sched-ext.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Andrea Righi" <arighi@nvidia.com>
Cc: sched-ext@lists.linux.dev
Subject: Re: [PATCH 17/18] sched_ext: scx_qmap: Add proxy execution support
Date: Mon, 31 Aug 2026 18:33:56 +0000	[thread overview]
Message-ID: <20260831183356.6E92E1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831134338.1531664-18-arighi@nvidia.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Missing bounds check on `cid` returned from `cmask_next_and_set_wrap()` due to a TOCTOU race with `qa.self_cids.mask` modifications.
--

commit 564b1258b3dc07e22341c55b61be164307b61870
Author: Andrea Righi <arighi@nvidia.com>

sched_ext: scx_qmap: Add proxy execution support

Add a -X option to opt scx_qmap into queueing mutex-blocked tasks for proxy
execution. When scx_qmap receives a blocked donor, it selects an eligible cid
and dispatches the donor to that local DSQ.

> diff --git a/tools/sched_ext/scx_qmap.bpf.c b/tools/sched_ext/scx_qmap.bpf.c
> index 5bb8b90a275a3..21f8a9be9650c 100644
> --- a/tools/sched_ext/scx_qmap.bpf.c
> +++ b/tools/sched_ext/scx_qmap.bpf.c
[ ... ]
> @@ -460,6 +464,53 @@ void BPF_STRUCT_OPS(qmap_enqueue, struct task_struct *p, u64 enq_flags)
[ ... ]
> +	/*
> +	 * Insert a blocked mutex donor at the head of an eligible local DSQ with
> +	 * a fresh slice and %SCX_ENQ_PREEMPT, requesting an immediate reschedule.
> +	 * The test above guarantees that cpus_allowed intersects self_cids, but
> +	 * the donor's current cid may have been delegated to a child. Search the
> +	 * intersection starting at the current cid, preserving it when qmap still
> +	 * holds it and wrapping to another eligible self cid otherwise.
> +	 *
> +	 * A self cid may be held exclusively with SCX_CAP_ENQ or time-shared with
> +	 * only SCX_CAP_ENQ_IMMED. Add needs_immed() so either kind can accept the
> +	 * local insertion instead of rejecting and reenqueuing the donor for a
> +	 * capability miss. Once selected, the core proxy-exec path can run the
> +	 * mutex owner using the donor's scheduling context.
> +	 *
> +	 * This policy is intentionally unfair and can strongly prioritize tasks
> +	 * using contended mutexes; scx_qmap is a demonstration scheduler and
> +	 * this behavior makes proxy-exec support easy to observe.
> +	 */
> +	if (enq_flags & SCX_ENQ_BLOCKED) {
> +		cid = cmask_next_and_set_wrap(&taskc->cpus_allowed,
> +					      &qa.self_cids.mask,
> +					      scx_bpf_task_cid(p));
> +		scx_bpf_dsq_insert(p, SCX_DSQ_LOCAL_ON | cid, slice_ns,
> +				   enq_flags | needs_immed(cid) | SCX_ENQ_PREEMPT);
> +		return;
> +	}

[Severity: High]
Does this code risk an out-of-bounds access if the intersection becomes
empty?

In qmap_enqueue(), there is an earlier check for
cmask_intersects(&taskc->cpus_allowed, &qa.self_cids.mask).

However, if apply_partition() modifies and zeroes qa.self_cids.mask
concurrently on another CPU after the check, the intersection might become
empty before cmask_next_and_set_wrap() executes.

If this happens, cmask_next_and_set_wrap() returns the out-of-bounds
sentinel scx_bpf_nr_cids().

This out-of-bounds cid is then used without a bounds check in:

    scx_bpf_dsq_insert(p, SCX_DSQ_LOCAL_ON | cid, ...)

which can cause scx_cpu_valid() to fail and forcefully eject the BPF
scheduler. It could also lead to an out-of-bounds read in needs_immed(cid).

