From: "Michael S. Tsirkin" <mst@redhat.com>
To: Karl Mehltretter <kmehltretter@gmail.com>
Cc: "Jason Wang" <jasowangio@gmail.com>,
"Gerd Hoffmann" <kraxel@redhat.com>,
"Xuan Zhuo" <xuanzhuo@linux.alibaba.com>,
"Eugenio Pérez" <eperezma@redhat.com>,
"Dmitry Torokhov" <dmitry.torokhov@gmail.com>,
"Rusty Russell" <rusty@rustcorp.com.au>,
"Pawel Moll" <pawel.moll@arm.com>,
"Cornelia Huck" <cohuck@redhat.com>,
"Halil Pasic" <pasic@linux.ibm.com>,
"Eric Farman" <farman@linux.ibm.com>,
"Richard Weinberger" <richard@nod.at>,
"Anton Ivanov" <anton.ivanov@cambridgegreys.com>,
"Johannes Berg" <johannes@sipsolutions.net>,
"Hans de Goede" <hansg@kernel.org>,
"Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>,
"Vadim Pasternak" <vadimp@nvidia.com>,
"Bjorn Andersson" <andersson@kernel.org>,
"Mathieu Poirier" <mathieu.poirier@linaro.org>,
virtualization@lists.linux.dev, linux-input@vger.kernel.org,
linux-s390@vger.kernel.org, kvm@vger.kernel.org,
linux-um@lists.infradead.org,
platform-driver-x86@vger.kernel.org,
linux-remoteproc@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2 2/3] virtio_input: stop callbacks before unregistering input device
Date: Sun, 6 Sep 2026 02:51:58 -0400 [thread overview]
Message-ID: <20260906025002-mutt-send-email-mst@kernel.org> (raw)
In-Reply-To: <20260905152059.89560-3-kmehltretter@gmail.com>
On Sat, Sep 05, 2026 at 05:20:58PM +0200, Karl Mehltretter wrote:
> virtinput_remove() unregisters the input device before resetting the
> virtio device. virtinput_recv_events() drops vi->lock around input_event(),
> so clearing vi->ready does not stop a callback that passed the entry check.
> It can still use vi->idev, requeue buffers and kick the queue.
>
> Reset first, as virtinput_freeze() already does. With the preceding core
> change, reset waits for callbacks before input_unregister_device() can
> free vi->idev. Recheck vi->ready after taking the lock again: keep draining
> completed events so an input packet is not truncated, but stop requeueing
> buffers and kicking the queue.
>
> With evdev attached, input_unregister_handle() currently waits for an RCU
> grace period, which also waits out IRQ callbacks. This masks the lifetime
> bug on PCI and MMIO, but does not protect sleepable callbacks on other
> transports.
And now I am completely confused. So it is other transports you are
worried about? Which ones did you test? And why don't you worry about
fixing other transports in 1/3?
> Fixes: 271c865161c5 ("Add virtio-input driver.")
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
> ---
> drivers/virtio/virtio_input.c | 8 ++++++--
> 1 file changed, 6 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/virtio/virtio_input.c b/drivers/virtio/virtio_input.c
> index deec24e8e682..7b654af0a42c 100644
> --- a/drivers/virtio/virtio_input.c
> +++ b/drivers/virtio/virtio_input.c
> @@ -49,9 +49,12 @@ static void virtinput_recv_events(struct virtqueue *vq)
> le16_to_cpu(event->code),
> le32_to_cpu(event->value));
> spin_lock_irqsave(&vi->lock, flags);
> + if (!vi->ready)
> + continue;
> virtinput_queue_evtbuf(vi, event);
> }
> - virtqueue_kick(vq);
> + if (vi->ready)
> + virtqueue_kick(vq);
> }
> spin_unlock_irqrestore(&vi->lock, flags);
> }
> @@ -350,8 +353,9 @@ static void virtinput_remove(struct virtio_device *vdev)
> vi->ready = false;
> spin_unlock_irqrestore(&vi->lock, flags);
>
> - input_unregister_device(vi->idev);
> + /* Callbacks use vi->idev. */
> virtio_reset_device(vdev);
> + input_unregister_device(vi->idev);
> while ((buf = virtqueue_detach_unused_buf(vi->sts)) != NULL)
> kfree(buf);
> vdev->config->del_vqs(vdev);
> --
> 2.39.5 (Apple Git-154)
next prev parent reply other threads:[~2026-09-06 6:52 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 15:20 [PATCH v2 0/3] virtio: synchronize callbacks during device reset Karl Mehltretter
2026-09-05 15:20 ` [PATCH v2 1/3] " Karl Mehltretter
2026-09-05 15:35 ` sashiko-bot
2026-09-06 6:49 ` Michael S. Tsirkin
2026-09-07 21:36 ` Michael S. Tsirkin
2026-09-05 15:20 ` [PATCH v2 2/3] virtio_input: stop callbacks before unregistering input device Karl Mehltretter
2026-09-05 15:33 ` sashiko-bot
2026-09-07 21:19 ` Michael S. Tsirkin
2026-09-06 6:51 ` Michael S. Tsirkin [this message]
2026-09-07 21:46 ` Michael S. Tsirkin
2026-09-07 22:15 ` Karl Mehltretter
2026-09-07 22:22 ` Michael S. Tsirkin
2026-09-07 22:32 ` Karl Mehltretter
2026-09-05 15:20 ` [PATCH v2 3/3] virtio: implement synchronize_cbs for remaining transports Karl Mehltretter
2026-09-05 15:35 ` sashiko-bot
2026-09-06 18:59 ` Michael S. Tsirkin
2026-09-06 6:43 ` [PATCH v2 0/3] virtio: synchronize callbacks during device reset Michael S. Tsirkin
2026-09-06 6:53 ` Michael S. Tsirkin
2026-09-06 16:32 ` Karl Mehltretter
2026-09-06 18:56 ` Michael S. Tsirkin
2026-09-07 13:13 ` Michael S. Tsirkin
2026-09-07 21:23 ` Karl Mehltretter
2026-09-07 21:41 ` Michael S. Tsirkin
2026-09-11 12:39 ` Michael S. Tsirkin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260906025002-mutt-send-email-mst@kernel.org \
--to=mst@redhat.com \
--cc=andersson@kernel.org \
--cc=anton.ivanov@cambridgegreys.com \
--cc=cohuck@redhat.com \
--cc=dmitry.torokhov@gmail.com \
--cc=eperezma@redhat.com \
--cc=farman@linux.ibm.com \
--cc=hansg@kernel.org \
--cc=ilpo.jarvinen@linux.intel.com \
--cc=jasowangio@gmail.com \
--cc=johannes@sipsolutions.net \
--cc=kmehltretter@gmail.com \
--cc=kraxel@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=linux-input@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-remoteproc@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=linux-um@lists.infradead.org \
--cc=mathieu.poirier@linaro.org \
--cc=pasic@linux.ibm.com \
--cc=pawel.moll@arm.com \
--cc=platform-driver-x86@vger.kernel.org \
--cc=richard@nod.at \
--cc=rusty@rustcorp.com.au \
--cc=vadimp@nvidia.com \
--cc=virtualization@lists.linux.dev \
--cc=xuanzhuo@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.