From nobody Thu Apr 9 15:03:40 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3DDFA37C0F8 for ; Mon, 2 Mar 2026 10:01:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772445697; cv=none; b=i9l+Zic+IhmAW2gDmJOk2p34J+CHQ6sdvmsgoXnRVRec5XDGZ/fLLPZxPEkM2HLhOl2RNZzOEzDI4zo1WjaVmQ+IUKyxEVC/cfnJIsKZdD7Q8z5w5ilO81uIcq/jUAqUrXrPzS7eJkrfpBAn+YIcuObLQSWjyUBFYeBnjIU5fk8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772445697; c=relaxed/simple; bh=4YHKfiBndz+zr8akYW0BE+cIA6SSuAkNMRrX8yKrChc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=ZbDzDo2y1pGEQYX52+LTnNC21lONFxUBy5tjju1qMp4vfgNbEbsDCq69bRvi9+A+mvRd8dptUvsY2hH3SEYE2+dqscxqA0BRZRBnHOu57e5+2fq6G2Fxqy/4FbOolzABcWPjwfvnLpXaygo4DXAYEb4zA5WBiCRANfobB/bsyJ4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Bl8WChbB; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Bl8WChbB" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1772445695; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=7RjcWX5IcfMtsts/i6JAdveOm0Inve92TcsWXJmDr8c=; b=Bl8WChbBB7DD96dwED7EqWegclTDzDAbhSRCqUmqZ9iOikXUl0r+bITSY3AxWb1b1NU3CS OplEzLlmuytuyaL57k7ifV5r76GVLyWJbLIb9JGaSr+jMyDHlb7kwdy2D63jJRxFk4ybj3 aJInq77Sb7O6yODEDp1O4L2Fy9ADxos= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-327-lwoBV5ZjOHa6IcCTQlLz7g-1; Mon, 02 Mar 2026 05:01:26 -0500 X-MC-Unique: lwoBV5ZjOHa6IcCTQlLz7g-1 X-Mimecast-MFC-AGG-ID: lwoBV5ZjOHa6IcCTQlLz7g_1772445685 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3164A18004AD; Mon, 2 Mar 2026 10:01:24 +0000 (UTC) Received: from jlelli-thinkpadt14gen4.remote.csb (unknown [10.45.224.78]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3457819560A7; Mon, 2 Mar 2026 10:01:19 +0000 (UTC) From: Juri Lelli Date: Mon, 02 Mar 2026 11:01:00 +0100 Subject: [PATCH v2] sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260302-upstream-fix-deadline-piboost-b4-v2-1-0c92b737f13c@redhat.com> X-B4-Tracking: v=1; b=H4sIAAAAAAAC/4WOyw6CMBBFf4V07ZhSy8uV/2FY9DHKGKGkLURD+ HcLxrWZ1UlO7pmFBfSEgZ2zhXmcKZAbEohDxkynhjsC2cRMcFFywQuYxhA9qh5u9AKLyj5pQBh JOxciaAnCNkJqzKu8FizNjB6Tuieu7ZfDpB9o4ra7GR2F6Px7/2HON++XK//n5hzSSS5PRVnpu jEXj7ZT8Whcz9p1XT9E24o24wAAAA== X-Change-ID: 20260205-upstream-fix-deadline-piboost-b4-2d924be17182 To: Ingo Molnar , Peter Zijlstra , Vincent Guittot , Dietmar Eggemann , Steven Rostedt , Ben Segall , Mel Gorman , Valentin Schneider Cc: Philip Auld , Gabriele Monaco , linux-kernel@vger.kernel.org, Bruno Goncalves , Juri Lelli X-Developer-Signature: v=1; a=ed25519-sha256; t=1772445679; l=5047; i=juri.lelli@redhat.com; s=20250626; h=from:subject:message-id; bh=4YHKfiBndz+zr8akYW0BE+cIA6SSuAkNMRrX8yKrChc=; b=+/XrrgLOLznz4VP09RE9IdCJAs8wSJAp90KFhFOg/5wvbvqSbgNTHnco31h+PYM4HzHy65h9o YiFsSWEe38LARN5JFXDveGEPL1wH9DSQM+kV4eoBeMehNQG1KRqgXnb X-Developer-Key: i=juri.lelli@redhat.com; a=ed25519; pk=kSwf88oiY/PYrNMRL/tjuBPiSGzc+U3bD13Zag6wO5Q= X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Running stress-ng --schedpolicy 0 on an RT kernel on a big machine might lead to the following WARNINGs (edited). sched: DL de-boosted task PID 22725: REPLENISH flag missing WARNING: CPU: 93 PID: 0 at kernel/sched/deadline.c:239 dequeue_task_dl+0x1= 5c/0x1f8 ... (running_bw underflow) Call trace: dequeue_task_dl+0x15c/0x1f8 (P) dequeue_task+0x80/0x168 deactivate_task+0x24/0x50 push_dl_task+0x264/0x2e0 dl_task_timer+0x1b0/0x228 __hrtimer_run_queues+0x188/0x378 hrtimer_interrupt+0xfc/0x260 arch_timer_handler_phys+0x34/0x60 handle_percpu_devid_irq+0xa4/0x230 generic_handle_domain_irq+0x34/0x60 __gic_handle_irq_from_irqson.isra.0+0x158/0x298 gic_handle_irq+0x28/0x80 call_on_irq_stack+0x30/0x48 do_interrupt_handler+0xdc/0xe8 el1_interrupt+0x44/0xc0 el1h_64_irq_handler+0x18/0x28 el1h_64_irq+0x80/0x88 cpuidle_enter_state+0xc4/0x520 (P) cpuidle_enter+0x40/0x60 cpuidle_idle_call+0x13c/0x220 