[PATCH net v10 01/14] rxrpc: Fix lack of short-send handling in rxrpc_kernel_send_data()
From: David Howells <dhowells@redhat.com>
Date: 2026-09-14 15:13:58
Also in:
lkml, stable
Subsystem:
afs filesystem, documentation, filesystems (vfs and infrastructure), networking [general], rxrpc sockets (af_rxrpc), the rest · Maintainers:
David Howells, Marc Dionne, Jonathan Corbet, Alexander Viro, Christian Brauner, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds
Fix rxrpc_kernel_send_data() to loop around if it detects a short send.
David Laight suggested doing it here rather than wrapping all the calls in
loops. Further, remove the len argument and use the iterator count instead
and return 0 on success, not the amount copied.
Note this is also a prerequisite for changing the way rxrpc_send_data()
works to return a short send rather than an error if some data was
buffered.
Fixes: 651350d10f93 ("[AF_RXRPC]: Add an interface to the AF_RXRPC module for the AFS filesystem to use")
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260824091645.415423-1-dhowells%40redhat.com
Suggested-by: David Laight <redacted>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Eric Dumazet <edumazet@google.com>
cc: "David S. Miller" <davem@davemloft.net>
cc: Jakub Kicinski <kuba@kernel.org>
cc: Paolo Abeni <pabeni@redhat.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@vger.kernel.org
---
Documentation/networking/rxrpc.rst | 6 ++++--
fs/afs/rxrpc.c | 28 ++++++++++----------------
include/net/af_rxrpc.h | 5 ++---
net/rxrpc/rxperf.c | 11 +++-------
net/rxrpc/sendmsg.c | 32 ++++++++++++++++++++----------
5 files changed, 42 insertions(+), 40 deletions(-)
diff --git a/Documentation/networking/rxrpc.rst b/Documentation/networking/rxrpc.rst
index 8926dab8e2e6..01ad12fdf305 100644
--- a/Documentation/networking/rxrpc.rst
+++ b/Documentation/networking/rxrpc.rst@@ -870,7 +870,6 @@ The kernel interface functions are as follows: int rxrpc_kernel_send_data(struct socket *sock, struct rxrpc_call *call, struct msghdr *msg, - size_t len, rxrpc_notify_end_tx_t notify_end_rx); This is used to supply either the request part of a client call or the
@@ -880,13 +879,16 @@ The kernel interface functions are as follows: MSG_MORE if there will be subsequent data sends for this call. The msg must not specify a destination address, control data or any flags - other than MSG_MORE. len is the total amount of data to transmit. + other than MSG_MORE. notify_end_rx can be NULL or it can be used to specify a function to be called when the call changes state to end the Tx phase. This function is called with a spinlock held to prevent the last DATA packet from being transmitted until the function returns. + It returns 0 if all the data is queued and a negative error code on + failure. + (#) Receive data from a call:: int rxrpc_kernel_recv_data(struct socket *sock,
diff --git a/fs/afs/rxrpc.c b/fs/afs/rxrpc.c
index d82916657a3d..09d9da92a1be 100644
--- a/fs/afs/rxrpc.c
+++ b/fs/afs/rxrpc.c@@ -412,8 +412,7 @@ void afs_make_call(struct afs_call *call, gfp_t gfp) msg.msg_controllen = 0; msg.msg_flags = MSG_WAITALL | (call->write_iter ? MSG_MORE : 0); - ret = rxrpc_kernel_send_data(call->net->socket, rxcall, - &msg, call->request_size, + ret = rxrpc_kernel_send_data(call->net->socket, rxcall, &msg, afs_notify_end_request_tx); if (ret < 0) goto error_do_abort;
@@ -425,7 +424,6 @@ void afs_make_call(struct afs_call *call, gfp_t gfp) ret = rxrpc_kernel_send_data(call->net->socket, call->rxcall, &msg, - iov_iter_count(&msg.msg_iter), afs_notify_end_request_tx); *call->write_iter = msg.msg_iter;
@@ -871,7 +869,7 @@ void afs_send_empty_reply(struct afs_call *call) msg.msg_controllen = 0; msg.msg_flags = 0; - switch (rxrpc_kernel_send_data(net->socket, call->rxcall, &msg, 0, + switch (rxrpc_kernel_send_data(net->socket, call->rxcall, &msg, afs_notify_end_reply_tx)) { case 0: _leave(" [replied]");
