io_uring: synchronise IOPOLL on task_submit fail
authorPavel Begunkov <asml.silence@gmail.com>
Tue, 12 Jan 2021 21:17:24 +0000 (21:17 +0000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 17 Jan 2021 13:16:52 +0000 (14:16 +0100)
commit 81b6d05ccad4f3d8a9dfb091fb46ad6978ee40e4 upstream

io_req_task_submit() might be called for IOPOLL, do the fail path under
uring_lock to comply with IOPOLL synchronisation based solely on it.

Cc: stable@vger.kernel.org # 5.5+
Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/io_uring.c

index 1f798c5..3974b4f 100644 (file)
@@ -2047,14 +2047,15 @@ static void io_req_task_cancel(struct callback_head *cb)
 static void __io_req_task_submit(struct io_kiocb *req)
 {
        struct io_ring_ctx *ctx = req->ctx;
+       bool fail;
 
-       if (!__io_sq_thread_acquire_mm(ctx)) {
-               mutex_lock(&ctx->uring_lock);
+       fail = __io_sq_thread_acquire_mm(ctx);
+       mutex_lock(&ctx->uring_lock);
+       if (!fail)
                __io_queue_sqe(req, NULL);
-               mutex_unlock(&ctx->uring_lock);
-       } else {
+       else
                __io_req_task_cancel(req, -EFAULT);
-       }
+       mutex_unlock(&ctx->uring_lock);
 }
 
 static void io_req_task_submit(struct callback_head *cb)