From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from CWXP265CU008.outbound.protection.outlook.com (mail-ukwestazon11020115.outbound.protection.outlook.com [52.101.195.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 700D53AAF44 for ; Tue, 25 Aug 2026 18:46:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.195.115 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787683607; cv=fail; b=Mr+s/k7tMryVh0kgmKKDjWnvGgQeJnlVG1y0e/SlZ266QYUj1NVT9w//rDCWJfnHXPBH2XvrhFPXw2TB2U3g+jazRooTbz3q/zHK+0dP9AnH5vQuMeAIMztXOlyKC2QhZ5owJNis5ONhM6/vu2kV74Dly3ZNRBwl6vbFiSF7wCw= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787683607; c=relaxed/simple; bh=WbOM+c+aY46VkgHc7PkbHyCuqg/h7tIS0EwakscGXvY=; h=From:To:Cc:Subject:Date:Message-ID:Content-Type:MIME-Version; b=MkavzqaXukfrd+IjIvC3YD49n1UWdWmum/r75nv4TIT0Cc4QG22mpQtDeOmai9r0MAzWZkpkCXTYCU9q5tkJ9nrWsb6bXQwO+wFuUybFX14OBu06w7/ERbtG3XQRwJGgR2cAGA1s8qMss39ZclaWopGoxr3imnvj0e58W7k8/kA= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com; spf=pass smtp.mailfrom=atomlin.com; arc=fail smtp.client-ip=52.101.195.115 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=atomlin.com ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=WVarqPILEjxJKBlqA9bThimvsPRGaZDaXptgLfBoBPdGZn9tFdpuwOn7kRdrPZBe7yuS56qdZtf5vC0TugsaYTDiVCqoGoPPyloEr3DBaMtVuP5lvdLrY6g5I7Az9fH1W8WxiDtYYIyUmq9NUsXws8/BhpSFvQtdmeZQB4tzmcE8VYxrJV+lrucTNKgRHcpWeBrjMUQR2i5v5p3Bn9/YtRQZThv/Ta8Wwh5Afl5Iwufx0PEtAch5Nc5daHql166RFUl3SN1wStTvKTjHTkPOvM9Cgu4J7Yqj13muOf7Trs5CCpGw6OvOIIiNHvv3zLbsv1LxG0H21YBA9dDvW7Wx0Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:MIME-Version; bh=RQfLBeadpR47e+nfzBtVMLi7OpIoCJHriX6YYQmzs0o=; b=JQ3BmQkY5ESJjf2o2qBQzeKuH/uq0eQVuEdzDtncEIZDfPR2TUdc/mCGEBKIwC2jLtN+/alOKteHC6HduA3T/g5PpFK0H35pMEEDn9u+GlPntrAk05i5u50c2eWSbxoB1+ICKrDPbuT3u6I3WeU6vxKBb90yBUkHDZmJdSr5WIsX5H4rMuFASCLdkJYRdX4bJC/fuT6JE+1/RLI2g15rRplV9gkvorsjN+LegdTmn3zJwNmpMODb0U1eRqioAuCHnffiuQinAAUts1MaaeYjkAzTVu6sQYI+cVzNuZpmO4Qu3kdUu4JdiQ96Hbpxq/KmOLuDcKyMoU0Cm20h2EhrDA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=atomlin.com; dmarc=pass action=none header.from=atomlin.com; dkim=pass header.d=atomlin.com; arc=none Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=atomlin.com; Received: from LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:2b2::11) by LO7P123MB7501.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:40c::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.8; Tue, 25 Aug 2026 18:46:40 +0000 Received: from LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM ([fe80::3975:c5e7:bc1a:f383]) by LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM ([fe80::3975:c5e7:bc1a:f383%4]) with mapi id 15.21.0360.005; Tue, 25 Aug 2026 18:46:39 +0000 From: Aaron Tomlin To: mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org Cc: dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, zhanxusheng1024@gmail.com, neelx@suse.com, atomlin@atomlin.com, chjohnst@mail.com, mproche@mail.com, sean@ashe.io, steve@abita.co, rishil1999@outlook.com, linux-kernel@vger.kernel.org Subject: [PATCH v6 0/6] sched/debug: Introduce per-CPU debugfs files Date: Tue, 25 Aug 2026 14:46:31 -0400 Message-ID: <20260825184637.888364-1-atomlin@atomlin.com> X-Mailer: git-send-email 2.55.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: LO2P123CA0076.