* Queue up 5.10 io_uring backport
@ 2022-04-10 16:46 Jens Axboe
2022-04-10 16:53 ` Jens Axboe
0 siblings, 1 reply; 3+ messages in thread
From: Jens Axboe @ 2022-04-10 16:46 UTC (permalink / raw)
To: stable
Hi,
Can you queue up this one for 5.10 stable? It has an extra hunk
that's needed for 5.10. 5.15/16/17 will be a direct port of
the 5.18-rc patch.
commit e677edbcabee849bfdd43f1602bccbecf736a646
Author: Jens Axboe <axboe@kernel.dk>
Date: Fri Apr 8 11:08:58 2022 -0600
io_uring: fix race between timeout flush and removal
commit e677edbcabee849bfdd43f1602bccbecf736a646 upstream.
io_flush_timeouts() assumes the timeout isn't in progress of triggering
or being removed/canceled, so it unconditionally removes it from the
timeout list and attempts to cancel it.
Leave it on the list and let the normal timeout cancelation take care
of it.
Cc: stable@vger.kernel.org # 5.5+
Signed-off-by: Jens Axboe <axboe@kernel.dk>
diff --git a/fs/io_uring.c b/fs/io_uring.c
index 5959b0359524..bc6bf17566f8 100644
--- a/fs/io_uring.c
+++ b/fs/io_uring.c
@@ -1556,6 +1556,7 @@ static void __io_queue_deferred(struct io_ring_ctx *ctx)
static void io_flush_timeouts(struct io_ring_ctx *ctx)
{
+ struct io_kiocb *req, *tmp;
u32 seq;
if (list_empty(&ctx->timeout_list))
@@ -1563,10 +1564,8 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
seq = ctx->cached_cq_tail - atomic_read(&ctx->cq_timeouts);
- do {
+ list_for_each_entry_safe(req, tmp, &ctx->timeout_list, timeout.list) {
u32 events_needed, events_got;
- struct io_kiocb *req = list_first_entry(&ctx->timeout_list,
- struct io_kiocb, timeout.list);
if (io_is_timeout_noseq(req))
break;
@@ -1583,9 +1582,8 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
if (events_got < events_needed)
break;
- list_del_init(&req->timeout.list);
io_kill_timeout(req, 0);
- } while (!list_empty(&ctx->timeout_list));
+ }
ctx->cq_last_tm_flush = seq;
}
@@ -5639,6 +5637,7 @@ static int io_timeout_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe,
else
data->mode = HRTIMER_MODE_REL;
+ INIT_LIST_HEAD(&req->timeout.list);
hrtimer_init(&data->timer, CLOCK_MONOTONIC, data->mode);
return 0;
}
@@ -6282,12 +6281,12 @@ static enum hrtimer_restart io_link_timeout_fn(struct hrtimer *timer)
if (!list_empty(&req->link_list)) {
prev = list_entry(req->link_list.prev, struct io_kiocb,
link_list);
- if (refcount_inc_not_zero(&prev->refs))
- list_del_init(&req->link_list);
- else
+ list_del_init(&req->link_list);
+ if (!refcount_inc_not_zero(&prev->refs))
prev = NULL;
}
+ list_del(&req->timeout.list);
spin_unlock_irqrestore(&ctx->completion_lock, flags);
if (prev) {
--
Jens Axboe
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: Queue up 5.10 io_uring backport
2022-04-10 16:46 Queue up 5.10 io_uring backport Jens Axboe
@ 2022-04-10 16:53 ` Jens Axboe
2022-04-11 7:47 ` Greg KH
0 siblings, 1 reply; 3+ messages in thread
From: Jens Axboe @ 2022-04-10 16:53 UTC (permalink / raw)
To: stable
[-- Attachment #1: Type: text/plain, Size: 320 bytes --]
On 4/10/22 10:46 AM, Jens Axboe wrote:
> Hi,
>
> Can you queue up this one for 5.10 stable? It has an extra hunk
> that's needed for 5.10. 5.15/16/17 will be a direct port of
> the 5.18-rc patch.
Here's the 5.15-stable backport. For 5.16 and 5.17, the upstream commit
will apply directly with no fuzz.
--
Jens Axboe
[-- Attachment #2: 5.15-port.patch --]
[-- Type: text/x-patch, Size: 1807 bytes --]
commit e677edbcabee849bfdd43f1602bccbecf736a646
Author: Jens Axboe <axboe@kernel.dk>
Date: Fri Apr 8 11:08:58 2022 -0600
io_uring: fix race between timeout flush and removal
io_flush_timeouts() assumes the timeout isn't in progress of triggering
or being removed/canceled, so it unconditionally removes it from the
timeout list and attempts to cancel it.
Leave it on the list and let the normal timeout cancelation take care
of it.
Cc: stable@vger.kernel.org # 5.5+
Signed-off-by: Jens Axboe <axboe@kernel.dk>
diff --git a/fs/io_uring.c b/fs/io_uring.c
index 5fc3a62eae72..0202a6c431df 100644
--- a/fs/io_uring.c
+++ b/fs/io_uring.c
@@ -1546,12 +1546,11 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
__must_hold(&ctx->completion_lock)
{
u32 seq = ctx->cached_cq_tail - atomic_read(&ctx->cq_timeouts);
+ struct io_kiocb *req, *tmp;
spin_lock_irq(&ctx->timeout_lock);
- while (!list_empty(&ctx->timeout_list)) {
+ list_for_each_entry_safe(req, tmp, &ctx->timeout_list, timeout.list) {
u32 events_needed, events_got;
- struct io_kiocb *req = list_first_entry(&ctx->timeout_list,
- struct io_kiocb, timeout.list);
if (io_is_timeout_noseq(req))
break;
@@ -1568,7 +1567,6 @@ static void io_flush_timeouts(struct io_ring_ctx *ctx)
if (events_got < events_needed)
break;
- list_del_init(&req->timeout.list);
io_kill_timeout(req, 0);
}
ctx->cq_last_tm_flush = seq;
@@ -6210,6 +6208,7 @@ static int io_timeout_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe,
if (get_timespec64(&data->ts, u64_to_user_ptr(sqe->addr)))
return -EFAULT;
+ INIT_LIST_HEAD(&req->timeout.list);
data->mode = io_translate_timeout_mode(flags);
hrtimer_init(&data->timer, io_timeout_get_clock(data), data->mode);
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: Queue up 5.10 io_uring backport
2022-04-10 16:53 ` Jens Axboe
@ 2022-04-11 7:47 ` Greg KH
0 siblings, 0 replies; 3+ messages in thread
From: Greg KH @ 2022-04-11 7:47 UTC (permalink / raw)
To: Jens Axboe; +Cc: stable
On Sun, Apr 10, 2022 at 10:53:46AM -0600, Jens Axboe wrote:
> On 4/10/22 10:46 AM, Jens Axboe wrote:
> > Hi,
> >
> > Can you queue up this one for 5.10 stable? It has an extra hunk
> > that's needed for 5.10. 5.15/16/17 will be a direct port of
> > the 5.18-rc patch.
>
> Here's the 5.15-stable backport. For 5.16 and 5.17, the upstream commit
> will apply directly with no fuzz.
Thanks, all now queued up.
greg k-h
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2022-04-11 7:47 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-04-10 16:46 Queue up 5.10 io_uring backport Jens Axboe
2022-04-10 16:53 ` Jens Axboe
2022-04-11 7:47 ` Greg KH
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.