Re: [PATCH liburing 1/2] test/send_recvmsg: Preserve msghdr until op_recvmsg completes

Gabriel Krisman Bertazi <[email protected]> Wed, 22 Jul 2026 16:00:09 -0400
Newsgroups org.kernel.vger.io-uring
Organization SUSE
Message-ID <[email protected]>
Jens Axboe <[email protected]> writes:

> On 7/22/26 12:17 PM, Gabriel Krisman Bertazi wrote:
>> msghdr is allocated on the stack at recv_prep, which means it may go out
>> of scope before the kernel has a chance to complete the operation.  This
>> results in spurious test failures when we reach far enough into recv_fn
>> to reuse the stack space before op_recvmsg executes.  I found it easily
>> reproducible when compiling with '-O0 -g3' to avoid gcc from optimizing
>> further local variables out of the stack.
>
> Hmm, but that should be fine as long as a) we submit in scope, and b)
> we're not using SQPOLL, where it does need to remain consistent until
> completion.
>
> And recv_prep() certainly submits before it returns, and we're not using
> SQPOLL. So I'm curious what issue this is?? Same questions on patch 2.

Hm, I assumed it was submitted via iowq, which would explain this,
because the execution in io_recvmsg() passes a pointer to the original
memory:

        ret = __sys_recvmsg_sock(sock, &kmsg->msg, sr->umsg,
	    			 kmsg->uaddr, flags);

and __sys_recvmsg_sock does write to it. which makes it clear the msghdr
needs to live until completion.

But honestly, whenever I try to probe to confirm the execution went
through iowq, the timing gets off and I can't reproduce the corruption.

I will take another look and see if I can explain better.

> -- 
> Jens Axboe

-- 
Gabriel Krisman Bertazi