BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: chenyuan_fl@163.com
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 1/2] bpf, sockmap: Fix udp_bpf_recvmsg() spinning on backlog-only ingress
Date: Tue, 29 Sep 2026 08:49:33 +0000	[thread overview]
Message-ID: <20260929084933.BEBD01F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260929083447.558818-2-chenyuan_fl@163.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf, sockmap: udp_bpf_recvmsg deadlocks on data in ingress_skb
--

commit 4b047bd002c9028eba9dda4d7ee00341f2525fa3
Author: Yuan Chen <chenyuan@kylinos.cn>

bpf, sockmap: Fix udp_bpf_recvmsg() spinning on backlog-only ingress
    
udp_bpf_recvmsg() re-arms its msg_bytes_ready loop whenever psock_has_data()
is true, but that predicate also covers an skb parked in psock->ingress_skb.
This commit changes it to re-arm only on !sk_psock_queue_empty(psock).

> diff --git a/net/ipv4/udp_bpf.c b/net/ipv4/udp_bpf.c
> index ad57c4c9eaab6..8aca9fb893349 100644
> --- a/net/ipv4/udp_bpf.c
> +++ b/net/ipv4/udp_bpf.c
> @@ -91,7 +91,7 @@ static int udp_bpf_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
>  		timeo = sock_rcvtimeo(sk, flags & MSG_DONTWAIT);
>  		data = udp_msg_wait_data(sk, psock, timeo);
>  		if (data) {
> -			if (psock_has_data(psock))
> +			if (!sk_psock_queue_empty(psock))
>  				goto msg_bytes_ready;
>  
>  			release_sock(sk);

[Severity: High]
Does this introduce a deadlock when data is parked in ingress_skb?

If a BPF program redirects UDP data into a socket's ingress_skb,
udp_msg_wait_data() will return 1 immediately because it relies on
udp_msg_has_data(), which evaluates to true when ingress_skb has data.

With this patch, the execution then strictly checks sk_psock_queue_empty().
Because this function only evaluates ingress_msg, it will return true when
ingress_msg is empty. This causes the if condition to evaluate to false,
routing the code to sk_udp_recvmsg():

    release_sock(sk);
    ret = sk_udp_recvmsg(sk, msg, len, flags);
    goto out;

When sk_udp_recvmsg() is called, it eventually sleeps in __skb_recv_udp()
waiting for data in sk_receive_queue. It completely ignores data parked in
the BPF ingress_msg queue. 

When the backlog workqueue eventually moves the data to ingress_msg and wakes
the socket, __skb_recv_udp() will ignore ingress_msg, find sk_receive_queue
still empty, and go back to sleep indefinitely. 

Could this cause the receiving thread to hang permanently in recv(), leading
to a denial of service?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929083447.558818-1-chenyuan_fl@163.com?part=1

  reply	other threads:[~2026-09-29  8:49 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  8:34 [PATCH bpf-next 0/2] bpf, sockmap: Fix udp_bpf_recvmsg() spinning on backlog-only ingress chenyuan_fl
2026-09-29  8:34 ` [PATCH bpf-next 1/2] " chenyuan_fl
2026-09-29  8:49   ` sashiko-bot [this message]
2026-09-30  9:01   ` Alexei Starovoitov
2026-09-29  8:34 ` [PATCH bpf-next 2/2] selftests/bpf: Add a test for udp_bpf_recvmsg() with a stuck backlog chenyuan_fl
2026-09-29  8:43   ` sashiko-bot
2026-09-29  9:26   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929084933.BEBD01F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=chenyuan_fl@163.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox