The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Chen Xiaokun <shinnkka1@gmail.com>
To: Greg KH <gregkh@linuxfoundation.org>
Cc: axboe@kernel.dk, linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH 6.1.y] Fix memory leak in io_wq_create() on success path
Date: Fri, 7 Aug 2026 00:07:56 +0800	[thread overview]
Message-ID: <baf66d46-773f-4094-991d-e726b0e3b159@gmail.com> (raw)
In-Reply-To: <2026080636-financial-iron-4bd9@gregkh>

在 2026/8/6 23:29, Greg KH 写道:

> On Thu, Aug 06, 2026 at 10:47:02PM +0800, xk c wrote:
>> Greg KH <gregkh@linuxfoundation.org> 于2026年8月6日周四 22:33写道:
>>> On Thu, Aug 06, 2026 at 10:23:14PM +0800, Chen Xiaokun wrote:
>>>> The commit 657ca82526d0 introduced a temporary allowed_mask cpumask in
>>>> io_wq_create(), which was freed only on the error path.  This caused a
>>>> memory leak of cpumask_size() bytes on every successful io_wq_create().
>>>>
>>>> Fixes: 657ca82526d0 ("io_uring/io-wq: inherit cpuset of cgroup in io worker")
>>>> Signed-off-by: Chen Xiaokun <shinnkka1@gmail.com>
>>>> ---
>>>>   io_uring/io-wq.c | 1 +
>>>>   1 file changed, 1 insertion(+)
>>>>
>>>> diff --git a/io_uring/io-wq.c b/io_uring/io-wq.c
>>>> index 66fdd69fd6cb..34a1a9067cc2 100644
>>>> --- a/io_uring/io-wq.c
>>>> +++ b/io_uring/io-wq.c
>>>> @@ -1218,6 +1218,7 @@ struct io_wq *io_wq_create(unsigned bounded, struct io_wq_data *data)
>>>>        wq->task = get_task_struct(data->task);
>>>>        atomic_set(&wq->worker_refs, 1);
>>>>        init_completion(&wq->worker_done);
>>>> +     free_cpumask_var(allowed_mask);
>>>>        return wq;
>>>>   err:
>>>>        io_wq_put_hash(data->hash);
>>>> --
>>>> 2.55.0
>>>>
>>>>
>>> Why is this a stable-only patch?  Was the backport wrong?  Or is this
>>> also in Linus's tree?
>>>
>> Linus's tree has not this issue.
> You need to explain why, in great detail, Linus's tree does not have
> this problem in the changelog.
>
> For example, try answering the questions I asked here, that should
> provide you a framework for what to write.
>
> thnanks,
This is a stable-only patch because the backport introduced a
temporary allowed_mask variable without freeing it on the success
path.  In Linus's tree, it is bound to wq, so there is no memory leak.
> greg k-h
>
>
Thanks for your patience,
Chen

      reply	other threads:[~2026-08-06 16:08 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 14:23 [PATCH 6.1.y] Fix memory leak in io_wq_create() on success path Chen Xiaokun
2026-08-06 14:33 ` Greg KH
2026-08-06 14:47   ` xk c
2026-08-06 15:29     ` Greg KH
2026-08-06 16:07       ` Chen Xiaokun [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=baf66d46-773f-4094-991d-e726b0e3b159@gmail.com \
    --to=shinnkka1@gmail.com \
    --cc=axboe@kernel.dk \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox