Re: [PATCH 6/6] io_uring/epoll: disallow adding an epoll file to an epoll context
Xi Ruoyao <[email protected]> Wed, 29 Jul 2026 09:29:01 +0800
| Newsgroups | org.kernel.vger.io-uring,org.kernel.vger.linux-fsdevel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 2026-05-14 at 08:07 -0600, Jens Axboe wrote: > One of the nastier things about epoll is how it allows adding epoll > files to epoll contexts. This leads to all sorts of loop detection > code, and has been a source of issues in the past. >=20 > Arguably adding IORING_EPOLL_CTL is a historical mistake on the > io_uring side, but we're kind of stuck with it now as it does seem > to be in use according to code searches. But we can at least minimize > the damage a bit and just disallow this part of epoll, where nesting > issues can arise. libuv uses this ... thing and there's even a test case against exercising the code path adding an epoll file: - https://github.com/libuv/libuv/commit/3b6a1a14caee - https://github.com/libuv/libuv/blob/09591002d38e/test/test-poll.c#L690 And the test triggers an abort on the EINVAL at https://github.com/libuv/libuv/blob/09591002d38e/src/unix/linux.c#L1360 I'm unsure what to do here. > Suggested-by: Linus Torvalds <[email protected]> > Signed-off-by: Jens Axboe <[email protected]> > --- > =C2=A0io_uring/epoll.c | 3 +++ > =C2=A01 file changed, 3 insertions(+) >=20 > diff --git a/io_uring/epoll.c b/io_uring/epoll.c > index b9db8bde27ec..eecd748cad01 100644 > --- a/io_uring/epoll.c > +++ b/io_uring/epoll.c > @@ -62,6 +62,9 @@ int io_epoll_ctl(struct io_kiocb *req, unsigned int > issue_flags) > =C2=A0 CLASS(fd, tf)(ie->fd); > =C2=A0 if (fd_empty(tf)) > =C2=A0 return -EBADF; > + /* disallow adding an epoll context to another epoll context > */ > + if (ie->op =3D=3D EPOLL_CTL_ADD && is_file_epoll(fd_file(tf))) > + return -EINVAL; > =C2=A0 > =C2=A0 key.file =3D fd_file(tf); > =C2=A0 key.fd =3D ie->fd; --=20 Xi Ruoyao <[email protected]>