io_uring: annotate remote tasks for kcoverage

Fuzzers use coverage information to guide generation of test cases
towards new or interesting code paths. Syzkaller, specifically, makes
use kcoverage (CONFIG_KCOV). Coverage information is not collected for
kernel tasks unless annotated by kcov_remote_start and kcov_remote_stop.
This patch annotates io-uring's work queue and sqpoll tasks.

Depends-On: 20260430-kcov-refactor-common-handle-v1-1-23a0c7a0ba38@google.com
Signed-off-by: Robert Femmer <robert@fmmr.tech>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
This commit is contained in:
Robert Femmer 2026-06-24 11:01:46 +02:00 committed by Jens Axboe
parent dc59e4fea9
commit c905736a46
4 changed files with 15 additions and 1 deletions

View File

@ -534,6 +534,8 @@ struct io_ring_ctx {
struct io_mapped_region ring_region;
/* used for optimised request parameter and wait argument passing */
struct io_mapped_region param_region;
struct kcov_common_handle_id kcov_handle;
};
/*

View File

@ -19,6 +19,7 @@
#include <linux/mmu_context.h>
#include <linux/sched/sysctl.h>
#include <uapi/linux/io_uring.h>
#include <linux/kcov.h>
#include "io-wq.h"
#include "slist.h"
@ -643,13 +644,17 @@ static void io_worker_handle_work(struct io_wq_acct *acct,
unsigned int hash = __io_wq_is_hashed(work_flags)
? __io_get_work_hash(work_flags)
: -1U;
struct io_kiocb *req;
next_hashed = wq_next_work(work);
if (do_kill &&
(work_flags & IO_WQ_WORK_UNBOUND))
atomic_or(IO_WQ_WORK_CANCEL, &work->flags);
req = container_of(work, struct io_kiocb, work);
kcov_remote_start_common(req->ctx->kcov_handle);
io_wq_submit_work(work);
kcov_remote_stop();
io_assign_current_work(worker, NULL);
linked = io_wq_free_work(work);

View File

@ -59,6 +59,7 @@
#include <linux/audit.h>
#include <linux/security.h>
#include <linux/jump_label.h>
#include <linux/kcov.h>
#define CREATE_TRACE_POINTS
#include <trace/events/io_uring.h>
@ -293,6 +294,7 @@ static __cold struct io_ring_ctx *io_ring_ctx_alloc(struct io_uring_params *p)
INIT_HLIST_HEAD(&ctx->cancelable_uring_cmd);
io_napi_init(ctx);
mutex_init(&ctx->mmap_lock);
ctx->kcov_handle = kcov_common_handle();
return ctx;

View File

@ -13,6 +13,7 @@
#include <linux/cpuset.h>
#include <linux/sched/cputime.h>
#include <linux/io_uring.h>
#include <linux/kcov.h>
#include <uapi/linux/io_uring.h>
@ -332,10 +333,14 @@ static int io_sq_thread(void *data)
cap_entries = !list_is_singular(&sqd->ctx_list);
list_for_each_entry(ctx, &sqd->ctx_list, sqd_list) {
int ret = __io_sq_thread(ctx, sqd, cap_entries, &ist);
int ret;
kcov_remote_start_common(ctx->kcov_handle);
ret = __io_sq_thread(ctx, sqd, cap_entries, &ist);
if (!sqt_spin && (ret > 0 || !list_empty(&ctx->iopoll_list)))
sqt_spin = true;
kcov_remote_stop();
}
if (io_sq_tw(IORING_TW_CAP_ENTRIES_VALUE))
sqt_spin = true;