From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1F4E936C0D6 for ; Mon, 8 Jun 2026 13:33:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780925614; cv=none; b=XlYRyiD7T6Qk3R4c1kXE4LW7mWtylriJLnCRUb9hJ9q01gN583hwtffLjTy+Xs7Dh1hfZoEZAJ559NXXYPZTGaXdXDTtgbnGzisd1Lug+YYRepzQzYfVobFdmaQjVoUrwTvls9KqYqRu+Ab+zmG0Loev2nQd+e4RSHRTeoYti8o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780925614; c=relaxed/simple; bh=Xmn251nvSpJo0undebzXVap0KXqK+G3jWZlPawuj8fg=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=RzOSTL0/qTs/lw8mB5R2SmE6NsZiLJdTlcJQesIVjojKSKXJpI7iQmAi/nDjLvip5KSJZQEB0ENAIpDRI/VbvgIgJ31bmzmOw5y8AgfwBRnrQSxhyGkH9y9/obtgWt5ViDZIKTOj6SnTk+PKRarfsJr+jzfGFmKDqg5oVDlXn/I= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XroM7rti; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XroM7rti" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-36b9b15af73so3850296a91.0 for ; Mon, 08 Jun 2026 06:33:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780925612; x=1781530412; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=jE4e+Ch7YZ/ecmySo10mEfolKNwDMzJHte9df/q8qqk=; b=XroM7rti2XYztFPW+x69RSxj0QdNYcr/b+VDMJWn0L+PQk1r5tkx6R63urg3Nb562/ D5J9P2OPUwbO0Ov9fjXUoOGUI5bmrz/Rnh+Bhji/kBA1qcGTFFXm5evaglLzIXB6+v2V gC9Fctxi+NxQ5ePSplUhCITBPIwAmbG9sOOEnOBaTPELf6185uKRwciT7/YxNHOBB6go o1PKVvCJ1gRrBDqThZGUtfraw+Dp9wshRWMv9Hf0QKhnrmZtqbdvOUdqmgTgG5YGyn3u ZflBfBCTzHvxdq30j+2aHyFdQbdeYHAS2tpFonEdxhYDxJlBtPy24+cFdCf16wpzks6E HafA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780925612; x=1781530412; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=jE4e+Ch7YZ/ecmySo10mEfolKNwDMzJHte9df/q8qqk=; b=XIDNGhKJTJ5piVZxa6fb64wiuoFnfM9u2Jk2IjH44Y5hwXy9KfW52dwwbbPb55QEoO bJC6W/mAScN25hYZA31BYp/Zz3v6mOCqi5SnN7UmG+bwFgd3raiFx/LLHiPItJ65vPj7 Ixy9MckcWSBdBjzUj1fC0SU76Wi/+oEnCtI+9na12Rr0Z+n99EzAnPVVzIcwmAKsbxyn UtlEezdy6HVAPkmKNawDeWxEcuWiH2vlF/eIgBArF72ASHmVQlcF2/fN6JayRidQHEUe Y6870wB4fV5KctKhfhvH5+bQ8GX1bttQg47RnYfjrGMFh7gxHSdObqqEL2HlfCrWXAl9 d18Q== X-Forwarded-Encrypted: i=1; AFNElJ/IMJQnNTSJqXLa+nEjkV6CQ2pMoqWzzvDkfXE+QK0k7sIKnLVuDqlAxl4svZZpGBOA9l47++egzJmf32E=@vger.kernel.org X-Gm-Message-State: AOJu0YyC5Ve1WDakpI3hjNWcGoLAbuSMu5RvW/WOtz8mBcVwjK7Zf7EV m8l0Hs23/CXTMiojilhBWOafWVWksU1SZj8N6DT8aB2qjSooERGd26Dl X-Gm-Gg: Acq92OHnmNRWH80u/OcRy8OaX9x/oAiTgbVUY1jZVzoo9mDRTCtRRbh/mtuEzk/FMia zbmlohB0mTnOFetWVHDyW3KcjkZtFWymdk6u8G+w2+N2vPcksuNf0TMZ2uhw9RP4R1p3UUMKL+S 0Lrfj2lBwWs2dRV58o6aPk77CDJw/SVRoH8fJOGjuR2UFr0ZeNtbfY9MkewADSipc25+rWWIA9S wlXABONBUtsRpueoEyOA5D+/1pnSD5MUyHYS1tx2IdlSIsLPUlZIrKQ9pEK1THBocCBwJmJvohx wprUXrgrwjLVh1d59uojgksRZFrjWcenNpIDw2bIE5PnP7+cS+KNRnIm5h6v/RQVj4/LqpKHcPF rNR2lrXwikVp/j1qnuX0IY+Bgj9RgFmf27/fqGTlaliUhn8fBBbZ9IoVcBPucANHrmTYPYcqkN0 RnB5mfqckVGlK560j9vzUcEPcOQr30DTG0YRqYnwGepSlQw7itdmt5 X-Received: by 2002:a17:90b:2d4e:b0:369:7421:75c3 with SMTP id 98e67ed59e1d1-370f096ab5emr14716407a91.16.1780925612269; Mon, 08 Jun 2026 06:33:32 -0700 (PDT) Received: from n232-175-066.byted.org ([36.110.163.106]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84282379db0sm17284571b3a.24.2026.06.08.06.33.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 08 Jun 2026 06:33:31 -0700 (PDT) From: guzebing To: Jens Axboe Cc: io-uring@vger.kernel.org, linux-kernel@vger.kernel.org, guzebing Subject: [PATCH] io_uring/register: preserve SQ array entries on resize Date: Mon, 8 Jun 2026 21:33:16 +0800 Message-Id: <20260608133316.3656440-1-guzebing1612@gmail.com> X-Mailer: git-send-email 2.20.