From nobody Wed Sep 30 09:51:22 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hvr0c1dzyz6v8cy for ; Wed, 30 Sep 2026 09:51:28 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hvr0b4TGzz3N0l for ; Wed, 30 Sep 2026 09:51:27 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790761887; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YXcAbsgbTBvMH58HvNV1YOW7yzoTasvxhXbHZTZfTfE=; b=P/0vGhO+o31IHdLxXFAB69T5yFI1HzQF6IY9PKQjgI8pgESSzJhtt70aWh7ZhbGHF1Adbi 5CWmsPj+NxG3nRYrNVDeGHBwoyUDHwYgagiWNDRJRz7NOZFAwkPQClKvvYq4nBwXhTbxHk 6HHNGNjwtRbxNk0EAf2nTebnVDXFZk9RVQel4tEn0RTMNm9E1LrOLzgZaX5CVVgAfTcQJG G8AinRUNyILH9l5S34VqBq47FyfXjL75TXebs70RwxE/61/nveLNSO1122KAGHULHf36uA 3B3pFgb17AGhCnkWyfjqiiGpdfiFZG+FDeyT0+36mnt5/vDwz+vxdvkW1jg4Ag== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790761887; b=qZjKS7YRw1wXAGRMJecAfuUkhK91ntBM2nM+n+sElFbgBITK3SigRfvLW0oMrlYkcF+Mib D/MOoTwEwlZFssE0amPYOr5rngIAKphXlz5kopzZpQ59YdYSFj4CaSatSNGtbJVDBes414 s81VV7shMCCUDo85CBBayz8oUqCqL45Y4rv4+rVu4t6hSISq2e6mlYgniQ2iKeX9lrVksX 615jG4rahWNfvx72h+Jb9IHrxQhX24Pt+GWzd4do8NiE97m/EWTIwigYsYyJNc21EnrQ7m 0b5p/sTQlSasCx33BsJZoo88MCIVVwOb1akU3kNKxiF30J0tp7ihb2w/tPUxtQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790761887; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YXcAbsgbTBvMH58HvNV1YOW7yzoTasvxhXbHZTZfTfE=; b=ty2hWJntPm/mZpG9mmcJXJOlbT4l0ItH3usUkQ9GZcn41Ifcb6ECOKxT7il6ROSQWiRqnr VgyWXeKhpQbODIkXMsKn1LPO4f+ux4XL2NhX+QkFKuIAeLq5+Lco1XJHR/0Lko18hY6EvU nXgq1h1xz/5NJYsxvGFbZQKIe0031hGQmpnmQxGXBOzA8DtNSVK0kXiI2pWUF17J9lnEb5 rviAQrI3uYPhQd31kNka9lFIwMas39tgWt5E9aBMnbrp2TMXEDR2ZedC28dFsOxBMO+ONG RvvfNHfZp9D1RzMH2+R9VmKIVlnUybFVUxtUMvYzJjrd7MYvvih1Z+R7vy/4qg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hvr0b3TvGzgvd for ; Wed, 30 Sep 2026 09:51:27 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 34344 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Wed, 30 Sep 2026 09:51:22 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Christos Margiolis Subject: git: 872c36cb6f2d - main - cuse: Fix hang on readv(2) and writev(2) with multiple iovecs List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: christos X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 872c36cb6f2de17278c559a300c2163d8b39b3c6 Auto-Submitted: auto-generated Date: Wed, 30 Sep 2026 09:51:22 +0000 Message-Id: <6abcdb9a.34344.5db12e1c@gitrepo.freebsd.org> The branch main has been updated by christos: URL: https://cgit.FreeBSD.org/src/commit/?id=872c36cb6f2de17278c559a300c2163d8b39b3c6 commit 872c36cb6f2de17278c559a300c2163d8b39b3c6 Author: Christos Margiolis AuthorDate: 2026-09-30 09:49:35 +0000 Commit: Christos Margiolis CommitDate: 2026-09-30 09:49:35 +0000 cuse: Fix hang on readv(2) and writev(2) with multiple iovecs uiomove() leaves an iovec it has just emptied as the current one, so cuse_client_read() and cuse_client_write() picked it up again on the next iteration, sent the server a zero-length command, and got zero bytes back. That left the residual count unchanged, so the loop never terminated and the call never returned. Step past empty iovecs at the start of every iteration. This also covers caller-supplied zero-length iovecs, which hung in the same way PR: 293489 MFC after: 1 week Sponsored by: The FreeBSD Foundation Reviewed by: kib, markj Differential Revision: https://reviews.freebsd.org/D59822 --- sys/fs/cuse/cuse.c | 28 ++++++++++++++++++++++++---- 1 file changed, 24 insertions(+), 4 deletions(-) diff --git a/sys/fs/cuse/cuse.c b/sys/fs/cuse/cuse.c index ef786d125c15..c6107b977dac 100644 --- a/sys/fs/cuse/cuse.c +++ b/sys/fs/cuse/cuse.c @@ -1666,11 +1666,21 @@ cuse_client_read(struct cdev *dev, struct uio *uio, int ioflag) cuse_cmd_lock(pccmd); while (uio->uio_resid != 0) { - if (uio->uio_iov->iov_len > CUSE_LENGTH_MAX) { + len = uio->uio_iov->iov_len; + /* + * The uiomove() below does not step past an iovec it has + * just emptied, so do it here, to avoid an infinite loop + * where we are requesting zero-byte transfers. + */ + if (len == 0) { + uio->uio_iov++; + uio->uio_iovcnt--; + continue; + } + if (len > CUSE_LENGTH_MAX) { error = ENOMEM; break; } - len = uio->uio_iov->iov_len; cuse_server_lock(pcs); if (len <= CUSE_COPY_BUFFER_MAX) { @@ -1754,11 +1764,21 @@ cuse_client_write(struct cdev *dev, struct uio *uio, int ioflag) cuse_cmd_lock(pccmd); while (uio->uio_resid != 0) { - if (uio->uio_iov->iov_len > CUSE_LENGTH_MAX) { + len = uio->uio_iov->iov_len; + /* + * The uiomove() below does not step past an iovec it has + * just emptied, so do it here, to avoid an infinite loop + * where we are requesting zero-byte transfers. + */ + if (len == 0) { + uio->uio_iov++; + uio->uio_iovcnt--; + continue; + } + if (len > CUSE_LENGTH_MAX) { error = ENOMEM; break; } - len = uio->uio_iov->iov_len; if (len <= CUSE_COPY_BUFFER_MAX) { error = copyin(uio->uio_iov->iov_base,