diff mbox series

[1/1] io_uring: fix false positive KASAN warnings

Message ID c6fbf7a82a341e66a0007c76eefd9d57f2d3ba51.1691541473.git.asml.silence@gmail.com (mailing list archive)
State New
Headers show
Series [1/1] io_uring: fix false positive KASAN warnings | expand

Commit Message

Pavel Begunkov Aug. 9, 2023, 12:22 p.m. UTC
io_req_local_work_add() peeks into the work list, which can be executed
in the meanwhile. It's completely fine without KASAN as we're in an RCU
read section and it's SLAB_TYPESAFE_BY_RCU. With KASAN though it may
trigger a false positive warning because internal io_uring caches are
sanitised.

Remove sanitisation from the io_uring request cache for now.

Cc: stable@vger.kernel.org
Fixes: 8751d15426a31 ("io_uring: reduce scheduling due to tw")
Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
---
 io_uring/io_uring.c | 1 -
 io_uring/io_uring.h | 1 -
 2 files changed, 2 deletions(-)

Comments

Jens Axboe Aug. 9, 2023, 3:36 p.m. UTC | #1
On Wed, 09 Aug 2023 13:22:16 +0100, Pavel Begunkov wrote:
> io_req_local_work_add() peeks into the work list, which can be executed
> in the meanwhile. It's completely fine without KASAN as we're in an RCU
> read section and it's SLAB_TYPESAFE_BY_RCU. With KASAN though it may
> trigger a false positive warning because internal io_uring caches are
> sanitised.
> 
> Remove sanitisation from the io_uring request cache for now.
> 
> [...]

Applied, thanks!

[1/1] io_uring: fix false positive KASAN warnings
      commit: e0b94f7b1ec218f73f9a1e3db4ff77a5fde27203

Best regards,
diff mbox series

Patch

diff --git a/io_uring/io_uring.c b/io_uring/io_uring.c
index 0eed797ef270..fb70ae436db6 100644
--- a/io_uring/io_uring.c
+++ b/io_uring/io_uring.c
@@ -245,7 +245,6 @@  static inline void req_fail_link_node(struct io_kiocb *req, int res)
 static inline void io_req_add_to_cache(struct io_kiocb *req, struct io_ring_ctx *ctx)
 {
 	wq_stack_add_head(&req->comp_list, &ctx->submit_state.free_list);
-	kasan_poison_object_data(req_cachep, req);
 }
 
 static __cold void io_ring_ctx_ref_free(struct percpu_ref *ref)
diff --git a/io_uring/io_uring.h b/io_uring/io_uring.h
index d3606d30cf6f..12769bad5cee 100644
--- a/io_uring/io_uring.h
+++ b/io_uring/io_uring.h
@@ -354,7 +354,6 @@  static inline struct io_kiocb *io_extract_req(struct io_ring_ctx *ctx)
 	struct io_kiocb *req;
 
 	req = container_of(ctx->submit_state.free_list.next, struct io_kiocb, comp_list);
-	kasan_unpoison_object_data(req_cachep, req);
 	wq_stack_extract(&ctx->submit_state.free_list);
 	return req;
 }