public inbox for io-uring@vger.kernel.org
 help / color / mirror / Atom feed
From: Jens Axboe <axboe@kernel.dk>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: io-uring <io-uring@vger.kernel.org>
Subject: [GIT PULL] io_uring fixes for 7.3-rc6
Date: Fri, 2 Oct 2026 08:48:26 -0600	[thread overview]
Message-ID: <0fc0ef2e-93aa-4b18-9816-4f47a77f74ab@kernel.dk> (raw)

Hi Linus,

A set of io_uring fixes for this week. It's really a collection of
things from the last few weeks, just various life things have got them
bundled up for this week. This pull request contains:

- Fix a task_work add use-after-free with SQPOLL, where the sqpoll
  thread could pop and complete the last request while
  io_req_normal_work_add() was still looking at them after the mpscq
  push. Use the same approach as DEFER_TASKRUN to protect from that,
  holding an RCU read lock across the add, and have exit wait for an RCU
  grace period for SQPOLL rings as well.

- CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
  big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
  rings

- Mark the source filter table as COW when cloning bpf filters, so
  registering another filter on the source doesn't modify the shared
  table in place

- Initialize the task context before running the BPF loop

- Requeue zcrx multishot receives stopped by a local resource

 - End a TX_TIMESTAMP multishot cmd when the CQ is full (lollipopkit)

Please pull!


The following changes since commit 47ccc3f1c615a46c25cbf7f3ae60df30b40eb2e6:

  io_uring/rw: keep CQE flags on iopoll requests when adding kbuf flags (2026-09-09 09:59:02 -0600)

are available in the Git repository at:

  https://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git tags/io_uring-7.3-20261002

for you to fetch changes up to a92193c91e8839fe5fc209616ea95465ae4b919d:

  io_uring: fix task_work add use-after-free with SQPOLL (2026-09-29 06:52:39 -0600)

----------------------------------------------------------------
io_uring-7.3-20261002

----------------------------------------------------------------
Hui Peng (4):
      io_uring/bpf_filter: mark source as COW when cloning filters
      io_uring: only post the dummy skip CQE on CQE_MIXED rings
      io_uring: fix free entry check for 32b CQEs on CQE32 rings
      io_uring: zero big_cqe for aux CQEs on CQE32 rings

Jens Axboe (1):
      io_uring: fix task_work add use-after-free with SQPOLL

Junyuan Feng (1):
      io_uring/zcrx: requeue multishot receives stopped by a local resource

Yao Kai (1):
      io_uring: initialize task context before running the BPF loop

lollipopkit (1):
      io_uring/cmd_net: end TX_TIMESTAMP multishot when the CQ is full

 io_uring/bpf_filter.c |  1 +
 io_uring/cmd_net.c    | 19 ++++++++++++++-----
 io_uring/io_uring.c   | 16 +++++++++-------
 io_uring/loop.c       |  5 +++++
 io_uring/tw.c         |  3 +++
 io_uring/zcrx.c       |  9 +++++++--
 6 files changed, 39 insertions(+), 14 deletions(-)

-- 
Jens Axboe


             reply	other threads:[~2026-10-02 14:48 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 14:48 Jens Axboe [this message]
2026-10-02 19:31 ` [GIT PULL] io_uring fixes for 7.3-rc6 pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0fc0ef2e-93aa-4b18-9816-4f47a77f74ab@kernel.dk \
    --to=axboe@kernel.dk \
    --cc=io-uring@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox