From nobody Mon Feb 9 01:29:16 2026 Received: from mail-lj1-f227.google.com (mail-lj1-f227.google.com [209.85.208.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 59E022DCBFD for ; Mon, 5 Jan 2026 21:05:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.227 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767647155; cv=none; b=V8ToimbYSukaDryGXK4eqEeTDbSXUm0JhPuIe80yRPbk3gBYQUjkbFncWkWmZAVMRDCrFt1CSAF78yrc9IRQ7ziuBmZEsUCzfIAAX9IiqXWt1dfyRpviuvAYbnOEWbRLlEc6nWyB4VFy1WT2jqryJgqEGetZtg0hByR2rmqsmK0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767647155; c=relaxed/simple; bh=viSjjzfK+LuCMgJk4GB2ln1Ib+FEY2Yal2i0Mc2zreo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=sPwMtoaAeaeKtpIZwisRtnlLduRqo8v8HtSA5qvkAElqz1UKsZV8NjuxFheRHKKkm0vngf68fCS3ogmLwsm6uKvLlWozei8HnrNcjWtrmi71oP8tJaQyEGsczV5GqTtYhx2J3qaWV3W7XfbuIWoKYsJJO85GS8id9u3TINVTvx8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=purestorage.com; spf=fail smtp.mailfrom=purestorage.com; dkim=pass (2048-bit key) header.d=purestorage.com header.i=@purestorage.com header.b=HbuWoRsz; arc=none smtp.client-ip=209.85.208.227 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=purestorage.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=purestorage.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=purestorage.com header.i=@purestorage.com header.b="HbuWoRsz" Received: by mail-lj1-f227.google.com with SMTP id 38308e7fff4ca-37a533a9f26so367201fa.2 for ; Mon, 05 Jan 2026 13:05:53 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=purestorage.com; s=google2022; t=1767647151; x=1768251951; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=hwMUEMHMzWqjRsw9Dq1TO0aqVGzfagUbxeaLhQQuCYE=; b=HbuWoRszVnJvkyOC1DfO99GQ0fw4CPTt9p/VIFiF0usbnaIir61cxy7yI/tOI8O2JO ABXz/CDYr7UgOCWpJpxxJSF4jqaQs7De1zfjN/erafvoQcfZSq4VIA1wlPL61Yqdu1Am cHk1nUYwRvILTrd7SV5QYXiIs6SfL4rRmeaOol+WtWyCBw8r0Afq4q97o1tk2LPetqml magBshXSCrrSQE3M6OybOpS3EkRXYQo+m4MA1Yw7NZtWtrBnek+TlppDJq2eJuagPNMn FLCj3RKKnvcB1Wns9UmSypg4RXy1gDLS8dN3Xtzz6sGxzREInweKin1QL6kv4bls0AE3 le+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767647151; x=1768251951; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=hwMUEMHMzWqjRsw9Dq1TO0aqVGzfagUbxeaLhQQuCYE=; b=I2mT3WT7Ikuzwy5+Gy5Zk915n8vFjxMZ4yIku7XRmMEkfMNYaebxJJtaD6uoYGik0v Z+qBOG+/YKsBTEGffVCzwZCGDzjTcB8VFR3AtuQ6V2ZIiIqcWviO68ipJtdylFCxhWtP o9+E4BaweqBp6/cKOTbFmlyjYoWF3TWj62nop3veGAHsHrdq+WA8eVXGuBd3h3lIkA5P dRJ0nX8tiq2vUqeX3jpz6lWtYwlOaneYsNAadtgD9sShxsr5HNZA1UOhH4UFIEQJG345 0XXT90mOpJYBMdLiupsjMXWDXmQwC8Q75g8UvycucuIiY5PW1cqOrNKk8j0B5nov6N+1 ntnQ== X-Forwarded-Encrypted: i=1; AJvYcCWLRUvjKdT/0kcZXDCf1koNs80zzeCqZZnYvE15wGsrieh+WHhq9AoqSvvqhNCumP0/7sN+FlhS+/n+YFM=@vger.kernel.org X-Gm-Message-State: AOJu0YweYMp9gv+czoC+wEopHa+9reR5PRqFCEtqVPSCPyIq2pIbB22C L/ki3ZW8IjMpQrdkIL5zP8PguQA0Bsl6fABUZsAvDRFcljUJdeSC/GK/Lrt2CtDf4AJPX8Ormin 54cUllCQj06m7PauC0PBCRnmj8v7bJGutPgBM X-Gm-Gg: AY/fxX41dSQf1d1j+97Brg21+7o7GPSKpot58h3xQCt8c02d+VKRTkxjvDMcv4alRDi buTpvdrWMxfSzxABfJ7wFXZFKMTQ51pHZ6iVf9TNZsVl6TwloDtt6LVRhQ4prk+ArLuY7LAJ+A2 OIvLqQ997V8oAzpaJiNyRpmrxyInCgCzEIUBM8e90+SG8tCaC1HCPiMeEoeJ5BU4X9KkCDCtN7Z beYjZ+VoufnYQeW8rmKW6dyXYpiiYUaB+y7CSjASAHHRX0OfZsVYkzO2QNaFM+qNG+/flgR+6l9 5STcn73C7IfRgouvDVjk/WXoVf2YRkAXcPSMC47IJnFiOUH9sfiKpCFWzfN/b0MYXWIVVlaPtMq K3zuKtRu4x3Ui49Q/c0L1zdph+iKJ+MlGGU1Pn9q0rg== X-Google-Smtp-Source: AGHT+IHq9xfUdD56ExprIKveYN6ABXutsP6x2ol6BJKZfSOWzDgQrOrFr+EvNDNHvpDTb78tIl0MqfgDkOUQ X-Received: by 2002:a05:6512:158b:b0:597:d7d6:eae1 with SMTP id 2adb3069b0e04-59b6527a359mr167691e87.2.1767647151230; Mon, 05 Jan 2026 13:05:51 -0800 (PST) Received: from c7-smtp-2023.dev.purestorage.com ([208.88.159.128]) by smtp-relay.gmail.com with ESMTPS id 2adb3069b0e04-59b65d91980sm22466e87.41.2026.01.05.13.05.