From nobody Mon Sep 28 11:40:15 2026 Received: from outbound.baidu.com (mx24.baidu.com [111.206.215.185]) by smtp.subspace.kernel.org (Postfix) with SMTP id 99F8B1419A4 for ; Sat, 22 Aug 2026 02:33:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=111.206.215.185 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787366020; cv=none; b=k59Wqel9C6LOFmfknrjsjpOOSZjKbw6mCA45IIPnhB5J6qr7Ttozp9hoq0PMb3hUPkn6RyWyqDFonkPQ1N+7ZjoEMjgY0riMEWImtg5aFpWdg/aH+fdclAJSHsesZlj1zgegWZzbkQaPAsrq7uNFbKqDV7iiZJxaowW4vLf3Klk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787366020; c=relaxed/simple; bh=U63DTai4Z00yemNwiC3jhS1vr9hcJV9mXizX87wbMG0=; h=From:To:CC:Subject:Date:Message-ID:MIME-Version:Content-Type; b=WYTZKPt0ufoQpN20RSPDR4nIcZ91Fkcy1o3/ubv0a1NZ603UAHgqXFDNGpnwMI3GgKFVhV0FOm++rbRmyYiPLPLBnhKMPtzeFTuHBFivQKmEZ6VkhbjjFZHj/o+tbGaxMd5F4Ao8dS0GHxOu1TRCh1cKz3B2GJES+yQrhqgQgsQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=baidu.com; spf=pass smtp.mailfrom=baidu.com; dkim=pass (2048-bit key) header.d=baidu.com header.i=@baidu.com header.b=O82PRbKb; arc=none smtp.client-ip=111.206.215.185 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=baidu.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=baidu.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=baidu.com header.i=@baidu.com header.b="O82PRbKb" X-MD-Sfrom: lirongqing@baidu.com X-MD-SrcIP: 172.31.50.47 From: lirongqing To: Ingo Molnar , Peter Zijlstra , Juri Lelli , Vincent Guittot , Dietmar Eggemann , Steven Rostedt , Ben Segall , Mel Gorman , Valentin Schneider , K Prateek Nayak , , Zhan Xusheng CC: Li RongQing Subject: [PATCH, Resend, v2] sched/debug: Reject invalid writes to numa_balancing scan_size_mb Date: Sat, 22 Aug 2026 10:33:13 +0800 Message-ID: <20260822023313.1721-1-lirongqing@baidu.com> X-Mailer: git-send-email 2.17.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-ClientProxiedBy: bjkjy-exc8.internal.baidu.com (172.31.50.52) To bjkjy-exc3.internal.baidu.com (172.31.50.47) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=baidu.com; s=selector1; t=1787366005; bh=vMYvUM8W1ItFvkZukU9PvNj6ksKp5Bz8f5gbKt9iOg8=; h=From:To:CC:Subject:Date:Message-ID:Content-Type; b=O82PRbKbAkRGtNQDBQuJQj04ACgKbWIl0/Q4XLFWMRHgHKSPDbiOEBEtxA3KXLboX REasy+kfmPkVr6dl0fH0O37D9Qr26ZK4jNIDj9eu7zgBa91TLtQD6fRWXlIe7AcbuS W2/jqJvaAt57sLJB04o8DI5P7zCk7kVXjGWy+U1jQU2jhz/ubwN17Dk0yCqfaHDOpQ x7f1U7ROS9MgwDMNWtpCNKV0yGoA47Gips4jZIjbbX0h5dxLeQTCjOr7RXi4M4Tzkg qgk7fyq8DA89/Ys58Pi3szIR16jyI3zhHhZprWDpfwsoGy0ITrUstVkZ8djshI+V4R qsFCUuvBQuCAg== Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Li RongQing The sysctl_numa_balancing_scan_size parameter is currently registered via debugfs_create_u32(), which accepts any u32 value including 0. A zero value triggers division-by-zero in two code paths: task_scan_min(): windows =3D MAX_SCAN_WINDOW / scan_size; task_nr_scan_windows(): rss =3D round_up(rss, nr_scan_pages); return rss / nr_scan_pages; Similarly, values exceeding UINT_MAX would be silently truncated by the write path before reaching this handler, potentially accepting unintended values. Reject them explicitly with -ERANGE Replace the debugfs_create_u32() interface with a custom file_operations handler that validates writes: reject 0 and values exceeding UINT_MAX with -ERANGE. Since the ops use DEFINE_DEBUGFS_ATTRIBUTE() which already provides removal protection via debugfs_file_get()/put(), debugfs_create_file_unsafe() is used instead of debugfs_create_file() to avoid an unnecessary full_proxy layer. Fixes: 8a99b6833c88 ("sched: Move SCHED_DEBUG sysctl to debugfs") Signed-off-by: Li RongQing --- Diff with v1: Rebase Replace debugfs_create_file with debugfs_create_file_unsafe; And rewrite commit message kernel/sched/debug.c | 23 ++++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) diff --git a/kernel/sched/debug.c b/kernel/sched/debug.c index 72236db..3e336b0 100644 --- a/kernel/sched/debug.c +++ b/kernel/sched/debug.c @@ -709,6 +709,26 @@ static const struct file_operations sched_cgroup_fops = =3D { }; #endif =20 +#ifdef CONFIG_NUMA_BALANCING +static int numa_scan_size_get(void *data, u64 *val) +{ + *val =3D *(u32 *)data; + return 0; +} + +static int numa_scan_size_set(void *data, u64 val) +{ + if (val =3D=3D 0 || val > UINT_MAX) + return -ERANGE; + + *(u32 *)data =3D (u32)val; + return 0; +} + +DEFINE_DEBUGFS_ATTRIBUTE(numa_scan_size_fops, numa_scan_size_get, + numa_scan_size_set, "%llu\n"); +#endif /* CONFIG_NUMA_BALANCING */ + static __init int sched_init_debug(void) { struct dentry __maybe_unused *numa, *llc; @@ -740,7 +760,8 @@ static __init int sched_init_debug(void) debugfs_create_u32("scan_delay_ms", 0644, numa, &sysctl_numa_balancing_sc= an_delay); debugfs_create_u32("scan_period_min_ms", 0644, numa, &sysctl_numa_balanci= ng_scan_period_min); debugfs_create_u32("scan_period_max_ms", 0644, numa, &sysctl_numa_balanci= ng_scan_period_max); - debugfs_create_u32("scan_size_mb", 0644, numa, &sysctl_numa_balancing_sca= n_size); + debugfs_create_file_unsafe("scan_size_mb", 0644, numa, + &sysctl_numa_balancing_scan_size, &numa_scan_size_fops); debugfs_create_u32("hot_threshold_ms", 0644, numa, &sysctl_numa_balancing= _hot_threshold); #endif /* CONFIG_NUMA_BALANCING */ =20 --=20 2.9.4