From nobody Mon Sep 28 21:03:56 2026 Received: from fanzine2.igalia.com (fanzine2.igalia.com [213.97.179.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8CE20439F71; Mon, 17 Aug 2026 14:31:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=213.97.179.56 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786977107; cv=none; b=r0zyGPJ7jQrEBk4ouY8pS2AhxL9ChFEpO0WBQ0QOncqmyP27Wh5ctsPjHz/yRM0o+afNZyFGJ3YICvSctnX1IYr8Epw8jxcd1WH+NH9v1LzNXnHImGq5ylvh1r7XaBnyMR3A239ogxPLRruN11kyX7Kh+mruHBF91vCd8vWR17o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786977107; c=relaxed/simple; bh=MxiHXBIhiR1FI2gfpS6C2vsSaaQBoNQz0JT+lg+gbNE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=IoT5UWnVoZ1HPrJvaijLsn6sRmL1RoJ5R4wx/6N8LrapxN6ycxQxykHkUrdNZLWbQfLAOfVRZ9iZ0ogrOb/m1WhmpdTCuWrwL5KbcpwLGnPVd9nXKbzMaSPxfEGDb+DiLMLPSKCGHsscIJ76BBF0X5cCPYaQEtiT8W0RohhuArE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=igalia.com; spf=pass smtp.mailfrom=igalia.com; dkim=pass (2048-bit key) header.d=igalia.com header.i=@igalia.com header.b=XmIGms/G; arc=none smtp.client-ip=213.97.179.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=igalia.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=igalia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=igalia.com header.i=@igalia.com header.b="XmIGms/G" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=igalia.com; s=20170329; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject: Cc:To:From:From:Reply-To; bh=w5iXU/N+YYn28QNVUEueSF3SrmtkOJMPjyresmGOZYA=; b= XmIGms/GLkJDAe3bUSvxQiBVZn4TSARt0DZa6S0wms+bAZ6jaRa/e8hzMqxewrEYLEFEkAXFPqOVs u/12AhUXyB53K/8Nd90767KAFcF0WR1Q+Rj/UO2cK67RcjCCxFVKkTVRsszq6HVtv+v8+DfTbs2t8 eJyj+8wQgsAUOt58ScaRy6UcB4MIK1Dra2eEdAyXe5k2L+8tWEwPNKdVF4t5uJoZjQvoaxW0b92rN UkL/FQxTnlyIKM8WF+nCTYZXkKZ5+eAvM41Wi6gxFi0lzhGA/fmWVU8fws0dhKVUMpAmueGLCThqW OAa47K+JDuLfp7HK7WEVELxnr3bZGxUp6A==; Received: from [58.29.145.179] (helo=localhost) by fanzine2.igalia.com with esmtpsa (Cipher TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim) id 1wvyNG-004Zy3-GW; Mon, 17 Aug 2026 16:31:39 +0200 From: Changwoo Min To: tj@kernel.org, void@manifault.com, arighi@nvidia.com, changwoo@igalia.com Cc: gavinguo@igalia.com, kernel-dev@igalia.com, sched-ext@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH 1/2] compat.bpf.h: Gate scx_bpf_dsq_peek kfunc behind kernel version 7.1.0 Date: Mon, 17 Aug 2026 23:31:25 +0900 Message-ID: <20260817143126.562923-2-changwoo@igalia.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260817143126.562923-1-changwoo@igalia.com> References: <20260817143126.562923-1-changwoo@igalia.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Gavin Guo __COMPAT_scx_bpf_dsq_peek() selects the lockless kfunc whenever the symbol resolves in the kernel BTF. However, its lockless implementation could return a stale task_struct pointer. The stale pointer issues are resolved only after v7.1 kernel with the following patches: commit 2f2ea7709266 ("sched_ext: Use dsq->first_task instead of list_empty(= ) in dispatch_enqueue() FIFO-tail") commit 71d7847cad44 ("sched_ext: Fix scx_bpf_dsq_peek() with FIFO DSQs") Require bpf_ksym_exists(scx_bpf_dsq_peek) AND LINUX_KERNEL_VERSION >=3D KERNEL_VERSION(7, 1, 0) before calling the kfunc to mitigate the issue; otherwise fall through to the existing bpf_iter_scx_dsq path instead. See also the lavd patch, working around the bug by avoiding calling the kfunc when unnecessary and having more context explanation: ac863374ce4f ("scx_lavd: Gate dsq_peek_task_load behind no-fast-lb") Signed-off-by: Gavin Guo Signed-off-by: Changwoo Min --- tools/sched_ext/include/scx/compat.bpf.h | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/tools/sched_ext/include/scx/compat.bpf.h