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 05 Jan 2026 13:05:51 -0800 (PST) X-Relaying-Domain: purestorage.com Received: from dev-csander.dev.purestorage.com (dev-csander.dev.purestorage.com [10.49.34.222]) by c7-smtp-2023.dev.purestorage.com (Postfix) with ESMTP id 5ECA5341BBA; Mon, 5 Jan 2026 14:05:49 -0700 (MST) Received: by dev-csander.dev.purestorage.com (Postfix, from userid 1557716354) id 5B270E41BCB; Mon, 5 Jan 2026 14:05:49 -0700 (MST) From: Caleb Sander Mateos To: Jens Axboe Cc: Joanne Koong , io-uring@vger.kernel.org, linux-kernel@vger.kernel.org, Caleb Sander Mateos Subject: [PATCH v7 2/3] io_uring/msg_ring: drop unnecessary submitter_task checks Date: Mon, 5 Jan 2026 14:05:41 -0700 Message-ID: <20260105210543.3471082-3-csander@purestorage.com> X-Mailer: git-send-email 2.45.2 In-Reply-To: <20260105210543.3471082-1-csander@purestorage.com> References: <20260105210543.3471082-1-csander@purestorage.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" __io_msg_ring_data() checks that the target_ctx isn't IORING_SETUP_R_DISABLED before calling io_msg_data_remote(), which calls io_msg_remote_post(). So submitter_task can't be modified concurrently with the read in io_msg_remote_post(). Additionally, submitter_task must exist, as io_msg_data_remote() is only called for io_msg_need_remote(), i.e. task_complete is set, which requires IORING_SETUP_DEFER_TASKRUN, which in turn requires IORING_SETUP_SINGLE_ISSUER. And submitter_task is assigned in io_uring_create() or io_register_enable_rings() before enabling any IORING_SETUP_SINGLE_ISSUER io_ring_ctx. Similarly, io_msg_send_fd() checks IORING_SETUP_R_DISABLED and io_msg_need_remote() before calling io_msg_fd_remote(). submitter_task therefore can't be modified concurrently with the read in io_msg_fd_remote() and must be non-null. io_register_enable_rings() can't run concurrently because it's called from io_uring_register() -> __io_uring_register() with uring_lock held. Thus, replace the READ_ONCE() and WRITE_ONCE() of submitter_task with plain loads and stores. And remove the NULL checks of submitter_task in io_msg_remote_post() and io_msg_fd_remote(). Signed-off-by: Caleb Sander Mateos Reviewed-by: Joanne Koong --- io_uring/io_uring.c | 7 +------ io_uring/msg_ring.c | 18 +++++------------- io_uring/register.c | 2 +- 3 files changed, 7 insertions(+), 20 deletions(-) diff --git a/io_uring/io_uring.c b/io_uring/io_uring.c index ec27fafcb213..b31d88295297 100644 --- a/io_uring/io_uring.c +++ b/io_uring/io_uring.c @@ -3663,17 +3663,12 @@ static __cold int io_uring_create(struct io_ctx_con= fig *config) ret =3D -EFAULT; goto err; } =20 if (ctx->flags & IORING_SETUP_SINGLE_ISSUER - && !(ctx->flags & IORING_SETUP_R_DISABLED)) { - /* - * Unlike io_register_enable_rings(), don't need WRITE_ONCE() - * since ctx isn't yet accessible from other tasks - */ + && !