do_idle+0xa4/0x120 cpu_startup_entry+0x40/0x50 secondary_start_kernel+0xe4/0x128 __secondary_switched+0xc0/0xc8 The problem is that when a SCHED_DEADLINE task (lock holder) is changed to a lower priority class via sched_setscheduler(), it may fail to properly inherit the parameters of potential DEADLINE donors if it didn't already inherit them in the past (shorter deadline than donor's at that time). This might lead to bandwidth accounting corruption, as enqueue_task_dl() won't recognize the lock holder as boosted. The scenario occurs when: 1. A DEADLINE task (donor) blocks on a PI mutex held by another DEADLINE task (holder), but the holder doesn't inherit parameters (e.g., it already has a shorter deadline) 2. sched_setscheduler() changes the holder from DEADLINE to a lower class while still holding the mutex 3. The holder should now inherit DEADLINE parameters from the donor and be enqueued with ENQUEUE_REPLENISH, but this doesn't happen Fix the issue by introducing __setscheduler_dl_pi(), which detects when a DEADLINE (proper or boosted) task gets setscheduled to a lower priority class. In case, the function makes the task inherit DEADLINE parameters of the donoer (pi_se) and sets ENQUEUE_REPLENISH flag to ensure proper bandwidth accounting during the next enqueue operation. Reported-by: Bruno Goncalves Signed-off-by: Juri Lelli --- Hello, v2 of the fix for the issue described in the changelog. The issue was discovered by Bruno Goncalves while running stress-ng --schedpolicy 0 on RT kernels on large systems (I believe lots of CPUs and PI enabled in-kernel mutexes makes it easier to trigger). Later on a simpler and more focused reproducer was created (with Claude Code help) and is available at https://github.com/jlelli/sched-deadline-tests/blob/master/test_dl_replenis= h_bug.c Fix also available from git@github.com:jlelli/linux.git fix-deadline-piboost-v2 --- Changes in v2: - Rebased to tip/sched/core as of today - Fix things inside !KEEP_PARAMS (Peter) - Create a different helper function - Link to v1: https://patch.msgid.link/20260206-upstream-fix-deadline-piboo= st-b4-v1-1-14043567b89c@redhat.com --- kernel/sched/syscalls.c | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/kernel/sched/syscalls.c b/kernel/sched/syscalls.c index a288ac0a633d7..b215b0ead9a60 100644 --- a/kernel/sched/syscalls.c +++ b/kernel/sched/syscalls.c @@ -284,6 +284,35 @@ static bool check_same_owner(struct task_struct *p) uid_eq(cred->euid, pcred->uid)); } =20 +#ifdef CONFIG_RT_MUTEXES +static inline void __setscheduler_dl_pi(int newprio, int policy, + struct task_struct *p, + struct sched_change_ctx *scope) +{ + /* + * In case a DEADLINE task (either proper or boosted) gets + * setscheduled to a lower priority class, check if it neeeds to + * inherit parameters from a potential pi_task. In that case make + * sure replenishment happens with the next enqueue. + */ + + if (dl_prio(newprio) && !dl_policy(policy)) { + struct task_struct *pi_task =3D rt_mutex_get_top_task(p); + + if (pi_task) { + p->dl.pi_se =3D pi_task->dl.pi_se; + scope->flags |=3D ENQUEUE_REPLENISH; + } + } +} +#else /* !CONFIG_RT_MUTEXES */ +static inline void __setscheduler_dl_pi(int newprio, int policy, + struct task_struct *p, + struct sched_change_ctx *scope) +{ +} +#endif /* !CONFIG_RT_MUTEXES */ + #ifdef CONFIG_UCLAMP_TASK =20 static int uclamp_validate(struct task_struct *p, @@ -655,6 +684,7 @@ int __sched_setscheduler(struct task_struct *p, __setscheduler_params(p, attr); p->sched_class =3D next_class; p->prio =3D newprio; + __setscheduler_dl_pi(newprio, policy, p, scope); } __setscheduler_uclamp(p, attr); =20 --- base-commit: 2e7af192697ef2a71c76fd57860b0fcd02754e14 change-id: 20260205-upstream-fix-deadline-piboost-b4-2d924be17182 Best regards, -- =20 Juri Lelli