From: Jens Axboe <axboe@kernel.dk>
To: io-uring <io-uring@vger.kernel.org>
Cc: Sung Keum <kambodi127@gmail.com>
Subject: [PATCH] io_uring/kbuf: cap buffer selection length at MAX_RW_COUNT
Date: Sun, 26 Jul 2026 16:28:14 -0600 [thread overview]
Message-ID: <aa826e79-ddc5-4a82-9863-a5edfdce709f@kernel.dk> (raw)
io_ring_buffers_peek() builds an iovec array from provided buffers, and
that in turn can be handed off to a lower level provider. Be prudent and
cap the total size to MAX_RW_COUNT, which is the Linux default for how
much IO do to in a single call.
No bugs here, but it's a good preventative measure to avoid truncation
issues.
Signed-off-by: Jens Axboe <axboe@kernel.dk>
---
diff --git a/io_uring/kbuf.c b/io_uring/kbuf.c
index de0129bceaba..1cf5be62bb65 100644
--- a/io_uring/kbuf.c
+++ b/io_uring/kbuf.c
@@ -266,6 +266,9 @@ static int io_ring_buffers_peek(struct io_kiocb *req, struct buf_sel_arg *arg,
if (unlikely(!nr_avail))
return -ENOBUFS;
+ /* MAX_RW_COUNT is the universal Linux per-call IO maximum */
+ arg->max_len = min_t(size_t, arg->max_len, MAX_RW_COUNT);
+
buf = io_ring_head_to_buf(br, head, bl->mask);
if (arg->max_len) {
u32 len = READ_ONCE(buf->len);
@@ -295,7 +298,7 @@ static int io_ring_buffers_peek(struct io_kiocb *req, struct buf_sel_arg *arg,
/* set it to max, if not set, so we can use it unconditionally */
if (!arg->max_len)
- arg->max_len = INT_MAX;
+ arg->max_len = MAX_RW_COUNT;
req->buf_index = READ_ONCE(buf->bid);
do {
--
Jens Axboe
next reply other threads:[~2026-07-26 22:28 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <CGME20260727140454epcas5p1a2306b5a87d2ff6d299e89b0af320213@epcas5p1.samsung.com>
2026-07-26 22:28 ` Jens Axboe [this message]
2026-07-27 0:12 ` [PATCH] io_uring/kbuf: cap buffer selection length at MAX_RW_COUNT Gabriel Krisman Bertazi
2026-07-27 14:04 ` Nitesh Shetty
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aa826e79-ddc5-4a82-9863-a5edfdce709f@kernel.dk \
--to=axboe@kernel.dk \
--cc=io-uring@vger.kernel.org \
--cc=kambodi127@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox