[PATCH] io_uring: preserve task restrictions across exec
이규민 <[email protected]> Fri, 31 Jul 2026 03:54:47 +0900
| Newsgroups | org.kernel.vger.io-uring,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAPLyb-a7bWCq0GzyOcztLm3-7H0GOP64JynosfO9k+yHy7diPw@mail.gmail.com> |
Per-task restrictions apply to all rings created by a task. Once
installed, they should not be dropped across exec. For a task that has
used io_uring, the exec cancellation path calls __io_uring_free().
This frees both the task context and the per-task restriction, so a
ring created after exec is unrestricted. Split task context cleanup
into io_uring_free_tctx(), and use it from the exec cancellation path.
Keep __io_uring_free() for final task cleanup, where both the context
and restriction are released. Fixes: ed82f35b926b ("io_uring: allow
registration of per-task restrictions") Cc: [email protected] #
7.1+ Signed-off-by: Kyumin Lee <[email protected]> ---
io_uring/cancel.c | 2 +- io_uring/tctx.c | 7 ++++++- io_uring/tctx.h |
1 + 3 files changed, 8 insertions(+), 2 deletions(-) diff --git
a/io_uring/cancel.c b/io_uring/cancel.c index
8c6fa6f367e4f..7d7820eab878b 100644 --- a/io_uring/cancel.c +++
b/io_uring/cancel.c @@ -660,6 +660,6 @@ __cold void
io_uring_cancel_generic(bool cancel_all, struct io_sq_data *sqd) */
atomic_dec(&tctx->in_cancel); /* for exec all current's requests
should be gone, kill tctx */ - __io_uring_free(current); +
io_uring_free_tctx(current); } } diff --git a/io_uring/tctx.c
b/io_uring/tctx.c index cc3bf2b3bdbc9..466b7300e208e 100644 ---
a/io_uring/tctx.c +++ b/io_uring/tctx.c @@ -43,7 +43,7 @@ static
struct io_wq *io_init_wq_offload(struct io_ring_ctx *ctx, return
io_wq_create(concurrency, &data); } -void __io_uring_free(struct
task_struct *tsk) +void io_uring_free_tctx(struct task_struct *tsk) {
struct io_uring_task *tctx = tsk->io_uring; struct io_tctx_node *node;
@@ -67,6 +67,11 @@ void __io_uring_free(struct task_struct *tsk)
kfree(tctx); tsk->io_uring = NULL; } +} + +void __io_uring_free(struct
task_struct *tsk) +{ + io_uring_free_tctx(tsk); if
(tsk->io_uring_restrict) { io_put_bpf_filters(tsk->io_uring_restrict);
kfree(tsk->io_uring_restrict); diff --git a/io_uring/tctx.h
b/io_uring/tctx.h index 2310d2a0c46d9..76ad1ad4594ef 100644 ---
a/io_uring/tctx.h +++ b/io_uring/tctx.h @@ -12,6 +12,7 @@ void
io_uring_del_tctx_node(unsigned long index); int
__io_uring_add_tctx_node(struct io_ring_ctx *ctx); int
__io_uring_add_tctx_node_from_submit(struct io_ring_ctx *ctx); void
io_uring_clean_tctx(struct io_uring_task *tctx); +void
io_uring_free_tctx(struct task_struct *tsk); void
io_uring_unreg_ringfd(void); int io_ringfd_register(struct io_ring_ctx
*ctx, void __user *__arg,