@@ -912,21 +910,17 @@ void afs_send_simple_reply(struct afs_call *call, const void *buf, size_t len) msg.msg_controllen = 0; msg.msg_flags = 0; - n = rxrpc_kernel_send_data(net->socket, call->rxcall, &msg, len, + n = rxrpc_kernel_send_data(net->socket, call->rxcall, &msg, afs_notify_end_reply_tx); - if (n >= 0) { - /* Success */ - _leave(" [replied]"); - return; - } - - if (n == -ENOMEM) { - _debug("oom"); - rxrpc_kernel_abort_call(net->socket, call->rxcall, - RXGEN_SS_MARSHAL, -ENOMEM, - afs_abort_oom); + if (n < 0) { + if (n == -ENOMEM) { + _debug("oom"); + rxrpc_kernel_abort_call(net->socket, call->rxcall, + RXGEN_SS_MARSHAL, -ENOMEM, + afs_abort_oom); + } + _leave(" [error]"); } - _leave(" [error]"); } /*
diff --git a/include/net/af_rxrpc.h b/include/net/af_rxrpc.h
index 0fb4c41c9bbf..f3980348ed34 100644
--- a/include/net/af_rxrpc.h
+++ b/include/net/af_rxrpc.h@@ -64,9 +64,8 @@ struct rxrpc_call *rxrpc_kernel_begin_call(struct socket *sock, bool upgrade, enum rxrpc_interruptibility interruptibility, unsigned int debug_id); -int rxrpc_kernel_send_data(struct socket *, struct rxrpc_call *, - struct msghdr *, size_t, - rxrpc_notify_end_tx_t); +int rxrpc_kernel_send_data(struct socket *sock, struct rxrpc_call *call, + struct msghdr *msg, rxrpc_notify_end_tx_t notify_end_tx); int rxrpc_kernel_recv_data(struct socket *, struct rxrpc_call *, struct iov_iter *, size_t *, bool, u32 *, u16 *); bool rxrpc_kernel_abort_call(struct socket *, struct rxrpc_call *,
diff --git a/net/rxrpc/rxperf.c b/net/rxrpc/rxperf.c
index b8df6d22314d..dad04062213f 100644
--- a/net/rxrpc/rxperf.c
+++ b/net/rxrpc/rxperf.c@@ -525,12 +525,10 @@ static int rxperf_process_call(struct rxperf_call *call) iov_iter_bvec(&msg.msg_iter, WRITE, &bv, 1, len); msg.msg_flags = MSG_MORE; n = rxrpc_kernel_send_data(rxperf_socket, call->rxcall, &msg, - len, rxperf_notify_end_reply_tx); + rxperf_notify_end_reply_tx); if (n < 0) return n; - if (n == 0) - return -EIO; - reply_len -= n; + reply_len -= len; } len = sizeof(rxperf_magic_cookie);
@@ -538,11 +536,8 @@ static int rxperf_process_call(struct rxperf_call *call) iov[0].iov_len = len; iov_iter_kvec(&msg.msg_iter, WRITE, iov, 1, len); msg.msg_flags = 0; - n = rxrpc_kernel_send_data(rxperf_socket, call->rxcall, &msg, len, + n = rxrpc_kernel_send_data(rxperf_socket, call->rxcall, &msg, rxperf_notify_end_reply_tx); - if (n >= 0) - return 0; /* Success */ - if (n == -ENOMEM) rxrpc_kernel_abort_call(rxperf_socket, call->rxcall, RXGEN_SS_MARSHAL, -ENOMEM,
diff --git a/net/rxrpc/sendmsg.c b/net/rxrpc/sendmsg.c
index ed2c9a51005a..34aae8e789a4 100644
--- a/net/rxrpc/sendmsg.c
+++ b/net/rxrpc/sendmsg.c@@ -794,7 +794,6 @@ int rxrpc_do_sendmsg(struct rxrpc_sock *rx, struct msghdr *msg, size_t len) * @sock: The socket the call is on * @call: The call to send data through * @msg: The data to send - * @len: The amount of data to send * @notify_end_tx: Notification that the last packet is queued. * * Allow a kernel service to send data on a call. The call must be in an state
@@ -805,8 +804,7 @@ int rxrpc_do_sendmsg(struct rxrpc_sock *rx, struct msghdr *msg, size_t len) * Return: %0 if successful and a negative error code otherwise. */ int rxrpc_kernel_send_data(struct socket *sock, struct rxrpc_call *call, - struct msghdr *msg, size_t len, - rxrpc_notify_end_tx_t notify_end_tx) + struct msghdr *msg, rxrpc_notify_end_tx_t notify_end_tx) { bool dropped_lock = false; int ret;
@@ -816,15 +814,29 @@ int rxrpc_kernel_send_data(struct socket *sock, struct rxrpc_call *call, ASSERTCMP(msg->msg_name, ==, NULL); ASSERTCMP(msg->msg_control, ==, NULL); - mutex_lock(&call->user_mutex); + for (;;) { + mutex_lock(&call->user_mutex); - ret = rxrpc_send_data(rxrpc_sk(sock->sk), call, msg, len, - notify_end_tx, &dropped_lock); - if (ret == -ESHUTDOWN) - ret = call->error; + ret = rxrpc_send_data(rxrpc_sk(sock->sk), call, msg, + msg_data_left(msg), + notify_end_tx, &dropped_lock); + if (ret == -ESHUTDOWN) + ret = call->error; + + if (!dropped_lock) + mutex_unlock(&call->user_mutex); + if (ret < 0) + break; + if (msg_data_left(msg) == 0) { + ret = 0; + break; + } + if (ret == 0) { + ret = -EIO; + break; + } + } - if (!dropped_lock) - mutex_unlock(&call->user_mutex); _leave(" = %d", ret); return ret; }