[PATCH 10/14] sched_ext: Split curr|donor references properly

From: Andrea Righi

Date: Sat Jul 25 2026 - 12:07:03 EST


With proxy execution, the task selected by the scheduler and the task
physically executing can differ. A blocked mutex waiter donates its
scheduling context to the lock owner:

D -----------------> M -------------> O ----------------> T
[donor] blocked on [mutex] owned by [owner] preempted by [task]
\_________________________________^
donates scheduling context

where:

D = blocked donor
M = mutex
O = mutex owner
T = competing runnable task

During a proxy execution switch, D supplies the scheduling class,
priority, and runtime budget, while O supplies the execution context: O
is the task whose code physically executes. T is a competing runnable
task which may preempt the D/O proxy execution.

Consider FAIR and EXT tasks with sched_ext running in partial mode. FAIR
can be replaced with a higher scheduling class such as RT or deadline
without changing the class interaction described here. The possible
combinations are:

1. D is EXT, O is EXT, T is EXT

D can interrupt T according to BPF scheduling policy. O executes
with D's EXT priority and runtime budget, while T waits in EXT.

2. D is EXT, O is EXT, T is FAIR

D is visible to the BPF scheduler, but cannot preempt T because
EXT is below FAIR. Once T stops, BPF can dispatch D and O executes
with D's EXT priority and runtime budget. If T becomes runnable
again, it preempts the D/O proxy execution.

3. D is EXT, O is FAIR, T is EXT

This cannot represent T preempting O because EXT is below FAIR.

4. D is EXT, O is FAIR, T is FAIR

D cannot boost O above T because EXT is below FAIR. O and T
continue competing under FAIR. Once O releases M, D wakes and
resumes normal EXT scheduling.

5. D is FAIR, O is EXT, T is EXT

D preempts T as the higher-class scheduling context. O executes
with D's FAIR priority and runtime budget, while T waits in EXT.
D is not visible to the BPF scheduler.

6. D is FAIR, O is EXT, T is FAIR

D competes with T according to its FAIR deadline. When D is
selected, O executes with D's FAIR priority and runtime budget.
D is not visible to the BPF scheduler.

7. D is FAIR, O is FAIR, T is EXT

This cannot represent T preempting O because EXT is below FAIR.

8. D is FAIR, O is FAIR, T is FAIR

O, T, and D all have FAIR scheduling contexts. D remains runnable
as a blocked proxy donor. When CFS selects D, O executes using D's
FAIR scheduling context. When CFS selects O, O executes using its
own FAIR context, and when CFS selects T, T executes normally. D
is not visible to the BPF scheduler.

Thus, sched_ext policy and accounting must generally use rq->donor, the
scheduler-selected task which supplies the scheduling context, rather
than rq->curr, the task whose code physically executes. Without proxy
execution they are the same task.

On nohz_full CPUs, a blocked proxy donor must retain the scheduler tick
even when it has an infinite slice. Otherwise, a full dynticks CPU could
stop the tick while rq->curr and rq->donor differ, violating assumptions
made by the remote NOHZ tick path.

This is a conservative compromise that keeps the change local to
sched_ext, at the cost of a periodic tick while a blocked proxy donor is
selected. Allowing blocked proxy donors to run tickless would require
making the core scheduler's remote tick handling aware that rq->curr and
rq->donor can differ.

Moreover, extend scx_dump_state() to report both contexts. Each CPU
record now includes a donor= line. If an EXT donor differs from
rq->curr, also emit its detailed task record. The existing '*' marker
continues to identify rq->curr, while the donor= line identifies the
otherwise unmarked donor record.

Note that at this point in the series, CONFIG_SCHED_PROXY_EXEC still
depends on !CONFIG_SCHED_CLASS_EXT, so proxy execution and sched_ext
cannot be enabled together. The scheduling changes are therefore
preparatory. A later patch removes this restriction.

Co-developed-by: John Stultz <jstultz@xxxxxxxxxx>
Signed-off-by: John Stultz <jstultz@xxxxxxxxxx>
Signed-off-by: Andrea Righi <arighi@xxxxxxxxxx>
---
Documentation/scheduler/sched-ext.rst | 6 ++
kernel/sched/ext/ext.c | 115 +++++++++++++++++---------
kernel/sched/ext/sub.h | 8 +-
3 files changed, 86 insertions(+), 43 deletions(-)

diff --git a/Documentation/scheduler/sched-ext.rst b/Documentation/scheduler/sched-ext.rst
index 2771ea4cc14af..4d8bcbdacb9fc 100644
--- a/Documentation/scheduler/sched-ext.rst
+++ b/Documentation/scheduler/sched-ext.rst
@@ -487,6 +487,12 @@ and edge cases, to name a few examples:
class, in which case it will exit the tick-dispatch loop even though it is runnable
and has a non-zero slice.

+* Under proxy execution, sched_ext continues to observe the donor as the current
+ scheduling context. A blocked donor does not enter an ``ops.running()`` /
+ ``ops.stopping()`` session because it does not execute itself, and the lock
+ owner executing on its behalf is intentionally not reported through these
+ callbacks.
+
See the "Scheduling Cycle" section for a more detailed description of how
a freshly woken up task gets on a CPU.

diff --git a/kernel/sched/ext/ext.c b/kernel/sched/ext/ext.c
index 95aca029a6e57..c6720e5c78dad 100644
--- a/kernel/sched/ext/ext.c
+++ b/kernel/sched/ext/ext.c
@@ -1327,20 +1327,27 @@ static void apply_task_slice_oob(struct rq *rq, struct task_struct *p)

static void update_curr_scx(struct rq *rq)
{
- struct task_struct *curr = rq->curr;
+ struct task_struct *donor;
s64 delta_exec;

+ /*
+ * update_curr_scx() is selected through rq->donor->sched_class, not
+ * rq->curr->sched_class, so @donor is always an EXT task here. If an EXT
+ * owner executes for a FAIR donor, FAIR's update_curr() runs instead.
+ */
+ donor = rq->donor;
+
/* apply even on 0 delta_exec, callers may still act on the slice */
- apply_task_slice_oob(rq, curr);
+ apply_task_slice_oob(rq, donor);

delta_exec = update_curr_common(rq);
if (unlikely(delta_exec <= 0))
return;

- if (curr->scx.slice != SCX_SLICE_INF) {
- curr->scx.slice -= min_t(u64, curr->scx.slice, delta_exec);
- if (!curr->scx.slice)
- touch_core_sched(rq, curr);
+ if (donor->scx.slice != SCX_SLICE_INF) {
+ donor->scx.slice -= min_t(u64, donor->scx.slice, delta_exec);
+ if (!donor->scx.slice)
+ touch_core_sched(rq, donor);
}

dl_server_update(&rq->ext_server, delta_exec);
@@ -1516,9 +1523,9 @@ static void rq_owned_post_enq(struct scx_sched *sch, struct rq *rq,
if (rq->scx.flags & SCX_RQ_IN_BALANCE)
return;

- if ((enq_flags & SCX_ENQ_PREEMPT) && p != rq->curr &&
- rq->curr->sched_class == &ext_sched_class) {
- set_task_slice(rq->curr, 0);
+ if ((enq_flags & SCX_ENQ_PREEMPT) && p != rq->donor &&
+ rq->donor->sched_class == &ext_sched_class) {
+ set_task_slice(rq->donor, 0);
resched_curr(rq);
}
}
@@ -2061,13 +2068,14 @@ static void enqueue_task_scx(struct rq *rq, struct task_struct *p, int core_enq_
rq->scx.flags |= SCX_RQ_IN_WAKEUP;

/*
- * Restoring a running task will be immediately followed by
- * set_next_task_scx() which expects the task to not be on the BPF
+ * Restoring the current scheduling context will be immediately followed
+ * by set_next_task_scx() which expects the task to not be on the BPF
* scheduler as tasks can only start running through local DSQs. Force
* direct-dispatch into the local DSQ by setting the sticky_cpu. Mark
* IGNORE_CAPS to force entry into the local DSQ.
*/
- if (unlikely(enq_flags & ENQUEUE_RESTORE) && task_current(rq, p)) {
+ if (unlikely(enq_flags & ENQUEUE_RESTORE) &&
+ task_current_donor(rq, p)) {
sticky_cpu = cpu_of(rq);
enq_flags |= SCX_ENQ_IGNORE_CAPS;
}
@@ -2783,7 +2791,8 @@ static void dispatch_to_local_dsq(struct scx_sched *sch, struct rq *rq,
}

/* if the destination CPU is idle, wake it up */
- if (!fallback && sched_class_above(p->sched_class, dst_rq->curr->sched_class))
+ if (!fallback && sched_class_above(p->sched_class,
+ dst_rq->donor->sched_class))
resched_curr(dst_rq);
}

@@ -3007,6 +3016,8 @@ static void scx_start_task_running(struct rq *rq, struct task_struct *p)

static void set_next_task_scx(struct rq *rq, struct task_struct *p, bool first)
{
+ bool can_stop_tick;
+
if (p->scx.flags & SCX_TASK_QUEUED) {
/*
* Core-sched might decide to execute @p before it is
@@ -3031,6 +3042,7 @@ static void set_next_task_scx(struct rq *rq, struct task_struct *p, bool first)

/* apply any pending out-of-band slice request before the tick decision */
apply_task_slice_oob(rq, p);
+ can_stop_tick = p->scx.slice == SCX_SLICE_INF && !p->is_blocked;

/*
* @p is getting newly scheduled or got kicked after someone updated its
@@ -3041,7 +3053,7 @@ static void set_next_task_scx(struct rq *rq, struct task_struct *p, bool first)
* nohz. In the future, we might want to add a mechanism to update
* load_avgs periodically on tick-stopped CPUs.
*/
- if (p->scx.slice == SCX_SLICE_INF) {
+ if (can_stop_tick) {
if (!(rq->scx.flags & SCX_RQ_CAN_STOP_TICK)) {
/*
* Bypass mode always assigns finite slices, so @p
@@ -3062,7 +3074,8 @@ static void set_next_task_scx(struct rq *rq, struct task_struct *p, bool first)

/*
* @rq still references the outgoing scheduling context. A finite
- * slice is sufficient by itself to require the tick.
+ * slice or a blocked proxy donor is sufficient by itself to require
+ * the tick.
*/
if (tick_nohz_full_cpu(cpu_of(rq)))
tick_nohz_dep_set_cpu(cpu_of(rq), TICK_DEP_BIT_SCHED);
@@ -3251,7 +3264,7 @@ static struct task_struct *first_local_task(struct rq *rq)
static struct task_struct *
do_pick_task_scx(struct rq *rq, struct rq_flags *rf, bool force_scx)
{
- struct task_struct *prev = rq->curr;
+ struct task_struct *prev = rq->donor;
bool keep_prev;
struct task_struct *p;

@@ -3650,9 +3663,9 @@ void scx_tick(struct rq *rq)
update_other_load_avgs(rq);
}

-static void task_tick_scx(struct rq *rq, struct task_struct *curr, int queued)
+static void task_tick_scx(struct rq *rq, struct task_struct *donor, int queued)
{
- struct scx_sched *sch = scx_task_sched(curr);
+ struct scx_sched *sch = scx_task_sched(donor);

update_curr_scx(rq);

@@ -3661,13 +3674,13 @@ static void task_tick_scx(struct rq *rq, struct task_struct *curr, int queued)
* we can't trust the slice management or ops.core_sched_before().
*/
if (scx_bypassing(sch, cpu_of(rq))) {
- set_task_slice(curr, 0);
- touch_core_sched(rq, curr);
+ set_task_slice(donor, 0);
+ touch_core_sched(rq, donor);
} else if (SCX_HAS_OP(sch, tick)) {
- SCX_CALL_OP_TASK(sch, tick, rq, curr);
+ SCX_CALL_OP_TASK(sch, tick, rq, donor);
}

- if (!curr->scx.slice)
+ if (!donor->scx.slice)
resched_curr(rq);
}

@@ -4305,16 +4318,16 @@ static u32 reenq_local(struct scx_sched *sch, struct rq *rq, u64 reenq_flags)
}

/*
- * The revoke that scheduled this scan may have raced the pick: curr
+ * The revoke that scheduled this scan may have raced the pick: donor
* may be a now-capless task, either one that kept running or one
* promoted off the local DSQ between the ecaps sync and this scan.
* Zero the slice to evict it. The enqueue gate blocks new capless
* inserts, so no later pick can slip through after the scan.
*/
if ((reenq_flags & SCX_REENQ_CAP_REVOKE) &&
- rq->curr->sched_class == &ext_sched_class &&
- scx_task_reenq_on_cap_revoke(rq, rq->curr)) {
- set_task_slice(rq->curr, 0);
+ rq->donor->sched_class == &ext_sched_class &&
+ scx_task_reenq_on_cap_revoke(rq, rq->donor)) {
+ set_task_slice(rq->donor, 0);
resched_curr(rq);
}

