From: sashiko-bot@kernel.org
To: "Tao Cui" <cui.tao@linux.dev>
Cc: sched-ext@lists.linux.dev
Subject: Re: [PATCH] sched_ext: Reset cpuperf_target when a sub-scheduler loses SCX_CAP_PERF or dies
Date: Sun, 04 Oct 2026 01:42:02 +0000 [thread overview]
Message-ID: <20261004014203.49F8A1F0089B@smtp.kernel.org> (raw)
In-Reply-To: <20261004012721.615419-1-cui.tao@linux.dev>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] sched_ext: UAF on scx_cid_to_cpu_tbl in scx_sub_reset_cpuperf() on teardown
- [Medium] sched_ext: TOCTOU race in scx_cpuperf_queue_reset() triggers offline CPU WARN
- [Medium] sched_ext: offline CPUs retain stale cpuperf_target causing frequency pinning
--
commit 8df3a4e837553ee14c5a70ecea2b4bec546c3881
Author: Tao Cui <cuitao@kylinos.cn>
sched_ext: Reset cpuperf_target when a sub-scheduler loses SCX_CAP_PERF or dies
This commit introduces a mechanism to reset rq->scx.cpuperf_target to the
neutral SCX_CPUPERF_ONE base when a sub-scheduler that wrote targets loses
its capabilities or dies. It queues per-CPU irq_works to perform the reset
under the target CPU's rq lock, and skips offline CPUs.
> diff --git a/kernel/sched/ext/sub.c b/kernel/sched/ext/sub.c
> index 0554448835bd0..38e48e4648da5 100644
> --- a/kernel/sched/ext/sub.c
> +++ b/kernel/sched/ext/sub.c
[ ... ]
> @@ -28,6 +28,57 @@
> */
> DEFINE_STATIC_KEY_FALSE(__scx_has_subs);
>
> +/*
> + * Reset rq->scx.cpuperf_target back to the neutral SCX_CPUPERF_ONE base
> + * when a sub-scheduler that wrote targets loses SCX_CAP_PERF or dies. The
[ ... ]
> +/*
> + * Queue a reset of @cpu's cpuperf target. Idempotent: the work is always a
> + * plain restore of the neutral base, so concurrent queues collapse into one
> + * run; CPUs that never had a sub-scheduler target no-op.
> + */
> +static void scx_cpuperf_queue_reset(s32 cpu)
> +{
> + if (cpu < 0 || cpu >= nr_cpu_ids || !cpu_online(cpu))
> + return;
[Severity: Medium]
If the CPU is already offline when this function is called, the early return
skips resetting the target. Does this leave the offline CPU with a stale
cpuperf_target in its rq, permanently pinning the CPU to a low frequency
when it comes back online?
> + irq_work_queue_on(&per_cpu(scx_cpuperf_reset_iw, cpu), cpu);
[Severity: Medium]
Since cpu_online() is checked without preemption disabled or any hotplug
locks held, is there a TOCTOU race window here? If a concurrent CPU offline
operation clears cpu_online_mask immediately after this check, wouldn't
calling irq_work_queue_on() trigger a WARN_ON_ONCE(cpu_is_offline(cpu))?
> +}
[ ... ]
> +static void scx_sub_reset_cpuperf(struct scx_sched *sch)
> +{
> + s32 si, cid;
> +
> + if (!READ_ONCE(sch->pshard))
> + return;
> +
> + for (si = 0; si < sch->nr_pshards; si++) {
> + struct scx_cmask *cm = &sch->pshard[si]->caps[__SCX_CAP_PERF].cmask;
> +
> + scx_cmask_for_each_cid(cid, cm)
> + scx_cpuperf_queue_reset(__scx_cid_to_cpu(cid));
[Severity: High]
This relies on __scx_cid_to_cpu(), which locklessly dereferences
scx_cid_to_cpu_tbl. Since scx_sub_reset_cpuperf() is called after dropping
scx_enable_mutex, if scx_root_disable() concurrently nulls and frees the
tables, wouldn't this cause a UAF or NULL pointer dereference?
> + }
> +}
[ ... ]
> @@ -1631,6 +1715,13 @@ void scx_sub_disable(struct scx_sched *sch)
>
> mutex_unlock(&scx_enable_mutex);
>
> + /*
> + * @sch can no longer receive grants or writes: queue a cpuperf reset
> + * for every CPU it held SCX_CAP_PERF on so schedutil doesn't keep
> + * consuming the targets it left behind.
> + */
> + scx_sub_reset_cpuperf(sch);
[Severity: Medium]
This calls scx_sub_reset_cpuperf() with preemption enabled and without
any hotplug protection, exposing the cpu_online() TOCTOU race mentioned
above.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261004012721.615419-1-cui.tao@linux.dev?part=1
prev parent reply other threads:[~2026-10-04 1:42 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 1:27 [PATCH] sched_ext: Reset cpuperf_target when a sub-scheduler loses SCX_CAP_PERF or dies Tao Cui
2026-10-04 1:42 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004014203.49F8A1F0089B@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=cui.tao@linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sched-ext@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox