From nobody Mon Sep 28 17:49:49 2026 Received: from mail-qv1-f43.google.com (mail-qv1-f43.google.com [209.85.219.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5675739A7EA for ; Wed, 19 Aug 2026 13:21:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787145673; cv=none; b=F6+MMQy6nWl01QqUiCtvtuQiDgWvLwMbBqBYikM6K310q31bK69Mue4k00HwGQkbk99/rhOz2zMWJotkfVw0M/IEorEoMKmgyGuIXLpaapMhG92Qc3EuO2CCJLNh6mEewmp5vZfeoanltdudX4QAMAd1XGALNsUBPqlOs8cOd/c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787145673; c=relaxed/simple; bh=Jim1wAXD4iHFPChMBC10PwuxmAUKP76/FI9HT614/wU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Y930IWNED+JtHHexWO2fvPA+CoTCf9DSTRt7i5HLsX8z2GVszd80m/+dj+zdrgI/Rijapk0+XvUKHPaYPd+4GzFp6FxDjhrHeQtRuWkPlOXqGDihNzMREpn3iPD8+/oFZfsMsOuYWsJpmEj8d27iHZYscBC8sOe1skIGG8kBjp0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=metarealtyinc.ca; spf=pass smtp.mailfrom=metarealtyinc.ca; dkim=pass (2048-bit key) header.d=metarealtyinc-ca.20251104.gappssmtp.com header.i=@metarealtyinc-ca.20251104.gappssmtp.com header.b=e99h6wuq; arc=none smtp.client-ip=209.85.219.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=metarealtyinc.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=metarealtyinc.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=metarealtyinc-ca.20251104.gappssmtp.com header.i=@metarealtyinc-ca.20251104.gappssmtp.com header.b="e99h6wuq" Received: by mail-qv1-f43.google.com with SMTP id 6a1803df08f44-8eeb4508f29so7707856d6.0 for ; Wed, 19 Aug 2026 06:21:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=metarealtyinc-ca.20251104.gappssmtp.com; s=20251104; t=1787145668; x=1787750468; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=rV8o38P8L7ym1wIEKuZA4cI3zO+vMhOv6I+Do+Xml2k=; b=e99h6wuq4viGZ6fgsyggXlRjuRcZJU6aa15/MVo4YUnMKnptyE64d0zzFmNxERw8P1 hqZEWiMKnfHMDUXbztuw8OI/o3zDWXIgCTTULWfXLwqrrIKnd8biDuor2KOS/F8R4cGm CmYXSOqohsQi4fwYvlJE7oxLeZCq20riM4GAdsp2b0q3Vg0hNMlitteobk9Q0ddn4xf+ eNGYCW/RbGcubjTPMiErgRzkR/p3Zt0A9VrOcQKS2uY+h04cBFWjPoyGUz0ScnpP6f1r RyRmQ4JcHFxu2ufFceH7iMyEbigWHIDRU15Pcgidhe9uqyVaIvKn/yFwKDxAK9IGMeYD ENjg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787145668; x=1787750468; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=rV8o38P8L7ym1wIEKuZA4cI3zO+vMhOv6I+Do+Xml2k=; b=Ghqvt7R3xDQUlXqxCULr//Fnxe1ZQXTO+n9ovp/3YgIDLEHQWFIiCmffZ1QXqp0LiO qr7sb+3HxUhUvwsJ5nxYmtnnN7s/QOIuIK/rhh6iFkKPi8DY/4rewIydnzhQA2K40FrS uv+yLTKy/e7DMVORKZgHKmwTasDa6NK6EX8FgtZjQ0UimP3gD8jeKpq6jp/sFM1g0eNZ 6CwJiEm34Gi1usd/ZbQZ2XcEFqK/IZrzvNUUbAT18CUBKk2GZP+HLdE7VoUrxQngCyZ6 GCerqv/LR/Az4/vRXkXdnkeofInwGPiT+v9rEF/Jt6Wc7RCXHQPS+fb63hqJQKeLYFXo w9Cw== X-Forwarded-Encrypted: i=1; AHgh+RqHMm63qjD0BGjEbEUpFUD5JE5RYftFoFNnul07c6HPahbFktBBatX6XeqtWuqFIGzHg3Yue2SE/zM7BiE=@vger.kernel.org X-Gm-Message-State: AFuF++nQgtDidDUWJhoTBWnDmiZsJTKEv/6MvZJM06Szbo41SiWBNkUR vr4T0RiNYDC0hpUKUkGE3/w7PaqNx5JYqz3fObFXmendL60ARXFvgmhtP5YOZAshl7U= X-Gm-Gg: AR+sD124o3aaDN/AQXa+AdkZuN+rK5k0Xts+VJeLegxnzfYN2lEmdPs9TPXBhUgP++v BKhsCOrLBV0LqhhnGmNnVeFgQB6h8wscQ9EaTM5PFWaIqrXbizqthNUUWrM659NMWgen9fQRLEr KC5w+Vzb+CswOmME787tyruDsMKVLOf1cK0vvsRbCw5JuO8HTutsCJuhnWaDt1x4oshtBZuNr9h 8bnHG8MiAW1Eij2YNdRTNz62vXPKY7qJ9c2RQU3G5YUABhHgUJPV/SYpSl18EcG/AAsdtf8COv3 1QFXqsA053dXQsIzhLjI8VpKm4xDUFNx2dxYG0fdTS/2IC5uwf3SYYlZpmdOcUJoHCrL3t1Zou7 eL7D4NAKsuvQZnajJkx+cCGS4scLilKlOuq3tILnS4fDqjZo3SE6BD6XjiMp4CwLSXwPQGfVF6+ vJXEZMyEnYwW/TD5hGvk7QBYrxlf0Q3cOINdSTefCC4qSSvNTd+9B+FFqDgtp17ksfEzsoKWn5Y KXxAi9rNZSiIEXUqw+0xsW1ZrmuDj+SMRMBPVcnY4uk6x+rcFjmNrEPNEfRW9qDZdg8STWEFJqK EtR3CIYqZuBCCdgHxAuiFnBESwK4PRnFKXzkPyVc7VQ= X-Received: by 2002:a05:6214:d4d:b0:8e7:d752:ab34 with SMTP id 6a1803df08f44-90c5e6fdb7dmr43203476d6.12.1787145668202; Wed, 19 Aug 2026 06:21:08 -0700 (PDT) Received: from jake-laptop ([2607:fea8:e5:500::95b9]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90c5eec1f31sm14392726d6.13.2026.08.19.06.21.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 06:21:07 -0700 (PDT) From: Jake Steinman To: Peter Zijlstra , Ingo Molnar , Juri Lelli , Vincent Guittot Cc: Jake Steinman , Dietmar Eggemann , Steven Rostedt , Ben Segall , Mel Gorman , Valentin Schneider , K Prateek Nayak , Waiman Long , Tejun Heo , Guopeng Zhang , linux-kernel@vger.kernel.org, cgroups@vger.kernel.org Subject: [PATCH] sched/fair: floor tg_cpus() at 1 Date: Wed, 19 Aug 2026 09:20:59 -0400 Message-ID: <20260819132104.2148918-1-j@metarealtyinc.ca> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260818231333.1441757-1-j@metarealtyinc.ca> References: <20260818231333.1441757-1-j@metarealtyinc.ca> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" tg_cpus() returns cpuset_num_cpus() unfloored, while its sibling tg_tasks() already floors its result at 1. calc_concur_shares() feeds nr =3D min(tg_tasks(tg), tg_cpus(tg)) into __calc_smp_shares() as shares_max, so an nr of 0 makes shares_max 0. __calc_smp_shares() ends with return clamp_t(long, shares, MIN_SHARES, shares_max); and clamp() yields hi when hi < lo, so a zero shares_max silently defeats the MIN_SHARES floor and returns 0 -- the exact case the comment above that line says must return MIN_SHARES instead of 0. That leaves a group sched_entity with load.weight =3D=3D 0, and __calc_prop_weight() then divides by cfs_rq->load.weight: weight *=3D se->load.weight; if (parent_entity(se)) weight /=3D cfs_rq->load.weight; which takes a #DE inside enqueue_task_fair(): Oops: divide error: 0000 [#1] SMP NOPTI RIP: 0010:enqueue_task_fair+0x422/0x950 Call Trace: enqueue_task+0x8e/0x250 wake_up_new_task+0x148/0x2e0 kernel_clone+0x1c6/0x390 __x64_sys_clone+0xcc/0x100 do_syscall_64+0x147/0x3c0 This is not survivable in practice: with panic_on_oops=3D0 the kernel took the first #DE and continued for 476 ms, then faulted at the same RIP with identical register state and an identical RSP, because the oops recovery path (kill task -> schedule()) re-enters the same enqueue while the rq lock is held mid-enqueue. The second fault escalates to a panic. Flooring tg_cpus() at 1 makes it symmetric with tg_tasks() and keeps shares_max >=3D tg_shares, so the MIN_SHARES floor in __calc_smp_shares() can no longer be bypassed. Note this only removes the division hazard. Whether cpuset_num_cpus() can legitimately return 0 -- via the cpu hotplug/suspend path where a v2 cpuset may transiently become empty, or via an RCU race -- is a separate question still open on the report thread. Link: https://lore.kernel.org/all/20260818231333.1441757-1-j@metarealtyinc.= ca/ Signed-off-by: Jake Steinman --- kernel/sched/fair.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c --- a/kernel/sched/fair.c +++ b/kernel/sched/fair.c @@ -4895,7 +4895,12 @@ static int tg_cpus(struct task_group *tg) nr =3D cpuset_num_cpus(cgrp); } - return nr; + /* + * An empty cpuset would propagate a 0 shares_max into + * __calc_smp_shares(), where clamp() yields hi when hi < lo and so + * defeats the MIN_SHARES floor. Match tg_tasks(), which floors at 1. + */ + return max(nr, 1); } static inline int tg_tasks(struct task_group *tg) -- 2.55.0