@@ -4560,14 +4573,18 @@ static void run_deferred(struct rq *rq)
#ifdef CONFIG_NO_HZ_FULL
bool scx_can_stop_tick(struct rq *rq)
{
- struct task_struct *p = rq->curr;
+ struct task_struct *p = rq->donor;
struct scx_sched *sch = scx_task_sched(p);

+ /* The remote tick path assumes that proxy execution is not active. */
+ if (rq->curr != rq->donor)
+ return false;
+
if (p->sched_class != &ext_sched_class)
return true;

/*
- * @rq->curr may still reference an outgoing EXT task after it has been
+ * @rq->donor may still reference an outgoing EXT task after it has been
* dequeued. If no EXT tasks are accounted on @rq, ignore its stale
* slice state. If another task is dispatched from a DSQ,
* set_next_task_scx() will update the dependency for the incoming task.
@@ -4581,7 +4598,8 @@ bool scx_can_stop_tick(struct rq *rq)
/*
* @rq can dispatch from different DSQs, so we can't tell whether it
* needs the tick or not by looking at nr_running. Allow stopping ticks
- * iff the BPF scheduler indicated so. See set_next_task_scx().
+ * iff set_next_task_scx() determined that the selected scheduling context
+ * can run tickless.
*/
return rq->scx.flags & SCX_RQ_CAN_STOP_TICK;
}
@@ -6775,6 +6793,9 @@ static void scx_dump_cpu(struct scx_sched *sch, struct seq_buf *s,
dump_line(&ns, " curr=%s[%d] class=%ps",
rq->curr->comm, rq->curr->pid,
rq->curr->sched_class);
+ dump_line(&ns, " donor=%s[%d] class=%ps",
+ rq->donor->comm, rq->donor->pid,
+ rq->donor->sched_class);
if (!cpumask_empty(pcpu->cpus_to_kick))
dump_line(&ns, " cpus_to_kick : %*pb",
cpumask_pr_args(pcpu->cpus_to_kick));
@@ -6818,6 +6839,10 @@ static void scx_dump_cpu(struct scx_sched *sch, struct seq_buf *s,
if (rq->curr->sched_class == &ext_sched_class &&
(dump_all_tasks || scx_task_on_sched(sch, rq->curr)))
scx_dump_task(sch, s, dctx, rq, rq->curr, '*');
+ if (rq->donor != rq->curr &&
+ rq->donor->sched_class == &ext_sched_class &&
+ (dump_all_tasks || scx_task_on_sched(sch, rq->donor)))
+ scx_dump_task(sch, s, dctx, rq, rq->donor, ' ');

list_for_each_entry(p, &rq->scx.runnable_list, scx.runnable_node)
if (dump_all_tasks || scx_task_on_sched(sch, p))
@@ -8331,7 +8356,7 @@ static bool kick_one_cpu(s32 cpu, struct scx_sched_pcpu *pcpu, struct rq *this_r
unsigned long flags;

raw_spin_rq_lock_irqsave(rq, flags);
- cur_class = rq->curr->sched_class;
+ cur_class = rq->donor->sched_class;

/*
* During CPU hotplug, a CPU may depend on kicking itself to make
@@ -8348,7 +8373,7 @@ static bool kick_one_cpu(s32 cpu, struct scx_sched_pcpu *pcpu, struct rq *this_r
if (cur_class == &ext_sched_class) {
if (likely(!scx_missing_caps(pcpu->sch, cpu,
scx_caps_for_preempt(pcpu->sch, rq))))
- set_task_slice(rq->curr, 0);
+ set_task_slice(rq->donor, 0);
else
__scx_add_event(pcpu->sch,
SCX_EV_SUB_PREEMPT_DENIED, 1);
@@ -9317,13 +9342,15 @@ __bpf_kfunc bool scx_bpf_task_set_slice(struct task_struct *p, u64 slice,
return false;

