All of lore.kernel.org
 help / color / mirror / Atom feed
* Queue up 5.10 io_uring backport
@ 2022-04-10 16:46 Jens Axboe
  2022-04-10 16:53 ` Jens Axboe
  0 siblings, 1 reply; 3+ messages in thread
From: Jens Axboe @ 2022-04-10 16:46 UTC (permalink / raw)
  To: stable

Hi,

Can you queue up this one for 5.10 stable? It has an extra hunk
that's needed for 5.10. 5.15/16/17 will be a direct port of
the 5.18-rc patch.


commit e677edbcabee849bfdd43f1602bccbecf736a646
Author: Jens Axboe <axboe@kernel.dk>
Date:   Fri Apr 8 11:08:58 2022 -0600

    io_uring: fix race between timeout flush and removal
    
    commit e677edbcabee849bfdd43f1602bccbecf736a646 upstream.

    io_flush_timeouts() assumes the timeout isn't in progress of triggering
    or being removed/canceled, so it unconditionally removes it from the
    timeout list and attempts to cancel it.
    
    Leave it on the list and let the normal timeout cancelation take care
    of it.
    
    Cc: stable@vger.kernel.org # 5.5+
    Signed-off-by: Jens Axboe <axboe@kernel.dk>

diff --git a/fs/io_uring.c b/fs/io_uring.c
index 5959b0359524..bc6bf17566f8 100644
--- a/fs/io_uring.c
+++ b/fs/io_uring.c
@@ -1556,6 +1556,7 @@ static void __io_queue_deferred(struct io_ring_ctx *ctx)
 
 static void io_flush_timeouts(struct io_ring_ctx *ctx)
 {
+	struct io_kiocb *req, *tmp;
 	u32 seq;
 
 	if (list_empty(&ctx->timeout_list))
@@ -1563,10 +1564,8 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
 
 	seq = ctx->cached_cq_tail - atomic_read(&ctx->cq_timeouts);
 
-	do {
+	list_for_each_entry_safe(req, tmp, &ctx->timeout_list, timeout.list) {
 		u32 events_needed, events_got;
-		struct io_kiocb *req = list_first_entry(&ctx->timeout_list,
-						struct io_kiocb, timeout.list);
 
 		if (io_is_timeout_noseq(req))
 			break;
@@ -1583,9 +1582,8 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
 		if (events_got < events_needed)
 			break;
 
-		list_del_init(&req->timeout.list);
 		io_kill_timeout(req, 0);
-	} while (!list_empty(&ctx->timeout_list));
+	}
 
 	ctx->cq_last_tm_flush = seq;
 }
@@ -5639,6 +5637,7 @@ static int io_timeout_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe,
 	else
 		data->mode = HRTIMER_MODE_REL;
 
+	INIT_LIST_HEAD(&req->timeout.list);
 	hrtimer_init(&data->timer, CLOCK_MONOTONIC, data->mode);
 	return 0;
 }
@@ -6282,12 +6281,12 @@ static enum hrtimer_restart io_link_timeout_fn(struct hrtimer *timer)
 	if (!list_empty(&req->link_list)) {
 		prev = list_entry(req->link_list.prev, struct io_kiocb,
 				  link_list);
-		if (refcount_inc_not_zero(&prev->refs))
-			list_del_init(&req->link_list);
-		else
+		list_del_init(&req->link_list);
+		if (!refcount_inc_not_zero(&prev->refs))
 			prev = NULL;
 	}
 
+	list_del(&req->timeout.list);
 	spin_unlock_irqrestore(&ctx->completion_lock, flags);
 
 	if (prev) {


-- 
Jens Axboe


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: Queue up 5.10 io_uring backport
  2022-04-10 16:46 Queue up 5.10 io_uring backport Jens Axboe
@ 2022-04-10 16:53 ` Jens Axboe
  2022-04-11  7:47   ` Greg KH
  0 siblings, 1 reply; 3+ messages in thread
From: Jens Axboe @ 2022-04-10 16:53 UTC (permalink / raw)
  To: stable

[-- Attachment #1: Type: text/plain, Size: 320 bytes --]

On 4/10/22 10:46 AM, Jens Axboe wrote:
> Hi,
> 
> Can you queue up this one for 5.10 stable? It has an extra hunk
> that's needed for 5.10. 5.15/16/17 will be a direct port of
> the 5.18-rc patch.

