From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from CWXP265CU008.outbound.protection.outlook.com (mail-ukwestazon11020115.outbound.protection.outlook.com [52.101.195.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8A0753AF65B for ; Tue, 25 Aug 2026 18:46:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.195.115 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787683611; cv=fail; b=TKzMmnVANX9PIcMF+aCoI7yZ2E9dW/syQmS55ejetlWywbN/3qLGhTQB2rmjdG0KYHajODpDvRI0o0hQRTgznceMkL4sRuBugOcdvzfDccbkTYO2dJSXwxJKJSdz8dAfeO+quXy2jKjvkoU4YxILVaZ4VL9BixbVR94We8Y8TQg= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787683611; c=relaxed/simple; bh=5ggOwnXG6FwY39eWmKBifexBY3w5FV3S+eN5Ith01pk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: Content-Type:MIME-Version; b=M4tG5fbw0ckMPRqHIm+GLnyOqvl+r2P5hSt4zTTs0P8ZVQYFqChgiJ7i2p2AbisGJPWCMcckhyWHUzQ3SGJGAkS2Z4Y/S0Av3KPmRPX0EQcevSYwGD5kHIo1Q/BNslDWBi7Qn1jlujrkpHh7ejFvKuXX7KM5UhFIeYAJXwIDuFg= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com; spf=pass smtp.mailfrom=atomlin.com; arc=fail smtp.client-ip=52.101.195.115 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=atomlin.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=atomlin.com ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=qoSMb+0kMEcrkPnRX6JLpPR3m/mg4svev/srRE9Kw2r4JUkRCb61iZBbSs4YjX4I3jq50eKxH9uZ5lBqKxVlfAoh12k1aRwo+Myqhk3iMMaPB5hg7k8Ze7RRbahIhUx05Kq6P/lu7ZZ2yGPp2ZPQc7gUNwgdSWvqNhtfQi6UM7u5t/6xiwpDmH4jkoCjx7fSInc4yhZ/jQ7mdPYfDl6Y5+rX2fYHm4whAXnuHfgVF6ftpeH1zaI36jMxpTJ0BQaNQy/Yu0qoFWzyn7ekHue4fZRXoviDF/q5rONGEsx7aysnLmHqfqDRxxv4LjXQT/CeqI6wxwN+7SJXKka3Resfqw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:MIME-Version; bh=uu/34oQjqA7QmlhwVpJPpy5Fsip8pSdNq5egJ3VBJUg=; b=ypUVOuLphj+vGFrtZMI44uadSidjVsVWNGbAPFvfgNjdcB5W0CF9SmmTsQ3UPaD+RUDlWFmB+IAU4zlMgsZYecHZVpR2j5ydmNCC7dumKnGWsfVGng8dFOBjfGTeqI2EKoi8Y7Pq12/0A4k1LPIJomMMH/qpNWKF4uiRf/mJIFHQ9VvZvUz+/B7L/ZmQu7NMwBZl5LJ/iVuUIED9feUZwdhP7a/85P2q5kVV/6zE0ptDqfA5HCQCh4uVzl7zbdokmcamSLBm4ZeoE58lsEtf9zadzTw4CQ2FpNcgtVkH993rueRGNsXF+nvi06z6n3CvYkBE8wcKca8ItMgL3sumIA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=atomlin.com; dmarc=pass action=none header.from=atomlin.com; dkim=pass header.d=atomlin.com; arc=none Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=atomlin.com; Received: from LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:2b2::11) by LO7P123MB7501.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:40c::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.8; Tue, 25 Aug 2026 18:46:43 +0000 Received: from LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM ([fe80::3975:c5e7:bc1a:f383]) by LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM ([fe80::3975:c5e7:bc1a:f383%4]) with mapi id 15.21.0360.005; Tue, 25 Aug 2026 18:46:43 +0000 From: Aaron Tomlin To: mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org Cc: dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, vschneid@redhat.com, kprateek.nayak@amd.com, zhanxusheng1024@gmail.com, neelx@suse.com, atomlin@atomlin.com, chjohnst@mail.com, mproche@mail.com, sean@ashe.io, steve@abita.co, rishil1999@outlook.com, linux-kernel@vger.kernel.org Subject: [PATCH v6 2/6] sched/debug: Protect lockless rq->rd access in print_dl_rq() Date: Tue, 25 Aug 2026 14:46:33 -0400 Message-ID: <20260825184637.888364-3-atomlin@atomlin.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260825184637.888364-1-atomlin@atomlin.com> References: <20260825184637.888364-1-atomlin@atomlin.com> Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: LO4P123CA0099.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:191::14) To LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:2b2::11) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: LO6P123MB6616:EE_|LO7P123MB7501:EE_ X-MS-Office365-Filtering-Correlation-Id: 7f0079da-b12c-4d9c-0b38-08df02d9353e X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|376014|7416014|1800799024|366016|6133799003|10067099003|56012099006|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: Js1Whz3arIjsntZ1toeYrmTry+DYoqHEdXjpKz7BnYcWq/7occs+k4TdkUaHi9VU5EemoVVYWdV9YFEk1fEGcgLMfEiao5tBo+ux8MYk34LJM2E8X++sVv4z20mBltf6VgWhpacAXJR63V7OZXYn8bWSDpHo/qB9E1kE1uKTBi19QQmrpmnvm/rOlK0/N6w5rqWKl1FlpijnHi7yzm9X5TAGUt4xzUlPPhvpgVxLfYPLBWtj++pZHZrGVyGstf5fukdC32/fL+kNTQwv0xv2wBOJ+P5Pj15J+pZIAL37oSCaKhMfDAwKDh0OjwFUnqTi/ToVy2nfo9D1SNSGkeTOH1MzdWGQ5p/68IKEevpHie7IpUYIjlS7GGAFWD0fjkG+o4WKuI7QbTfVozMA+KJT8TjBy2YRu69ElGBYVhsmn9tzPoZND6p9edonV13AiCuKDnqWLO0eq8RPEW/W2DQpJ4PLgmO5Q8bvOj744l0fC+Nq/fHFcI7bbY3yUKs4h+x5Gp8fMjQJV8GyNGNrfc57jbcocp4T1DCLpMuBbuDaY0EgJY0mP/6M5sGUJBKetxW7lwZjb5jx63G3N0JDctDxz0GdTwCejBac9HsuzJSC3CsmbjhlritRjgIJu2oefyZPolQ3MrZhpMRzhQGa7+d8X811bO8mMV4HDeu5O/wWk7w= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(376014)(7416014)(1800799024)(366016)(6133799003)(10067099003)(56012099006)(18002099003)(22082099003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?sgS0S+9wjuX33TKwFlDzJbmOtnxm1RU4o2wgHBTLSM9d/YmK2setjzV0L/7g?= =?us-ascii?Q?23KCPIpPkijdIyXMAI7h527ZBriDG8sA49FsFGu5xr3pIEw3nX9uVZIgw1tr?= =?us-ascii?Q?XJDSQ4TcLJYeosdIy7lqh8KBV1r+XWhFwcriC8bnCndWJqjmzIhonNGPfMQb?