From: sashiko-bot@kernel.org
To: "Andrea Righi" <arighi@nvidia.com>
Cc: sched-ext@lists.linux.dev
Subject: Re: [PATCH 17/18] sched_ext: scx_qmap: Add proxy execution support
Date: Mon, 31 Aug 2026 18:33:56 +0000 [thread overview]
Message-ID: <20260831183356.6E92E1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831134338.1531664-18-arighi@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Missing bounds check on `cid` returned from `cmask_next_and_set_wrap()` due to a TOCTOU race with `qa.self_cids.mask` modifications.
--
commit 564b1258b3dc07e22341c55b61be164307b61870
Author: Andrea Righi <arighi@nvidia.com>
sched_ext: scx_qmap: Add proxy execution support
Add a -X option to opt scx_qmap into queueing mutex-blocked tasks for proxy
execution. When scx_qmap receives a blocked donor, it selects an eligible cid
and dispatches the donor to that local DSQ.
> diff --git a/tools/sched_ext/scx_qmap.bpf.c b/tools/sched_ext/scx_qmap.bpf.c
> index 5bb8b90a275a3..21f8a9be9650c 100644
> --- a/tools/sched_ext/scx_qmap.bpf.c
> +++ b/tools/sched_ext/scx_qmap.bpf.c
[ ... ]
> @@ -460,6 +464,53 @@ void BPF_STRUCT_OPS(qmap_enqueue, struct task_struct *p, u64 enq_flags)
[ ... ]
> + /*
> + * Insert a blocked mutex donor at the head of an eligible local DSQ with
> + * a fresh slice and %SCX_ENQ_PREEMPT, requesting an immediate reschedule.
> + * The test above guarantees that cpus_allowed intersects self_cids, but
> + * the donor's current cid may have been delegated to a child. Search the
> + * intersection starting at the current cid, preserving it when qmap still
> + * holds it and wrapping to another eligible self cid otherwise.
> + *
> + * A self cid may be held exclusively with SCX_CAP_ENQ or time-shared with
> + * only SCX_CAP_ENQ_IMMED. Add needs_immed() so either kind can accept the
> + * local insertion instead of rejecting and reenqueuing the donor for a
> + * capability miss. Once selected, the core proxy-exec path can run the
> + * mutex owner using the donor's scheduling context.
> + *
> + * This policy is intentionally unfair and can strongly prioritize tasks
> + * using contended mutexes; scx_qmap is a demonstration scheduler and
> + * this behavior makes proxy-exec support easy to observe.
> + */
> + if (enq_flags & SCX_ENQ_BLOCKED) {
> + cid = cmask_next_and_set_wrap(&taskc->cpus_allowed,
> + &qa.self_cids.mask,
> + scx_bpf_task_cid(p));
> + scx_bpf_dsq_insert(p, SCX_DSQ_LOCAL_ON | cid, slice_ns,
> + enq_flags | needs_immed(cid) | SCX_ENQ_PREEMPT);
> + return;
> + }
[Severity: High]
Does this code risk an out-of-bounds access if the intersection becomes
empty?
In qmap_enqueue(), there is an earlier check for
cmask_intersects(&taskc->cpus_allowed, &qa.self_cids.mask).
However, if apply_partition() modifies and zeroes qa.self_cids.mask
concurrently on another CPU after the check, the intersection might become
empty before cmask_next_and_set_wrap() executes.
If this happens, cmask_next_and_set_wrap() returns the out-of-bounds
sentinel scx_bpf_nr_cids().
This out-of-bounds cid is then used without a bounds check in:
scx_bpf_dsq_insert(p, SCX_DSQ_LOCAL_ON | cid, ...)
which can cause scx_cpu_valid() to fail and forcefully eject the BPF
scheduler. It could also lead to an out-of-bounds read in needs_immed(cid).
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260831134338.1531664-1-arighi@nvidia.com?part=17
next prev parent reply other threads:[~2026-08-31 18:33 UTC|newest]
Thread overview: 46+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 13:42 [PATCHSET v13 sched_ext/for-7.4] sched: Make proxy execution compatible with sched_ext Andrea Righi
2026-08-31 13:42 ` [PATCH 01/18] sched/core: Drop mutex locks before proxy rescheduling Andrea Righi
2026-08-31 13:42 ` [PATCH 02/18] sched/core: Dequeue waking proxy donors before reset Andrea Righi
2026-09-01 5:24 ` K Prateek Nayak
2026-09-08 9:28 ` Andrea Righi
2026-08-31 13:42 ` [PATCH 03/18] sched: Make NOHZ CFS bandwidth checks follow proxy donor Andrea Righi
2026-09-10 9:54 ` Peter Zijlstra
2026-09-15 15:59 ` Andrea Righi
2026-08-31 13:42 ` [PATCH 04/18] sched/core: Avoid false migration warning for proxy donors Andrea Righi
2026-09-10 10:06 ` Peter Zijlstra
2026-09-15 16:05 ` Andrea Righi
2026-09-15 17:20 ` Andrea Righi
2026-09-15 17:24 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 05/18] sched: Pass next class to sched_change_begin() Andrea Righi
2026-09-10 10:12 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 06/18] sched: Add helper to block retained proxy donors Andrea Righi
2026-08-31 13:42 ` [PATCH 07/18] sched: Add sched_ext hooks for proxy execution Andrea Righi
2026-09-10 10:38 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 08/18] sched: Introduce WF_ON_RQ wake flag Andrea Righi
2026-09-10 10:45 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 09/18] sched_ext: Block proxy donors across scheduler transitions Andrea Righi
2026-09-10 10:53 ` Peter Zijlstra
2026-09-10 11:41 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 10/18] sched_ext: Fix ops.running/stopping() pairing for proxy-exec donors Andrea Righi
2026-08-31 13:42 ` [PATCH 11/18] sched_ext: Move reject DSQ draining into core Andrea Righi
2026-08-31 13:42 ` [PATCH 12/18] sched_ext: Generalize the reject DSQ reenqueue path Andrea Righi
2026-09-03 22:39 ` Tejun Heo
2026-09-08 9:34 ` Andrea Righi
2026-08-31 13:42 ` [PATCH 13/18] sched_ext: Handle proxy-exec races in remote DSQ transfers Andrea Righi
2026-08-31 13:42 ` [PATCH 14/18] sched_ext: Split curr|donor references properly Andrea Righi
2026-08-31 17:49 ` sashiko-bot
2026-09-08 10:15 ` Andrea Righi
2026-09-10 11:47 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 15/18] sched_ext: Delegate proxy donor admission to BPF schedulers Andrea Righi
2026-08-31 18:08 ` sashiko-bot
2026-09-08 10:08 ` Andrea Righi
2026-09-10 13:39 ` Peter Zijlstra
2026-09-10 13:41 ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 16/18] sched_ext: Add selftest for blocked donor admission Andrea Righi
2026-08-31 13:42 ` [PATCH 17/18] sched_ext: scx_qmap: Add proxy execution support Andrea Righi
2026-08-31 18:33 ` sashiko-bot [this message]
2026-09-01 7:52 ` Richard Cheng
2026-09-08 9:42 ` Andrea Righi
2026-08-31 13:42 ` [PATCH 18/18] sched: Allow enabling proxy exec with sched_ext Andrea Righi
2026-09-03 22:51 ` [PATCHSET v13 sched_ext/for-7.4] sched: Make proxy execution compatible " Tejun Heo
2026-09-08 8:02 ` Peter Zijlstra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831183356.6E92E1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=arighi@nvidia.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sched-ext@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).