From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BF5D537F75B for ; Wed, 8 Apr 2026 09:06:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775639185; cv=none; b=orAN9r/Icg8PypkV/GHA4jEq6ETSXoBIQWIG0t0iijBfpzziVdUBWgWDhAq2aLNobwpIrjRu8FMd7hGw3Y1/zbotf0vn7IA6vy7k2+cHB5JMjLuKuXYg+aRmElFKt767J9RgbPOgzWI9jH+5RfVaBDI3IkoJMINbfeXpbxQ3NRM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775639185; c=relaxed/simple; bh=mdm06uitMSIygZ2FFukfM08Ps+ox3D4Zv39fmrbxrNY=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=tHLy2Rsjch4uS25Y/uA8R75F/bPT1HOD0ag9Pqj9xhxcy+BwIoOjItb/UvmxfTVbKuvjD9lge9PRPNW7mOLGIOGWD7RA+b792PpCq7Mrg5zKutEDwhZYJyQtxUgEcsLrPIn4bVZjx1Ksz5revnLdjVU2aXmAfktmY03IZCn7Oyg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=feoWZSg5; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="feoWZSg5" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4838c15e3cbso46429615e9.3 for ; Wed, 08 Apr 2026 02:06:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1775639178; x=1776243978; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=NIhuu56MjNTiGSChY1cvm3H2MZijRdRaDUQH6s036E4=; b=feoWZSg5P7kF6fv47qFKXPWQBO0DaaIXa0DCjqrqzw9KVM27JVjM7cHPTMTcFWpuUU iNGwJFRxRMOUV3gyZhNyV8qBzXB61duaqBegKxlsdh+LeUSfMaKik0HyxiPCx3CEus8s swh1/M0Q3BkAtyVp/4wH4knQe0sNB5qv4SZRqy2X9h64GHipaypAVd/YZn5oVjDoW6BN LzG6BEoI0oWsGqzIR3AbM7SYC5QqVNLkbmVR4TdXA3S2QJfcxunwUH6lQZ0s2nDf8x0d BrbpaD2svigGW7vHnpJkII3F4tz2ytDE13z1RU9Zo52suMdWNB3lsUwgeNLdSOuLCPoF Ih0Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775639178; x=1776243978; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=NIhuu56MjNTiGSChY1cvm3H2MZijRdRaDUQH6s036E4=; b=VjWkoDcIrFMG6RMSSzM1TBS7pZKcl1A9HKX+RplcSxY6XoAp3dh6RrNCgOi/nNqEgH M9iL8DaDrtwHomSmy8bKvTV2QfmvmD5fVUufTKfjx9b6spaque3Kqr4BGlHWXJLQD6I3 J0k5joPenEzg6SNKeMRvVuzge4eBRM1XkIGsHUiUBsrU0H/SDL5vpVr4fI4Xf4mKjPMi 144SG+faAiwnzPjUtcOHqJggobiGyF/eTg6P9LsfmKVdaTQE9riknDGQZnMwInZYhlkV oZHKzUNqc7qtc8fM1BXUxVBBkzOH0kVNUtU1rzowJ8blE54tdqsfiAn/NdOyhOQp9u+Z iZig== X-Forwarded-Encrypted: i=1; AJvYcCVnEZVFngd6plbj5kCIEo/B39rNnj3amrSru4GVHLMnLjjan5Sz01D490fQ7q2YKnLec3suzBt8CxyW/6E=@vger.kernel.org X-Gm-Message-State: AOJu0Yx5eGhvFPUkP65I1J/3nUy/hytfNlHwW385Jw1GlYDfzJyGwD9i T2wG3+KHM55xICDipKLKbOuh00Hwq1Btc2MXIhPnDLShGxTv9MrwNK2x X-Gm-Gg: AeBDiev8pIlG/UoM95e89ttbOJmX6dgTLYHd3tz7gl90zsCyN3bKm7vwr3py3MmCGuI 6m7WQocNwyh/Ow2tqw6MWw0SRLWe0Q+crHmIRsiKqWszYFw5h5UVJPnN8fGf0SOmSLpAeh6N8ZT XJh6eI/8QW9jM8LioOnCDDCfPqVQ+ZPFwqiOEjP9N6n8tpQifpkutpaGbeEs30+JYbstfOI/kcD HLDe1YNR0aYe3U1QL0okNNk+77necKiZugcCDpg+p9P0S2Vg4VXmkC4ByKSdF9ouRUBoV4k8J5t Ah3AUwCyUmPYQ1Dim9nvpGuoYka5dHVaINCO1uEIkD5YR/fSh7fXi3HNLmAfxqyPOmv6cqFHhfZ 8X8TL7vnoP7ipbxG6S7T2iAW55TrUPYThyNJK2f/BVNTiwHGwwQiFRTJgq2oWlErjm3Wgbyt05F 49UxCwJ9T8Shrwums300bcufksW5nbdBeHqEa95syhnpMq3wMXuOSiNrZ+bPpbb5n5EDZm+9UPt pFpFXvoxUvQlCPNjLgFgZP4+04GqXziWgcLZ1ePPK4vi9bEjImOkDMCoxg= X-Received: by 2002:a05:600c:4f4e:b0:488:a98b:b891 with SMTP id 5b1f17b1804b1-488a98bbd04mr227789945e9.3.1775639178483; Wed, 08 Apr 2026 02:06:18 -0700 (PDT) Received: from ?IPV6:2620:10d:c096:325:77fd:1068:74c8:af87? ([2620:10d:c092:600::1:eaba]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-488a952a03asm293928175e9.0.2026.04.08.02.06.17 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 08 Apr 2026 02:06:17 -0700 (PDT) Message-ID: Date: Wed, 8 Apr 2026 10:06:23 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 3/3] io_uring/zcrx: fix resource leak and double-free hazard in io_import_umem To: KobaK , Jens Axboe Cc: Keith Busch , Ming Lei , io-uring@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260408065408.2017967-1-kobak@nvidia.com> <20260408065408.2017967-4-kobak@nvidia.com> Content-Language: en-US From: Pavel Begunkov In-Reply-To: <20260408065408.2017967-4-kobak@nvidia.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 4/8/26 07:54, KobaK wrote: > From: Koba Ko > > io_import_umem() has two problems: > > 1. When io_account_mem() fails, the function returns an error but leaves > live pinned pages and sg_table in the mem struct without cleaning them > up. The caller happens to handle this today via io_zcrx_free_area() -> > io_release_area_mem(), but the contract is fragile. That was the intention for the caller to clean it up, but in either case the function has already been rewritten. In general, it seems you based your patches on top of an outdated tree. > 2. io_release_area_mem() doesn't NULL out mem->pages after kvfree(), > making it unsafe to call twice. Since io_zcrx_free_area() always > calls it during teardown, any earlier cleanup call would cause a > double-free. > > Fix both: populate mem fields before io_account_mem() so > io_release_area_mem() can do a proper cleanup on failure, and add > mem->pages = NULL in io_release_area_mem() to make it idempotent. > > Fixes: 262ab205180d2 ("io_uring/zcrx: account area memory") > Signed-off-by: Koba Ko > --- ... > > static void io_release_area_mem(struct io_zcrx_mem *mem) > @@ -236,6 +242,7 @@ static void io_release_area_mem(struct io_zcrx_mem *mem) > sg_free_table(mem->sgt); > mem->sgt = NULL; > kvfree(mem->pages); > + mem->pages = NULL; The entire struct io_zcrx_mem / area is freed right after, calling io_zcrx_free_area() multiple times for the same area is not allowed. -- Pavel Begunkov