From nobody Mon Jun 8 04:19:35 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BC48A2045AD for ; Tue, 2 Jun 2026 02:32:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367545; cv=none; b=PQ9cmuoIePy3rOx+7FIpNpVGON9s0i2Saj1+HqG1R3am8ZZUH5gzHLWRYr9enb2c637P0wKfIvERf4sULe6Mv0q5wRX3Hwwe+XMfuZ2hCYINBVzcIwqjJTH4YvItLbYEVaHViqhEEYDIBeYv7QT69LqksGqtW6+F4WFXYowzEPE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367545; c=relaxed/simple; bh=XBAJxyZqUX0ALETEDD0MgcI+6Bp7AfBfOWB4lGG4Oko=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FTvkQqmihVAxGOw85bbpNqUFDjkBqqk5BPN50vFfDfZaOlmz+SGm2Zqn6hgQ5Xxh2adWie35YgTp6yY7plfS0sHqIj9QzYYwuJvgEBAoAXalJ6A0+nBbrvZB2JmVL2M8ATJco3lDuA4gmDhtWiYKq+CsVPhxZqYYgp5Rsy6srnE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Cq8DDmSZ; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Cq8DDmSZ" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780367543; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=z1m/cWlSGK8FWpAi8JBVhmx5QFYxTp9JmxVDregWSNs=; b=Cq8DDmSZvFOc7TUgBMfwhNxWNu1mEphvU0SpsTyKinAAZjoI+3tcwcbId5gZNU0GJGY+Kw kpKtF5mmJ/FDNL31bnMRuVWXk5Iqok+RZEFAI/O0R10KctV1bP7AaQD0FWMl1m+AoMj9e6 +YGU/QwU6AfgtfWEJSvRm3IsYBJDrYo= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-499-guPd016aN2CimhZFjAg3jw-1; Mon, 01 Jun 2026 22:32:18 -0400 X-MC-Unique: guPd016aN2CimhZFjAg3jw-1 X-Mimecast-MFC-AGG-ID: guPd016aN2CimhZFjAg3jw_1780367537 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B34E8195608B; Tue, 2 Jun 2026 02:32:16 +0000 (UTC) Received: from llong-thinkpadp16vgen1.westford.csb (unknown [10.22.88.124]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 70BCE19560A6; Tue, 2 Jun 2026 02:32:14 +0000 (UTC) From: Waiman Long To: Chen Ridong , Tejun Heo , Johannes Weiner , =?UTF-8?q?Michal=20Koutn=C3=BD?= , Peter Zijlstra Cc: cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Aaron Tomlin , Guopeng Zhang , Waiman Long Subject: [PATCH-next v5 1/6] cgroup/cpuset: Fix node inconsistencies between cpuset_update_tasks_nodemask() and cpuset_attach() Date: Mon, 1 Jun 2026 22:31:58 -0400 Message-ID: <20260602023203.248077-2-longman@redhat.com> In-Reply-To: <20260602023203.248077-1-longman@redhat.com> References: <20260602023203.248077-1-longman@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" Whenever memory node mask is changed, there are 4 places where the node mask has to be updated or used. 1) task's node mask via cpuset_change_task_nodemask() 2) memory policy binding via mpol_rebind_mm() 3) if memory migration is enabled, migrate from old_mems_allowed to the new node mask via cpuset_migrate_mm(). 4) setting old_mems_allowed These memory actions are done in cpuset_update_tasks_nodemask() and cpuset_attach(). However there are inconsistencies in what node masks are being used in these 2 functions. In cpuset_update_tasks_nodemask(), - cpuset_change_task_nodemask(): guarantee_online_mems() - mpol_rebind_mm(): mems_allowed - cpuset_migrate_mm(): guarantee_online_mems() - old_mems_allowed: guarantee_online_mems() In cpuset_attach(), - cpuset_change_task_nodemask(): guarantee_online_mems() - mpol_rebind_mm(): effective_mems - cpuset_migrate_mm(): effective_mems - old_mems_allowed: effective_mems These inconsistencies dates back to quite a long time ago and it is hard to say what should be the correct values. The guarantee_online_mems() function returns a node mask from current or an ancestor cpuset that is a subset of node_states[N_MEMORY]. Nodes in node_states[N_MEMORY] are all online, i.e. in node_states[N_ONLINE]. However, node in node_states[N_ONLINE] may not have memory. So node_states[N_MEMORY] should be a subset of node_states[N_ONLINE]. The guarantee_online_mems() function should only be useful for v1 where mems_allowed is the same as effective_mems. With v2, the memory nodes in effective_mems should always be a subset of node_states[N_MEMORY]. The only time that may not be true is when a memory hot-unplug operation is in progress and a memory node is removed from node_states[N_MEMORY] but not yet reflected in effective_mems as cpuset_handle_hotplug() has not yet been called from cpuset_track_online_nodes(). When cpuset_handle_hotplug() is called later, the memory node setting of the relevant cpusets and tasks will be updated. So replacing the guarantee_online_mems() call by just using cs->effective_mems should be fine. Let use the following setup for both of them and make them consistent. - cpuset_change_task_nodemask(): guarantee_online_mems() - mpol_rebind_mm(): effective_mems - cpuset_migrate_mm(): guarantee_online_mems() - old_mems_allowed: guarantee_online_mems() So for v2, it is effectively all effective_mems. For v1, mpol_rebind_mm() uses cpus_allowed which may differ from what guarantee_online_mems() returns. Signed-off-by: Waiman Long --- kernel/cgroup/cpuset.c | 32 +++++++++++++++++++++----------- 1 file changed, 21 insertions(+), 11 deletions(-) diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c index 6bdb68689c24..987456b6d879 100644 --- a/kernel/cgroup/cpuset.c +++ b/kernel/cgroup/cpuset.c @@ -2616,6 +2616,13 @@ static void *cpuset_being_rebound; * Iterate through each task of @cs updating its mems_allowed to the * effective cpuset's. As this function is called with cpuset_mutex held, * cpuset membership stays stable. + * + * - cpuset_change_task_nodemask(): guarantee_online_mems() + * - mpol_rebind_mm(): effective_mems + * - cpuset_migrate_mm(): guarantee_online_mems() + * - old_mems_allowed: guarantee_online_mems() + * + * For v2, guarantee_online_mems() should just return effective_mems. */ void cpuset_update_tasks_nodemask(struct cpuset *cs) { @@ -2625,7 +2632,10 @@ void cpuset_update_tasks_nodemask(struct cpuset *cs) =20 cpuset_being_rebound =3D cs; /* causes mpol_dup() rebind */ =20 - guarantee_online_mems(cs, &newmems); + if (cpuset_v2()) + newmems =3D