[SRU][J][PATCH 1/1] io_uring: check if we need to reschedule during overflow flush
Tim Whisonant
tim.whisonant at canonical.com
Wed Mar 25 01:37:34 UTC 2026
From: Jens Axboe <axboe at kernel.dk>
In terms of normal application usage, this list will always be empty.
And if an application does overflow a bit, it'll have a few entries.
However, nothing obviously prevents syzbot from running a test case
that generates a ton of overflow entries, and then flushing them can
take quite a while.
Check for needing to reschedule while flushing, and drop our locks and
do so if necessary. There's no state to maintain here as overflows
always prune from head-of-list, hence it's fine to drop and reacquire
the locks at the end of the loop.
Link: https://lore.kernel.org/io-uring/66ed061d.050a0220.29194.0053.GAE@google.com/
Reported-by: syzbot+5fca234bd7eb378ff78e at syzkaller.appspotmail.com
Signed-off-by: Jens Axboe <axboe at kernel.dk>
(backported from commit eac2ca2d682f94f46b1973bdf5e77d85d77b8e53)
[tswhison: context adjustment due to missing commits
253993210bd ("io_uring: introduce locking helpers for CQE posting")
6971253f078 ("io_uring: revise completion_lock locking")]
CVE-2024-50060
Signed-off-by: Tim Whisonant <tim.whisonant at canonical.com>
---
io_uring/io_uring.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/io_uring/io_uring.c b/io_uring/io_uring.c
index eaed0fc05e934..9e1e5272c96d2 100644
--- a/io_uring/io_uring.c
+++ b/io_uring/io_uring.c
@@ -1718,6 +1718,23 @@ static bool __io_cqring_overflow_flush(struct io_ring_ctx *ctx, bool force)
posted = true;
list_del(&ocqe->list);
kfree(ocqe);
+
+ /*
+ * For silly syzbot cases that deliberately overflow by huge
+ * amounts, check if we need to resched and drop and
+ * reacquire the locks if so. Nothing real would ever hit this.
+ * Ideally we'd have a non-posting unlock for this, but hard
+ * to care for a non-real case.
+ */
+ if (need_resched()) {
+ io_commit_cqring(ctx);
+ spin_unlock(&ctx->completion_lock);
+ io_cqring_ev_posted(ctx);
+ mutex_unlock(&ctx->uring_lock);
+ cond_resched();
+ mutex_lock(&ctx->uring_lock);
+ spin_lock(&ctx->completion_lock);
+ }
}
all_flushed = list_empty(&ctx->cq_overflow_list);
--
2.43.0
More information about the kernel-team
mailing list