Re: [PATCH v2] rust: file: handle fd table teardown in file descriptor APIs

From: Gary Guo

Date: Tue Sep 29 2026 - 14:23:14 EST


On Tue Sep 29, 2026 at 6:02 PM BST, Al Viro wrote:
> On Tue, Sep 29, 2026 at 05:07:40PM +0100, Gary Guo wrote:
>
>> The reproducer that Georgios posted on GitHub is some cleanup job being added to
>> task_work, which drops FileDescriptorReservation. And since exit_task_work()
>> happens after exit_files(), put_unused_fd in that cleanup observe that
>> current->files is NULL.
>>
>> So it's not from random thread, it's from the current task. And I find that
>> particular case of doing per-task cleanup not unrealistic.
>
> FWIW, descriptor reservation ought to be tied to specific files_struct
> instance; note that dup_fd() can be called when there are outstanding
> reservations and the copy does *NOT* have those reserved.
>
> What rules would you suggest for such delayed put_unused_fd() wrt e.g.
> files_struct unsharing?

Ah, is this about `unshare(CLONE_FILES)`? For that case indeed our existing
abstraction break down.

So put_unused_fd must be called in the same syscall context as
get_unused_fd_flags.. I think we can address this by give it a lifetime
parameter

struct FileDescriptorReservation<'a>(..);

and require `current!()` to be passed in:

impl<'a> FileDescriptorReservation<'a> {
pub fn get_unused_fd_flags(_current: &'a CurrentTask, flags: u32);
}

// User
FileDescriptorReservation::get_unused_fd_flags(current!(), flags)

I checked binder I think its current use can work with this, although it needs
some changes to pass this `&CurrentTask` token in.

Best,
Gary