(ctx->flags & IORING_SETUP_R_DISABLED)) ctx->submitter_task =3D get_task_struct(current); - } =20 file =3D io_uring_get_file(ctx); if (IS_ERR(file)) { ret =3D PTR_ERR(file); goto err; diff --git a/io_uring/msg_ring.c b/io_uring/msg_ring.c index 87b4d306cf1b..57ad0085869a 100644 --- a/io_uring/msg_ring.c +++ b/io_uring/msg_ring.c @@ -78,26 +78,21 @@ static void io_msg_tw_complete(struct io_tw_req tw_req,= io_tw_token_t tw) io_add_aux_cqe(ctx, req->cqe.user_data, req->cqe.res, req->cqe.flags); kfree_rcu(req, rcu_head); percpu_ref_put(&ctx->refs); } =20 -static int io_msg_remote_post(struct io_ring_ctx *ctx, struct io_kiocb *re= q, +static void io_msg_remote_post(struct io_ring_ctx *ctx, struct io_kiocb *r= eq, int res, u32 cflags, u64 user_data) { - if (!READ_ONCE(ctx->submitter_task)) { - kfree_rcu(req, rcu_head); - return -EOWNERDEAD; - } req->opcode =3D IORING_OP_NOP; req->cqe.user_data =3D user_data; io_req_set_res(req, res, cflags); percpu_ref_get(&ctx->refs); req->ctx =3D ctx; req->tctx =3D NULL; req->io_task_work.func =3D io_msg_tw_complete; io_req_task_work_add_remote(req, IOU_F_TWQ_LAZY_WAKE); - return 0; } =20 static int io_msg_data_remote(struct io_ring_ctx *target_ctx, struct io_msg *msg) { @@ -109,12 +104,12 @@ static int io_msg_data_remote(struct io_ring_ctx *tar= get_ctx, return -ENOMEM; =20 if (msg->flags & IORING_MSG_RING_FLAGS_PASS) flags =3D msg->cqe_flags; =20 - return io_msg_remote_post(target_ctx, target, msg->len, flags, - msg->user_data); + io_msg_remote_post(target_ctx, target, msg->len, flags, msg->user_data); + return 0; } =20 static int __io_msg_ring_data(struct io_ring_ctx *target_ctx, struct io_msg *msg, unsigned int issue_flags) { @@ -125,11 +120,11 @@ static int __io_msg_ring_data(struct io_ring_ctx *tar= get_ctx, return -EINVAL; if (!(msg->flags & IORING_MSG_RING_FLAGS_PASS) && msg->dst_fd) return -EINVAL; /* * Keep IORING_SETUP_R_DISABLED check before submitter_task load - * in io_msg_data_remote() -> io_msg_remote_post() + * in io_msg_data_remote() -> io_req_task_work_add_remote() */ if (smp_load_acquire(&target_ctx->flags) & IORING_SETUP_R_DISABLED) return -EBADFD; =20 if (io_msg_need_remote(target_ctx)) @@ -225,14 +220,11 @@ static void io_msg_tw_fd_complete(struct callback_hea= d *head) =20 static int io_msg_fd_remote(struct io_kiocb *req) { struct io_ring_ctx *ctx =3D req->file->private_data; struct io_msg *msg =3D io_kiocb_to_cmd(req, struct io_msg); - struct task_struct *task =3D READ_ONCE(ctx->submitter_task); - - if (unlikely(!task)) - return -EOWNERDEAD; + struct task_struct *task =3D ctx->submitter_task; =20 init_task_work(&msg->tw, io_msg_tw_fd_complete); if (task_work_add(task, &msg->tw, TWA_SIGNAL)) return -EOWNERDEAD; =20 diff --git a/io_uring/register.c b/io_uring/register.c index 12318c276068..8104728af294 100644 --- a/io_uring/register.c +++ b/io_uring/register.c @@ -179,11 +179,11 @@ static int io_register_enable_rings(struct io_ring_ct= x *ctx) { if (!(ctx->flags & IORING_SETUP_R_DISABLED)) return -EBADFD; =20 if (ctx->flags & IORING_SETUP_SINGLE_ISSUER && !ctx->submitter_task) { - WRITE_ONCE(ctx->submitter_task, get_task_struct(current)); + ctx->submitter_task =3D get_task_struct(current); /* * Lazy activation attempts would fail if it was polled before * submitter_task is set. */ if (wq_has_sleeper(&ctx->poll_wq)) --=20 2.45.2