[PATCH sched/core] sched/rt: Fix RT_PUSH_IPI soft lockup loop

From: Tejun Heo

Date: Wed May 06 2026 - 19:57:20 EST


push_rt_task() picks the highest pushable RT task next_task. If it
outranks rq->donor, the existing path calls resched_curr() and
returns 0, trusting local schedule() to pick next_task soon.

The RT_PUSH_IPI relay caller (rto_push_irq_work_func()) cannot rely
on that. When this CPU has a steady supply of softirq work (e.g.,
incoming packets), the next push IPI arrives before schedule() can
run. Other CPUs keep seeing this CPU as overloaded and keep sending
IPIs, this CPU keeps taking the same bail, and the loop repeats
until soft lockup.

Seen in production on hosts with sustained NET_RX softirq load:
the loop ran millions of iterations before tripping the soft-lockup
watchdog.

Skip the prio bail when called via the IPI relay (pull=true) so
push_rt_task() migrates next_task to another CPU. Verified with a
synthetic reproducer.

Fixes: b6366f048e0c ("sched/rt: Use IPI to trigger RT task push migration instead of pulling")
Cc: Kyle McMartin <jkkm@xxxxxxxx>
Cc: stable@xxxxxxxxxxxxxxx # v5.10+
Signed-off-by: Tejun Heo <tj@xxxxxxxxxx>
---
This looks minimal to me, but happy for suggestions. Thanks.

kernel/sched/rt.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)

--- a/kernel/sched/rt.c
+++ b/kernel/sched/rt.c
@@ -1968,8 +1968,14 @@ retry:
* It's possible that the next_task slipped in of
* higher priority than current. If that's the case
* just reschedule current.
+ *
+ * This doesn't work for the IPI relay caller (pull). When this CPU
+ * has a steady supply of softirq work (e.g., incoming packets), the
+ * next push IPI arrives before schedule() can run. Other CPUs keep
+ * seeing it as overloaded and keep sending IPIs, this CPU keeps
+ * taking the same bail, and the loop repeats until soft lockup.
*/
- if (unlikely(next_task->prio < rq->donor->prio)) {
+ if (unlikely(next_task->prio < rq->donor->prio) && !pull) {
resched_curr(rq);
return 0;
}