From: sashiko-bot@kernel.org
To: chenyuan_fl@163.com
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 1/2] bpf, sockmap: Fix udp_bpf_recvmsg() spinning on backlog-only ingress
Date: Tue, 29 Sep 2026 08:49:33 +0000 [thread overview]
Message-ID: <20260929084933.BEBD01F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260929083447.558818-2-chenyuan_fl@163.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf, sockmap: udp_bpf_recvmsg deadlocks on data in ingress_skb
--
commit 4b047bd002c9028eba9dda4d7ee00341f2525fa3
Author: Yuan Chen <chenyuan@kylinos.cn>
bpf, sockmap: Fix udp_bpf_recvmsg() spinning on backlog-only ingress
udp_bpf_recvmsg() re-arms its msg_bytes_ready loop whenever psock_has_data()
is true, but that predicate also covers an skb parked in psock->ingress_skb.
This commit changes it to re-arm only on !sk_psock_queue_empty(psock).
> diff --git a/net/ipv4/udp_bpf.c b/net/ipv4/udp_bpf.c
> index ad57c4c9eaab6..8aca9fb893349 100644
> --- a/net/ipv4/udp_bpf.c
> +++ b/net/ipv4/udp_bpf.c
> @@ -91,7 +91,7 @@ static int udp_bpf_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
> timeo = sock_rcvtimeo(sk, flags & MSG_DONTWAIT);
> data = udp_msg_wait_data(sk, psock, timeo);
> if (data) {
> - if (psock_has_data(psock))
> + if (!sk_psock_queue_empty(psock))
> goto msg_bytes_ready;
>
> release_sock(sk);
[Severity: High]
Does this introduce a deadlock when data is parked in ingress_skb?
If a BPF program redirects UDP data into a socket's ingress_skb,
udp_msg_wait_data() will return 1 immediately because it relies on
udp_msg_has_data(), which evaluates to true when ingress_skb has data.
With this patch, the execution then strictly checks sk_psock_queue_empty().
Because this function only evaluates ingress_msg, it will return true when
ingress_msg is empty. This causes the if condition to evaluate to false,
routing the code to sk_udp_recvmsg():
release_sock(sk);
ret = sk_udp_recvmsg(sk, msg, len, flags);
goto out;
When sk_udp_recvmsg() is called, it eventually sleeps in __skb_recv_udp()
waiting for data in sk_receive_queue. It completely ignores data parked in
the BPF ingress_msg queue.
When the backlog workqueue eventually moves the data to ingress_msg and wakes
the socket, __skb_recv_udp() will ignore ingress_msg, find sk_receive_queue
still empty, and go back to sleep indefinitely.
Could this cause the receiving thread to hang permanently in recv(), leading
to a denial of service?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929083447.558818-1-chenyuan_fl@163.com?part=1
next prev parent reply other threads:[~2026-09-29 8:49 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 8:34 [PATCH bpf-next 0/2] bpf, sockmap: Fix udp_bpf_recvmsg() spinning on backlog-only ingress chenyuan_fl
2026-09-29 8:34 ` [PATCH bpf-next 1/2] " chenyuan_fl
2026-09-29 8:49 ` sashiko-bot [this message]
2026-09-30 9:01 ` Alexei Starovoitov
2026-09-29 8:34 ` [PATCH bpf-next 2/2] selftests/bpf: Add a test for udp_bpf_recvmsg() with a stuck backlog chenyuan_fl
2026-09-29 8:43 ` sashiko-bot
2026-09-29 9:26 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929084933.BEBD01F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=chenyuan_fl@163.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox