Re: [PATCH v2 1/3] fuse: fix missing barrier when checking io-uring readiness
Bernd Schubert <[email protected]> Thu, 16 Jul 2026 00:26:40 +0200
| Newsgroups | dev.linux.lists.fuse-devel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On 7/15/26 19:43, Joanne Koong wrote:
> fuse_block_alloc() reads fch->initialized and then fch->io_uring.
> fch->io_uring is set before fch->initialized, ordered by the smp_wmb()
> in fuse_chan_set_intialized(), but fuse_block_alloc() has no matching
> read barrier between the two loads.
>
> This may lead a CPU to observe fch->initialized=1 but fch->io_uring=0,
> and skip the check that blocks request allocation until the io-uring
> queues are ready. This can reintroduce the lock-order inversion deadlock
> that commit 3393ff964e0f prevents.
>
> Add an smp_rmb() barrier to pair with the smp_wmb() in
> fuse_chan_set_initialized() to prevent this.
>
> Fixes: 3393ff964e0f ("fuse: block request allocation until io-uring init is complete")
> Cc: [email protected]
> Signed-off-by: Joanne Koong <[email protected]>
> ---
> fs/fuse/dev.c | 8 +++++++-
> 1 file changed, 7 insertions(+), 1 deletion(-)
>
> diff --git a/fs/fuse/dev.c b/fs/fuse/dev.c
> index 5763a7cd3b37..b70c536d7e25 100644
> --- a/fs/fuse/dev.c
> +++ b/fs/fuse/dev.c
> @@ -85,7 +85,13 @@ void fuse_chan_set_initialized(struct fuse_chan *fch, struct fuse_chan_param *pa
>
> static bool fuse_block_alloc(struct fuse_chan *fch, bool for_background)
> {
> - return !fch->initialized || (for_background && fch->blocked) ||
> + if (!fch->initialized)
> + return true;
> +
> + /* Pairs with smp_wmb() in fuse_chan_set_initialized() */
> + smp_rmb();
> +
> + return (for_background && fch->blocked) ||
> (fch->io_uring && fch->connected && !fuse_uring_ready(fch));
> }
>
I wonder if we could remove smp_rmb() in fuse_get_req(), it follows
fuse_block_alloc().
Otherwise,
Reviewed-by: Bernd Schubert <[email protected]>