All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Michael S. Tsirkin" <mst@redhat.com>
To: virtualization@lists.linux.dev
Cc: jasowangio@gmail.com, eperezma@redhat.com,
	xuanzhuo@linux.alibaba.com, jiri@resnulli.us,
	kmehltretter@gmail.com, sashiko-bot@kernel.org,
	linux-kernel@vger.kernel.org
Subject: [PATCH v3 0/3] virtio: fix callback synchronization and avq cleanup on reset
Date: Fri, 11 Sep 2026 17:20:06 -0400	[thread overview]
Message-ID: <cover.1789160982.git.mst@redhat.com> (raw)

Two issues with virtio device reset:

1. Karl Mehltretter reported that virtio_reset_device() promises
   callbacks are not in progress after reset, but only PCI transports
   actually synchronize callbacks - other transports leave a window
   where a handler already executing keeps running while the driver
   tears down state.

2. sashiko reported a race in virtio_pci_modern: the avq interrupt
   handler calls virtqueue_get_buf concurrently with
   virtqueue_detach_unused_buf in vp_modern_avq_cleanup, and there
   is no synchronize_irq between reset and cleanup.

Fix 1 by adding virtio_synchronize_cbs in the core after reset,
then dropping the now-redundant per-transport sync calls. Fix 2 by
moving avq cleanup from vp_reset to vp_del_vqs, which runs after
callbacks have been synchronized - and is where buffer teardown
conceptually belongs.

Changes v2->v3:
    patch 1: unchanged
    patch 2: split from v2 patch 2 - legacy part only
    patch 3: new - v2 just dropped the sync from modern vp_reset,
        leaving avq_cleanup there before the removed sync. v3
        moves avq_cleanup out of vp_reset entirely into vp_del_vqs,
        fixing the race. Adds NULL check for admin_vq.info needed
        because find_vqs error paths call vp_del_vqs before it is
        allocated.

Michael S. Tsirkin (3):
  virtio: synchronize callbacks after device reset
  virtio_pci_legacy: drop callback sync on reset
  virtio_pci_modern: move avq cleanup from reset to del_vqs

 drivers/virtio/virtio.c            |  2 ++
 drivers/virtio/virtio_pci_common.c |  2 ++
 drivers/virtio/virtio_pci_common.h |  1 +
 drivers/virtio/virtio_pci_legacy.c |  2 --
 drivers/virtio/virtio_pci_modern.c | 10 ++++------
 5 files changed, 9 insertions(+), 8 deletions(-)

-- 
MST


             reply	other threads:[~2026-09-11 21:20 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11 21:20 Michael S. Tsirkin [this message]
2026-09-11 21:20 ` [PATCH v3 1/3] virtio: synchronize callbacks after device reset Michael S. Tsirkin
2026-09-11 21:37   ` sashiko-bot
2026-09-11 22:50   ` Karl Mehltretter
2026-09-11 21:20 ` [PATCH v3 3/3] virtio_pci_modern: move avq cleanup from reset to del_vqs Michael S. Tsirkin
2026-09-11 21:38   ` sashiko-bot
2026-09-11 22:48   ` Karl Mehltretter
2026-09-11 22:51     ` Michael S. Tsirkin
2026-09-11 21:20 ` [PATCH v3 2/3] virtio_pci_legacy: drop callback sync on reset Michael S. Tsirkin
2026-09-11 21:38   ` sashiko-bot
2026-09-11 22:51   ` Karl Mehltretter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1789160982.git.mst@redhat.com \
    --to=mst@redhat.com \
    --cc=eperezma@redhat.com \
    --cc=jasowangio@gmail.com \
    --cc=jiri@resnulli.us \
    --cc=kmehltretter@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sashiko-bot@kernel.org \
    --cc=virtualization@lists.linux.dev \
    --cc=xuanzhuo@linux.alibaba.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.