From: Gabriel Krisman Bertazi <krisman@suse.de>
To: Jens Axboe <axboe@kernel.dk>
Cc: io-uring@vger.kernel.org
Subject: Re: [PATCH liburing 1/2] test/send_recvmsg: Preserve msghdr until op_recvmsg completes
Date: Wed, 22 Jul 2026 16:00:09 -0400 [thread overview]
Message-ID: <87fr1aeqwm.fsf@mailhost.krisman.be> (raw)
In-Reply-To: <6f31dd5b-639e-4018-815b-0fa04a39b337@kernel.dk>
Jens Axboe <axboe@kernel.dk> writes:
> On 7/22/26 12:17 PM, Gabriel Krisman Bertazi wrote:
>> msghdr is allocated on the stack at recv_prep, which means it may go out
>> of scope before the kernel has a chance to complete the operation. This
>> results in spurious test failures when we reach far enough into recv_fn
>> to reuse the stack space before op_recvmsg executes. I found it easily
>> reproducible when compiling with '-O0 -g3' to avoid gcc from optimizing
>> further local variables out of the stack.
>
> Hmm, but that should be fine as long as a) we submit in scope, and b)
> we're not using SQPOLL, where it does need to remain consistent until
> completion.
>
> And recv_prep() certainly submits before it returns, and we're not using
> SQPOLL. So I'm curious what issue this is?? Same questions on patch 2.
Hm, I assumed it was submitted via iowq, which would explain this,
because the execution in io_recvmsg() passes a pointer to the original
memory:
ret = __sys_recvmsg_sock(sock, &kmsg->msg, sr->umsg,
kmsg->uaddr, flags);
and __sys_recvmsg_sock does write to it. which makes it clear the msghdr
needs to live until completion.
But honestly, whenever I try to probe to confirm the execution went
through iowq, the timing gets off and I can't reproduce the corruption.
I will take another look and see if I can explain better.
> --
> Jens Axboe
--
Gabriel Krisman Bertazi
next prev parent reply other threads:[~2026-07-22 20:00 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 18:17 [PATCH liburing 0/2] Fix op_recv stack corruption Gabriel Krisman Bertazi
2026-07-22 18:17 ` [PATCH liburing 1/2] test/send_recvmsg: Preserve msghdr until op_recvmsg completes Gabriel Krisman Bertazi
2026-07-22 18:24 ` Gabriel Krisman Bertazi
2026-07-22 19:21 ` Jens Axboe
2026-07-22 20:00 ` Gabriel Krisman Bertazi [this message]
2026-07-22 20:33 ` Gabriel Krisman Bertazi
2026-07-22 18:17 ` [PATCH liburing 2/2] test/recv-msgall-stream: " Gabriel Krisman Bertazi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87fr1aeqwm.fsf@mailhost.krisman.be \
--to=krisman@suse.de \
--cc=axboe@kernel.dk \
--cc=io-uring@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox