:To:Cc:Subject:Date:Message-ID:Content-Type:MIME-Version; b=FBf1rpZB81y/g6QjLbOldRhazmP8tdjws8sF+zTCYSa31amZWZ8rCXTp/DsZnXCX3/jyVb6GURGBDfiUNI6MLXbhtL+fO0Ik1LGRkuBKTCMrlqN8Cyr7J3Yhf9HpcNSA+9XPqvSfM69d1TJMFxrbn/4X9ATHjDKCtb5XOsnAzWY= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com; spf=pass smtp.mailfrom=atomlin.com; arc=fail smtp.client-ip=52.101.95.120 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=atomlin.com ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=n7J0BnBJM8YLNZX8uGR9+Toph7raDO76T7z0F0npR8QlbELyAEpekkYy6wAYvGaOTKY2xDfajkFjoLU1jgwRG3x4Rc1+sLsPfSxihkpB2XL3gwy1ftDkn22lNEdqOG98uQ1g3MMwv9NtO7soBjRkJxEDP5kL8IY6k0LCkw9naFH4BfLWWAHThWzHKQ1xgael5VAx4SqZOfW/FINGRVw1Z5++k2jj/x3RDozhMq+Weh0c6cn/01jtUf7BVxDd2aRJIXIJQDXl6H/am+lXqLvcwxlhHn4AQTlrZWEsVtNaGQWuhweyHC6GoohstdAu/pJDDpdDw2yvKC6I1qSqfdDjMg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:MIME-Version; bh=CLyx1Ongk4vL7F+ycxGm9W+7zmPr9TJ08/hzwz3AyVc=; b=urW5xsxSU/5OEmb4EeURHuqWlklNNdmDZJSjuwM7AIiR43KctOvuU2pc353telDw4afqFy9wIhMseIM1JmBgel7A1vJFtnrlpZZcCZeqdedTlwtnr8vJSPw1kX5R7l7hnTH5XgnwJX2UHWn2GeAJ/ZA+unAG6Q+fNM3Sq3KTW/SpuEWtceU3nDE0YrvUB8hZS8mNJ5QUpo3k3OdQ2J3ggQgtGWk5SKEL42NXwoc8k8QwYdn3BOujYqvURyI6EkEcRibtGiIS/r9LRsrLQeVPfliVaDjLwDF8cnpaxzKRfnXuwIA4B+f6TQ87zDOagXUf0a9uv9H7mEOJnM8L/LmPHw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=atomlin.com; dmarc=pass action=none header.from=atomlin.com; dkim=pass header.d=atomlin.com; arc=none Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=atomlin.com; Received: from CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:183::5) by CWLP123MB3891.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:a2::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.292.25; Mon, 10 Aug 2026 01:58:17 +0000 Received: from CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM ([fe80::cec4:77ab:262e:d230]) by CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM ([fe80::cec4:77ab:262e:d230%4]) with mapi id 15.21.0292.024; Mon, 10 Aug 2026 01:58:17 +0000 From: Aaron Tomlin To: mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org Cc: dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, zhanxusheng1024@gmail.com, neelx@suse.com, chjohnst@mail.com, mproche@mail.com, sean@ashe.io, steve@abita.co, linux-kernel@vger.kernel.org Subject: [PATCH v4 0/5] sched/debug: Introduce per-CPU debugfs files Date: Sun, 9 Aug 2026 21:58:07 -0400 Message-ID: <20260810015812.428999-1-atomlin@atomlin.com> X-Mailer: git-send-email 2.55.