All of lore.kernel.org
 help / color / mirror / Atom feed
From: Gabriel Krisman Bertazi <krisman@suse.de>
To: Jens Axboe <axboe@kernel.dk>
Cc: io-uring@vger.kernel.org
Subject: Re: [PATCH liburing 1/2] test/send_recvmsg: Preserve msghdr until op_recvmsg completes
Date: Wed, 22 Jul 2026 16:00:09 -0400	[thread overview]
Message-ID: <87fr1aeqwm.fsf@mailhost.krisman.be> (raw)
In-Reply-To: <6f31dd5b-639e-4018-815b-0fa04a39b337@kernel.dk>

Jens Axboe <axboe@kernel.dk> writes:

> On 7/22/26 12:17 PM, Gabriel Krisman Bertazi wrote:
>> msghdr is allocated on the stack at recv_prep, which means it may go out
>> of scope before the kernel has a chance to complete the operation.  This
>> results in spurious test failures when we reach far enough into recv_fn
>> to reuse the stack space before op_recvmsg executes.  I found it easily
>> reproducible when compiling with '-O0 -g3' to avoid gcc from optimizing
>> further local variables out of the stack.
>
> Hmm, but that should be fine as long as a) we submit in scope, and b)
> we're not using SQPOLL, where it does need to remain consistent until
> completion.
>
> And recv_prep() certainly submits before it returns, and we're not using
> SQPOLL. So I'm curious what issue this is?? Same questions on patch 2.

Hm, I assumed it was submitted via iowq, which would explain this,
because the execution in io_recvmsg() passes a pointer to the original
memory:

        ret = __sys_recvmsg_sock(sock, &kmsg->msg, sr->umsg,
	    			 kmsg->uaddr, flags);

and __sys_recvmsg_sock does write to it. which makes it clear the msghdr
needs to live until completion.

But honestly, whenever I try to probe to confirm the execution went
through iowq, the timing gets off and I can't reproduce the corruption.

I will take another look and see if I can explain better.

> -- 
> Jens Axboe

-- 
Gabriel Krisman Bertazi

  reply	other threads:[~2026-07-22 20:00 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 18:17 [PATCH liburing 0/2] Fix op_recv stack corruption Gabriel Krisman Bertazi
2026-07-22 18:17 ` [PATCH liburing 1/2] test/send_recvmsg: Preserve msghdr until op_recvmsg completes Gabriel Krisman Bertazi
2026-07-22 18:24   ` Gabriel Krisman Bertazi
2026-07-22 19:21   ` Jens Axboe
2026-07-22 20:00     ` Gabriel Krisman Bertazi [this message]
2026-07-22 20:33       ` Gabriel Krisman Bertazi
2026-07-22 18:17 ` [PATCH liburing 2/2] test/recv-msgall-stream: " Gabriel Krisman Bertazi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87fr1aeqwm.fsf@mailhost.krisman.be \
    --to=krisman@suse.de \
    --cc=axboe@kernel.dk \
    --cc=io-uring@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.