[PATCH v5 0/6] sched/debug: Introduce per-CPU debugfs files
From: Aaron Tomlin
Date: Tue Aug 25 2026 - 10:51:20 EST
Hi Peter, Juri, Ingo, Vincent,
This patch series addresses a few pre-existing memory safety and list
traversal concurrency issues in scheduler debugfs handlers, and introduces
per-CPU debugfs files under /sys/kernel/debug/sched/cpu/cpu<N>/debug.
Patch 1 introduces a new prerequisite patch that annotates struct rq's rd
(root_domain) pointer with __rcu in kernel/sched/sched.h and updates
lockless readers across the core scheduler to use rcu_dereference(),
ensuring Sparse compliance and proper memory barriers on weakly ordered
architectures.
Patch 2 fixes a use-after-free in print_dl_rq() where cpu_rq(cpu)->rd is
dereferenced locklessly to display deadline bandwidth statistics. During
CPU hot-unplug or cgroup cpuset repartitioning events,
partition_sched_domains() calls rq_attach_root() to detach the CPU from its
root_domain and schedules free_rootdomain() via call_rcu(). Without an RCU
read lock, an RCU grace period can resolve concurrently while debugfs reads
the file, allowing free_rootdomain() to execute kfree() and causing a UAF
when reading dl_bw->bw. This patch adds rcu_assign_pointer() on the writer
side in rq_attach_root() and uses guard(rcu)() with rcu_dereference() in
print_dl_rq().
Patch 3 fixes a potential use-after-free in print_cpu() where rq->curr is
dereferenced locklessly to output the running task's PID. If the task exits
concurrently and its reference count drops to zero, put_task_struct()
schedules __put_task_struct_rcu_cb() via call_rcu(). Without holding an RCU
read lock, an RCU grace period can elapse concurrently and free the task
structure via free_task(), leading to a use-after-free race condition. This
patch protects rq->curr access using rcu_dereference() inside an RCU
read-side critical section.
Patch 4 fixes both a time-of-check to time-of-use race condition and a
potential use-after-free in sched_show_numa(), where p->mm is checked
locklessly and then passed to P(mm->numa_scan_seq). If the task exits
concurrently via exit_mm(p), current->mm is set to NULL under task_lock(p)
before mmput() is called to free the struct mm_struct. Wrapping the p->mm
check and dereference in task_lock(p) eliminates both hazards.
Patch 5 fixes an RCU traversal violation in print_cfs_stats() where
rq->leaf_cfs_rq_list is traversed locklessly using
for_each_leaf_cfs_rq_safe(), which expands to list_for_each_entry_safe().
Although leaf_cfs_rq_list is modified using list_add_rcu(),
list_for_each_entry_safe() lacks READ_ONCE() and pre-fetches the next
pointer without memory barriers. Furthermore, because cfs_rq nodes are
re-linked on enqueue/dequeue without waiting for RCU grace periods,
concurrent list churn can cause backward jumps or infinite loops. This
patch introduces for_each_leaf_cfs_rq_rcu(), bounds traversal with a
circuit-breaker ceiling, and emits an explicit truncation notice if the
ceiling is reached.
Patch 6 introduces per-CPU debugfs entries under
/sys/kernel/debug/sched/cpu/cpu<N>/debug, allowing targeted inspection of
an individual CPU's runqueue on demand. If the target CPU is currently
offline, reading its file returns -ENODEV.
Changes since v4:
- Added a new prerequisite patch to annotate struct rq's rd field with
__rcu and updated lockless readers to use
rcu_dereference()/rcu_dereference_sched()
- Updated print_dl_rq() to use guard(rcu)() and rcu_dereference() on
rq->rd (Daniel Vacek and K Prateek Nayak)
- Replaced READ_ONCE(p->mm) with task_lock(p)/task_unlock(p) in
sched_show_numa() to prevent use-after-free against concurrent exit_mm()
and mmput()
- Updated print_cfs_stats() to use guard(rcu)()
- Increased SCHED_DEBUG_MAX_ITER from 1024 to 4096 and added an explicit
truncation notice
- Moved SEQ_printf() and SEQ_printf_task_group_path() to
kernel/sched/sched.h, replaced strcpy() with strscpy(), and used
IS_ENABLED(CONFIG_FAIR_GROUP_SCHED) with a typed static inline fallback
stub
- Corrected the "Fixes:" commit tag in Patch 5 to 039ae8bcf7a5 ("sched/fair:
Fix O(nr_cgroups) in the load balancing path")
- Linked to v4: https://lore.kernel.org/lkml/20260810015812.428999-1-atomlin@xxxxxxxxxxx/
Changes since v3:
- Updated Patch 1 to use rcu_dereference(rq->curr) instead of READ_ONCE()
to preserve __rcu
- Added missing writer-side RCU publication barrier (rcu_assign_pointer())
in rq_attach_root() for Patch 2
- Added Patch 3 to fix a TOCTOU condition in sched_show_numa() using
READ_ONCE(p->mm)
- Added a safety iteration ceiling in print_cfs_stats() for Patch 4 to
prevent unbounded list iteration and RCU stalls under heavy
leaf_cfs_rq_list churn
- Linked to v3: https://lore.kernel.org/lkml/20260808235522.380038-1-atomlin@xxxxxxxxxxx/
Changes since v2:
- Protected lockless rq->curr dereferencing in print_cpu() with
rcu_read_lock() and READ_ONCE()
- Protected lockless rq->rd dereferencing in print_dl_rq() against CPU
hot-unplug and cgroup cpuset repartitioning races
- Introduced for_each_leaf_cfs_rq_rcu() using list_for_each_entry_rcu()
for lockless leaf_cfs_rq_list iteration
- Linked to v2: https://lore.kernel.org/lkml/20260728205238.18447-1-atomlin@xxxxxxxxxxx/
Changes since v1:
- Reframed commit message motivation around targeted interactive
debugging on large SMP topologies (Peter Zijlstra and Zhan Xusheng)
- Gated sched_debug_cpu_show() with a cpu_online(cpu) check
returning -ENODEV when target CPU is offline (Zhan Xusheng)
- Linked to v1: https://lore.kernel.org/lkml/20260728020309.6169-1-atomlin@xxxxxxxxxxx/
Aaron Tomlin (6):
sched: Annotate rq->rd with __rcu and update lockless readers
sched/debug: Protect lockless rq->rd access in print_dl_rq()
sched/debug: Protect lockless rq->curr access in print_cpu()
sched/debug: Protect p->mm access in sched_show_numa()
sched/fair: Use list_for_each_entry_rcu() in print_cfs_stats()
sched/debug: Introduce per-CPU debugfs files
kernel/sched/core.c | 16 ++++---
kernel/sched/deadline.c | 8 ++--
kernel/sched/debug.c | 92 ++++++++++++++++++++++++-----------------
kernel/sched/fair.c | 62 +++++++++++++++++++--------
kernel/sched/sched.h | 53 +++++++++++++++++++++++-
kernel/sched/topology.c | 2 +-
6 files changed, 165 insertions(+), 68 deletions(-)
--
2.55.0