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: BN9PR03CA0068.namprd03.prod.outlook.com (2603:10b6:408:fc::13) To CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:183::5) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CWLP123MB6607:EE_|CWLP123MB3891:EE_ X-MS-Office365-Filtering-Correlation-Id: 398f533c-fce9-41ff-414e-08def682d845 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|366016|1800799024|376014|7416014|56012099006|10067099003|6133799003|3023799007|18002099003; X-Microsoft-Antispam-Message-Info: ziSdsgdpgFKwyTiJdJFQnuTsI4jOgYyaHGqwxIqjg4xod39QpLKuLMOUWJSNwzzHmWM7M/VN/zKSZ+dQLq6u6nVpZ8qfTBqTlKiDcY/8xYpqgftXdfs4vyDHKySkT94yym/nce58/h7nq5L+Op6a+6oBsi2H0xXpV3n7UI0b7H1noizNRuCZcPjmbfkaH8jBXPfrLRb7QavYNiM8qgoiCvO56A6jv6wRj2qv1ycsSXbGTa2qK3817URI4uw9wjE6ztMpgZyX1j+v3hW+8vUOo5u+kytkealP1JX/v9k2OS4lm0g8hUl25HK6h7Yu37DMdi3Zy9ylgpOmB4HLb00UFjlV/dTIj2Nt0X8j/OAn0WS3zXqpPlonct3aCdq4PYiXBM02vqSacyUk1K7K8VLl5QNZSoO8asiQXvqeXNN9/cDjOGmWkEio6TWV3qXvS+NPPg62J1Eqli2EXClm0xK+GBDNxKnGeNuxP0YI0hMUD0UTzY9wvEryp69DWfHKWaaQ6NL3EWEQMSSSVo2BMyYirsYEQ6QnuSK7UTVi4om179bEJEqCO7VHZbxSmwtHSV8D5buJFMk+beF3ZzFApLkiSd1qSk9LPIWy6ek6WhmrggpDIZr6wHpUpnn85XwNqWgm8DhpCvV4btLcaYw1UUab1voT2Tb9pxQ9ia+QkwDuNsE= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(366016)(1800799024)(376014)(7416014)(56012099006)(10067099003)(6133799003)(3023799007)(18002099003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?hfWeS8A0uI4aIRat7HX85s9fe2Oie8lx4v1/OF7X0CuSwxndvOye7HHH+HZr?= =?us-ascii?Q?9UEVlidI9R48yjKWIJ2QJ5hgKJGuqWuNt7vDqM6b/sr2QtZPjLqFFbqIMkeI?= =?us-ascii?Q?EXhboJAOqP9szFPR0ESlVJdFXc5qm1PbyH5BGWOPS/7VWls2ULZWfdoINTwH?= =?us-ascii?Q?5YGVk0eNtzdoESPOvhJz3HyRZAfMlqijyAqY4VJixiY4T0DwGZauxx6mhpCH?= =?us-ascii?Q?BN4RsIOZUHujJiiKfRUv/vuFRrNQgEGWaqaOUH3nzP4cRSb4+YtI5zGJDJDx?= =?us-ascii?Q?4+NWtUFxUJ4Go6kUWBZGHGkn0J00XlmlVBMRE+Sccg/aMOzP7aRfkbD3fVQj?= =?us-ascii?Q?4zq8kigtd5hFr/qlgFoPKqrfaqqZjL6SvICOBPnHH9rUZVSSEat2RArszaPj?= =?us-ascii?Q?8AYjc5jj7AIsg8dpiCPCVbSFdbZUbXhllNMhyVGXesOAofDY08+yUviiyyvG?= =?us-ascii?Q?wfQa3W70uQpnXjyEqcBT/HXJ5WV6IvGb2iQor1TpJfpxqS1xPQA7ynh6UQSS?= =?us-ascii?Q?W4w8OoNck2d/2mdNnb501D/oNSiojG7ZGNrOENvQEAfA5u5k6ShfJvZWTLhu?= =?us-ascii?Q?nzqk89pQd7HYcHDJaXAESuPD2lcQB0VT6SDN4uWpWztZAy5kIkQNBoRyhINS?= =?us-ascii?Q?1Td13kdbWIH/3chs2QhqkZm1VMH7R/17NwFkyJ5iuxe30K5h99M3Q0Gnkyqm?= =?us-ascii?Q?F5rpFCECVZQg6Lxt6SY23WOrg6zPGIDdNgX4NuMXHmvR/wUMnPmEyzMhy170?= =?us-ascii?Q?cmQZ5/lYrLe9ZaZpwK4++48PcN+WbgVzEgsgSsN9xdfkqj3//bVEKcMyY0RV?= =?us-ascii?Q?W8rJTtU++zf/RWxc7tUWU2EJLJ1RhFX3m5KE6apmccfQOzcrHTLTnDUc2PMQ?= =?us-ascii?Q?Su/srEls7PsYaqsA48cgmex4lCaQkf/N3jH65aX9Ly58YSVIdvooqv5wU+h6?= =?us-ascii?Q?3Gm2+DKdZjnlEy75HpQ6tYFqe5Rizrfdsv2ga6mM7adhjVSjz9ZA96itPPTI?= =?us-ascii?Q?mGRPL7MHV4B75599gGT1UfQleWHX1GEIJzShHk6ZA7nBALvpAsHLE69P4Nma?= =?us-ascii?Q?9kkqVKKZgWcd+ScHs5t6FIYMet4is16zQgwYLis2yipsSH5U858hRbQJR/OU?= =?us-ascii?Q?p0q5c42CyN3AHXIPEmxOQskzeMD6Tocv2UcwKmWZn86NKRYGdqbhRME8/pox?= =?us-ascii?Q?UdhzIC5xFjB55Vw0DJ6sCKsVy5F8Ll96j0qtpKXjeMv25fpXNPoaXYAROiXq?= =?us-ascii?Q?Ej69SyIL/d5OV9GFi4DK2lSOX4iaSYdJyywEmdaOweBpqu/f9tQVZkAWyTDy?= =?us-ascii?Q?V734BuiScfRObL+41Br8vIGqLM7t3GoAnSd8LI+77ciVab0TeW+t8HbfibvA?= =?us-ascii?Q?ozaI7EBEIXKSWQkqG0q6cOzVYD3XkYzWIGk6DEajYw1DV2J3VHhgUWWjgQS5?= =?us-ascii?Q?hkFx3J/BAVmZjV9DJs2Udx9NlguVksXRNFdsL6amWW0J8dg/L56f5VJmeEQT?= =?us-ascii?Q?1QlOg0imq8KLu0KmXLuUkCLuB6V+2yYPrw8MPMkW6EuHY4NwCM4l+GHl3Czk?= =?us-ascii?Q?IXXS9F+LWdboLyMZs/JF0cKKDuPXkd+H11uhPkUWAofhLfYD6niO/ze5DcxU?= =?us-ascii?Q?WTGAjaTRTo7fJCvvQ8PeCSj+EajosIMrfnXgV631BfrIEVuUAl4ChF9GUta1?= =?us-ascii?Q?D1RgTdKai07eHZRnczX7vfxy9npW6vit8RJtsEbN+JuZVix+UgY2cUfOlJJx?= =?us-ascii?Q?8JrTRhlIbQ=3D=3D?= X-OriginatorOrg: atomlin.com X-MS-Exchange-CrossTenant-Network-Message-Id: 398f533c-fce9-41ff-414e-08def682d845 X-MS-Exchange-CrossTenant-AuthSource: CWLP123MB6607.GBRP123.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Aug 2026 01:58:16.9722 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: e6a32402-7d7b-4830-9a2b-76945bbbcb57 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: z75VgyFc0qqXgdb+xaWXHH+sOXYgjlPmwfaFZscttHC6p3VKZAqW+xKN0jTgSpZ92bnDOwsq9WLtIK+fzQktAw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: CWLP123MB3891 Hi Peter, Juri, Ingo, Vincent, This patch series addresses a few pre-existing memory safety and list traversal concurrency issues in scheduler debugfs handlers, and introduces per-CPU debugfs files under /sys/kernel/debug/sched/cpu/cpu/debug. Patch 1 fixes a potential use-after-free in print_cpu() where rq->curr is dereferenced locklessly to output the running task's PID. If the task exits concurrently and its reference count drops to zero, put_task_struct() schedules __put_task_struct_rcu_cb() via call_rcu(). Without holding an RCU read lock, an RCU grace period can elapse concurrently and free the task structure via free_task(), leading to a use-after-free race condition. This patch protects rq->curr access using rcu_dereference() inside an RCU read-side critical section, ensuring sparse compliance. Patch 2 fixes a use-after-free in print_dl_rq() where cpu_rq(cpu)->rd is dereferenced locklessly to display deadline bandwidth statistics. During CPU hot-unplug or cgroup cpuset repartitioning events, partition_sched_domains() calls rq_attach_root() to detach the CPU from its root_domain and schedules free_rootdomain() via call_rcu(). Without an RCU read lock, an RCU grace period can resolve concurrently while debugfs reads the file, allowing free_rootdomain() to execute kfree() and causing a UAF when reading dl_bw->bw. This patch adds rcu_assign_pointer() on the writer side in rq_attach_root() and fetches rq->rd using READ_ONCE() inside an RCU read-side critical section in print_dl_rq(). Patch 3 fixes a time-of-check to time-of-use race condition in sched_show_numa(), where p->mm is checked locklessly and then passed to P(mm->numa_scan_seq), causing a double-evaluation of p->mm. If the task exits concurrently (exit_mm(p)), p->mm can be set to NULL on another CPU between the check and the macro expansion, causing