Re: [PATCH v2] rust: file: handle fd table teardown in file descriptor APIs
From: Christian Brauner
Date: Fri Sep 25 2026 - 12:21:06 EST
On Thu, Sep 24, 2026 at 08:39:37AM +0000, Alice Ryhl wrote:
> On Tue, Sep 22, 2026 at 10:23:39PM -0400, Georgios Androutsopoulos wrote:
> > Several Rust file descriptor APIs rely on `current->files` being
> > available. However, `exit_files()` clears it while execution may still
> > continue on the same task.
> >
> > This affects `LocalFile::fget()` and the
> > `FileDescriptorReservation` operations that call
> > `get_unused_fd_flags()`, `fd_install()`, and `put_unused_fd()`.
> > `FileDescriptorReservation` cannot cross task boundaries, but remaining
> > on the same task does not guarantee that `current->files` is still
> > available when these operations are performed.
> >
> > Guard the affected operations against a missing `current->files`.
> > `LocalFile::fget()` returns `EBADF` and
> > `FileDescriptorReservation::get_unused_fd_flags()` returns `EMFILE`.
> > For `fd_install()`, warn and abandon the reservation when the fd table
> > is already gone. In the drop path, skip `put_unused_fd()` after the fd
> > table has been torn down.
> >
> > This prevents NULL dereferences through these safe Rust APIs after
> > `exit_files()`.
> >
> > Fixes: 851849824bb5 ("rust: file: add Rust abstraction for `struct file`")
> > Fixes: 5da9857b127e ("rust: file: add `FileDescriptorReservation`")
> > Closes: https://github.com/Rust-for-Linux/linux/issues/1256
> > Signed-off-by: Georgios Androutsopoulos <georgeandrout13@xxxxxxxxx>
>
> This looks like it should ideally be on the C side instead.
Where is this godforsaken broken code, that tries to fd_install() after
exit_files(). It is _a bug in the program_ that is not something the
apis need to work around.