Re: [PATCH 6/6] io_uring/epoll: disallow adding an epoll file to an epoll context

Xi Ruoyao <[email protected]> Wed, 29 Jul 2026 09:29:01 +0800
Newsgroups org.kernel.vger.io-uring,org.kernel.vger.linux-fsdevel
Message-ID <[email protected]>
On Thu, 2026-05-14 at 08:07 -0600, Jens Axboe wrote:
> One of the nastier things about epoll is how it allows adding epoll
> files to epoll contexts. This leads to all sorts of loop detection
> code, and has been a source of issues in the past.
>=20
> Arguably adding IORING_EPOLL_CTL is a historical mistake on the
> io_uring side, but we're kind of stuck with it now as it does seem
> to be in use according to code searches. But we can at least minimize
> the damage a bit and just disallow this part of epoll, where nesting
> issues can arise.

libuv uses this ... thing and there's even a test case against
exercising the code path adding an epoll file:

- https://github.com/libuv/libuv/commit/3b6a1a14caee
- https://github.com/libuv/libuv/blob/09591002d38e/test/test-poll.c#L690

And the test triggers an abort on the EINVAL at
https://github.com/libuv/libuv/blob/09591002d38e/src/unix/linux.c#L1360

I'm unsure what to do here.

> Suggested-by: Linus Torvalds <[email protected]>
> Signed-off-by: Jens Axboe <[email protected]>
> ---
> =C2=A0io_uring/epoll.c | 3 +++
> =C2=A01 file changed, 3 insertions(+)
>=20
> diff --git a/io_uring/epoll.c b/io_uring/epoll.c
> index b9db8bde27ec..eecd748cad01 100644
> --- a/io_uring/epoll.c
> +++ b/io_uring/epoll.c
> @@ -62,6 +62,9 @@ int io_epoll_ctl(struct io_kiocb *req, unsigned int
> issue_flags)
> =C2=A0	CLASS(fd, tf)(ie->fd);
> =C2=A0	if (fd_empty(tf))
> =C2=A0		return -EBADF;
> +	/* disallow adding an epoll context to another epoll context
> */
> +	if (ie->op =3D=3D EPOLL_CTL_ADD && is_file_epoll(fd_file(tf)))
> +		return -EINVAL;
> =C2=A0
> =C2=A0	key.file =3D fd_file(tf);
> =C2=A0	key.fd =3D ie->fd;

--=20
Xi Ruoyao <[email protected]>