a NULL-pointer dereference crash. This patch reads p->mm once into a local variable using READ_ONCE(p->mm) before checking and dereferencing its numa_scan_seq field. Patch 4 fixes an RCU traversal violation in print_cfs_stats() where rq->leaf_cfs_rq_list is traversed locklessly using for_each_leaf_cfs_rq_safe(), which expands to list_for_each_entry_safe(). Although leaf_cfs_rq_list is modified using list_add_rcu(), list_for_each_entry_safe() lacks READ_ONCE(), allowing compiler reordering or re-fetching that can cause readers to observe newly inserted cfs_rq nodes before internal fields are initialised. This patch introduces for_each_leaf_cfs_rq_rcu() using list_for_each_entry_rcu() and adds a hard iteration ceiling to prevent RCU stalls under list churn. Patch 5 introduces per-CPU debugfs entries under /sys/kernel/debug/sched/cpu/, allowing targeted inspection of an individual CPU's runqueue on demand. If the target CPU is currently offline, reading its file returns -ENODEV. Changes since v3: - Updated Patch 1 to use rcu_dereference(rq->curr) instead of READ_ONCE() to preserve __rcu - Added missing writer-side RCU publication barrier (rcu_assign_pointer()) in rq_attach_root() for Patch 2 - Added Patch 3 to fix a TOCTOU condition in sched_show_numa() using READ_ONCE(p->mm) - Added a safety iteration ceiling in print_cfs_stats() for Patch 4 to prevent unbounded list iteration and RCU stalls under heavy leaf_cfs_rq_list churn - Linked to v3: https://lore.kernel.org/lkml/20260808235522.380038-1-atomlin@atomlin.com/ Changes since v2: - Protected lockless rq->curr dereferencing in print_cpu() with rcu_read_lock() and READ_ONCE() - Protected lockless rq->rd dereferencing in print_dl_rq() against CPU hot-unplug and cgroup cpuset repartitioning races - Introduced for_each_leaf_cfs_rq_rcu() using list_for_each_entry_rcu() for lockless leaf_cfs_rq_list iteration - Linked to v2: https://lore.kernel.org/lkml/20260728205238.18447-1-atomlin@atomlin.com/ Changes since v1: - Reframed commit message motivation around targeted interactive debugging on large SMP topologies (Peter Zijlstra and Zhan Xusheng) - Gated sched_debug_cpu_show() with a cpu_online(cpu) check returning -ENODEV when target CPU is offline (Zhan Xusheng) - Linked to v1: https://lore.kernel.org/lkml/20260728020309.6169-1-atomlin@atomlin.com/ Aaron Tomlin (5): sched/debug: Protect lockless rq->rd access in print_dl_rq() sched/debug: Protect lockless rq->curr access in print_cpu() sched/debug: Protect lockless p->mm access in sched_show_numa() sched/fair: Use list_for_each_entry_rcu() in print_cfs_stats() sched/debug: Introduce per-CPU debugfs files kernel/sched/debug.c | 66 +++++++++++++++++++++++++++++++++++++---- kernel/sched/fair.c | 17 +++++++++-- kernel/sched/topology.c | 2 +- 3 files changed, 76 insertions(+), 9 deletions(-) -- 2.55.0