All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] virtio: validate split queue head count before popping
@ 2026-07-09 10:05 Jia Jia
  2026-07-09 12:43 ` Michael S. Tsirkin
  0 siblings, 1 reply; 7+ messages in thread
From: Jia Jia @ 2026-07-09 10:05 UTC (permalink / raw)
  To: qemu-devel; +Cc: mst, Jia Jia

virtqueue_split_pop() reads the next split avail ring entry after
virtio_queue_empty_rcu() reports work. Call virtqueue_num_heads() before
consuming that entry, so an avail index distance larger than the queue
size is rejected.

virtqueue_num_heads() also keeps the read barrier needed before the avail
ring entry is read.

This prevents an invalid split queue state from being expanded into
repeated device command processing.

Link: https://gitlab.com/qemu-project/qemu/-/issues/3930
Signed-off-by: Jia Jia <physicalmtea@gmail.com>
---
Tested with qemu-system-x86_64 11.0.50, built from origin/master
f893c46c3931 plus this patch, configured with:
  --target-list=x86_64-softmmu --enable-kvm --disable-tcg

The original virtio-iommu live-vring qtest reproducer used for the
report completed successfully on the patched build without host OOM,
confirming that this reproducer is fixed by the patch.

 hw/virtio/virtio.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/hw/virtio/virtio.c b/hw/virtio/virtio.c
index f4d86a3655..252bff8641 100644
--- a/hw/virtio/virtio.c
+++ b/hw/virtio/virtio.c
@@ -1751,9 +1751,11 @@ static void *virtqueue_split_pop(VirtQueue *vq, size_t sz)
     if (virtio_queue_empty_rcu(vq)) {
         goto done;
     }
-    /* Needed after virtio_queue_empty(), see comment in
-     * virtqueue_num_heads(). */
-    smp_rmb();
+
+    rc = virtqueue_num_heads(vq, vq->last_avail_idx);
+    if (rc <= 0) {
+        goto done;
+    }
 
     /* When we start there are none of either input nor output. */
     out_num = in_num = elem_entries = 0;
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-07-26  1:29 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-09 10:05 [PATCH] virtio: validate split queue head count before popping Jia Jia
2026-07-09 12:43 ` Michael S. Tsirkin
2026-07-10  1:34   ` m'te'a physical
2026-07-10  6:21     ` Michael S. Tsirkin
2026-07-10  7:35       ` [PATCH v2] " Jia Jia
2026-07-25 15:32         ` Michael S. Tsirkin
2026-07-26  1:28           ` [PATCH v3] virtio: reduce code duplication for split ring Jia Jia

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.