cs->effective_mems; + else + guarantee_online_mems(cs, &newmems); =20 /* * The mpol_rebind_mm() call takes mmap_lock, which we couldn't @@ -2650,7 +2660,7 @@ void cpuset_update_tasks_nodemask(struct cpuset *cs) =20 migrate =3D is_memory_migrate(cs); =20 - mpol_rebind_mm(mm, &cs->mems_allowed); + mpol_rebind_mm(mm, &cs->effective_mems); if (migrate) cpuset_migrate_mm(mm, &cs->old_mems_allowed, &newmems); else @@ -3148,17 +3158,18 @@ static void cpuset_attach(struct cgroup_taskset *ts= et) =20 /* * In the default hierarchy, enabling cpuset in the child cgroups - * will trigger a number of cpuset_attach() calls with no change - * in effective cpus and mems. In that case, we can optimize out - * by skipping the task iteration and update. + * will trigger a cpuset_attach() call with no change in effective cpus + * and mems. In that case, we can optimize out by skipping the task + * iteration and update. */ - if (cpuset_v2() && !cpus_updated && !mems_updated) { + if (cpuset_v2()) { cpuset_attach_nodemask_to =3D cs->effective_mems; - goto out; + if (!cpus_updated && !mems_updated) + goto out; + } else { + guarantee_online_mems(cs, &cpuset_attach_nodemask_to); } =20 - guarantee_online_mems(cs, &cpuset_attach_nodemask_to); - cgroup_taskset_for_each(task, css, tset) cpuset_attach_task(cs, task); =20 @@ -3168,7 +3179,6 @@ static void cpuset_attach(struct cgroup_taskset *tset) * if there is no change in effective_mems and CS_MEMORY_MIGRATE is * not set. */ - cpuset_attach_nodemask_to =3D cs->effective_mems; if (!is_memory_migrate(cs) && !mems_updated) goto out; =20 @@ -3176,7 +3186,7 @@ static void cpuset_attach(struct cgroup_taskset *tset) struct mm_struct *mm =3D get_task_mm(leader); =20 if (mm) { - mpol_rebind_mm(mm, &cpuset_attach_nodemask_to); + mpol_rebind_mm(mm, &cs->effective_mems); =20 /* * old_mems_allowed is the same with mems_allowed --=20 2.54.0 From nobody Mon Jun 8 04:19:35 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D706A31F986 for ; Tue, 2 Jun 2026 02:32:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367544; cv=none; b=o/wyQJKEAWxPOtXz09gifT8CllvHTaiaVtyS49GpfEvIyBKNmAJ0/SqxRYqTLWWRZFs/O6+94D4MMZwHtHbF9HCZnmbUraywoszPQrlkjakyjjYx+2y0C/egJpXY8yL8NAaTkMPGFFPK73Gifuh/HPUpNITgTNT0zzl7hE+SQgk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367544; c=relaxed/simple; bh=hAt3Fzf5cLQ8BxuESPxh0KKL8HMll2ypRDyjViW/Mu4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=N2BEDrjxqRQLzb8etWLXbf4HZTaVeGlJzGEy6Ej3KHN3AMDyF4pAhUD5H9i/UeK59tM2pOwK3tUpiGwpzghzqzWY/et+AA73GPonLuw+TPWRTMfVhJhzCNGnRpePPGU6+1ZMOJvNFA8SnVn8luv7XUD5NSLEyycpqp0vxo59bw4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=HscuC5mG; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="HscuC5mG" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780367541; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=3y7nMyTu3kQkrJ6atXgJ7VISqjpf9waGjBxe8Iprw6o=; b=HscuC5mGLwqLwqdNF3DwWarLr/hQl0y0x4eGfrzkNDDq3ntOT1Zt1qRU9t64B5IWw8N8Y5 czXcAnWLOwpWbNUTbxqY9k7+i+c957GcxSBZZrhu+5mNr0P3igZUijqPEqeWH//VWRWSM/ 2L2zl9iroiPICzyipA3PlIYoZVOHoM0= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-393-UpY0cOtTPG-3CjsEDoimLQ-1; Mon, 01 Jun 2026 22:32:20 -0400 X-MC-Unique: UpY0cOtTPG-3CjsEDoimLQ-1 X-Mimecast-MFC-AGG-ID: UpY0cOtTPG-3CjsEDoimLQ_1780367539 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id ABDD31956052; Tue, 2 Jun 2026 02:32:18 +0000 (UTC) Received: from llong-thinkpadp16vgen1.westford.csb (unknown [10.22.88.124]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 2330B19560A3; Tue, 2 Jun 2026 02:32:16 +0000 (UTC) From: Waiman Long To: Chen Ridong , Tejun Heo , Johannes Weiner , =?UTF-8?q?Michal=20Koutn=C3=BD?= , Peter Zijlstra Cc: cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Aaron Tomlin , Guopeng Zhang , Waiman Long Subject: [PATCH-next v5 2/6] cgroup/cpuset: Add a cpuset_reserve_dl_bw() helper Date: Mon, 1 Jun 2026 22:31:59 -0400 Message-ID: <20260602023203.248077-3-longman@redhat.com> In-Reply-To: <20260602023203.248077-1-longman@redhat.com> References: <20260602023203.248077-1-longman@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" Extract the DL bandwidth allocation code in cpuset_attach() to a new cpuset_reserve_dl_bw() helper to simplify code. No functional change is expected. Signed-off-by: Waiman Long Reviewed-by: Ridong Chen --- kernel/cgroup/cpuset.c | 53 ++++++++++++++++++++++++------------------ 1 file changed, 30 insertions(+), 23 deletions(-) diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c index 987456b6d879..5c1f3ee48d5d 100644 --- a/kernel/cgroup/cpuset.c +++ b/kernel/cgroup/cpuset.c @@ -2991,6 +2991,25 @@ static int cpuset_can_attach_check(struct cpuset *cs) return 0; } =20 +static int cpuset_reserve_dl_bw(struct cpuset *cs) +{ + int cpu, ret; + + if (!cs->sum_migrate_dl_bw) + return 0; + + cpu =3D cpumask_any_and(cpu_active_mask, cs->effective_cpus); + if (unlikely(cpu >=3D nr_cpu_ids)) + return -EINVAL; + + ret =3D dl_bw_alloc(cpu, cs->sum_migrate_dl_bw); + if (ret) + return ret; + + cs->dl_bw_cpu =3D cpu; + return 0; +} + static void reset_migrate_dl_data(struct cpuset *cs) { cs->nr_migrate_dl_tasks =3D 0; @@ -3005,7 +3024,7 @@ static int cpuset_can_attach(struct cgroup_taskset *t= set) struct cpuset *cs, *oldcs; struct task_struct *task; bool setsched_check; - int cpu, ret; + int ret; =20 /* used later by cpuset_attach() */ cpuset_attach_old_cs =3D task_cs(cgroup_taskset_first(tset, &css)); @@ -3061,31 +3080,19 @@ static int cpuset_can_attach(struct cgroup_taskset = *tset) } } =20 - if (!cs->sum_migrate_dl_bw) - goto out_success; - - cpu =3D cpumask_any_and(cpu_active_mask, cs->effective_cpus); - if (unlikely(cpu >=3D nr_cpu_ids)) { - ret =3D -EINVAL; - goto out_unlock; - } - - ret =3D dl_bw_alloc(cpu, cs->sum_migrate_dl_bw); - if (ret) - goto out_unlock; - - cs->dl_bw_cpu =3D cpu; - -out_success: - /* - * Mark attach is in progress. This makes validate_change() fail - * changes which zero cpus/mems_allowed. - */ - cs->attach_in_progress++; + ret =3D cpuset_reserve_dl_bw(cs); =20 out_unlock: - if (ret) + if (ret) { reset_migrate_dl_data(cs); + } else { + /* + * Mark attach is in progress. This makes validate_change() fail + * changes which zero cpus/mems_allowed. + */ + cs->attach_in_progress++; + } + mutex_unlock(&cpuset_mutex); return ret; } --=20 2.54.0 From nobody Mon Jun 8 04:19:35 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 965F5367B90 for ; Tue, 2 Jun 2026 02:32:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367548; cv=none; b=tBA5tWcqAARwEWjSFL9/08jEl5wsyYe5h9aujZ1iWlecp/JEcE+1dHrUzjrQsPuydhryfjwtI2VhJ3O6OPsdN4eefqrD057/ylCPh3QL39XhC693bHabr3z/NJv7wuIZB9JDbaHP+7mwOprDpAmq09Q8O608Ei4VRW0tizMEv8E= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367548; c=relaxed/simple; bh=Ha+GLcoT+d9T71Kb0/2qK0ydN3RAS84T8DmJICgVA5c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dm/WnAmcekMA0B+mcI4Tbe5rApTfmDlYba7VsQm8axDSIgHkgXmVnP1dhGYlUFqEL6lcqsWN7BiJNTf8WIh4xqqOpJbH3dXp4FyMEOzutXj8LMMNOofL1QtAUif7+q8mgjL7aWaqJz7ubcZ7lMuUApv4loigprfel2RFbQ8Dxe4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=ORydZClM; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="ORydZClM" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780367545; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=xyGU4Uu7TBP3fnhGw8V6NIlxG+lhDxqP5/XKrDp/tpw=; b=ORydZClMf9m8FVaz9GTzKamALrb4QpRvA+W/B915dkSMj+YMpy2ptcoAHB+OJqUM/UIBV+ NJKRwa0hNnC69ldTeoruUMbnLbLGRdfc88HQ0wbvdXQWf3fckKdrCwf7vDISafdtnOs9+I KCgJvZJzT7VSQ3XMuuV3MoaskdMa1X0= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-638-RltBZh7YMdu_PuO0Pk34kw-1; Mon, 01 Jun 2026 22:32:22 -0400 X-MC-Unique: RltBZh7YMdu_PuO0Pk34kw-1 X-Mimecast-MFC-AGG-ID: RltBZh7YMdu_PuO0Pk34kw_1780367541 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B4050180034C; Tue, 2 Jun 2026 02:32:20 +0000 (UTC) Received: from llong-thinkpadp16vgen1.westford.csb (unknown [10.22.88.124]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E3AE319560A6; Tue, 2 Jun 2026 02:32:18 +0000 (UTC) From: Waiman Long To: Chen Ridong , Tejun Heo , Johannes Weiner , =?UTF-8?q?Michal=20Koutn=C3=BD?= , Peter Zijlstra Cc: cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Aaron Tomlin , Guopeng Zhang , Waiman Long Subject: [PATCH-next v5 3/6] cgroup/cpuset: Expand the scope of cpuset_can_attach_check() Date: Mon, 1 Jun 2026 22:32:00 -0400 Message-ID: <20260602023203.248077-4-longman@redhat.com> In-Reply-To: <20260602023203.248077-1-longman@redhat.com> References: <20260602023203.248077-1-longman@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" Expand the scope of cpuset_can_attach_check() by including the setting of setsched flag inside cpuset_can_attach_check() with the new @oldcs and @psetsched argument. As cpuset_can_attach_check() is also called from cpuset_can_fork(), set the new arguments to NULL from that caller. While at it, expose the source and destination cpuset cpu/memory check results in the new attach_cpus_updated and attach_mems_updated static flags so that these flags can be used directly from cpuset_attach() without the need to do the same computations again. Two new global attach related flags are added (attach_cpus_updated & attach_mems_updated) which are set to indicate that CPUs or memory nodes are updated. These 2 flags are set in cpuset_can_attach() and are used in cpuset_attach() for optimization. Since cpuset_mutex will be released between the 2 calls, it is possible that an intervening cpuset action may change the CPU or node mask of the relevant cpusets, so check is added to set these flags if the effective_cpus or effective_mems of those cpusets is changed. Signed-off-by: Waiman Long Reviewed-by: Ridong Chen --- kernel/cgroup/cpuset.c | 52 ++++++++++++++++++++++++------------------ 1 file changed, 30 insertions(+), 22 deletions(-) diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c index 5c1f3ee48d5d..5c777b1237a8 100644 --- a/kernel/cgroup/cpuset.c +++ b/kernel/cgroup/cpuset.c @@ -2982,12 +2982,39 @@ static struct cpuset *cpuset_attach_old_cs; * For v1, cpus_allowed and mems_allowed can't be empty. * For v2, effective_cpus can't be empty. * Note that in v1, effective_cpus =3D cpus_allowed. + * + * Also set the boolean flag passed in by @psetsched depending on if + * security_task_setscheduler() call is needed and @oldcs is not NULL. */ -static int cpuset_can_attach_check(struct cpuset *cs) +static int cpuset_can_attach_check(struct cpuset *cs, struct cpuset *oldcs, + bool *psetsched) { if (cpumask_empty(cs->effective_cpus) || (!is_in_v2_mode() && nodes_empty(cs->mems_allowed))) return -ENOSPC; + + if (!oldcs) + return 0; + + /* + * Skip rights over task setsched check in v2 when nothing changes, + * migration permission derives from hierarchy ownership in + * cgroup_procs_write_permission()). + */ + *psetsched =3D !cpuset_v2() || + !cpumask_equal(cs->effective_cpus, oldcs->effective_cpus) || + !nodes_equal(cs->effective_mems, oldcs->effective_mems); + + /* + * A v1 cpuset with tasks will have no CPU left only when CPU hotplug + * brings the last online CPU offline as users are not allowed to empty + * cpuset.cpus when there are active tasks inside. When that happens, + * we should allow tasks to migrate out without security check to make + * sure they will be able to run after migration. + */ + if (!is_in_v2_mode() && cpumask_empty(oldcs->effective_cpus)) + *psetsched =3D false; + return 0; } =20 @@ -3034,29 +3061,10 @@ static int cpuset_can_attach(struct cgroup_taskset = *tset) mutex_lock(&cpuset_mutex); =20 /* Check to see if task is allowed in the cpuset */ - ret =3D cpuset_can_attach_check(cs); + ret =3D cpuset_can_attach_check(cs, oldcs, &setsched_check); if (ret) goto out_unlock; =20 - /* - * Skip rights over task setsched check in v2 when nothing changes, - * migration permission derives from hierarchy ownership in - * cgroup_procs_write_permission()). - */ - setsched_check =3D !cpuset_v2() || - !cpumask_equal(cs->effective_cpus, oldcs->effective_cpus) || - !nodes_equal(cs->effective_mems, oldcs->effective_mems); - - /* - * A v1 cpuset with tasks will have no CPU left only when CPU hotplug - * brings the last online CPU offline as users are not allowed to empty - * cpuset.cpus when there are active tasks inside. When that happens, - * we should allow tasks to migrate out without security check to make - * sure they will be able to run after migration. - */ - if (!is_in_v2_mode() && cpumask_empty(oldcs->effective_cpus)) - setsched_check =3D false; - cgroup_taskset_for_each(task, css, tset) { ret =3D task_can_attach(task); if (ret) @@ -3601,7 +3609,7 @@ static int cpuset_can_fork(struct task_struct *task, = struct css_set *cset) mutex_lock(&cpuset_mutex); =20 /* Check to see if task is allowed in the cpuset */ - ret =3D cpuset_can_attach_check(cs); + ret =3D cpuset_can_attach_check(cs, NULL, NULL); if (ret) goto out_unlock; =20 --=20 2.54.0 From nobody Mon Jun 8 04:19:35 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 97C083655D1 for ; Tue, 2 Jun 2026 02:32:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367550; cv=none; b=FZ0h88WhvnC1gHncHFmu9imhK0YAgiN5ECb19hwxILf7Hu0K2d3F0NHK9BsdvAh1CGVONPU8mGri1xhR5Ko7MgxfeZnhR8HeX2MQtXpJ6bZ2gfm+BTj+cERkmoorxoc9M0tOWceoHRYguR/ypi+qX6bqlSJdaDCoK90mCm8TJsY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367550; c=relaxed/simple; bh=e0tF03sz0fkUMkvZhKDfyygUxl+jIyGjwPqmI6JduJw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Iqn/rtrdqkAp5SC5kiJvpM/L3OW8TaJQn1ZvxPSafnTKFKktlha8lC7r/BPD7MTQ5vcqylklIQyDb5U6/1pDYtZMnINltmNxAdEikirtDEj99Cv1zUzzjvlc2EpOprj1xhvIe+wGE5gecZRbYT3AopORzgdPr+H9SuTiQNGCOyM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=FkKiMRyq; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="FkKiMRyq" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780367548; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=P766uOaEzf7FaP4mrGt+IxDVIY80/uF6sL77FXvH+7k=; b=FkKiMRyqgu70fpw4bSvhKO+gCpqcNg/pQExE0dgsuPXUjwaje8750TgBF5KgM0PCG57lzT tw83jxCdq5M2vvXgtLnWvBoGyvuGmL48sNwcVVh9wL/FIVZimNMGpDADFdt41clG24yKmL 8rQg6yWCQodNiLJDXDWuphdx0ut3I7w= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-600-4bpSQxgyMESgmowRTR4PNg-1; Mon, 01 Jun 2026 22:32:24 -0400 X-MC-Unique: 4bpSQxgyMESgmowRTR4PNg-1 X-Mimecast-MFC-AGG-ID: 4bpSQxgyMESgmowRTR4PNg_1780367542 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C257F195608F; Tue, 2 Jun 2026 02:32:22 +0000 (UTC) Received: from llong-thinkpadp16vgen1.westford.csb (unknown [10.22.88.124]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id EB5E019560A7; Tue, 2 Jun 2026 02:32:20 +0000 (UTC) From: Waiman Long To: Chen Ridong , Tejun Heo , Johannes Weiner , =?UTF-8?q?Michal=20Koutn=C3=BD?= , Peter Zijlstra Cc: cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Aaron Tomlin , Guopeng Zhang , Waiman Long , Ridong Chen Subject: [PATCH-next v5 4/6] cgroup/cpuset: Make cpuset_attach_old_cs track task group leaders Date: Mon, 1 Jun 2026 22:32:01 -0400 Message-ID: <20260602023203.248077-5-longman@redhat.com> In-Reply-To: <20260602023203.248077-1-longman@redhat.com> References: <20260602023203.248077-1-longman@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" There are two possible ways that migration of tasks from multiple source cpusets to a target cpuset can happen. Either a multithread application with threads in different cpusets is wholely moved to a new cpuset or disabling of v2 cpuset controller will move all the tasks in child cpusets to the parent cpuset. In the former case, it is the mm setting of the group leader that really matters. So cpuset_attach_old_cs should track the oldcs of the thread leader. In the latter case, effective_mems of child cpusets must always be a subset of the parent. So no real page migration will be necessary no matter which child cpuset is selected as cpuset_attach_old_cs. IOW, cpuset_attach_old_cs should be updated to match the latest task group leader in cpuset_can_attach(), but fall back to that of the first task if there is no group leader in the taskset. Suggested-by: Ridong Chen Signed-off-by: Waiman Long Reviewed-by: Ridong Chen --- kernel/cgroup/cpuset.c | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c index 5c777b1237a8..60e8149cc907 100644 --- a/kernel/cgroup/cpuset.c +++ b/kernel/cgroup/cpuset.c @@ -2975,6 +2975,10 @@ static int update_prstate(struct cpuset *cs, int new= _prs) return 0; } =20 +/* + * cpuset_can_attach() and cpuset_attach() specific internal data + * Protected by cpuset_mutex + */ static struct cpuset *cpuset_attach_old_cs; =20 /* @@ -3065,11 +3069,32 @@ static int cpuset_can_attach(struct cgroup_taskset = *tset) if (ret) goto out_unlock; =20 + /* + * The cpuset_attach_old_cs is used mainly by cpuset_migrate_mm() to get + * the old_mems_allowed value. There are two ways that many-to-one + * cpuset migration can happen: + * 1) A multithread application with threads in different cpusets is + * wholely migrated to a new cpuset. + * 2) Disabling v2 cpuset controller will move all the tasks in child + * cpusets to the parent cpuset. + * + * In the former case, it is the mm setting of the group leader that + * really matters. So cpuset_attach_old_cs should track the oldcs of the + * group leader. It falls back to the oldcs of the first task if there + * is no group leader in the taskset. In the latter case, effective_mems + * of child cpusets must always be a subset of the parent. So no real + * page migration will be necessary no matter which child cpuset is + * selected as cpuset_attach_old_cs. + */ cgroup_taskset_for_each(task, css, tset) { ret =3D task_can_attach(task); if (ret) goto out_unlock; =20 + /* Update cpuset_attach_old_cs to the latest group leader */ + if (task =3D=3D task->group_leader) + cpuset_attach_old_cs =3D task_cs(task); + if (setsched_check) { ret =3D security_task_setscheduler(task); if (ret) --=20 2.54.0 From nobody Mon Jun 8 04:19:35 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4DBA9366DB5 for ; Tue, 2 Jun 2026 02:32:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367554; cv=none; b=nS9YmVt5fL3jIq/8N5mp5L8Bw/NWtqdFG8OC86V4bhxrX+6KRnflOHLSBVHG3vB70HJ8rYl9w7p22HWvRJFkCdpHNheXWw5Vp5K5/NgRX1S2XY6DvBKT4iouB3DNBTa7oc8iaSZJjqjK5T61hjnyiC4MC+qekhPUyi8WLMDfD2s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367554; c=relaxed/simple; bh=HQCvVe56NaRzi12GaxnNyzC/7fVnERC1Knnay7jjn1Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NdwPU0skVZ0eRyQtXkVtLE0DwNiEPgb7Fi8sDQ4VSunKdzBAOXD3eV4mZ8FygVMFF6DPooxQ2s4NshrW0DxeR9sj09Ymri5YaoElURS8vFLN63YywOmDWp/iBIgIVhvf0TMwfjRZG+kp8h7skhVdD9WjLMYYlWga7ScYVkdArKQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=LrmpFWe1; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="LrmpFWe1" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780367552; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=PPJhyuKyKW5m95bvMJtgDKchT6XlrtNxJvoZ3uaQdl8=; b=LrmpFWe10pGZXR4JEVPrIrzyW/7btVzEuWVCTkOyzJty0xUdrF6iz2+uybbF5pQ/oruF/N G0qeY1+Rl5ASVEesVg1gmVd+y5cKRh70TWOBRhrXJWrFmEq2sk9uvL06NI8kATG//cR2oh jfsp6WEdya55DwSTp5PtUY8gHQDPfJc= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-83-PH8BRYIYMieaXaPmm2iOew-1; Mon, 01 Jun 2026 22:32:26 -0400 X-MC-Unique: PH8BRYIYMieaXaPmm2iOew-1 X-Mimecast-MFC-AGG-ID: PH8BRYIYMieaXaPmm2iOew_1780367545 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 086E5195608F; Tue, 2 Jun 2026 02:32:25 +0000 (UTC) Received: from llong-thinkpadp16vgen1.westford.csb (unknown [10.22.88.124]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3ADD419560A3; Tue, 2 Jun 2026 02:32:22 +0000 (UTC) From: Waiman Long To: Chen Ridong , Tejun Heo , Johannes Weiner , =?UTF-8?q?Michal=20Koutn=C3=BD?= , Peter Zijlstra Cc: cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Aaron Tomlin , Guopeng Zhang , Waiman Long Subject: [PATCH-next v5 5/6] cgroup/cpuset: Move mpol_rebind_mm/cpuset_migrate_mm() calls inside cpuset_attach_task() Date: Mon, 1 Jun 2026 22:32:02 -0400 Message-ID: <20260602023203.248077-6-longman@redhat.com> In-Reply-To: <20260602023203.248077-1-longman@redhat.com> References: <20260602023203.248077-1-longman@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" The cpuset_attach_task() was introduced in commit 42a11bf5c543 ("cgroup/cpuset: Make cpuset_fork() handle CLONE_INTO_CGROUP properly") to enable the CLONE_INTO_CGROUP flag of clone(2) to behave more like moving a task from one cpuset into another one. That commits didn't move the mpol_rebind_mm() and cpuset_migrate_mm() calls for group leader into cpuset_attach_task(). When the CLONE_INTO_CGROUP flag is used without CLONE_THREAD, the new task is its own group leader. So it is still not equivalent to moving task between cpusets in this case. Make CLONE_INTO_CGROUP behaves more close to cpuset_attach() by moving the mpol_rebind_mm() and cpuset_migrate_mm() calls inside cpuset_attach_task(). As a result, the following static variables will have to be updated in cpuset_fork(). - cpuset_attach_old_cs - attach_cpus_updated - attach_mems_updated - queue_task_work Signed-off-by: Waiman Long --- kernel/cgroup/cpuset.c | 103 ++++++++++++++++++++++++----------------- 1 file changed, 60 insertions(+), 43 deletions(-) diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c index 60e8149cc907..5b5352ec0e69 100644 --- a/kernel/cgroup/cpuset.c +++ b/kernel/cgroup/cpuset.c @@ -2978,8 +2978,13 @@ static int update_prstate(struct cpuset *cs, int new= _prs) /* * cpuset_can_attach() and cpuset_attach() specific internal data * Protected by cpuset_mutex + * + * The attach_cpus_updated/attach_mems_updated flags are set in either + * cpuset_attach() or cpuset_fork() and used in cpuset_attach_task(). */ static struct cpuset *cpuset_attach_old_cs; +static bool attach_cpus_updated; +static bool attach_mems_updated; =20 /* * Check to see if a cpuset can accept a new task @@ -3157,9 +3162,12 @@ static void cpuset_cancel_attach(struct cgroup_tasks= et *tset) */ static cpumask_var_t cpus_attach; static nodemask_t cpuset_attach_nodemask_to; +static bool queue_task_work; =20 static void cpuset_attach_task(struct cpuset *cs, struct task_struct *task) { + struct mm_struct *mm; + lockdep_assert_cpuset_lock_held(); =20 if (cs !=3D &top_cpuset) @@ -3173,28 +3181,60 @@ static void cpuset_attach_task(struct cpuset *cs, s= truct task_struct *task) */ WARN_ON_ONCE(set_cpus_allowed_ptr(task, cpus_attach)); =20 + if (cpuset_v2() && !attach_mems_updated) + return; + cpuset_change_task_nodemask(task, &cpuset_attach_nodemask_to); cpuset1_update_task_spread_flags(cs, task); + + if ((task !