mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Yao Kai <yaokai34@huawei.com>
To: <asml.silence@gmail.com>, <axboe@kernel.dk>
Cc: <io-uring@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
	<liuyongqiang13@huawei.com>
Subject: [PATCH] io_uring: initialize task context before running the BPF loop
Date: Tue, 22 Sep 2026 14:54:43 +0800	[thread overview]
Message-ID: <20260922065443.359417-1-yaokai34@huawei.com> (raw)

Submitting SQEs through an io_uring BPF loop can trigger a NULL pointer
dereference in io_submit_sqes(), as shown by the following arm64 report:

  [ 2049.380301] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
  [ 2049.388788] pc : io_submit_sqes+0x48/0x6c4
  [ 2049.389153] lr : bpf_io_uring_submit_sqes+0x10/0x1c
  [ 2049.396310] Call trace:
  [ 2049.396531]  io_submit_sqes+0x48/0x6c4 (P)
  [ 2049.396893]  bpf_io_uring_submit_sqes+0x10/0x1c
  [ 2049.397293]  bpf_prog_1a2a95cb199202b5+0x3c/0x68
  [ 2049.397699]  bpf__io_uring_bpf_ops_loop_step+0x5c/0x94
  [ 2049.398149]  io_run_loop+0x70/0x2e4
  [ 2049.398461]  __arm64_sys_io_uring_enter+0xf0/0x710
  [ 2049.398882]  invoke_syscall+0x54/0x10c
  [ 2049.399414]  el0_svc_common.constprop.0+0x40/0xe0
  [ 2049.399829]  do_el0_svc+0x1c/0x28
  [ 2049.400125]  el0_svc+0x38/0x1d0
  [ 2049.400409]  el0t_64_sync_handler+0xa0/0xe4
  [ 2049.400779]  el0t_64_sync+0x198/0x19c

io_uring_enter() dispatches to io_run_loop() before reaching the normal
submission path's io_uring_add_tctx_node() call. The loop only checks
whether the caller is allowed to run task work; it does not initialize
current->io_uring or associate the task with the ring. A BPF call to
bpf_io_uring_submit_sqes() then reaches io_get_task_refs(), which assumes
that current->io_uring is valid.

A ring created with IORING_SETUP_R_DISABLED, IORING_SETUP_SINGLE_ISSUER
and IORING_SETUP_DEFER_TASKRUN can be enabled by a different task that
has never used io_uring. Enabling the ring makes that task the submitter
without allocating its io_uring task context. Its first BPF-driven
submission of a pending SQE can therefore cause a kernel Oops.

Call io_uring_add_tctx_node() in io_run_loop() before invoking the loop
and propagate any initialization error. Do this before acquiring
uring_lock, since task context setup may acquire the same mutex. This
also establishes the task-to-ring association used for cancellation.

Fixes: 033af2b3eb19 ("io_uring: introduce callback driven main loop")
Signed-off-by: Yao Kai <yaokai34@huawei.com>
---
 io_uring/loop.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/io_uring/loop.c b/io_uring/loop.c
index bbbb6ef14e6a..c923cae6dfc7 100644
--- a/io_uring/loop.c
+++ b/io_uring/loop.c
@@ -2,6 +2,7 @@
 #include "io_uring.h"
 #include "wait.h"
 #include "loop.h"
+#include "tctx.h"
 
 static inline int io_loop_nr_cqes(const struct io_ring_ctx *ctx,
 				  const struct iou_loop_params *lp)
@@ -84,6 +85,10 @@ int io_run_loop(struct io_ring_ctx *ctx)
 	if (!io_allowed_run_tw(ctx))
 		return -EEXIST;
 
+	ret = io_uring_add_tctx_node(ctx);
+	if (unlikely(ret))
+		return ret;
+
 	mutex_lock(&ctx->uring_lock);
 	ret = __io_run_loop(ctx);
 	mutex_unlock(&ctx->uring_lock);
-- 
2.54.0


             reply	other threads:[~2026-09-22  6:36 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22  6:54 Yao Kai [this message]
2026-09-22 11:58 ` Pavel Begunkov
2026-09-23  1:43   ` [PATCH v2] " Yao Kai
2026-09-23 11:20     ` Jens Axboe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922065443.359417-1-yaokai34@huawei.com \
    --to=yaokai34@huawei.com \
    --cc=asml.silence@gmail.com \
    --cc=axboe@kernel.dk \
    --cc=io-uring@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=liuyongqiang13@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®