= =?us-ascii?Q?wI4SQe/Nv1RfzIr9ii/71gPB0bS3obQvuZHQwqPhWtmqXmkrK6aPpepAYZ1H?= =?us-ascii?Q?L2qGqeK85PBsEsnPT4KD2ZWrHpq6VpX5VBtsaJV0u0MOREkTPibKksY+7Ysk?= =?us-ascii?Q?QBkBn/0uwUpoSn6RYDA5A7/lq5bunExCBqlAfBx63vRdfu7UXCkppuv4dNSa?= =?us-ascii?Q?9snY1fsVJ7KpRqDx3SrJE2ZDgFBadPEvT7lqOnhFHmoILQc2X1WoAdVu5QUZ?= =?us-ascii?Q?28Y9Ijdg79xvOqWuHUY1saa2ojzndDqyyChjJYxd/c3iSpdIE6BaNHIQ6TO5?= =?us-ascii?Q?oSy6tfUBlMmCPkPUN/n7jPuMsd/ofRYWLO0a1UFI/rQkTiezupMZ1euL+4xq?= =?us-ascii?Q?JaSFKRax2l9jDR5NY7fkhFNRzynaJWqv977jSEfq/gJCbXt8+QUiaT4/u0BS?= =?us-ascii?Q?9ZDa6sYR+uqrsOyD7jLVHN4JFqhpM/vVQv+z7x8P39JVF72ZmQmT/SnjcUXX?= =?us-ascii?Q?rwl6loBeQDidYSZe1p5OSYI0VEQ1LZnQOhqsUrv70nfpQPYuPKC+2ZsX2LV+?= =?us-ascii?Q?Y2tL/2z4OmE9rXTKKfEvp2P7rPi9JV9YApwdBGPBIBM0WuS1pjESCQv1W1sb?= =?us-ascii?Q?noPwLz3MCyoo3YObnql/yywUTxL+qY1GT61Bo+98fgY4CzM5PeDr/tAwVl+M?= =?us-ascii?Q?48ARViNNjCIHnObqNYgC9Ic9JVT//VzzzbuIiRkOQbe0wdT8xkIXj+5nWhN+?= =?us-ascii?Q?nscMxswHYcoOFZXe4y/nGHcgWpxJxSfM72VN+7YO/hVPcviYY+5y4NXxnc4m?= =?us-ascii?Q?xrcHkMVBWb6JKaXyN+2k8bOqhpqFMkz1U4Q4jX9zHpZf5Z7zyHoYpPhNUYHP?= =?us-ascii?Q?dJ8NOeoeTqHsRhQ08GlUlpKIJMWltEy3v08kmVJfcjA2kYkQSdeog+djCT3B?= =?us-ascii?Q?xw9DhI6r/NouQgdsZdDpfMBEUQyq3IVC1YTXrzjM7enYIvU/Y4gR7hQs02dO?= =?us-ascii?Q?F+ukU03Gu0a+pILJLau1zsg0Wg1n+W6GBLEIm8P/crTq5SQNWUUkcTB8Kilk?= =?us-ascii?Q?VIxmOykTpLzXGAFcC+UJ8DE+qiIGp99XR90nUy+AKnJpo1B9LUoSAh2O0U8K?= =?us-ascii?Q?Ab8XxpWFJuMLFd7ostMTBwwh1fR+ZSXtQPWJZW0pK8qkUWScbQ2gcQp4LnhH?= =?us-ascii?Q?L+dMbXIbRiKF8NDTfTG04nayuE1YhAvP+gNASQeVRjW57hJUnS37Wvu/KWrY?= =?us-ascii?Q?+Y4RN7+TT8W0JAadBzwk7t+/C2qlsFjYjcVGX+DRiHQ0hl7akdzAMHMIOFxn?= =?us-ascii?Q?gip6rXXqDGefFZUj91pnad4v60waYCFVc21QtDu/Vge71OESYySvlak7lRbz?= =?us-ascii?Q?P04pDOt7snR8WFLQgh3Vj4p6kEWStb+QiAukwpS5pQ2nSjk8ZD3aghl/7cES?= =?us-ascii?Q?zplyBBYy2ESnVBjiQ8GXqBubx+MNrsfVTRfBNgVMtJwpgUDtyHTRXbuoiIYO?= =?us-ascii?Q?3MTbPfFz29XfH/P95wpUhaXpkY91iWOB5PLDukQu5O7ZkOPYPlDwPKgfW2tC?= =?us-ascii?Q?P2SEyLcy/ynN8vpdpAGk93RztPAF8MQWlb5MrNs4nJMW7I64wjXM1jNs8BnE?= =?us-ascii?Q?Ohe+SxkOgg=3D=3D?= X-OriginatorOrg: atomlin.com X-MS-Exchange-CrossTenant-Network-Message-Id: 7f0079da-b12c-4d9c-0b38-08df02d9353e X-MS-Exchange-CrossTenant-AuthSource: LO6P123MB6616.GBRP123.