* [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown
@ 2026-07-29 18:58 Weiming Shi
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
0 siblings, 1 reply; 7+ messages in thread
From: Weiming Shi @ 2026-07-29 18:58 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Virtio-vsock workers can remain queued while freeze deletes the
virtqueues. This series prevents workers delayed across freeze and
restore from retaining pointers to deleted queues, and prevents the RX
worker from refilling its queue after teardown.
Changes in v2:
- Split the worker pointer changes from the RX refill fix because they
fix different commits.
- Use bd50c5dc182b as the Fixes tag for the worker pointer changes.
- Keep b917507e5ad9 as the Fixes tag for the RX refill fix.
- Use the suggested out_nofill label when rx_run is clear.
Weiming Shi (2):
vsock/virtio: read virtqueues under worker locks
vsock/virtio: avoid refilling the RX queue after teardown
net/vmw_vsock/virtio_transport.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
base-commit: 51b093a7ba27476e1f639455f005e8d2e75390e4
--
2.55.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 0/2] vsock/virtio: fix worker access after virtqueue teardown
2026-07-29 18:58 [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown Weiming Shi
@ 2026-07-29 19:16 ` Weiming Shi
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
0 siblings, 2 replies; 7+ messages in thread
From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Virtio-vsock workers can remain queued while freeze deletes the
virtqueues. This series prevents workers delayed across freeze and
restore from retaining pointers to deleted queues, and prevents the RX
worker from refilling its queue after teardown.
Changes in v3:
- Resend the series with proper email threading; no code changes.
Changes in v2:
- Split the worker pointer changes from the RX refill fix because they
fix different commits.
- Use bd50c5dc182b as the Fixes tag for the worker pointer changes.
- Keep b917507e5ad9 as the Fixes tag for the RX refill fix.
- Use the suggested out_nofill label when rx_run is clear.
Weiming Shi (2):
vsock/virtio: read virtqueues under worker locks
vsock/virtio: avoid refilling the RX queue after teardown
net/vmw_vsock/virtio_transport.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
base-commit: 51b093a7ba27476e1f639455f005e8d2e75390e4
--
2.55.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
@ 2026-07-29 19:16 ` Weiming Shi
2026-07-30 21:46 ` Bobby Eshleman
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
1 sibling, 1 reply; 7+ messages in thread
From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Commit bd50c5dc182b ("vsock/virtio: add support for device
suspend/resume") made the *_run flags transition from false to true when
restore installs replacement virtqueues. The RX, TX and event workers
read their virtqueue before locking and checking the corresponding flag,
so a worker delayed across freeze and restore can observe the replacement
queue's running state while retaining a pointer to the deleted queue.
Read each virtqueue under its mutex after checking the run flag, keeping
the pointer and state in the same queue generation.
Fixes: bd50c5dc182b ("vsock/virtio: add support for device suspend/resume")
Cc: stable@vger.kernel.org
Reported-by: Xiang Mei <xmei5@asu.edu>
Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
Assisted-by: OpenAI-Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
---
net/vmw_vsock/virtio_transport.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
index 57f2d6ec3ffc..a8e1dd95ba8c 100644
--- a/net/vmw_vsock/virtio_transport.c
+++ b/net/vmw_vsock/virtio_transport.c
@@ -346,12 +346,13 @@ static void virtio_transport_tx_work(struct work_struct *work)
struct virtqueue *vq;
bool added = false;
- vq = vsock->vqs[VSOCK_VQ_TX];
mutex_lock(&vsock->tx_lock);
if (!vsock->tx_run)
goto out;
+ vq = vsock->vqs[VSOCK_VQ_TX];
+
do {
struct sk_buff *skb;
unsigned int len;
@@ -451,13 +452,13 @@ static void virtio_transport_event_work(struct work_struct *work)
container_of(work, struct virtio_vsock, event_work);
struct virtqueue *vq;
- vq = vsock->vqs[VSOCK_VQ_EVENT];
-
mutex_lock(&vsock->event_lock);
if (!vsock->event_run)
goto out;
+ vq = vsock->vqs[VSOCK_VQ_EVENT];
+
do {
struct virtio_vsock_event *event;
unsigned int len;
@@ -634,13 +635,13 @@ static void virtio_transport_rx_work(struct work_struct *work)
container_of(work, struct virtio_vsock, rx_work);
struct virtqueue *vq;
- vq = vsock->vqs[VSOCK_VQ_RX];
-
mutex_lock(&vsock->rx_lock);
if (!vsock->rx_run)
goto out;
+ vq = vsock->vqs[VSOCK_VQ_RX];
+
do {
virtqueue_disable_cb(vq);
for (;;) {
--
2.55.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
@ 2026-07-29 19:16 ` Weiming Shi
2026-07-30 19:17 ` sashiko-bot
2026-07-30 21:46 ` Bobby Eshleman
1 sibling, 2 replies; 7+ messages in thread
From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
made the RX worker jump to its common exit when rx_run is clear. That
exit still refills the RX queue when the buffer count is low, so work
queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
have been deleted.
