Re: [PATCH v2 1/3] fuse: fix missing barrier when checking io-uring readiness

Bernd Schubert <[email protected]> Thu, 16 Jul 2026 00:26:40 +0200
Newsgroups dev.linux.lists.fuse-devel,org.kernel.vger.stable
Message-ID <[email protected]>

On 7/15/26 19:43, Joanne Koong wrote:
> fuse_block_alloc() reads fch->initialized and then fch->io_uring.
> fch->io_uring is set before fch->initialized, ordered by the smp_wmb()
> in fuse_chan_set_intialized(), but fuse_block_alloc() has no matching
> read barrier between the two loads.
> 
> This may lead a CPU to observe fch->initialized=1 but fch->io_uring=0,
> and skip the check that blocks request allocation until the io-uring
> queues are ready. This can reintroduce the lock-order inversion deadlock
> that commit 3393ff964e0f prevents.
> 
> Add an smp_rmb() barrier to pair with the smp_wmb() in
> fuse_chan_set_initialized() to prevent this.
> 
> Fixes: 3393ff964e0f ("fuse: block request allocation until io-uring init is complete")
> Cc: [email protected]
> Signed-off-by: Joanne Koong <[email protected]>
> ---
>  fs/fuse/dev.c | 8 +++++++-
>  1 file changed, 7 insertions(+), 1 deletion(-)
> 
> diff --git a/fs/fuse/dev.c b/fs/fuse/dev.c
> index 5763a7cd3b37..b70c536d7e25 100644
> --- a/fs/fuse/dev.c
> +++ b/fs/fuse/dev.c
> @@ -85,7 +85,13 @@ void fuse_chan_set_initialized(struct fuse_chan *fch, struct fuse_chan_param *pa
>  
>  static bool fuse_block_alloc(struct fuse_chan *fch, bool for_background)
>  {
> -	return !fch->initialized || (for_background && fch->blocked) ||
> +	if (!fch->initialized)
> +		return true;
> +
> +	/* Pairs with smp_wmb() in fuse_chan_set_initialized() */
> +	smp_rmb();
> +
> +	return (for_background && fch->blocked) ||
>  	       (fch->io_uring && fch->connected && !fuse_uring_ready(fch));
>  }
>  

I wonder if we could remove smp_rmb() in fuse_get_req(), it follows
fuse_block_alloc().

Otherwise,

Reviewed-by: Bernd Schubert <[email protected]>