diff options
| author | Kyumin Lee <fyonglkm@gmail.com> | 2026-07-31 04:27:34 +0900 |
|---|---|---|
| committer | Jens Axboe <axboe@kernel.dk> | 2026-07-30 14:40:22 -0600 |
| commit | bc0e8faf90e776a2f1f3967a04e8091e6bdb4977 (patch) | |
| tree | 63d6f026d28a891ebf05add5aa7e6bcd1809895d | |
| parent | fa1ac3b9eb62918f039276d4d11cc02f682bf93c (diff) | |
| download | linux-next-bc0e8faf90e776a2f1f3967a04e8091e6bdb4977.tar.gz linux-next-bc0e8faf90e776a2f1f3967a04e8091e6bdb4977.zip | |
io_uring: preserve task restrictions across exec
Per-task restrictions apply to all rings created by a task. Once
installed, they should not be dropped across exec.
For a task that has used io_uring, the exec cancellation path calls
__io_uring_free(). This frees both the task context and the per-task
restriction, so a ring created after exec is unrestricted.
Split task context cleanup into io_uring_free_tctx(), and use it from
the exec cancellation path. Keep __io_uring_free() for final task
cleanup, where both the context and restriction are released.
Fixes: ed82f35b926b ("io_uring: allow registration of per-task restrictions")
Cc: stable@vger.kernel.org # 7.1+
Signed-off-by: Kyumin Lee <fyonglkm@gmail.com>
Link: https://patch.msgid.link/20260730192734.459247-1-fyonglkm@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
| -rw-r--r-- | io_uring/cancel.c | 2 | ||||
| -rw-r--r-- | io_uring/tctx.c | 7 | ||||
| -rw-r--r-- | io_uring/tctx.h | 1 |
3 files changed, 8 insertions, 2 deletions
diff --git a/io_uring/cancel.c b/io_uring/cancel.c index 8c6fa6f367e4..7d7820eab878 100644 --- a/io_uring/cancel.c +++ b/io_uring/cancel.c @@ -660,6 +660,6 @@ end_wait: */ atomic_dec(&tctx->in_cancel); /* for exec all current's requests should be gone, kill tctx */ - __io_uring_free(current); + io_uring_free_tctx(current); } } diff --git a/io_uring/tctx.c b/io_uring/tctx.c index cc3bf2b3bdbc..466b7300e208 100644 --- a/io_uring/tctx.c +++ b/io_uring/tctx.c @@ -43,7 +43,7 @@ static struct io_wq *io_init_wq_offload(struct io_ring_ctx *ctx, return io_wq_create(concurrency, &data); } -void __io_uring_free(struct task_struct *tsk) +void io_uring_free_tctx(struct task_struct *tsk) { struct io_uring_task *tctx = tsk->io_uring; struct io_tctx_node *node; @@ -67,6 +67,11 @@ void __io_uring_free(struct task_struct *tsk) kfree(tctx); tsk->io_uring = NULL; } +} + +void __io_uring_free(struct task_struct *tsk) +{ + io_uring_free_tctx(tsk); if (tsk->io_uring_restrict) { io_put_bpf_filters(tsk->io_uring_restrict); kfree(tsk->io_uring_restrict); diff --git a/io_uring/tctx.h b/io_uring/tctx.h index 2310d2a0c46d..76ad1ad4594e 100644 --- a/io_uring/tctx.h +++ b/io_uring/tctx.h @@ -12,6 +12,7 @@ void io_uring_del_tctx_node(unsigned long index); int __io_uring_add_tctx_node(struct io_ring_ctx *ctx); int __io_uring_add_tctx_node_from_submit(struct io_ring_ctx *ctx); void io_uring_clean_tctx(struct io_uring_task *tctx); +void io_uring_free_tctx(struct task_struct *tsk); void io_uring_unreg_ringfd(void); int io_ringfd_register(struct io_ring_ctx *ctx, void __user *__arg, |