BUG: KASAN: slab-use-after-free in virtqueue_add_sgs
Read of size 4 by task kworker/0:1
Workqueue: virtio_vsock virtio_transport_rx_work
Call Trace:
virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)
virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)
virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3478)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
...
Freed by task 141:
kfree (mm/slub.c:6566)
vp_del_vq (drivers/virtio/virtio_pci_common.c:259)
vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)
virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)
virtio_device_freeze (drivers/virtio/virtio.c:658)
virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)
pci_pm_freeze (drivers/pci/pci-driver.c:1098)
device_suspend (drivers/base/power/main.c:1968)
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Jump to a no-refill exit when rx_run is clear, leaving the normal exit
to replenish a running queue.
Fixes: b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
Cc: stable@vger.kernel.org
Reported-by: Xiang Mei <xmei5@asu.edu>
Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
Suggested-by: Stefano Garzarella <sgarzare@redhat.com>
Assisted-by: OpenAI-Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
---
net/vmw_vsock/virtio_transport.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
index a8e1dd95ba8c..96c9fe8d357c 100644
--- a/net/vmw_vsock/virtio_transport.c
+++ b/net/vmw_vsock/virtio_transport.c
@@ -638,7 +638,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
mutex_lock(&vsock->rx_lock);
if (!vsock->rx_run)
- goto out;
+ goto out_nofill;
vq = vsock->vqs[VSOCK_VQ_RX];
@@ -692,6 +692,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
out:
if (vsock->rx_buf_nr < vsock->rx_buf_max_nr / 2)
virtio_vsock_rx_fill(vsock);
+out_nofill:
mutex_unlock(&vsock->rx_lock);
}
--
2.55.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
@ 2026-07-30 19:17 ` sashiko-bot
2026-07-30 21:46 ` Bobby Eshleman
1 sibling, 0 replies; 7+ messages in thread
From: sashiko-bot @ 2026-07-30 19:17 UTC (permalink / raw)
To: Weiming Shi; +Cc: kvm
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Incorrect `flush_work` ordering in `virtio_vsock_remove()` allows `virtio_transport_rx_work` to execute after the `vsock` object has been freed.
--
--- Patch [2]: [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown ---
commit e28975cab51c80e977d0774ef653bc9c4660fff0
Author: Weiming Shi <bestswngs@gmail.com>
vsock/virtio: avoid refilling the RX queue after teardown
Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
made the RX worker jump to its common exit when rx_run is clear. That
exit still refills the RX queue when the buffer count is low, so work
queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
have been deleted.
Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
> diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
> index 57f2d6ec3ffc6..96c9fe8d357c6 100644
> --- a/net/vmw_vsock/virtio_transport.c
> +++ b/net/vmw_vsock/virtio_transport.c
[ ... ]
> @@ -634,12 +635,12 @@ static void virtio_transport_rx_work(struct work_struct *work)
> container_of(work, struct virtio_vsock, rx_work);
> struct virtqueue *vq;
>
> - vq = vsock->vqs[VSOCK_VQ_RX];
> -
> mutex_lock(&vsock->rx_lock);
>
> if (!vsock->rx_run)
> - goto out;
> + goto out_nofill;
[Severity: High]
This is a pre-existing issue, but I have a question about the workqueue
teardown logic that can still trigger a use-after-free for vsock.
In virtio_vsock_remove(), the workqueues are flushed in this order:
net/vmw_vsock/virtio_transport.c:virtio_vsock_remove() {
...
flush_work(&vsock->rx_work);
flush_work(&vsock->tx_work);
flush_work(&vsock->event_work);
flush_work(&vsock->send_pkt_work);
...
}
However, virtio_transport_send_pkt_work() can queue rx_work without holding
locks if restart_rx is true:
net/vmw_vsock/virtio_transport.c:virtio_transport_send_pkt_work() {
...
out:
mutex_unlock(&vsock->tx_lock);
if (restart_rx)
queue_work(virtio_vsock_workqueue, &vsock->rx_work);
}
If a worker executing virtio_transport_send_pkt_work() is preempted just
before calling queue_work(), and a concurrent virtio_vsock_remove() flushes
rx_work and then blocks flushing send_pkt_work, couldn't the preempted
worker then resume and queue a new rx_work?
This newly queued rx_work would be left pending after virtio_vsock_remove()
completes, causing a use-after-free when the vsock structure is freed.
Should virtio_vsock_remove() flush send_pkt_work before rx_work to prevent
this race?
> +
> + vq = vsock->vqs[VSOCK_VQ_RX];
>
> do {
> virtqueue_disable_cb(vq);
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1785352330.git.bestswngs@gmail.com?part=2
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
2026-07-30 19:17 ` sashiko-bot
@ 2026-07-30 21:46 ` Bobby Eshleman
1 sibling, 0 replies; 7+ messages in thread
From: Bobby Eshleman @ 2026-07-30 21:46 UTC (permalink / raw)
To: Weiming Shi
Cc: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman,
virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
On Wed, Jul 29, 2026 at 12:16:55PM -0700, Weiming Shi wrote:
> Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
> made the RX worker jump to its common exit when rx_run is clear. That
> exit still refills the RX queue when the buffer count is low, so work
> queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
> have been deleted.
>
> BUG: KASAN: slab-use-after-free in virtqueue_add_sgs
> Read of size 4 by task kworker/0:1
> Workqueue: virtio_vsock virtio_transport_rx_work
> Call Trace:
> virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)
> virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)
> virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)
> process_one_work (kernel/workqueue.c:3314)
> worker_thread (kernel/workqueue.c:3478)
> kthread (kernel/kthread.c:436)
> ret_from_fork (arch/x86/kernel/process.c:158)
> ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
> ...
> Freed by task 141:
> kfree (mm/slub.c:6566)
> vp_del_vq (drivers/virtio/virtio_pci_common.c:259)
> vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)
> virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)
> virtio_device_freeze (drivers/virtio/virtio.c:658)
> virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)
> pci_pm_freeze (drivers/pci/pci-driver.c:1098)
> device_suspend (drivers/base/power/main.c:1968)
> Kernel panic - not syncing: KASAN: panic_on_warn set ...
>
> Jump to a no-refill exit when rx_run is clear, leaving the normal exit
> to replenish a running queue.