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:138::9) To LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:2b2::11) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: LO6P123MB6616:EE_|LO7P123MB7501:EE_ X-MS-Office365-Filtering-Correlation-Id: 2be50504-3c23-4d6b-5803-08df02d932be X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|376014|7416014|1800799024|366016|3023799007|6133799003|10067099003|56012099006|18002099003; X-Microsoft-Antispam-Message-Info: 7YxMwQub5Sp6QfHQLaq0hBzgMtuGN8QD8ZcD57/bITctD+Galnt8whtR+fo3umHNYBIlWyDnt8XbHI0zNsS/7SWsVv4vGwgYLoUeW+LlQV7z5D21dAfvTrwPXactkW2R+H7Y+3d+uGAJbhVe2J4aB0jRnAzt4AkvYgksO3OrjAfnKBeih8XSR4YnIeQmu4DlZSw3jEQtP1MfsgPyFDKpDQ2ay1fVnlRSCMI7fzrY5XOdvtVf/3eleP5DaIlVHGYtYXTUgwDcqMT7HG1XxEhDkU8lVwB8aJfDghyoFEulRyy09Amo9qWOG45MdsdjL89YU+3TCT+jAmcJKcjqcA9MRUez6L0aKuddRrBEaGQ/T5Ri4CuPYTTYHX4rNQSsdXboMx0QTbTKKqxi2IzOvd7bmN1akPnlPfyDxw4L+SbXiXJko+VJuiwv0RRikPOE1ZkULzkbShYxBxSHd9Y72DkmvN0INZn0YSpi2GWL0HfTL96wtISr9vYRWvaLBNJIy1mqYRzEtx8K5O1Luw4u4sSh+IkOrto1use9nuzgUY+urooDDcpNXQ87ImRfUd3B2NUq1sObsVYCaMKq6THbQUvSLR0aXyMChOOYKK7el9a9CfChuoE+0cCp4YjG85d5azJOPzSWBPCezwxXygrC8+GkUmfACCQ0feO476AEAcMsxpY= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(376014)(7416014)(1800799024)(366016)(3023799007)(6133799003)(10067099003)(56012099006)(18002099003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?EGy9elh8s5sAqcX5V4CF1woWm1v98Ry7fABhtz5PDF9g0x8Lr8CGRn577FEa?= =?us-ascii?Q?dxUU+tz5XsL7yYnmOMEDu1RZo69RQAg4MzVYcnMk2o+napQrdIpSGmAfX0ti?= =?us-ascii?Q?26M4YHwi7bzmL8+xrCkPKQlXk1CefmrzZ7Sv73vjf1TCAO0mB7tPRgWRSWVG?= =?us-ascii?Q?TIiS35DtmDMhwJUR0PEQMg9nDneJFoZcL3wYHShzwMx4bd02Gk5DZRz+G7AC?= =?us-ascii?Q?e4UvxOdagADghmPWH1xTrEHHxj+lPBHSCin/F6aY8vxah2LTbsMNNv3aW6AG?= =?us-ascii?Q?JQVCe5B/kBUsAnE51kwtCS8H2Butv5w8RKk0N5Bkf+toRsjXCrJ4dJUq3Bwg?= =?us-ascii?Q?VPyihF8gBeht6QPlXoZvmkAm2ToJBJ2Vf5PQwKk4x/J4ani3UZvgCuvg3yTm?= =?us-ascii?Q?OnyxY4kNAj0wrJ1VSUo2oDBzzTmTCn3m6AFgriJuyggrAzGdAPTMyU2M0pSl?= =?us-ascii?Q?PuPrbTe8IiKMYt+RRfXOk2xbhGnEeYhzoQ25CVX+8zeWzAMaj/3wV0n2r6uq?= =?us-ascii?Q?Qs8PWUcCXVeakdokRzUI4a8NaTx3CGzP18+q3Y+VFZcPoIbbRvLjBMYHkwvs?= =?us-ascii?Q?H1o5NSsF4TX2zNr6/YJy6XeR8P2kre2urcZCbpZgWtrUSO6tHKyPudIa6HNW?= =?us-ascii?Q?MTZmm02d08ip8AGsKXRNscLRya97qJvP0KVCsP6HULZbyxEg1fVpK8ef7xES?= =?us-ascii?Q?TokL27ceLGQg0L21YFjXihyTbj8dmdP4pUm8jm6AQIbvqvUD2T+d1I0mx+k4?= =?us-ascii?Q?TrNJlEGmir7mOLuzoonhdEvOxTDw21EjU+ZdTOYKw/KF2tRzvu6y/skiK4kG?= =?us-ascii?Q?RyRhgITsGqbGSqxCVAdrhEkPy76NG6C0VDggDQQGW0iiF/b3n49TVfTHklqV?= =?us-ascii?Q?RVXlu0NAvruVnl8Ppg5SWdQRyum2+mfy2UcXYESoQEkTtUwdw1/QCYXWKt06?= =?us-ascii?Q?LvnDuhBUJbhOcrFqj8/iiOgtn9DVFBevPfHc8kbD1/0gmMvUXe1e8owDKGc6?= =?us-ascii?Q?FlCi1MAcbaGW5Rqc2rldMkO4O1ukXoEzgS6kAvBks/XXKjm/hbLs5/z0OKXi?= =?us-ascii?Q?A2cjpV1q4CFA00fpHl9fI9XjBVkiLBgLJWuD0iroXqplonhJ020mDPJmq7xa?= =?us-ascii?Q?av2zCIkV3c9B3URKbpJISfg25xS5QggtJjUF1Np21DqQ04z2LPyApCGLvFAD?= =?us-ascii?Q?8t7jDuHIcNU7HdtbHGjFyipRaqEQ3tR9zey9lKsUIEBRmnHGAUarAz+K9fSd?= =?us-ascii?Q?VNz1CGWmdeQ8f91j/a2rkY5ScauYP/3x9cs7HTux21E4l7AHmGMEJWxR+qrI?= =?us-ascii?Q?hBExX5WDmiZsPVzQAMP7juWQs5KUbiTregn3vq59/YrR2jy6a0ooqmDdTLpD?= =?us-ascii?Q?yzq5qLEAxJk7cuHuaDHnZ+2ck9U68QRqjmfYDO6q/fsxJobsTsius4idUnK2?= =?us-ascii?Q?5G1mAylFSuAiUAcim4wovKCxzdvy+XT8pf5pXorhn+GnhgC/flog3NJAr1bK?= =?us-ascii?Q?vc4LijUsqI/wfUYfboWGREkilPH94nvs3t5DEUlD6rWlN0Hqob1RnDcsB2eE?= =?us-ascii?Q?lYUdqffF1gSp2cd11FBQYTqDm5cvFLiQHgLeE0trWR1pqWaA/ZH1lK0vvPMo?= =?us-ascii?Q?KKCBc5gg0QxjpMG+IqQ3jbVMKI1hJcy4lsBC26v/dCMEwqthGySkLHT6JVkA?= =?us-ascii?Q?ijZaQciVwP8bv1FIWDuT9WPVJL20ixzABDzxZUyoSlp4ex6P?