b/tools/sched_ext/inc= lude/scx/compat.bpf.h index 3ab642f92c8a..03976f5851d9 100644 --- a/tools/sched_ext/include/scx/compat.bpf.h +++ b/tools/sched_ext/include/scx/compat.bpf.h @@ -92,15 +92,20 @@ int bpf_cpumask_populate(struct bpf_cpumask *dst, void = *src, size_t src__sz) __k =20 /* * v6.19: Introduce lockless peek API for user DSQs. + * v7.1: Resolve the stale pointer issue of the lockless peek API. + * + * The kfunc exists on earlier kernels but its lockless implementation cou= ld + * return stale task pointers. Require kernel version >=3D 7.1.0 before ca= lling + * it; otherwise fall through to the bpf_iter_scx_dsq fallback below. * - * Preserve the following macro until v6.21. */ static inline struct task_struct *__COMPAT_scx_bpf_dsq_peek(u64 dsq_id) { struct task_struct *p =3D NULL; struct bpf_iter_scx_dsq it; =20 - if (bpf_ksym_exists(scx_bpf_dsq_peek)) + if (bpf_ksym_exists(scx_bpf_dsq_peek) && + LINUX_KERNEL_VERSION >=3D KERNEL_VERSION(7, 1, 0)) return scx_bpf_dsq_peek(dsq_id); if (!bpf_iter_scx_dsq_new(&it, dsq_id, 0)) p =3D bpf_iter_scx_dsq_next(&it); --=20 2.55.0 From nobody Mon Sep 28 21:03:56 2026 Received: from fanzine2.igalia.com (fanzine2.igalia.com [213.97.179.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CF4904432FE; Mon, 17 Aug 2026 14:31:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=213.97.179.56 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786977113; cv=none; b=WetM7qdw30YaOuYAISbY346qBEkmerw3O9kxYdnaI8pA17TaRwO8vbH1kb2d5CyIt5XwpI49I5cqOoZfs9dSynw54fy2F+xtVtb1p/01BhbCDLVJG4LEQtgDb1Hlzvklcge2oD4E8k3hgwZaqn9hUWD6QFr88VTc0U7HRva4+fg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786977113; c=relaxed/simple; bh=zrUJzhpnlXLVnFkqfPcF4LST9uOIgpAzdeSqFCZ01As=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=P53mjIZI9jE7GHLx+LAmsG6au8Sh5zRBGEbacn5U1mdY0SmfclnwYWDuedE7TjGCc/CGAARkCxhqZQ+RS7Ojc/44MJvCZ6Gm06GfXW8xvBMr+s541GyEtACt27ob+DGiCcEO531wo95rddIU7PNw2QR7AXToloM3puIbFjbyV+c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=igalia.com; spf=pass smtp.mailfrom=igalia.com; dkim=pass (2048-bit key) header.d=igalia.com header.i=@igalia.com header.b=Q207Nj76; arc=none smtp.client-ip=213.97.179.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=igalia.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=igalia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=igalia.com header.i=@igalia.com header.b="Q207Nj76" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=igalia.com; s=20170329; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject: Cc:To:From:From:Reply-To; bh=hP//wKAQV3uEOAjGKWED5jJsXM3myIIhDRnVw0xciEE=; b= Q207Nj766q9d7rqQ7L3e8iDpjvUTnPcz4BlE4nEOOftUURch/vwRsyPlplOXf3uXenUu9UPH7aXWr wjUQtW8EUngChSXgZMzgMllFBsqN4NQqfSvJhf6GO7CQEScMw4ev8NOvsuWZEiBZsPuR1X8wvmunm aTA0vH+goGuinWF3kKg07HUAX2/PRSwfsjgh6KrVWpPFjmUnv0IvaAaNyPD0npO611y0HvHzlaAHe C0sRj+oZp4qb2RcXp/oD2jl7fgVM3paGULjSX7jMTr1m7jxzB6YUcX4RqOe2tmm/j6gEc7fApLrtO Eaz5T+xkatFxhygiP6RwlMH/V14SnVzKsg==; Received: from [58.29.145.179] (helo=localhost) by fanzine2.igalia.com with esmtpsa (Cipher TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim) id 1wvyNM-004Zyj-H6; Mon, 17 Aug 2026 16:31:45 +0200 From: Changwoo Min To: tj@kernel.org, void@manifault.com, arighi@nvidia.com, changwoo@igalia.com Cc: gavinguo@igalia.com, kernel-dev@igalia.com, sched-ext@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH 2/2] compat.bpf.h: add scx_bpf_reenqueue_local_from_anywhere() compat helper Date: Mon, 17 Aug 2026 23:31:26 +0900 Message-ID: <20260817143126.562923-3-changwoo@igalia.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260817143126.562923-1-changwoo@igalia.com> References: <20260817143126.562923-1-changwoo@igalia.