]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
io_uring/zcrx: account area memory
authorPavel Begunkov <asml.silence@gmail.com>
Wed, 16 Jul 2025 21:04:09 +0000 (22:04 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 20 Aug 2025 16:40:43 +0000 (18:40 +0200)
commit 262ab205180d2ba3ab6110899a4dbe439c51dfaa upstream.

zcrx areas can be quite large and need to be accounted and checked
against RLIMIT_MEMLOCK. In practise it shouldn't be a big issue as
the inteface already requires cap_net_admin.

Cc: stable@vger.kernel.org
Fixes: cf96310c5f9a0 ("io_uring/zcrx: add io_zcrx_area")
Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
Link: https://lore.kernel.org/r/4b53f0c575bd062f63d12bec6cac98037fc66aeb.1752699568.git.asml.silence@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
io_uring/zcrx.c
io_uring/zcrx.h

index 4a7011c799f013c97c07ff6323682f530dc773d9..713267ed3b1d1784b49509dc058c41cddb2016e2 100644 (file)
@@ -152,12 +152,29 @@ static int io_zcrx_map_area_dmabuf(struct io_zcrx_ifq *ifq, struct io_zcrx_area
        return niov_idx;
 }
 
+static unsigned long io_count_account_pages(struct page **pages, unsigned nr_pages)
+{
+       struct folio *last_folio = NULL;
+       unsigned long res = 0;
+       int i;
+
+       for (i = 0; i < nr_pages; i++) {
+               struct folio *folio = page_folio(pages[i]);
+
+               if (folio == last_folio)
+                       continue;
+               last_folio = folio;
+               res += 1UL << folio_order(folio);
+       }
+       return res;
+}
+
 static int io_import_umem(struct io_zcrx_ifq *ifq,
                          struct io_zcrx_mem *mem,
                          struct io_uring_zcrx_area_reg *area_reg)
 {
        struct page **pages;
-       int nr_pages;
+       int nr_pages, ret;
 
        if (area_reg->dmabuf_fd)
                return -EINVAL;
@@ -168,6 +185,13 @@ static int io_import_umem(struct io_zcrx_ifq *ifq,
        if (IS_ERR(pages))
                return PTR_ERR(pages);
 
+       mem->account_pages = io_count_account_pages(pages, nr_pages);
+       ret = io_account_mem(ifq->ctx, mem->account_pages);
+       if (ret < 0) {
+               mem->account_pages = 0;
+               return ret;
+       }
+
        mem->pages = pages;
        mem->nr_folios = nr_pages;
        mem->size = area_reg->len;
@@ -374,6 +398,9 @@ static void io_zcrx_free_area(struct io_zcrx_area *area)
                io_zcrx_unmap_area(area->ifq, area);
        io_release_area_mem(&area->mem);
 
+       if (area->mem.account_pages)
+               io_unaccount_mem(area->ifq->ctx, area->mem.account_pages);
+
        kvfree(area->freelist);
        kvfree(area->nia.niovs);
        kvfree(area->user_refs);
index 2f5e26389f2218b15469a3c78bfc03affdbbea8d..67ed6b179f3d3fa9ded95a0ac882bfd3849895a6 100644 (file)
@@ -14,6 +14,7 @@ struct io_zcrx_mem {
 
        struct page                     **pages;
        unsigned long                   nr_folios;
+       unsigned long                   account_pages;
 
        struct dma_buf_attachment       *attach;
        struct dma_buf                  *dmabuf;