[PATCH bpf-next 1/2] bpf, sockmap: Fix udp_bpf_recvmsg() spinning on backlog-only ingress

From: chenyuan_fl

Date: Tue Sep 29 2026 - 04:40:20 EST


From: Yuan Chen <chenyuan@xxxxxxxxxx>

udp_bpf_recvmsg() re-arms its msg_bytes_ready loop whenever
psock_has_data() is true, but that predicate also covers an skb parked
in psock->ingress_skb, which sk_msg_recvmsg() can never consume: it
only walks psock->ingress_msg.

When the backlog stays populated, e.g. while sk_psock_handle_skb()
keeps returning -EAGAIN, every round gets copied == 0 and
udp_msg_wait_data() returns 1 again from that same skb, so the loop
never sleeps: recvmsg() spins at 100% CPU while holding the socket
lock, ignores SO_RCVTIMEO and never returns to user space.

The wide probe is intended for the entry check and the wait condition,
but re-arming can only make progress from ingress_msg. TCP and
unix_bpf_recvmsg() therefore re-arm on !sk_psock_queue_empty(psock)
and otherwise fall back to the plain receive path. Do the same for UDP
so the reader sleeps and returns -EAGAIN on timeout as expected.

Fixes: 9f2470fbc4cb ("skmsg: Improve udp_bpf_recvmsg() accuracy")
Signed-off-by: Yuan Chen <chenyuan@xxxxxxxxxx>
---
net/ipv4/udp_bpf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv4/udp_bpf.c b/net/ipv4/udp_bpf.c
index ad57c4c9eaab..8aca9fb89334 100644
--- a/net/ipv4/udp_bpf.c
+++ b/net/ipv4/udp_bpf.c
@@ -91,7 +91,7 @@ static int udp_bpf_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
timeo = sock_rcvtimeo(sk, flags & MSG_DONTWAIT);
data = udp_msg_wait_data(sk, psock, timeo);
if (data) {
- if (psock_has_data(psock))
+ if (!sk_psock_queue_empty(psock))
goto msg_bytes_ready;

release_sock(sk);
--
2.54.0