From nobody Mon Sep 28 17:49:53 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 32EB93246EC; Thu, 20 Aug 2026 09:10:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217007; cv=none; b=cwoNjwbZ6CI+6/vcQkpUlo3Q80qIG65jS88/4TGfrA549KZ+cblB26o5waKmu+vwmoBwq63nkhxUOovuBlkhoKwXlr3YfQAujS7ahnrOP2IEkV46t0p9gdpC/xqV0weRO1KKYy0C7WiNDgblwjUOQrwzksS7yaUcmBfW5jh2dDo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217007; c=relaxed/simple; bh=q8e2MRxMjbiPaZmyod88Bu6SfEUm1COwYqJ1wLmdlc8=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=Oj9wm/UOtxRmqQKQWmRIz8vWI8+lucnoWZFi84XFauP9FUIHRQFnvNmKjUpZ97ptKx1DvHS1Z2RrJ/NDX9UJOhPE9zBtXIjXbnrRjCpu9PQqZwpi8ZZyxY2B4ge4ZCGoor/3hAHu+oFRFVjXYfV/9lEbehj0P2zs78n2f+ncQQI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=Jm7PGbyO; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=QiGZpO5u; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="Jm7PGbyO"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="QiGZpO5u" Date: Thu, 20 Aug 2026 09:10:02 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1787217004; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=l4+o/KEPYBES1ZUxfHFeht/DtqenBgzOOH8gMyAeSC0=; b=Jm7PGbyO1nQ4TQvW/4uuxRqRFoEaLLlONibPEQ89RcVaHgPGSzoKyRC+uLUE6fq8Mok0Be NwlhsF0d8UNMkzH9ffoIIIj3/gFyNgmvllKcli459FQ6uTF7Os2hZcZqmzboZXVFPzKv+h UeE1IEnl+86SjzUOHEAgSjyufwzet1q56hAea4I9Xz+9I0+1FVItueAQ8zSE131Bk9VE/X AVBroi/O2iOdGwkq9xYRjvkQJIh0NWIRj4gHvT4WxCC/o+2Yg5nIeM1rnrXdjr//mU8cfL RXd4pVcMdC7SHHieI8/UzjjhwanAPeA7EPvgsuUI13FVZrRDgaqekad/3e1VTQ== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1787217004; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=l4+o/KEPYBES1ZUxfHFeht/DtqenBgzOOH8gMyAeSC0=; b=QiGZpO5uhrbZ1s2EIjX6DkTO+gO2Fbmd4cXoatJsuPPF70B0NloORPVsnc7T9GgUshlk21 D8u0V137cU6qOPDA== From: "tip-bot2 for Jake Steinman" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: sched/urgent] sched/fair: Floor tg_cpus() at 1 Cc: Jake Steinman , "Peter Zijlstra (Intel)" , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260819132104.2148918-1-j@metarealtyinc.ca> References: <20260819132104.2148918-1-j@metarealtyinc.ca> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178721700284.1542179.13109595241014970942.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the sched/urgent branch of tip: Commit-ID: 23906f3a1686c737bf356fdd21183b40722b2437 Gitweb: https://git.kernel.org/tip/23906f3a1686c737bf356fdd21183b407= 22b2437 Author: Jake Steinman AuthorDate: Wed, 19 Aug 2026 09:20:59 -04:00 Committer: Peter Zijlstra CommitterDate: Thu, 20 Aug 2026 11:01:34 +02:00 sched/fair: Floor tg_cpus() at 1 tg_cpus() returns cpuset_num_cpus() unfloored, while its sibling tg_tasks() already floors its result at 1. calc_concur_shares() feeds nr =3D min(tg_tasks(tg), tg_cpus(tg)) into __calc_smp_shares() as shares_max, so an nr of 0 makes shares_max 0. __calc_smp_shares() ends with return clamp_t(long, shares, MIN_SHARES, shares_max); and clamp() yields hi when hi < lo, so a zero shares_max silently defeats the MIN_SHARES floor and returns 0 -- the exact case the comment above that line says must return MIN_SHARES instead of 0. That leaves a group sched_entity with load.weight =3D=3D 0, and __calc_prop_weight() then divides by cfs_rq->load.weight: weight *=3D se->load.weight; if (parent_entity(se)) weight /=3D cfs_rq->load.weight; which takes a #DE inside enqueue_task_fair(): Oops: divide error: 0000 [#1] SMP NOPTI RIP: 0010:enqueue_task_fair+0x422/0x950 Call Trace: enqueue_task+0x8e/0x250 wake_up_new_task+0x148/0x2e0 kernel_clone+0x1c6/0x390 __x64_sys_clone+0xcc/0x100 do_syscall_64+0x147/0x3c0 This is not survivable in practice: with panic_on_oops=3D0 the kernel took the first #DE and continued for 476 ms, then faulted at the same RIP with identical register state and an identical RSP, because the oops recovery path (kill task -> schedule()) re-enters the same enqueue while the rq lock is held mid-enqueue. The second fault escalates to a panic. Flooring tg_cpus() at 1 makes it symmetric with tg_tasks() and keeps shares_max >=3D tg_shares, so the MIN_SHARES floor in __calc_smp_shares() can no longer be bypassed. Note this only removes the division hazard. Whether cpuset_num_cpus() can legitimately return 0 -- via the cpu hotplug/suspend path where a v2 cpuset may transiently become empty, or via an RCU race -- is a separate question still open on the report thread. Fixes: 90ac22ffef48 ("sched/fair: Add cgroup_mode: max") Signed-off-by: Jake Steinman Signed-off-by: Peter Zijlstra (Intel) Link: https://lore.kernel.org/all/20260818231333.1441757-1-j@metarealtyinc.= ca/ Link: https://patch.msgid.link/20260819132104.2148918-1-j@metarealtyinc.ca --- kernel/sched/fair.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c index 0011401..6d881e5 100644 --- a/kernel/sched/fair.c +++ b/kernel/sched/fair.c @@ -4934,7 +4934,12 @@ static int tg_cpus(struct task_group *tg) nr =3D cpuset_num_cpus(cgrp); } =20 - return nr; + /* + * An empty cpuset would propagate a 0 shares_max into + * __calc_smp_shares(), where clamp() yields hi when hi < lo and so + * defeats the MIN_SHARES floor. Match tg_tasks(), which floors at 1. + */ + return max(nr, 1); } =20 static inline int tg_tasks(struct task_group *tg)