Put an io_uring on it – Exploiting the Linux Kernel (2022)
chompie.rip
chompie.rip
https://www.openwall.com/lists/oss-security/2023/05/08/3
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=io_uring
That tells me that io_uring stabilized a lot during 2021.
Google yanking support for it seems like a bad decision. Instead, they should upgrade their 3-year-old kernels, which certainly contain other fixed-but-not-backported security vulnerabilites.
Learnings from kCTF VRP's 42 Linux kernel exploits submissions - https://news.ycombinator.com/item?id=36350693 - June 2023 (87 comments)
Past discussion of current article:
Put an io_uring on it: Exploiting the Linux kernel - https://news.ycombinator.com/item?id=30605356 - March 2022 (22 comments)
0: http://web.archive.org/web/20221130215710/https://www.grapls...
This is now mirrored since Grapl shut down (RIP)
My careers been in mobile, I thought “blocking” and “synchronous” were synonymous.
Does blocking in this context mean “needs to make a system call?”
No. Neither thread involved here (the userspace thread or the kernel thread) will "wait" in either scenario. The userspace thread will either work on the syscall (because it was ready to be performed immediately) or it will be released to go do something else. The kernel thread will either not be involved (because the syscall was performed by the userspace thread already) or it will start working on the syscall.
When the IO operation is ready the thread is then marked to be awakened and the scheduler will context switch back to it whenever it sees fit (given other considerations like thread priority, etc).
From the POV of the thread that blocks nothing really happens while it's waiting. Once it awakens it has the result of the operation (or an error) and it can observe that more time has passed by inspecting the timer. For all intents and purposes the operation was "synchronous" from the POV of the thread.
My understanding is its incorrect to compare to kqueue.
No. (Not for security reasons, but for lack of an army of motivated and talented developers like Jens Axboe et al.)
> My understanding is its incorrect to compare to kqueue.
Right. kqueue is more like an extended version of epoll.
A lot of people are coming to the conclusion that io_uring's userspace interface is fundamentally insecure. That couldn't be farther from the truth. I've read the spec (which is only a few pages). I could implement + security validate both sides in a day or two (and have done similar in the past).
In a way, async sendfile is like iouring in that a web / file server does not have to supply a blocking thread context to wait for io -- once data arrives from the storage driver, its pushed through the TCP stack in the storage driver's ithread context. But its just that single sequence.
(Thank you & the team for all you do)