= X-OriginatorOrg: atomlin.com X-MS-Exchange-CrossTenant-Network-Message-Id: 2be50504-3c23-4d6b-5803-08df02d932be X-MS-Exchange-CrossTenant-AuthSource: LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Aug 2026 18:46:39.4788 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: e6a32402-7d7b-4830-9a2b-76945bbbcb57 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: qxKXE6A2wmnw2SmGvFwwi55KEHa5Kgvg5FoAVVLeJH5zceFu6R3X/npmEXsC8JbOWWfrhvlV7duH2BIN2cC6Zg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO7P123MB7501 Hi Peter, Juri, Ingo, Vincent, This patch series addresses a few pre-existing memory safety and list traversal concurrency issues in scheduler debugfs handlers, and introduces per-CPU debugfs files under /sys/kernel/debug/sched/cpu/cpu/debug. Patch 1 introduces a new prerequisite patch that annotates struct rq's rd (root_domain) pointer with __rcu in kernel/sched/sched.h and updates lockless readers across the core scheduler to use rcu_dereference(), ensuring Sparse compliance and proper memory barriers on weakly ordered architectures. Patch 2 fixes a use-after-free in print_dl_rq() where cpu_rq(cpu)->rd is dereferenced locklessly to display deadline bandwidth statistics. During CPU hot-unplug or cgroup cpuset repartitioning events, partition_sched_domains() calls rq_attach_root() to detach the CPU from its root_domain and schedules free_rootdomain() via call_rcu(). Without an RCU read lock, an RCU grace period can resolve concurrently while debugfs reads the file, allowing free_rootdomain() to execute kfree() and causing a UAF when reading dl_bw->bw. This patch adds rcu_assign_pointer() on the writer side in rq_attach_root() and uses guard(rcu)() with rcu_dereference() in print_dl_rq(). Patch 3 fixes a potential use-after-free in print_cpu() where rq->curr is dereferenced locklessly to output the running task's PID. If the task exits concurrently and its reference count drops to zero, put_task_struct() schedules __put_task_struct_rcu_cb() via call_rcu(). Without holding an RCU read lock, an RCU grace period can elapse concurrently and free the task structure via free_task(), leading to a use-after-free race condition. This patch protects rq->curr access using rcu_dereference() inside an RCU read-side critical section. Patch 4 fixes both a time-of-check to time-of-use race condition and a potential use-after-free in sched_show_numa(), where p->mm is checked locklessly and then passed to P(mm->numa_scan_seq). If the task exits concurrently via exit_mm(p), current->mm is set to NULL under task_lock(p) before mmput() is called to free the struct mm_struct. Wrapping the p->mm check and dereference in task_lock(p) eliminates both hazards. Patch 5 fixes an RCU traversal violation in print_cfs_stats() where rq->leaf_cfs_rq_list is traversed locklessly using for_each_leaf_cfs_rq_safe(), which expands to list_for_each_entry_safe(). Although leaf_cfs_rq_list is modified using list_add_rcu(), list_for_each_entry_safe() lacks READ_ONCE() and pre-fetches the next pointer without memory barriers. Furthermore, because cfs_rq nodes are re-linked on enqueue/dequeue without waiting for RCU grace periods, concurrent list churn can cause backward jumps or infinite loops. This patch introduces for_each_leaf_cfs_rq_rcu(), bounds traversal with a circuit-breaker ceiling, and emits an explicit truncation notice if the ceiling is reached. Patch 6 introduces per-CPU debugfs entries