Here's the 5.15-stable backport. For 5.16 and 5.17, the upstream commit
will apply directly with no fuzz.

-- 
Jens Axboe

[-- Attachment #2: 5.15-port.patch --]
[-- Type: text/x-patch, Size: 1807 bytes --]

commit e677edbcabee849bfdd43f1602bccbecf736a646
Author: Jens Axboe <axboe@kernel.dk>
Date:   Fri Apr 8 11:08:58 2022 -0600

    io_uring: fix race between timeout flush and removal
    
    io_flush_timeouts() assumes the timeout isn't in progress of triggering
    or being removed/canceled, so it unconditionally removes it from the
    timeout list and attempts to cancel it.
    
    Leave it on the list and let the normal timeout cancelation take care
    of it.
    
    Cc: stable@vger.kernel.org # 5.5+
    Signed-off-by: Jens Axboe <axboe@kernel.dk>

diff --git a/fs/io_uring.c b/fs/io_uring.c
index 5fc3a62eae72..0202a6c431df 100644
--- a/fs/io_uring.c
+++ b/fs/io_uring.c
@@ -1546,12 +1546,11 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
 	__must_hold(&ctx->completion_lock)
 {
 	u32 seq = ctx->cached_cq_tail - atomic_read(&ctx->cq_timeouts);
+	struct io_kiocb *req, *tmp;
 
 	spin_lock_irq(&ctx->timeout_lock);
-	while (!list_empty(&ctx->timeout_list)) {
+	list_for_each_entry_safe(req, tmp, &ctx->timeout_list, timeout.list) {
 		u32 events_needed, events_got;
-		struct io_kiocb *req = list_first_entry(&ctx->timeout_list,
-						struct io_kiocb, timeout.list);
 
 		if (io_is_timeout_noseq(req))
 			break;
@@ -1568,7 +1567,6 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
 		if (events_got < events_needed)
 			break;
 
-		list_del_init(&req->timeout.list);
 		io_kill_timeout(req, 0);
 	}
 	ctx->cq_last_tm_flush = seq;
@@ -6210,6 +6208,7 @@ static int io_timeout_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe,
 	if (get_timespec64(&data->ts, u64_to_user_ptr(sqe->addr)))
 		return -EFAULT;
 
+	INIT_LIST_HEAD(&req->timeout.list);
 	data->mode = io_translate_timeout_mode(flags);
 	hrtimer_init(&data->timer, io_timeout_get_clock(data), data->mode);
 

^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: Queue up 5.10 io_uring backport
  2022-04-10 16:53 ` Jens Axboe
@ 2022-04-11  7:47   ` Greg KH
  0 siblings, 0 replies; 3+ messages in thread
From: Greg KH @ 2022-04-11  7:47 UTC (permalink / raw)
  To: Jens Axboe; +Cc: stable

On Sun, Apr 10, 2022 at 10:53:46AM -0600, Jens Axboe wrote:
> On 4/10/22 10:46 AM, Jens Axboe wrote:
> > Hi,
> > 
> > Can you queue up this one for 5.10 stable? It has an extra hunk
> > that's needed for 5.10. 5.15/16/17 will be a direct port of
> > the 5.18-rc patch.
> 
> Here's the 5.15-stable backport. For 5.16 and 5.17, the upstream commit
> will apply directly with no fuzz.

Thanks, all now queued up.

greg k-h

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2022-04-11  7:47 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-04-10 16:46 Queue up 5.10 io_uring backport Jens Axboe
2022-04-10 16:53 ` Jens Axboe
2022-04-11  7:47   ` Greg KH

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.