[PATCH net v2 0/2] net/sched: taprio: fix RCU stall from replayed schedule entries

From: Krystian Kaniewski

Date: Fri Oct 09 2026 - 08:43:58 EST


syzbot reported an RCU stall with a software taprio schedule made of a
single 127 ns entry. When advance_sched() falls behind, it replays every
missed entry inside the timer interrupt and the backlog only grows.
Patch 2 makes it continue from the entry in progress instead.

Patch 2 then checks for an admin schedule handover once after catching
up. That requires the cycle_time_extension comparison to be monotonic,
so the sum now saturates instead of wrapping. As a result a large
extension can hand over to an admin schedule whose start time leaves no
room for the timestamps derived from it. Initializing such a schedule
already overflows today, and a carefully chosen extension can already
reach it. Patch 1 rejects these schedules at configuration time and
comes first, so the series never hands over to one.

v2:
- patch 2: do not use the list iterator after the loop in
taprio_entry_at(). The helper returns the entry through a separate
pointer that is set inside the loop (Jakub)
- patch 2: wrap the lines longer than 80 columns
- patch 1: no change
v1: https://lore.kernel.org/all/20261006113335.241564-1-krystianmkaniewski@xxxxxxxxx/

Krystian Kaniewski (2):
net/sched: taprio: reject software schedules that overflow their
timestamps
net/sched: taprio: do not replay missed entries in advance_sched()

net/sched/sch_taprio.c | 179 ++++++++++++++++++++++++++++++++++++-----
1 file changed, 157 insertions(+), 22 deletions(-)


base-commit: af39eb111ce6b5eba9c08513b62c4868eb7e7fd5
--
2.53.0