>
> Fixes: b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
> Cc: stable@vger.kernel.org
> Reported-by: Xiang Mei <xmei5@asu.edu>
> Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
> Suggested-by: Stefano Garzarella <sgarzare@redhat.com>
> Assisted-by: OpenAI-Codex:gpt-5
> Signed-off-by: Weiming Shi <bestswngs@gmail.com>
> ---
> net/vmw_vsock/virtio_transport.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
> index a8e1dd95ba8c..96c9fe8d357c 100644
> --- a/net/vmw_vsock/virtio_transport.c
> +++ b/net/vmw_vsock/virtio_transport.c
> @@ -638,7 +638,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
> mutex_lock(&vsock->rx_lock);
>
> if (!vsock->rx_run)
> - goto out;
> + goto out_nofill;
>
> vq = vsock->vqs[VSOCK_VQ_RX];
>
> @@ -692,6 +692,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
> out:
> if (vsock->rx_buf_nr < vsock->rx_buf_max_nr / 2)
> virtio_vsock_rx_fill(vsock);
> +out_nofill:
> mutex_unlock(&vsock->rx_lock);
> }
>
> --
> 2.55.0
>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
@ 2026-07-30 21:46 ` Bobby Eshleman
0 siblings, 0 replies; 7+ messages in thread
From: Bobby Eshleman @ 2026-07-30 21:46 UTC (permalink / raw)
To: Weiming Shi
Cc: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman,
virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
On Wed, Jul 29, 2026 at 12:16:54PM -0700, Weiming Shi wrote:
> Commit bd50c5dc182b ("vsock/virtio: add support for device
> suspend/resume") made the *_run flags transition from false to true when
> restore installs replacement virtqueues. The RX, TX and event workers
> read their virtqueue before locking and checking the corresponding flag,
> so a worker delayed across freeze and restore can observe the replacement
> queue's running state while retaining a pointer to the deleted queue.
>
> Read each virtqueue under its mutex after checking the run flag, keeping
> the pointer and state in the same queue generation.
>
> Fixes: bd50c5dc182b ("vsock/virtio: add support for device suspend/resume")
> Cc: stable@vger.kernel.org
> Reported-by: Xiang Mei <xmei5@asu.edu>
> Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
> Assisted-by: OpenAI-Codex:gpt-5
> Signed-off-by: Weiming Shi <bestswngs@gmail.com>
> ---
> net/vmw_vsock/virtio_transport.c | 11 ++++++-----
> 1 file changed, 6 insertions(+), 5 deletions(-)
>
> diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
> index 57f2d6ec3ffc..a8e1dd95ba8c 100644
> --- a/net/vmw_vsock/virtio_transport.c
> +++ b/net/vmw_vsock/virtio_transport.c
> @@ -346,12 +346,13 @@ static void virtio_transport_tx_work(struct work_struct *work)
> struct virtqueue *vq;
> bool added = false;
>
> - vq = vsock->vqs[VSOCK_VQ_TX];
> mutex_lock(&vsock->tx_lock);
>
> if (!vsock->tx_run)
> goto out;
>
> + vq = vsock->vqs[VSOCK_VQ_TX];
> +
> do {
> struct sk_buff *skb;
> unsigned int len;
> @@ -451,13 +452,13 @@ static void virtio_transport_event_work(struct work_struct *work)
> container_of(work, struct virtio_vsock, event_work);
> struct virtqueue *vq;
>
> - vq = vsock->vqs[VSOCK_VQ_EVENT];
> -
> mutex_lock(&vsock->event_lock);
>
> if (!vsock->event_run)
> goto out;
>
> + vq = vsock->vqs[VSOCK_VQ_EVENT];
> +
> do {
> struct virtio_vsock_event *event;
> unsigned int len;
> @@ -634,13 +635,13 @@ static void virtio_transport_rx_work(struct work_struct *work)
> container_of(work, struct virtio_vsock, rx_work);
> struct virtqueue *vq;
>
> - vq = vsock->vqs[VSOCK_VQ_RX];
> -
> mutex_lock(&vsock->rx_lock);
>
> if (!vsock->rx_run)
> goto out;
>
> + vq = vsock->vqs[VSOCK_VQ_RX];
> +
> do {
> virtqueue_disable_cb(vq);
> for (;;) {
> --
> 2.55.0
>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-07-30 21:47 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 18:58 [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown Weiming Shi
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
2026-07-30 21:46 ` Bobby Eshleman
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
2026-07-30 19:17 ` sashiko-bot
2026-07-30 21:46 ` Bobby Eshleman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.