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Aug 2026 18:46:43.4947 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: e6a32402-7d7b-4830-9a2b-76945bbbcb57 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: tnCv/jjUjSwOw15yZPUDstdUpM+XtvOTrOsYFOVBuBXrCQG4W0aUmQCQiNSAg7r/Ks+uPivpDOiXTtERFrJtYg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO7P123MB7501 In print_dl_rq(), cpu_rq(cpu)->rd is dereferenced locklessly to display deadline bandwidth statistics. During CPU hot-unplug or cgroup cpuset repartitioning events, partition_sched_domains() calls cpu_attach_domain(), which executes rq_attach_root() to detach the CPU from its root_domain. When the reference count of the detached root_domain drops to zero, rq_attach_root() calls call_rcu(&old_rd->rcu, free_rootdomain) to schedule memory teardown after an RCU grace period. However, rq_attach_root() previously updated rq->rd using a plain C store without an RCU publication barrier (i.e., rcu_assign_pointer()). Without a release memory barrier on the writer side, CPU or compiler reordering could allow the new rq->rd pointer store to become visible to other CPUs before the initialization writes to rd->dl_bw are committed. Furthermore, because print_dl_rq() did not hold an RCU read lock while dereferencing cpu_rq(cpu)->rd, an RCU grace period could elapse concurrently while debugfs is reading the file, allowing free_rootdomain() to execute kfree(old_rd) and causing a use-after-free race condition when print_dl_rq() reads dl_bw->bw. Resolve this by using rcu_assign_pointer(rq->rd, rd) in rq_attach_root() to guarantee a release memory barrier when publishing a root_domain. Finally, fetch rq->rd using guard(rcu)() and rcu_dereference() in print_dl_rq(). Fixes: 02968ccf7b80 ("sched: add /proc/sched_debug file") Reported-by: sashiko-bot Signed-off-by: Aaron Tomlin --- kernel/sched/debug.c | 3 ++- kernel/sched/topology.c | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/kernel/sched/debug.c b/kernel/sched/debug.c index 72236db67983..b8be86bf8849 100644 --- a/kernel/sched/debug.c +++ b/kernel/sched/debug.c @@ -1172,7 +1172,8 @@ void print_dl_rq(struct seq_file *m, int cpu, struct dl_rq *dl_rq) SEQ_printf(m, " .%-30s: %lu\n", #x, (unsigned long)(dl_rq->x)) PU(dl_nr_running); - dl_bw = &cpu_rq(cpu)->rd->dl_bw; + guard(rcu)(); + dl_bw = &rcu_dereference(cpu_rq(cpu)->rd)->dl_bw; SEQ_printf(m, " .%-30s: %lld\n", "dl_bw->bw", dl_bw->bw); SEQ_printf(m, " .%-30s: %lld\n", "dl_bw->total_bw", dl_bw->total_bw); diff --git a/kernel/sched/topology.c b/kernel/sched/topology.c index 21e816ad23ee..40c3bcf82a68 100644 --- a/kernel/sched/topology.c +++ b/kernel/sched/topology.c @@ -496,7 +496,7 @@ void rq_attach_root(struct rq *rq, struct root_domain *rd) } atomic_inc(&rd->refcount); - rq->rd = rd; + rcu_assign_pointer(rq->rd, rd); cpumask_set_cpu(rq->cpu, rd->span); if (cpumask_test_cpu(rq->cpu, cpu_active_mask)) -- 2.55.0