From: Jens Axboe Date: Thu, 23 Jan 2025 00:29:31 +0000 (-0700) Subject: io_uring/uring_cmd: use cached cmd_op in io_uring_cmd_sock() X-Git-Tag: v6.14-rc1~18^2~14 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=d58d82bd0efd6c8edd452fc2f6c6dd052ec57cb2;p=thirdparty%2Fkernel%2Flinux.git io_uring/uring_cmd: use cached cmd_op in io_uring_cmd_sock() io_uring_cmd_sock() does a normal read of cmd->sqe->cmd_op, where it really should be using a READ_ONCE() as ->sqe may still be pointing to the original SQE. Since the prep side already does this READ_ONCE() and stores it locally, use that value rather than re-read it. Fixes: 8e9fad0e70b7b ("io_uring: Add io_uring command support for sockets") Link: https://lore.kernel.org/r/20250121-uring-sockcmd-fix-v1-1-add742802a29@google.com Signed-off-by: Jens Axboe --- diff --git a/io_uring/uring_cmd.c b/io_uring/uring_cmd.c index fc94c465a9850..3993c9339ac76 100644 --- a/io_uring/uring_cmd.c +++ b/io_uring/uring_cmd.c @@ -350,7 +350,7 @@ int io_uring_cmd_sock(struct io_uring_cmd *cmd, unsigned int issue_flags) if (!prot || !prot->ioctl) return -EOPNOTSUPP; - switch (cmd->sqe->cmd_op) { + switch (cmd->cmd_op) { case SOCKET_URING_OP_SIOCINQ: ret = prot->ioctl(sk, SIOCINQ, &arg); if (ret)