Re: [PATCH v4 1/2] arm64: topology: fix arch_freq_get_on_cpu() overflow above 4.19 GHz
From: Peter Zijlstra
Date: Thu Sep 17 2026 - 11:37:49 EST
On Thu, Sep 17, 2026 at 02:51:11PM +0200, Oleg Keri wrote:
> arch_freq_get_on_cpu() computes the product of the frequency scale and
> the reference frequency as a u64, but assigns it to an unsigned int
> before shifting it back down:
>
> freq = scale * arch_scale_freq_ref(cpu);
> freq >>= SCHED_CAPACITY_SHIFT;
>
> The product is truncated to 32 bits before the shift, so the result
> wraps once arch_scale_freq_ref() exceeds 2^32 / SCHED_CAPACITY_SCALE,
> i.e. 4194304 kHz.
>
> On a Snapdragon X2 Elite (Glymur) laptop, whose boost OPP is 4723200
> kHz, cpuinfo_avg_freq reports 524283 kHz instead of ~4723200 kHz while
> the CPU demonstrably runs at the boost frequency: a fixed workload
> completes in 1.72 s at the 4723200 kHz OPP versus 2.01 s at 4032000
> kHz, matching the 1.171 frequency ratio.
>
> Use cap_scale(), which the scheduler already has for exactly this
> capacity scaling, so the multiply and the shift stay in 64 bits and
> only the final value is narrowed by the return type. Move the macro
> from the scheduler's private header to <linux/topology.h> so it can be
> used outside kernel/sched.
>
> Fixes: 16d1e27475f6 ("arm64: Provide an AMU-based version of arch_freq_get_on_cpu")
> Signed-off-by: Oleg Keri <okerixx@xxxxxxxxx>
> ---
> arch/arm64/kernel/topology.c | 5 +----
> include/linux/topology.h | 2 ++
> kernel/sched/sched.h | 2 --
> 3 files changed, 3 insertions(+), 6 deletions(-)
>
> diff --git a/arch/arm64/kernel/topology.c b/arch/arm64/kernel/topology.c
> index d28438f8b83f..07b8c497c9e6 100644
> --- a/arch/arm64/kernel/topology.c
> +++ b/arch/arm64/kernel/topology.c
> @@ -186,7 +186,6 @@ int arch_freq_get_on_cpu(int cpu)
> struct amu_cntr_sample *amu_sample;
> unsigned int start_cpu = cpu;
> unsigned long last_update;
> - unsigned int freq = 0;
> u64 scale;
>
> if (!amu_fie_cpu_supported(cpu) || !arch_scale_freq_ref(cpu))
> @@ -245,9 +244,7 @@ int arch_freq_get_on_cpu(int cpu)
> * (see amu_scale_freq_tick for details)
> */
> scale = arch_scale_freq_capacity(cpu);
> - freq = scale * arch_scale_freq_ref(cpu);
> - freq >>= SCHED_CAPACITY_SHIFT;
> - return freq;
> + return cap_scale(arch_scale_freq_ref(cpu), scale);
> }
>
> static void amu_fie_setup(const struct cpumask *cpus)
> diff --git a/include/linux/topology.h b/include/linux/topology.h
> index 709a2dcf4c73..0a4ee12a98d5 100644
> --- a/include/linux/topology.h
> +++ b/include/linux/topology.h
> @@ -351,4 +351,6 @@ static inline unsigned long topology_get_cpu_scale(int cpu)
>
> void topology_set_cpu_scale(unsigned int cpu, unsigned long capacity);
>
> +#define cap_scale(v, s) ((v)*(s) >> SCHED_CAPACITY_SHIFT)
This might not be a very good generic helper, since it relies on either
of the variables to be u64 for correctness.