=3D task->group_leader) || + (!is_memory_migrate(cs) && !attach_mems_updated)) + return; + + /* + * Change mm for threadgroup leader. This is expensive and may + * sleep and should be moved outside migration path proper. + */ + mm =3D get_task_mm(task); + if (mm) { + struct cpuset *oldcs =3D cpuset_attach_old_cs; + + mpol_rebind_mm(mm, &cs->effective_mems); + + /* + * old_mems_allowed is the same with mems_allowed + * here, except if this task is being moved + * automatically due to hotplug. In that case + * @mems_allowed has been updated and is empty, so + * @old_mems_allowed is the right nodesets that we + * migrate mm from. + */ + if (is_memory_migrate(cs)) { + cpuset_migrate_mm(mm, &oldcs->old_mems_allowed, + &cpuset_attach_nodemask_to); + queue_task_work =3D true; + } else { + mmput(mm); + } + } } =20 static void cpuset_attach(struct cgroup_taskset *tset) { struct task_struct *task; - struct task_struct *leader; struct cgroup_subsys_state *css; struct cpuset *cs; struct cpuset *oldcs =3D cpuset_attach_old_cs; - bool cpus_updated, mems_updated; - bool queue_task_work =3D false; =20 cgroup_taskset_first(tset, &css); cs =3D css_cs(css); =20 lockdep_assert_cpus_held(); /* see cgroup_attach_lock() */ mutex_lock(&cpuset_mutex); - cpus_updated =3D !cpumask_equal(cs->effective_cpus, - oldcs->effective_cpus); - mems_updated =3D !nodes_equal(cs->effective_mems, oldcs->effective_mems); + queue_task_work =3D false; + + attach_cpus_updated =3D !cpumask_equal(cs->effective_cpus, oldcs->effecti= ve_cpus); + attach_mems_updated =3D !nodes_equal(cs->effective_mems, oldcs->effective= _mems); =20 /* * In the default hierarchy, enabling cpuset in the child cgroups @@ -3204,7 +3244,7 @@ static void cpuset_attach(struct cgroup_taskset *tset) */ if (cpuset_v2()) { cpuset_attach_nodemask_to =3D cs->effective_mems; - if (!cpus_updated && !mems_updated) + if (!attach_cpus_updated && !attach_mems_updated) goto out; } else { guarantee_online_mems(cs, &cpuset_attach_nodemask_to); @@ -3213,38 +3253,6 @@ static void cpuset_attach(struct cgroup_taskset *tse= t) cgroup_taskset_for_each(task, css, tset) cpuset_attach_task(cs, task); =20 - /* - * Change mm for all threadgroup leaders. This is expensive and may - * sleep and should be moved outside migration path proper. Skip it - * if there is no change in effective_mems and CS_MEMORY_MIGRATE is - * not set. - */ - if (!is_memory_migrate(cs) && !mems_updated) - goto out; - - cgroup_taskset_for_each_leader(leader, css, tset) { - struct mm_struct *mm =3D get_task_mm(leader); - - if (mm) { - mpol_rebind_mm(mm, &cs->effective_mems); - - /* - * old_mems_allowed is the same with mems_allowed - * here, except if this task is being moved - * automatically due to hotplug. In that case - * @mems_allowed has been updated and is empty, so - * @old_mems_allowed is the right nodesets that we - * migrate mm from. - */ - if (is_memory_migrate(cs)) { - cpuset_migrate_mm(mm, &oldcs->old_mems_allowed, - &cpuset_attach_nodemask_to); - queue_task_work =3D true; - } else - mmput(mm); - } - } - out: if (queue_task_work) schedule_flush_migrate_mm(); @@ -3678,15 +3686,14 @@ static void cpuset_cancel_fork(struct task_struct *= task, struct css_set *cset) */ static void cpuset_fork(struct task_struct *task) { - struct cpuset *cs; - bool same_cs; + struct cpuset *cs, *oldcs; =20 rcu_read_lock(); cs =3D task_cs(task); - same_cs =3D (cs =3D=3D task_cs(current)); + oldcs =3D task_cs(current); rcu_read_unlock(); =20 - if (same_cs) { + if (cs =3D=3D oldcs) { if (cs =3D=3D &top_cpuset) return; =20 @@ -3698,7 +3705,17 @@ static void cpuset_fork(struct task_struct *task) /* CLONE_INTO_CGROUP */ mutex_lock(&cpuset_mutex); guarantee_online_mems(cs, &cpuset_attach_nodemask_to); + /* + * Assume CPUs and memory nodes are updated + * A CLONE_INTO_CGROUP operation should have taken the cgroup mutex + * and so there shouldn't be a competing cpuset_attach() operation. + */ + attach_cpus_updated =3D attach_mems_updated =3D true; + queue_task_work =3D false; + cpuset_attach_old_cs =3D oldcs; cpuset_attach_task(cs, task); + if (queue_task_work) + schedule_flush_migrate_mm(); =20 dec_attach_in_progress_locked(cs); mutex_unlock(&cpuset_mutex); --=20 2.54.0 From nobody Mon Jun 8 04:19:35 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BC669369D7A for ; Tue, 2 Jun 2026 02:32:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367554; cv=none; b=i7TSxSfmuPPd/7hqKnHOc2bckCbpQ5zFG8GNoq671diCWcXPAUIVgJUfcVigsH1pfNQhb6AFFfLOF/X3R2V6Sz4w7+yOMObHz1pfbvk+zMXrx0U06Rzc64EhRPuvPwj6FBmzmJ+HSuSmUAx6KNTU/xtgXszzUn24CjSUdRL6LEQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780367554; c=relaxed/simple; bh=XPphyOyhhTMw452KxBtqveVXGR7Wz64Yz9sfuyd9+Y8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=WSUuRGBBrzUMY/MfkPBds24U4rJxI0cnisMaGOJffN54xrwSH5mxDa3HLE9wF4c9O6ntLOcGbQOVq2xaBh4RGf3YWfIRRy5OV9wnXgn8D+1OZ7D8YUpRqgrANofzj64GK3EgnUc7x2QgLWwOrfjiVexfd6CS/QZV7zeqG0Kq+M4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=BtQDcP0N; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="BtQDcP0N" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780367552; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=TjQW84JAI0mOLGpS3lSQF9ZfsTcu2a2RFOFXnbAorQ8=; b=BtQDcP0NN89GETvRzdUCEE9S0aUb2aM4rKZd2WhVMV8giZfIbavpzRCEb9pHSnTelsjZdW cyXJp0m8/JfXMzhGTEkBYRsGrC+CdDW8IggxF4g+UTr9Ar0WVgPkVpP4AyE8nG6aQLfYFC aMv8l5MSKPha0u6YTFc6jC17bxK+rC0= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-149-pyQcABZTPaynTzRvuCSnEg-1; Mon, 01 Jun 2026 22:32:28 -0400 X-MC-Unique: pyQcABZTPaynTzRvuCSnEg-1 X-Mimecast-MFC-AGG-ID: pyQcABZTPaynTzRvuCSnEg_1780367547 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 084DB1800451; Tue, 2 Jun 2026 02:32:27 +0000 (UTC) Received: from llong-thinkpadp16vgen1.westford.csb (unknown [10.22.88.124]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 534AC19560A3; Tue, 2 Jun 2026 02:32:25 +0000 (UTC) From: Waiman Long To: Chen Ridong , Tejun Heo , Johannes Weiner , =?UTF-8?q?Michal=20Koutn=C3=BD?