From: Bobby Eshleman <bobbyeshleman@gmail.com>
To: Weiming Shi <bestswngs@gmail.com>
Cc: "Michael S. Tsirkin" <mst@redhat.com>,
"Jason Wang" <jasowangio@gmail.com>,
"Xuan Zhuo" <xuanzhuo@linux.alibaba.com>,
"Eugenio Pérez" <eperezma@redhat.com>,
"Stefan Hajnoczi" <stefanha@redhat.com>,
"Stefano Garzarella" <sgarzare@redhat.com>,
"David S. Miller" <davem@davemloft.net>,
"Eric Dumazet" <edumazet@google.com>,
"Jakub Kicinski" <kuba@kernel.org>,
"Paolo Abeni" <pabeni@redhat.com>,
"Simon Horman" <horms@kernel.org>,
virtualization@lists.linux.dev, kvm@vger.kernel.org,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
"Xiang Mei" <xmei5@asu.edu>,
"Bobby Eshleman" <bobbyeshleman@meta.com>
Subject: Re: [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown
Date: Thu, 30 Jul 2026 14:46:28 -0700 [thread overview]
Message-ID: <amvGNBmggisFqA0k@devvm29614.prn0.facebook.com> (raw)
In-Reply-To: <f9c8c1d64cad9d262f305d02ffe164c2f900fadf.1785352330.git.bestswngs@gmail.com>
On Wed, Jul 29, 2026 at 12:16:55PM -0700, Weiming Shi wrote:
> Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
> made the RX worker jump to its common exit when rx_run is clear. That
> exit still refills the RX queue when the buffer count is low, so work
> queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
> have been deleted.
>
> BUG: KASAN: slab-use-after-free in virtqueue_add_sgs
> Read of size 4 by task kworker/0:1
> Workqueue: virtio_vsock virtio_transport_rx_work
> Call Trace:
> virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)
> virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)
> virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)
> process_one_work (kernel/workqueue.c:3314)
> worker_thread (kernel/workqueue.c:3478)
> kthread (kernel/kthread.c:436)
> ret_from_fork (arch/x86/kernel/process.c:158)
> ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
> ...
> Freed by task 141:
> kfree (mm/slub.c:6566)
> vp_del_vq (drivers/virtio/virtio_pci_common.c:259)
> vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)
> virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)
> virtio_device_freeze (drivers/virtio/virtio.c:658)
> virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)
> pci_pm_freeze (drivers/pci/pci-driver.c:1098)
> device_suspend (drivers/base/power/main.c:1968)
> Kernel panic - not syncing: KASAN: panic_on_warn set ...
>
> Jump to a no-refill exit when rx_run is clear, leaving the normal exit
> to replenish a running queue.
>
> Fixes: b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
> Cc: stable@vger.kernel.org
> Reported-by: Xiang Mei <xmei5@asu.edu>
> Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
> Suggested-by: Stefano Garzarella <sgarzare@redhat.com>
> Assisted-by: OpenAI-Codex:gpt-5
> Signed-off-by: Weiming Shi <bestswngs@gmail.com>
> ---
> net/vmw_vsock/virtio_transport.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
> index a8e1dd95ba8c..96c9fe8d357c 100644
> --- a/net/vmw_vsock/virtio_transport.c
> +++ b/net/vmw_vsock/virtio_transport.c
> @@ -638,7 +638,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
> mutex_lock(&vsock->rx_lock);
>
> if (!vsock->rx_run)
> - goto out;
> + goto out_nofill;
>
> vq = vsock->vqs[VSOCK_VQ_RX];
>
> @@ -692,6 +692,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
> out:
> if (vsock->rx_buf_nr < vsock->rx_buf_max_nr / 2)
> virtio_vsock_rx_fill(vsock);
> +out_nofill:
> mutex_unlock(&vsock->rx_lock);
> }
>
> --
> 2.55.0
>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
prev parent reply other threads:[~2026-07-30 21:46 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 18:58 [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown Weiming Shi
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
2026-07-30 21:46 ` Bobby Eshleman
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
2026-07-30 19:17 ` sashiko-bot
2026-07-30 21:46 ` Bobby Eshleman [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amvGNBmggisFqA0k@devvm29614.prn0.facebook.com \
--to=bobbyeshleman@gmail.com \
--cc=bestswngs@gmail.com \
--cc=bobbyeshleman@meta.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=eperezma@redhat.com \
--cc=horms@kernel.org \
--cc=jasowangio@gmail.com \
--cc=kuba@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mst@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=sgarzare@redhat.com \
--cc=stefanha@redhat.com \
--cc=virtualization@lists.linux.dev \
--cc=xmei5@asu.edu \
--cc=xuanzhuo@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.