mirror of
https://github.com/linux-msm/laptops-kernel.git
synced 2026-08-13 14:19:53 -07:00
Merge tag 'io_uring-7.2-20260717' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux
Pull io_uring fixes from Jens Axboe: - Fix a use-after-free in the bpf-ops struct_ops path, where the same io_uring_bpf_ops map could be registered more than once. - Fix the deferred iovec free for the provided-buffer grow path, which could leave the caller with a dangling iovec and result in repeated frees. Follow-up to the earlier fix in this series. - Zero-check the unused addr3/pad2 SQE fields for unlinkat * tag 'io_uring-7.2-20260717' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: io_uring/bpf-ops: reject re-registration of an already-bound ops io_uring/fs: check unused sqe fields for unlinkat io_uring/kbuf: free the replaced iovec after a successful grow
This commit is contained in:
@@ -168,6 +168,8 @@ static int io_install_bpf(struct io_ring_ctx *ctx, struct io_uring_bpf_ops *ops)
|
||||
|
||||
if (ctx->bpf_ops)
|
||||
return -EBUSY;
|
||||
if (ops->priv)
|
||||
return -EBUSY;
|
||||
if (WARN_ON_ONCE(!ops->loop_step))
|
||||
return -EINVAL;
|
||||
|
||||
|
||||
+2
-1
@@ -110,7 +110,8 @@ int io_unlinkat_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe)
|
||||
const char __user *fname;
|
||||
int err;
|
||||
|
||||
if (sqe->off || sqe->len || sqe->buf_index || sqe->splice_fd_in)
|
||||
if (sqe->off || sqe->len || sqe->buf_index || sqe->splice_fd_in ||
|
||||
sqe->addr3 || sqe->__pad2[0])
|
||||
return -EINVAL;
|
||||
if (unlikely(req->flags & REQ_F_FIXED_FILE))
|
||||
return -EBADF;
|
||||
|
||||
+2
-2
@@ -328,8 +328,8 @@ static int io_ring_buffers_peek(struct io_kiocb *req, struct buf_sel_arg *arg,
|
||||
buf = io_ring_head_to_buf(br, ++head, bl->mask);
|
||||
} while (--nr_iovs);
|
||||
|
||||
if (arg->mode & KBUF_MODE_FREE)
|
||||
kfree(arg->iovs);
|
||||
if (arg->iovs != org_iovs && (arg->mode & KBUF_MODE_FREE))
|
||||
kfree(org_iovs);
|
||||
|
||||
if (head == tail)
|
||||
req->flags |= REQ_F_BL_EMPTY;
|
||||
|
||||
Reference in New Issue
Block a user