WARNING: at fs/io_uring.c:8578 io_ring_exit_work.cold+0x0/0x18 As reissuing is now passed back by REQ_F_REISSUE, kiocb_done() may just set the flag and do nothing leaving dangling requests. The handling is a bit fragile, e.g. can't just complete them because the case of reading beyond file boundary needs blocking context to return 0, otherwise it may be -EAGAIN. Go the easy way for now, just emulate how it was by io_rw_reissue() in kiocb_done() Fixes: 230d50d448ac ("io_uring: move reissue into regular IO path") Signed-off-by: Pavel Begunkov <asml.silence@xxxxxxxxx> --- fs/io_uring.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/fs/io_uring.c b/fs/io_uring.c index f1881ac0744b..de5822350345 100644 --- a/fs/io_uring.c +++ b/fs/io_uring.c @@ -2762,6 +2762,7 @@ static void kiocb_done(struct kiocb *kiocb, ssize_t ret, { struct io_kiocb *req = container_of(kiocb, struct io_kiocb, rw.kiocb); struct io_async_rw *io = req->async_data; + bool check_reissue = (kiocb->ki_complete == io_complete_rw); /* add previously done IO, if any */ if (io && io->bytes_done > 0) { @@ -2777,6 +2778,11 @@ static void kiocb_done(struct kiocb *kiocb, ssize_t ret, __io_complete_rw(req, ret, 0, issue_flags); else io_rw_done(kiocb, ret); + + if (check_reissue && req->flags & REQ_F_REISSUE) { + req->flags &= ~REQ_F_REISSUE; + io_rw_reissue(req); + } } static int io_import_fixed(struct io_kiocb *req, int rw, struct iov_iter *iter) -- 2.24.0