Re: [PATCH 1/2] xen/credit: fix race with schedule_cpu_rm() in csched_timer()
Oleksii Kurochko <[email protected]> Wed, 29 Jul 2026 15:32:05 +0200
| Newsgroups | gmane.comp.emulators.xen.devel |
|---|---|
| Message-ID | <[email protected]> |
On 7/29/26 2:27 PM, Andrew Cooper wrote:
> On 29/07/2026 1:06 pm, Juergen Gross wrote:
>> When removing a CPU from a cpupool running the credit scheduler, a
>> race might happen between schedule_cpu_rm() and csched_timer(),
>> resulting in a NULL dereference.
>>
>> The timer associated with csched_timer() is killed only in
>> csched_deinit_pdata(), which is called by schedule_cpu_rm() after
>> setting the scheduler's per-cpu data to NULL AND after enabling
>> interrupts again. This can result in the timer to fire before it is
>> being killed,
>
> "... the timer firing before being killed,"
>
>> so csched_timer() needs to test the per-cpu data to be
>> set before accessing it.
>>
>> Fixes: 78be3dbbfefa ("cpupools [1/6]: hypervisor changes")
>> Reported-by: Dietmar Hahn <[email protected]>
>> Signed-off-by: Juergen Gross <[email protected]>
>
> Acked-by: Andrew Cooper <[email protected]>
>
Despite the fact that the race is very unlikely, the fix is very simple
and still resolves a race condition, so we could consider including it
in 4.22:
Release-Acked-by: Oleksii Kurochko <[email protected]>
Thanks.
~ Oleksii