/*
- * Directly write only when we hold the lock of the rq @p is queued or
- * running on. See the slice write rules above.
+ * Directly write only when we hold the lock of the rq @p is queued on or
+ * provides the current scheduling context for. Under proxy execution,
+ * rq->donor owns and consumes the slice while rq->curr executes on its
+ * behalf. See the slice write rules above.
*/
locked_rq = scx_locked_rq();
if (!locked_rq ||
(READ_ONCE(p->scx.runnable_cpu) != cpu_of(locked_rq) &&
- !task_current(locked_rq, p))) {
+ !task_current_donor(locked_rq, p))) {
set_task_slice_oob(sch, p, slice);
return true;
}
@@ -10160,12 +10187,17 @@ __bpf_kfunc void scx_bpf_put_cpumask(const struct cpumask *cpumask)
}

/**
- * scx_bpf_task_running - Is task currently running?
+ * scx_bpf_task_running - Is task the current scheduling context?
* @p: task of interest
+ *
+ * Under proxy execution, this reports the donor rather than the task whose
+ * code is physically executing. The physical execution context is intentionally
+ * not exposed to the BPF scheduler, which continues to observe the donor as the
+ * running scheduling context.
*/
__bpf_kfunc bool scx_bpf_task_running(const struct task_struct *p)
{
- return task_rq(p)->curr == p;
+ return rcu_access_pointer(task_rq(p)->donor) == p;
}

/**
@@ -10226,10 +10258,15 @@ __bpf_kfunc struct rq *scx_bpf_locked_rq(const struct bpf_prog_aux *aux)
}

/**
- * scx_bpf_cpu_curr - Return remote CPU's curr task
+ * scx_bpf_cpu_curr - Return remote CPU's current scheduling context
* @cpu: CPU of interest
* @aux: implicit BPF argument to access bpf_prog_aux hidden from BPF progs
*
+ * Under proxy execution, this returns the donor, which supplies the scheduling
+ * policy and runtime budget, rather than the task whose code is physically
+ * executing. The physical execution context is intentionally not exposed to
+ * the BPF scheduler.
+ *
* Callers must hold RCU read lock (KF_RCU).
*/
__bpf_kfunc struct task_struct *scx_bpf_cpu_curr(s32 cpu, const struct bpf_prog_aux *aux)
@@ -10245,7 +10282,7 @@ __bpf_kfunc struct task_struct *scx_bpf_cpu_curr(s32 cpu, const struct bpf_prog_
if (!scx_cpu_valid(sch, cpu, NULL))
return NULL;

- return rcu_dereference(cpu_rq(cpu)->curr);
+ return rcu_dereference(cpu_rq(cpu)->donor);
}

/**
@@ -10269,7 +10306,7 @@ __bpf_kfunc struct task_struct *scx_bpf_cid_curr(s32 cid, const struct bpf_prog_
cpu = scx_cid_to_cpu(sch, cid);
if (cpu < 0)
return NULL;
- return rcu_dereference(cpu_rq(cpu)->curr);
+ return rcu_dereference(cpu_rq(cpu)->donor);
}

/**
diff --git a/kernel/sched/ext/sub.h b/kernel/sched/ext/sub.h
index 08d46b92633a6..e2e3c2f52a146 100644
--- a/kernel/sched/ext/sub.h
+++ b/kernel/sched/ext/sub.h
@@ -139,14 +139,14 @@ static inline u64 scx_caps_for_task(struct task_struct *p)
return SCX_CAP_ENQ;
}

-/* the cap @sch needs to preempt @rq's current task, 0 if none */
+/* the cap @sch needs to preempt @rq's current scheduling context, 0 if none */
static inline u64 scx_caps_for_preempt(struct scx_sched *sch, struct rq *rq)
{
- struct task_struct *curr = rq->curr;
+ struct task_struct *donor = rq->donor;

/* a non-ext task can't be preempted by ext, own-subtree needs no cap */
- if (curr->sched_class != &ext_sched_class ||
- scx_is_descendant(scx_task_sched(curr), sch))
+ if (donor->sched_class != &ext_sched_class ||
+ scx_is_descendant(scx_task_sched(donor), sch))
return 0;
return SCX_CAP_PREEMPT;
}
--
2.55.0