Re: [PATCH 2/2] sched/psi: Shut down rtpoll_timer in psi_cgroup_free()

Suren Baghdasaryan <[email protected]> Mon, 13 Jul 2026 07:07:55 -0700
Newsgroups dev.linux.lists.sched-ext,org.kernel.vger.cgroups,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <CAJuCfpEocgh+s_R_C6K25ESaSub=-vx6ZwqE-5HJddfBPMt7NA@mail.gmail.com>
On Mon, Jul 13, 2026 at 3:56 AM Johannes Weiner <[email protected]> wrote:
>
> On Sun, Jul 12, 2026 at 07:46:19AM -1000, Tejun Heo wrote:
> > psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath
> > and can race psi_trigger_destroy() taking down the last rtpoll trigger under
> > rtpoll_trigger_lock:
> >
> >   psi_schedule_rtpoll_work()        psi_trigger_destroy()
> >
> >   rcu_read_lock();
> >   task = rcu_dereference(rtpoll_task);
> >                                     rcu_assign_pointer(rtpoll_task, NULL);
> >                                     timer_delete(&rtpoll_timer);
> >   mod_timer(&rtpoll_timer, ...);
> >   rcu_read_unlock();
> >                                     synchronize_rcu();
> >                                     kthread_stop(task_to_destroy);
> >
> > The group can then be freed with the re-armed timer still pending, and
> > poll_timer_fn() runs on freed memory.
> >
> > 461daba06bdc ("psi: eliminate kthread_worker from psi trigger scheduling
> > mechanism") deleted the timer synchronously after the synchronize_rcu(),
> > which prevented this but raced trigger creation instead: the deletion could
> > cancel the timer that a new trigger set armed during the grace period and,
> > as creation also reinitialized the timer at the time, corrupt it.
> > 8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy") moved the
> > initialization into group_init() and the deletion into the locked section,
> > trading the creation races for the window above.
> >
> > Neither placement in the destruction path works. A pending timer firing
> > while the group is alive is harmless though. poll_timer_fn() just wakes the
> > rtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's
> > lifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it
> > by then. timer_shutdown_sync() because the timer is never armed again.
> >
> > Fixes: 8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy")
> > Cc: [email protected] # v5.10+
> > Reported-by: Sashiko AI <[email protected]>
> > Closes: https://lore.kernel.org/all/[email protected]/
> > Signed-off-by: Tejun Heo <[email protected]>
>
> Acked-by: Johannes Weiner <[email protected]>
>
> Both these patches look good to me, but Suren can you please also take
> a look?

Yes, I'm on it. Need some time to remind myself of all the details of
the implementation.