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260831134338.1531664-1-arighi@nvidia.com?part=17

  reply	other threads:[~2026-08-31 18:33 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 13:42 [PATCHSET v13 sched_ext/for-7.4] sched: Make proxy execution compatible with sched_ext Andrea Righi
2026-08-31 13:42 ` [PATCH 01/18] sched/core: Drop mutex locks before proxy rescheduling Andrea Righi
2026-08-31 13:42 ` [PATCH 02/18] sched/core: Dequeue waking proxy donors before reset Andrea Righi
2026-09-01  5:24   ` K Prateek Nayak
2026-09-08  9:28     ` Andrea Righi
2026-08-31 13:42 ` [PATCH 03/18] sched: Make NOHZ CFS bandwidth checks follow proxy donor Andrea Righi
2026-09-10  9:54   ` Peter Zijlstra
2026-09-15 15:59     ` Andrea Righi
2026-08-31 13:42 ` [PATCH 04/18] sched/core: Avoid false migration warning for proxy donors Andrea Righi
2026-09-10 10:06   ` Peter Zijlstra
2026-09-15 16:05     ` Andrea Righi
2026-09-15 17:20       ` Andrea Righi
2026-09-15 17:24         ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 05/18] sched: Pass next class to sched_change_begin() Andrea Righi
2026-09-10 10:12   ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 06/18] sched: Add helper to block retained proxy donors Andrea Righi
2026-08-31 13:42 ` [PATCH 07/18] sched: Add sched_ext hooks for proxy execution Andrea Righi
2026-09-10 10:38   ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 08/18] sched: Introduce WF_ON_RQ wake flag Andrea Righi
2026-09-10 10:45   ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 09/18] sched_ext: Block proxy donors across scheduler transitions Andrea Righi
2026-09-10 10:53   ` Peter Zijlstra
2026-09-10 11:41     ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 10/18] sched_ext: Fix ops.running/stopping() pairing for proxy-exec donors Andrea Righi
2026-08-31 13:42 ` [PATCH 11/18] sched_ext: Move reject DSQ draining into core Andrea Righi
2026-08-31 13:42 ` [PATCH 12/18] sched_ext: Generalize the reject DSQ reenqueue path Andrea Righi
2026-09-03 22:39   ` Tejun Heo
2026-09-08  9:34     ` Andrea Righi
2026-08-31 13:42 ` [PATCH 13/18] sched_ext: Handle proxy-exec races in remote DSQ transfers Andrea Righi
2026-08-31 13:42 ` [PATCH 14/18] sched_ext: Split curr|donor references properly Andrea Righi
2026-08-31 17:49   ` sashiko-bot
2026-09-08 10:15     ` Andrea Righi
2026-09-10 11:47   ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 15/18] sched_ext: Delegate proxy donor admission to BPF schedulers Andrea Righi
2026-08-31 18:08   ` sashiko-bot
2026-09-08 10:08     ` Andrea Righi
2026-09-10 13:39   ` Peter Zijlstra
2026-09-10 13:41   ` Peter Zijlstra
2026-08-31 13:42 ` [PATCH 16/18] sched_ext: Add selftest for blocked donor admission Andrea Righi
2026-08-31 13:42 ` [PATCH 17/18] sched_ext: scx_qmap: Add proxy execution support Andrea Righi
2026-08-31 18:33   ` sashiko-bot [this message]
2026-09-01  7:52   ` Richard Cheng
2026-09-08  9:42     ` Andrea Righi
2026-08-31 13:42 ` [PATCH 18/18] sched: Allow enabling proxy exec with sched_ext Andrea Righi
2026-09-03 22:51 ` [PATCHSET v13 sched_ext/for-7.4] sched: Make proxy execution compatible " Tejun Heo
2026-09-08  8:02   ` Peter Zijlstra

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831183356.6E92E1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=arighi@nvidia.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sched-ext@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).