under /sys/kernel/debug/sched/cpu/cpu/debug, allowing targeted inspection of an individual CPU's runqueue on demand. If the target CPU is currently offline, reading its file returns -ENODEV. Changes since v5: - Rebased against tip/sched/core (sched-core-2026-08-17) - Linked to v5: https://lore.kernel.org/lkml/20260825141413.868997-1-atomlin@atomlin.com/ Changes since v4: - Added a new prerequisite patch to annotate struct rq's rd field with __rcu and updated lockless readers to use rcu_dereference()/rcu_dereference_sched() - Updated print_dl_rq() to use guard(rcu)() and rcu_dereference() on rq->rd (Daniel Vacek and K Prateek Nayak) - Replaced READ_ONCE(p->mm) with task_lock(p)/task_unlock(p) in sched_show_numa() to prevent use-after-free against concurrent exit_mm() and mmput() - Updated print_cfs_stats() to use guard(rcu)() - Increased SCHED_DEBUG_MAX_ITER from 1024 to 4096 and added an explicit truncation notice - Moved SEQ_printf() and SEQ_printf_task_group_path() to kernel/sched/sched.h, replaced strcpy() with strscpy(), and used IS_ENABLED(CONFIG_FAIR_GROUP_SCHED) with a typed static inline fallback stub - Corrected the "Fixes:" commit tag in Patch 5 to 039ae8bcf7a5 ("sched/fair: Fix O(nr_cgroups) in the load balancing path") - Linked to v4: https://lore.kernel.org/lkml/20260810015812.428999-1-atomlin@atomlin.com/ Changes since v3: - Updated Patch 1 to use rcu_dereference(rq->curr) instead of READ_ONCE() to preserve __rcu - Added missing writer-side RCU publication barrier (rcu_assign_pointer()) in rq_attach_root() for Patch 2 - Added Patch 3 to fix a TOCTOU condition in sched_show_numa() using READ_ONCE(p->mm) - Added a safety iteration ceiling in print_cfs_stats() for Patch 4 to prevent unbounded list iteration and RCU stalls under heavy leaf_cfs_rq_list churn - Linked to v3: https://lore.kernel.org/lkml/20260808235522.380038-1-atomlin@atomlin.com/ Changes since v2: - Protected lockless rq->curr dereferencing in print_cpu() with rcu_read_lock() and READ_ONCE() - Protected lockless rq->rd dereferencing in print_dl_rq() against CPU hot-unplug and cgroup cpuset repartitioning races - Introduced for_each_leaf_cfs_rq_rcu() using list_for_each_entry_rcu() for lockless leaf_cfs_rq_list iteration - Linked to v2: https://lore.kernel.org/lkml/20260728205238.18447-1-atomlin@atomlin.com/ Changes since v1: - Reframed commit message motivation around targeted interactive debugging on large SMP topologies (Peter Zijlstra and Zhan Xusheng) - Gated sched_debug_cpu_show() with a cpu_online(cpu) check returning -ENODEV when target CPU is offline (Zhan Xusheng) - Linked to v1: https://lore.kernel.org/lkml/20260728020309.6169-1-atomlin@atomlin.com/ Aaron Tomlin (6): sched: Annotate rq->rd with __rcu and update lockless readers sched/debug: Protect lockless rq->rd access in print_dl_rq() sched/debug: Protect lockless rq->curr access in print_cpu() sched/debug: Protect p->mm access in sched_show_numa() sched/fair: Use list_for_each_entry_rcu() in print_cfs_stats() sched/debug: Introduce per-CPU debugfs files kernel/sched/core.c | 16 ++++--- kernel/sched/deadline.c | 8 ++-- kernel/sched/debug.c | 92 ++++++++++++++++++++++++----------------- kernel/sched/fair.c | 62 +++++++++++++++++++-------- kernel/sched/sched.h | 53 +++++++++++++++++++++++- kernel/sched/topology.c | 2 +- 6 files changed, 165 insertions(+), 68 deletions(-) base-commit: 68e37487810a3da43c48340fab7a55b3b6efdae3 -- 2.55.0