Re: [PATCH 1/2] xen/credit: fix race with schedule_cpu_rm() in csched_timer()

Andrew Cooper <[email protected]> Wed, 29 Jul 2026 13:27:59 +0100
Newsgroups gmane.comp.emulators.xen.devel
Message-ID <[email protected]>
On 29/07/2026 1:06 pm, Juergen Gross wrote:
> When removing a CPU from a cpupool running the credit scheduler, a
> race might happen between schedule_cpu_rm() and csched_timer(),
> resulting in a NULL dereference.
>
> The timer associated with csched_timer() is killed only in
> csched_deinit_pdata(), which is called by schedule_cpu_rm() after
> setting the scheduler's per-cpu data to NULL AND after enabling
> interrupts again. This can result in the timer to fire before it is
> being killed,

"... the timer firing before being killed,"

>  so csched_timer() needs to test the per-cpu data to be
> set before accessing it.
>
> Fixes: 78be3dbbfefa ("cpupools [1/6]: hypervisor changes")
> Reported-by: Dietmar Hahn <[email protected]>
> Signed-off-by: Juergen Gross <[email protected]>

Acked-by: Andrew Cooper <[email protected]>