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" scx_bpf_reenqueue_local()'s generic compat wrapper inlines a v1 fallback that is only callable from ops.cpu_release, and veristat rejects it on kernels without v2. Callers draining a local DSQ from an arbitrary context (e.g. a tracepoint) must gate on a call-from-anywhere kfunc directly. Add scx_bpf_reenqueue_local_from_anywhere() to compat.bpf.h to encapsulate that: call a call-from-anywhere kfunc when present and return 0, else return -ENOTSUP so the caller knows the drain did not run. Two kfuncs qualify -- the v7.1 generic scx_bpf_dsq_reenq(), which will eventually deprecate scx_bpf_reenqueue_local(), and the v6.19 v2 reenqueue-local variant. Prefer the generic one; v1 cannot be called from anywhere, so it maps to -ENOTSUP. scx_bpf_reenqueue_local() itself grows the same generic-first preference, and the scx_bpf_dsq_reenq___compat declaration and __COMPAT_has_generic_reenq() helper move above the v6.19 block so both wrappers can use them. Test each ksym in its own branch: ORing two bpf_ksym_exists() checks folds into a bitwise OR of the two weak ksym addresses, which the verifier rejects. No functional change intended. Suggested-by: Andrea Righi Signed-off-by: Changwoo Min Signed-off-by: Tejun Heo --- tools/sched_ext/include/scx/compat.bpf.h | 39 ++++++++++++++++++------ 1 file changed, 30 insertions(+), 9 deletions(-) diff --git a/tools/sched_ext/include/scx/compat.bpf.h b/tools/sched_ext/inc= lude/scx/compat.bpf.h index 03976f5851d9..55f118e40545 100644 --- a/tools/sched_ext/include/scx/compat.bpf.h +++ b/tools/sched_ext/include/scx/compat.bpf.h @@ -383,6 +383,17 @@ static inline void scx_bpf_task_set_dsq_vtime(struct t= ask_struct *p, u64 vtime) p->scx.dsq_vtime =3D vtime; } =20 +/* + * v7.1: New scx_bpf_dsq_reenq() that allows re-enqueues on more DSQs. This + * will eventually deprecate scx_bpf_reenqueue_local(). + */ +void scx_bpf_dsq_reenq___compat(u64 dsq_id, u64 reenq_flags) __ksym __weak; + +static inline bool __COMPAT_has_generic_reenq(void) +{ + return bpf_ksym_exists(scx_bpf_dsq_reenq___compat); +} + /* * v6.19: The new void variant can be called from anywhere while the older= v1 * variant can only be called from ops.cpu_release(). The double ___ prefi= xes on @@ -400,21 +411,31 @@ static inline bool __COMPAT_scx_bpf_reenqueue_local_f= rom_anywhere(void) =20 static inline void scx_bpf_reenqueue_local(void) { - if (__COMPAT_scx_bpf_reenqueue_local_from_anywhere()) + if (__COMPAT_has_generic_reenq()) + scx_bpf_dsq_reenq___compat(SCX_DSQ_LOCAL, 0); + else if (__COMPAT_scx_bpf_reenqueue_local_from_anywhere()) scx_bpf_reenqueue_local___v2___compat(); else scx_bpf_reenqueue_local___v1(); } =20 -/* - * v7.1: New scx_bpf_dsq_reenq() that allows re-enqueues on more DSQs. This - * will eventually deprecate scx_bpf_reenqueue_local(). - */ -void scx_bpf_dsq_reenq___compat(u64 dsq_id, u64 reenq_flags) __ksym __weak; - -static inline bool __COMPAT_has_generic_reenq(void) +static inline int scx_bpf_reenqueue_local_from_anywhere(void) { - return bpf_ksym_exists(scx_bpf_dsq_reenq___compat); + /* + * The generic reenq kfunc and the v2 reenqueue-local variant can both be + * called from anywhere; v1 cannot. Test each ksym in its own branch with= a + * distinct call: combining them with || would fold into a bitwise OR of = the + * two ksym addresses, which the verifier rejects. + */ + if (__COMPAT_has_generic_reenq()) { + scx_bpf_dsq_reenq___compat(SCX_DSQ_LOCAL, 0); + return 0; + } + if (__COMPAT_scx_bpf_reenqueue_local_from_anywhere()) { + scx_bpf_reenqueue_local___v2___compat(); + return 0; + } + return -ENOTSUP; } =20 static inline void scx_bpf_dsq_reenq(u64 dsq_id, u64 reenq_flags) --=20 2.55.0