io_uring: mark known and harmless racy ctx->int_flags uses
authorJens Axboe <axboe@kernel.dk>
Sat, 14 Mar 2026 14:46:17 +0000 (08:46 -0600)
committerJens Axboe <axboe@kernel.dk>
Mon, 16 Mar 2026 21:33:10 +0000 (15:33 -0600)
There are a few of these, where flags are read outside of the
uring_lock, yet it's harmless to race on them.

Signed-off-by: Jens Axboe <axboe@kernel.dk>
io_uring/io_uring.c
io_uring/io_uring.h
io_uring/tw.c

index bfeb3bc..fb5a263 100644 (file)
@@ -2242,7 +2242,7 @@ static __poll_t io_uring_poll(struct file *file, poll_table *wait)
        struct io_ring_ctx *ctx = file->private_data;
        __poll_t mask = 0;
 
-       if (unlikely(!(ctx->int_flags & IO_RING_F_POLL_ACTIVATED)))
+       if (unlikely(!(data_race(ctx->int_flags) & IO_RING_F_POLL_ACTIVATED)))
                io_activate_pollwq(ctx);
        /*
         * provides mb() which pairs with barrier from wq_has_sleeper
index 5cb1983..91cf67b 100644 (file)
@@ -470,11 +470,12 @@ static inline void io_req_complete_defer(struct io_kiocb *req)
        wq_list_add_tail(&req->comp_list, &state->compl_reqs);
 }
 
+#define SHOULD_FLUSH_MASK      (IO_RING_F_OFF_TIMEOUT_USED | \
+                                IO_RING_F_HAS_EVFD | IO_RING_F_POLL_ACTIVATED)
+
 static inline void io_commit_cqring_flush(struct io_ring_ctx *ctx)
 {
-       if (unlikely(ctx->int_flags & (IO_RING_F_OFF_TIMEOUT_USED |
-                                      IO_RING_F_HAS_EVFD |
-                                      IO_RING_F_POLL_ACTIVATED)))
+       if (unlikely(data_race(ctx->int_flags) & SHOULD_FLUSH_MASK))
                __io_commit_cqring_flush(ctx);
 }
 
index 022fe87..fdff81e 100644 (file)
@@ -222,7 +222,7 @@ void io_req_local_work_add(struct io_kiocb *req, unsigned flags)
 
        if (!head) {
                io_ctx_mark_taskrun(ctx);
-               if (ctx->int_flags & IO_RING_F_HAS_EVFD)
+               if (data_race(ctx->int_flags) & IO_RING_F_HAS_EVFD)
                        io_eventfd_signal(ctx, false);
        }