= , Peter Zijlstra Cc: cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Aaron Tomlin , Guopeng Zhang , Waiman Long Subject: [PATCH-next v5 6/6] cgroup/cpuset: Support multiple source/destination cpusets for cpuset_*attach() Date: Mon, 1 Jun 2026 22:32:03 -0400 Message-ID: <20260602023203.248077-7-longman@redhat.com> In-Reply-To: <20260602023203.248077-1-longman@redhat.com> References: <20260602023203.248077-1-longman@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" With cgroup v2, the cgroup_taskset structure passed into the cgroup can_attach() and attach() methods can contain task migration data with multiple destination or source cpusets when the cpuset controller is enabled or disabled respectively. Since cpuset is threaded in both v1 and v2, another possible way to cause many-to-one migration is to move the whole process with multiple threads in different cpuset enabled threaded cgroups into another cpuset enabled cgroup. The current cpuset_can_attach() and cpuset_attach() functions still expect task migration is from one source cpuset to one destination cpuset. This has been the case since cpuset was enabled for cgroup v2 in commit 4ec22e9c5a90 ("cpuset: Enable cpuset controller in default hierarchy"). This problem is less an issue when enabling the cpuset controller as all the newly created child cpusets will have exactly the same set of CPUs and memory nodes except when deadline tasks are involved in migration as the deadline task accounting data can be off. It can be more problematic when the cpuset controller is disabled as their set of CPUs and memory nodes may differ from their parent or with the moving of multi-threaded process from different threaded cgroups. Fix that by tracking the set of source (old) and destination cpusets in singly linked lists and iterating them all to properly update the internal data. Also keep the current cs and oldcs variables up-to-date with the css and task iterators. To ensure proper DL tasks accounting, the nr_migrate_dl_tasks in both the source and destination cpusets are decremented/incremented with their values added to nr_deadline_tasks when the migration is successful. Fixes: 4ec22e9c5a90 ("cpuset: Enable cpuset controller in default hierarchy= ") Signed-off-by: Waiman Long --- kernel/cgroup/cpuset-internal.h | 6 + kernel/cgroup/cpuset.c | 208 ++++++++++++++++++++++++-------- 2 files changed, 164 insertions(+), 50 deletions(-) diff --git a/kernel/cgroup/cpuset-internal.h b/kernel/cgroup/cpuset-interna= l.h index f7aaf01f7cd5..4c2772a7fd5e 100644 --- a/kernel/cgroup/cpuset-internal.h +++ b/kernel/cgroup/cpuset-internal.h @@ -161,6 +161,12 @@ struct cpuset { */ bool remote_partition; =20 + /* + * cpuset_can_attach() and cpuset_attach() specific data + */ + bool attach_node_in_llist; + struct llist_node attach_node; + /* * number of SCHED_DEADLINE tasks attached to this cpuset, so that we * know when to rebuild associated root domain bandwidth information. diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c index 5b5352ec0e69..53a9d3cc8407 100644 --- a/kernel/cgroup/cpuset.c +++ b/kernel/cgroup/cpuset.c @@ -37,6 +37,7 @@ #include #include #include +#include =20 DEFINE_STATIC_KEY_FALSE(cpusets_pre_enable_key); DEFINE_STATIC_KEY_FALSE(cpusets_enabled_key); @@ -2983,6 +2984,8 @@ static int update_prstate(struct cpuset *cs, int new_= prs) * cpuset_attach() or cpuset_fork() and used in cpuset_attach_task(). */ static struct cpuset *cpuset_attach_old_cs; +static LLIST_HEAD(src_cs_head); +static LLIST_HEAD(dst_cs_head); static bool attach_cpus_updated; static bool attach_mems_updated; =20 @@ -3005,6 +3008,15 @@ static int cpuset_can_attach_check(struct cpuset *cs= , struct cpuset *oldcs, if (!oldcs) return 0; =20 + if (!cs->attach_node_in_llist) { + llist_add(&cs->attach_node, &dst_cs_head); + cs->attach_node_in_llist =3D true; + } + if (!oldcs->attach_node_in_llist) { + llist_add(&oldcs->attach_node, &src_cs_head); + oldcs->attach_node_in_llist =3D true; + } + /* * Skip rights over task setsched check in v2 when nothing changes, * migration permission derives from hierarchy ownership in @@ -3027,33 +3039,101 @@ static int cpuset_can_attach_check(struct cpuset *= cs, struct cpuset *oldcs, return 0; } =20 -static int cpuset_reserve_dl_bw(struct cpuset *cs) +/* + * If reset_dl_bw is set, reset the previous dl_bw_alloc() call. Otherwise, + * update nr_deadline_tasks according to nr_migrate_dl_tasks in both source + * and destination cpusets. + */ +static void clear_attach_data(bool reset_dl_bw) { + struct cpuset *cs, *next; + + llist_for_each_entry_safe(cs, next, src_cs_head.first, attach_node) { + cs->attach_node.next =3D NULL; + cs->attach_node_in_llist =3D false; + if (cs->nr_migrate_dl_tasks && !reset_dl_bw) + cs->nr_deadline_tasks +=3D cs->nr_migrate_dl_tasks; + cs->nr_migrate_dl_tasks =3D 0; + } + + llist_for_each_entry_safe(cs, next, dst_cs_head.first, attach_node) { + cs->attach_node.next =3D NULL; + cs->attach_node_in_llist =3D false; + if (reset_dl_bw && cs->dl_bw_cpu >=3D 0) + dl_bw_free(cs->dl_bw_cpu, cs->sum_migrate_dl_bw); + if (cs->nr_migrate_dl_tasks && !reset_dl_bw) + cs->nr_deadline_tasks +=3D cs->nr_migrate_dl_tasks; + cs->nr_migrate_dl_tasks =3D 0; + cs->sum_migrate_dl_bw =3D 0; + cs->dl_bw_cpu =3D -1; + } + + src_cs_head.first =3D NULL; + dst_cs_head.first =3D NULL; +} + +static int cpuset_reserve_dl_bw(void) +{ + struct cpuset *cs; int cpu, ret; =20 - if (!cs->sum_migrate_dl_bw) - return 0; + llist_for_each_entry(cs, dst_cs_head.first, attach_node) { + if (!cs->sum_migrate_dl_bw) + continue; =20 - cpu =3D cpumask_any_and(cpu_active_mask, cs->effective_cpus); - if (unlikely(cpu >=3D nr_cpu_ids)) - return -EINVAL; + cpu =3D cpumask_any_and(cpu_active_mask, cs->effective_cpus); + if (unlikely(cpu >=3D nr_cpu_ids)) + return -EINVAL; =20 - ret =3D dl_bw_alloc(cpu, cs->sum_migrate_dl_bw); - if (ret) - return ret; + ret =3D dl_bw_alloc(cpu, cs->sum_migrate_dl_bw); + if (ret) + return ret; =20 - cs->dl_bw_cpu =3D cpu; + cs->dl_bw_cpu =3D cpu; + } return 0; } =20 -static void reset_migrate_dl_data(struct cpuset *cs) +static void set_attach_in_progress(void) { - cs->nr_migrate_dl_tasks =3D 0; - cs->sum_migrate_dl_bw =3D 0; - cs->dl_bw_cpu =3D -1; + struct cpuset *cs; + + /* + * Mark attach is in progress. This makes validate_change() fail + * changes which zero cpus/mems_allowed. + */ + llist_for_each_entry(cs, dst_cs_head.first, attach_node) + cs->attach_in_progress++; +} + +static void reset_attach_in_progress(void) +{ + struct cpuset *cs; + + llist_for_each_entry(cs, dst_cs_head.first, attach_node) + dec_attach_in_progress_locked(cs); } =20 -/* Called by cgroups to determine if a cpuset is usable; cpuset_mutex held= */ +/* + * Called by cgroups to determine if a cpuset is usable; cpuset_mutex held. + * + * With cgroup v2, enabling of cpuset controller in a cgroup subtree can + * cause @tset to contain task migration data from one parent cpuset to mu= ltiple + * child cpusets. Not much is needed to be done here other than tracking t= he + * number of DL tasks in each cpuset as the CPUs and memory nodes of the c= hild + * cpusets are exactly the same as the parent. + * + * Conversely, disabling of cpuset controller can cause @tset to contain t= ask + * migration data from multiple child cpusets to one parent cpuset. Here, = the + * CPUs and memory nodes of the child cpusets may be different from the pa= rent, + * but must be a subset of its parent. + * + * Another possible many-to-one migration is the moving of the whole + * multithreaded process with threads in different cpusets to another cpus= et. + * + * For all other use cases, @tset task migration data should be from one s= ource + * cpuset to one destination cpuset. + */ static int cpuset_can_attach(struct cgroup_taskset *tset) { struct cgroup_subsys_state *css; @@ -3092,6 +3172,16 @@ static int cpuset_can_attach(struct cgroup_taskset *= tset) * selected as cpuset_attach_old_cs. */ cgroup_taskset_for_each(task, css, tset) { + struct cpuset *newcs =3D css_cs(css); + struct cpuset *new_oldcs =3D task_cs(task); + + if ((newcs !=3D cs) || (new_oldcs !=3D oldcs)) { + cs =3D newcs; + oldcs =3D new_oldcs; + ret =3D cpuset_can_attach_check(cs, oldcs, &setsched_check); + if (ret) + goto out_unlock; + } ret =3D task_can_attach(task); if (ret) goto out_unlock; @@ -3113,23 +3203,19 @@ static int cpuset_can_attach(struct cgroup_taskset = *tset) * contribute to sum_migrate_dl_bw. */ cs->nr_migrate_dl_tasks++; + oldcs->nr_migrate_dl_tasks--; if (dl_task_needs_bw_move(task, cs->effective_cpus)) cs->sum_migrate_dl_bw +=3D task->dl.dl_bw; } } =20 - ret =3D cpuset_reserve_dl_bw(cs); + ret =3D cpuset_reserve_dl_bw(); =20 out_unlock: - if (ret) { - reset_migrate_dl_data(cs); - } else { - /* - * Mark attach is in progress. This makes validate_change() fail - * changes which zero cpus/mems_allowed. - */ - cs->attach_in_progress++; - } + if (ret) + clear_attach_data(true); + else + set_attach_in_progress(); =20 mutex_unlock(&cpuset_mutex); return ret; @@ -3144,14 +3230,8 @@ static void cpuset_cancel_attach(struct cgroup_tasks= et *tset) cs =3D css_cs(css); =20 mutex_lock(&cpuset_mutex); - dec_attach_in_progress_locked(cs); - - if (cs->dl_bw_cpu >=3D 0) - dl_bw_free(cs->dl_bw_cpu, cs->sum_migrate_dl_bw); - - if (cs->nr_migrate_dl_tasks) - reset_migrate_dl_data(cs); - + reset_attach_in_progress(); + clear_attach_data(true); mutex_unlock(&cpuset_mutex); } =20 @@ -3224,48 +3304,76 @@ static void cpuset_attach(struct cgroup_taskset *ts= et) struct task_struct *task; struct cgroup_subsys_state *css; struct cpuset *cs; - struct cpuset *oldcs =3D cpuset_attach_old_cs; + bool many_cs_to_one =3D !!src_cs_head.first->next; =20 cgroup_taskset_first(tset, &css); - cs =3D css_cs(css); =20 lockdep_assert_cpus_held(); /* see cgroup_attach_lock() */ mutex_lock(&cpuset_mutex); queue_task_work =3D false; =20 - attach_cpus_updated =3D !cpumask_equal(cs->effective_cpus, oldcs->effecti= ve_cpus); - attach_mems_updated =3D !nodes_equal(cs->effective_mems, oldcs->effective= _mems); + /* + * attach_cpus_updated/attach_mems_updated can be set to false if + * source and destination masks are the same and there is only one + * source cpuset. IOW, a many-cs-to-one migration is always treated as + * updated as the tasks to old cpuset mapping is lost. + */ + if (many_cs_to_one) { + attach_cpus_updated =3D true; + attach_mems_updated =3D true; + } else { + /* one_cs_to_one or one_cs_to_many */ + struct cpuset *oldcs =3D cpuset_attach_old_cs; =20 + attach_cpus_updated =3D false; + attach_mems_updated =3D false; + llist_for_each_entry(cs, dst_cs_head.first, attach_node) { + attach_cpus_updated |=3D !cpumask_equal(cs->effective_cpus, + oldcs->effective_cpus); + attach_mems_updated |=3D !nodes_equal(cs->effective_mems, + oldcs->effective_mems); + } + } + + cs =3D css_cs(css); /* * In the default hierarchy, enabling cpuset in the child cgroups * will trigger a cpuset_attach() call with no change in effective cpus * and mems. In that case, we can optimize out by skipping the task - * iteration and update. + * iteration and update, but the destination cpuset list is iterated to + * set old_mems_sllowed. */ if (cpuset_v2()) { cpuset_attach_nodemask_to =3D cs->effective_mems; - if (!attach_cpus_updated && !attach_mems_updated) + if (!attach_cpus_updated && !attach_mems_updated) { + llist_for_each_entry(cs, dst_cs_head.first, attach_node) + cs->old_mems_allowed =3D cs->effective_mems; goto out; + } } else { guarantee_online_mems(cs, &cpuset_attach_nodemask_to); } =20 - cgroup_taskset_for_each(task, css, tset) + cgroup_taskset_for_each(task, css, tset) { + struct cpuset *newcs =3D css_cs(css); + + if (newcs !=3D cs) { + cs->old_mems_allowed =3D cpuset_attach_nodemask_to; + cs =3D newcs; + if (cpuset_v2()) + cpuset_attach_nodemask_to =3D cs->effective_mems; + else + guarantee_online_mems(cs, &cpuset_attach_nodemask_to); + } cpuset_attach_task(cs, task); + } =20 -out: if (queue_task_work) schedule_flush_migrate_mm(); cs->old_mems_allowed =3D cpuset_attach_nodemask_to; - - if (cs->nr_migrate_dl_tasks) { - cs->nr_deadline_tasks +=3D cs->nr_migrate_dl_tasks; - oldcs->nr_deadline_tasks -=3D cs->nr_migrate_dl_tasks; - reset_migrate_dl_data(cs); - } - - dec_attach_in_progress_locked(cs); - +out: + reset_attach_in_progress(); + clear_attach_data(false); mutex_unlock(&cpuset_mutex); } =20 --=20 2.54.0