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Ring resizing copies pending SQEs from the old SQE array into the new one so submissions queued before the resize can still be consumed afterwards. That copy currently walks the SQ head/tail range directly. This is only correct when there is no SQ array indirection. With a regular SQ array, each pending SQ entry contains an index into the SQE array. After resize, ctx->sq_array is repointed at the newly allocated array, so pending entries lose their old logical-to-physical mapping and may submit the wrong SQE. Remember the old and new SQ arrays while migrating pending SQ entries. For each pending entry, copy the SQE selected by the old array into the new destination slot and rebuild the new array entry to point at the copied SQE. Keep invalid user-provided entries invalid so the normal submission path still drops them after resize. Fixes: 79cfe9e59c2a1 ("io_uring/register: add IORING_REGISTER_RESIZE_RINGS") Signed-off-by: guzebing --- io_uring/register.c | 31 +++++++++++++++++++++---------- 1 file changed, 21 insertions(+), 10 deletions(-) diff --git a/io_uring/register.c b/io_uring/register.c index dce5e2f9cf770..02bc103bcc9d5 100644 --- a/io_uring/register.c +++ b/io_uring/register.c @@ -503,6 +503,7 @@ static int io_register_resize_rings(struct io_ring_ctx *ctx, void __user *arg) unsigned i, tail, old_head; struct io_uring_params *p = &config.p; struct io_rings_layout *rl = &config.layout; + u32 *o_sq_array, *n_sq_array = NULL; int ret; memset(&config, 0, sizeof(config)); @@ -589,6 +590,9 @@ static int io_register_resize_rings(struct io_ring_ctx *ctx, void __user *arg) ctx->rings = NULL; o.sq_sqes = ctx->sq_sqes; ctx->sq_sqes = NULL; + o_sq_array = ctx->sq_array; + if (!(ctx->flags & IORING_SETUP_NO_SQARRAY)) + n_sq_array = (u32 *)((char *)n.rings + rl->sq_array_offset); /* * Now copy SQ and CQ entries, if any. If either of the destination @@ -599,20 +603,27 @@ static int io_register_resize_rings(struct io_ring_ctx *ctx, void __user *arg) if (tail - old_head > p->sq_entries) goto overflow; for (i = old_head; i < tail; i++) { - unsigned index, dst_mask, src_mask; + unsigned int dst, src; size_t sq_size; - index = i; + dst = i & (p->sq_entries - 1); + src = i & (ctx->sq_entries - 1); + if (n_sq_array) { + src = READ_ONCE(o_sq_array[src]); + if (unlikely(src >= ctx->sq_entries)) { + WRITE_ONCE(n_sq_array[dst], UINT_MAX); + continue; + } + WRITE_ONCE(n_sq_array[dst], dst); + } + sq_size = sizeof(struct io_uring_sqe); - src_mask = ctx->sq_entries - 1; - dst_mask = p->sq_entries - 1; if (ctx->flags & IORING_SETUP_SQE128) { - index <<= 1; + dst <<= 1; + src <<= 1; sq_size <<= 1; - src_mask = (ctx->sq_entries << 1) - 1; - dst_mask = (p->sq_entries << 1) - 1; } - memcpy(&n.sq_sqes[index & dst_mask], &o.sq_sqes[index & src_mask], sq_size); + memcpy(&n.sq_sqes[dst], &o.sq_sqes[src], sq_size); } WRITE_ONCE(n.rings->sq.head, old_head); WRITE_ONCE(n.rings->sq.tail, tail); @@ -655,8 +666,8 @@ static int io_register_resize_rings(struct io_ring_ctx *ctx, void __user *arg) WRITE_ONCE(n.rings->cq_overflow, READ_ONCE(o.rings->cq_overflow)); /* all done, store old pointers and assign new ones */ - if (!(ctx->flags & IORING_SETUP_NO_SQARRAY)) - ctx->sq_array = (u32 *)((char *)n.rings + rl->sq_array_offset); + if (n_sq_array) + ctx->sq_array = n_sq_array; ctx->sq_entries = p->sq_entries; ctx->cq_entries = p->cq_entries; -- 2.20.1