io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF
authorJens Axboe <axboe@kernel.dk>
Thu, 19 Mar 2026 20:29:09 +0000 (14:29 -0600)
committerJens Axboe <axboe@kernel.dk>
Thu, 19 Mar 2026 21:09:40 +0000 (15:09 -0600)
commit3ecd3e03144b38a21a3b70254f1b9d2e16629b09
treef22e192299277974691d60645d808aeb4f84d6b6
parenta68ed2df72131447d131531a08fe4dfcf4fa4653
io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF

For a zero length transfer, io_kbuf_inc_commit() is called with !len.
Since we never enter the while loop to consume the buffers,
io_kbuf_inc_commit() ends up returning true, consuming the buffer. But
if no data was consumed, by definition it cannot have consumed the
buffer. Return false for that case.

Reported-by: Martin Michaelis <code@mgjm.de>
Cc: stable@vger.kernel.org
Fixes: ae98dbf43d75 ("io_uring/kbuf: add support for incremental buffer consumption")
Link: https://github.com/axboe/liburing/issues/1553
Signed-off-by: Jens Axboe <axboe@kernel.dk>
io_uring/kbuf.c