mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] io_uring/rw: commit the ring buffer when a read is queued
@ 2026-10-02 13:56 Miguel Garcia via B4 Relay
  0 siblings, 0 replies; only message in thread
From: Miguel Garcia via B4 Relay @ 2026-10-02 13:56 UTC (permalink / raw)
  To: Jens Axboe; +Cc: io-uring, linux-kernel, stable, Miguel Garcia

From: Miguel Garcia <miguelgarciaroman8@gmail.com>

io_read() recycles a provided buffer ring on every negative return
while REQ_F_BUFFERS_COMMIT is set. -EIOCBQUEUED is one of those
returns. IOU_ISSUE_SKIP_COMPLETE is defined as -EIOCBQUEUED, and
io_issue_sqe() turns that into success and leaves the request in
flight. The queued read still writes the user address chosen at
buffer selection.

For a pollable file issued under uring_lock, io_should_commit() is
false, so recycle clears REQ_F_BUFFER_RING and REQ_F_BUFFERS_COMMIT
without moving the ring head. io_req_rw_complete() then skips
io_put_kbuf(). The CQE is posted without IORING_CQE_F_BUFFER, and a
later IOSQE_BUFFER_SELECT takes the same slot while the first read
is still in flight.

FUSE reaches this from a user mount. fuse_file_operations supplies
both .poll and .read_iter. A daemon that negotiates FUSE_ASYNC_DIO,
reports a non-zero size, opens with FOPEN_DIRECT_IO, and answers
FUSE_POLL with -ENOSYS or POLLIN makes io_file_supports_nowait()
succeed. fuse_direct_IO() returns -EIOCBQUEUED for an async kiocb
and keeps the user pages pinned.

Commit the selected length before returning IOU_ISSUE_SKIP_COMPLETE
and leave REQ_F_BUFFER_RING set, so completion still reports the
buffer id. io_req_rw_complete() passes a NULL buffer list, so
dropping the recycle alone leaves the head unchanged. The list
pointer is stack-local, so the issue path has to commit before it
returns. The committed length is rw->len, the same length
io_ring_buffer_select() commits when io_should_commit() is true.
Non-pollable and IO_URING_F_UNLOCKED issues have already cleared
REQ_F_BUFFERS_COMMIT. -EAGAIN still recycles.

Commit d8e1dec2f860 ("io_uring/rw: recycle buffers manually for
non-mshot reads") made io_read() recycle provided buffers on every
negative return, including -EIOCBQUEUED.

Grok, a coding assistant, found this by reading io_read() and
fuse_direct_IO() and drafted the change. Debian gcc 12.2.0 built
io_uring/rw.o and the kernel image. QEMU TCG booted both images.
On the unpatched image two buffered reads shared one address, the
ring head stayed 0, and both CQEs lacked IORING_CQE_F_BUFFER. With
this change the head moved to 1 while the first read was still
queued, that CQE carried the buffer id, and the second read returned
-ENOBUFS.

Fixes: d8e1dec2f860 ("io_uring/rw: recycle buffers manually for non-mshot reads")
Cc: stable@vger.kernel.org # 6.18+
Assisted-by: LLM
Signed-off-by: Miguel Garcia <miguelgarciaroman8@gmail.com>
---
 io_uring/rw.c | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/io_uring/rw.c b/io_uring/rw.c
index 0c9494fd21be..a40263d21afe 100644
--- a/io_uring/rw.c
+++ b/io_uring/rw.c
@@ -1034,6 +1034,21 @@ int io_read(struct io_kiocb *req, unsigned int issue_flags)
 	if (ret >= 0)
 		return kiocb_done(req, ret, &sel, issue_flags);
 
+	/*
+	 * -EIOCBQUEUED leaves the kiocb in flight on the selected user
+	 * address. Commit the ring buffer here. Completion reports the
+	 * id with a NULL list. Error returns still recycle below.
+	 */
+	if (ret == IOU_ISSUE_SKIP_COMPLETE) {
+		if ((req->flags & REQ_F_BUFFERS_COMMIT) && sel.buf_list) {
+			struct io_rw *rw = io_kiocb_to_cmd(req, struct io_rw);
+
+			if (!io_kbuf_commit(req, sel.buf_list, rw->len, 1))
+				req->flags |= REQ_F_BUF_MORE;
+		}
+		return io_fixup_restart_res(ret);
+	}
+
 	if (req->flags & REQ_F_BUFFERS_COMMIT)
 		io_kbuf_recycle(req, sel.buf_list, issue_flags);
 

---
base-commit: 648611ee6ed0d27f8b43b7b5863facc3ec94c31b
change-id: 20261002-codex-io-uring-eiocbqueued-c97655b372cb

Best regards,
-- 
Miguel Garcia <miguelgarciaroman8@gmail.com>



^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-02 13:57 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 13:56 [PATCH] io_uring/rw: commit the ring buffer when a read is queued Miguel Garcia via B4 Relay

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®