* [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown @ 2026-07-29 18:58 Weiming Shi 2026-07-29 19:16 ` [PATCH v3 " Weiming Shi 0 siblings, 1 reply; 7+ messages in thread From: Weiming Shi @ 2026-07-29 18:58 UTC (permalink / raw) To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez, Stefan Hajnoczi, Stefano Garzarella, David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei, Bobby Eshleman Virtio-vsock workers can remain queued while freeze deletes the virtqueues. This series prevents workers delayed across freeze and restore from retaining pointers to deleted queues, and prevents the RX worker from refilling its queue after teardown. Changes in v2: - Split the worker pointer changes from the RX refill fix because they fix different commits. - Use bd50c5dc182b as the Fixes tag for the worker pointer changes. - Keep b917507e5ad9 as the Fixes tag for the RX refill fix. - Use the suggested out_nofill label when rx_run is clear. Weiming Shi (2): vsock/virtio: read virtqueues under worker locks vsock/virtio: avoid refilling the RX queue after teardown net/vmw_vsock/virtio_transport.c | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) base-commit: 51b093a7ba27476e1f639455f005e8d2e75390e4 -- 2.55.0 ^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 0/2] vsock/virtio: fix worker access after virtqueue teardown 2026-07-29 18:58 [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown Weiming Shi @ 2026-07-29 19:16 ` Weiming Shi 2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi 2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi 0 siblings, 2 replies; 7+ messages in thread From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw) To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez, Stefan Hajnoczi, Stefano Garzarella, David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei, Bobby Eshleman Virtio-vsock workers can remain queued while freeze deletes the virtqueues. This series prevents workers delayed across freeze and restore from retaining pointers to deleted queues, and prevents the RX worker from refilling its queue after teardown. Changes in v3: - Resend the series with proper email threading; no code changes. Changes in v2: - Split the worker pointer changes from the RX refill fix because they fix different commits. - Use bd50c5dc182b as the Fixes tag for the worker pointer changes. - Keep b917507e5ad9 as the Fixes tag for the RX refill fix. - Use the suggested out_nofill label when rx_run is clear. Weiming Shi (2): vsock/virtio: read virtqueues under worker locks vsock/virtio: avoid refilling the RX queue after teardown net/vmw_vsock/virtio_transport.c | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) base-commit: 51b093a7ba27476e1f639455f005e8d2e75390e4 -- 2.55.0 ^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks 2026-07-29 19:16 ` [PATCH v3 " Weiming Shi @ 2026-07-29 19:16 ` Weiming Shi 2026-07-30 21:46 ` Bobby Eshleman 2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi 1 sibling, 1 reply; 7+ messages in thread From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw) To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez, Stefan Hajnoczi, Stefano Garzarella, David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei, Bobby Eshleman Commit bd50c5dc182b ("vsock/virtio: add support for device suspend/resume") made the *_run flags transition from false to true when restore installs replacement virtqueues. The RX, TX and event workers read their virtqueue before locking and checking the corresponding flag, so a worker delayed across freeze and restore can observe the replacement queue's running state while retaining a pointer to the deleted queue. Read each virtqueue under its mutex after checking the run flag, keeping the pointer and state in the same queue generation. Fixes: bd50c5dc182b ("vsock/virtio: add support for device suspend/resume") Cc: stable@vger.kernel.org Reported-by: Xiang Mei <xmei5@asu.edu> Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com Assisted-by: OpenAI-Codex:gpt-5 Signed-off-by: Weiming Shi <bestswngs@gmail.com> --- net/vmw_vsock/virtio_transport.c | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c index 57f2d6ec3ffc..a8e1dd95ba8c 100644 --- a/net/vmw_vsock/virtio_transport.c +++ b/net/vmw_vsock/virtio_transport.c @@ -346,12 +346,13 @@ static void virtio_transport_tx_work(struct work_struct *work) struct virtqueue *vq; bool added = false; - vq = vsock->vqs[VSOCK_VQ_TX]; mutex_lock(&vsock->tx_lock); if (!vsock->tx_run) goto out; + vq = vsock->vqs[VSOCK_VQ_TX]; + do { struct sk_buff *skb; unsigned int len; @@ -451,13 +452,13 @@ static void virtio_transport_event_work(struct work_struct *work) container_of(work, struct virtio_vsock, event_work); struct virtqueue *vq; - vq = vsock->vqs[VSOCK_VQ_EVENT]; - mutex_lock(&vsock->event_lock); if (!vsock->event_run) goto out; + vq = vsock->vqs[VSOCK_VQ_EVENT]; + do { struct virtio_vsock_event *event; unsigned int len; @@ -634,13 +635,13 @@ static void virtio_transport_rx_work(struct work_struct *work) container_of(work, struct virtio_vsock, rx_work); struct virtqueue *vq; - vq = vsock->vqs[VSOCK_VQ_RX]; - mutex_lock(&vsock->rx_lock); if (!vsock->rx_run) goto out; + vq = vsock->vqs[VSOCK_VQ_RX]; + do { virtqueue_disable_cb(vq); for (;;) { -- 2.55.0 ^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks 2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi @ 2026-07-30 21:46 ` Bobby Eshleman 0 siblings, 0 replies; 7+ messages in thread From: Bobby Eshleman @ 2026-07-30 21:46 UTC (permalink / raw) To: Weiming Shi Cc: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez, Stefan Hajnoczi, Stefano Garzarella, David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman, virtualization, kvm, netdev, linux-kernel, Xiang Mei, Bobby Eshleman On Wed, Jul 29, 2026 at 12:16:54PM -0700, Weiming Shi wrote: > Commit bd50c5dc182b ("vsock/virtio: add support for device > suspend/resume") made the *_run flags transition from false to true when > restore installs replacement virtqueues. The RX, TX and event workers > read their virtqueue before locking and checking the corresponding flag, > so a worker delayed across freeze and restore can observe the replacement > queue's running state while retaining a pointer to the deleted queue. > > Read each virtqueue under its mutex after checking the run flag, keeping > the pointer and state in the same queue generation. > > Fixes: bd50c5dc182b ("vsock/virtio: add support for device suspend/resume") > Cc: stable@vger.kernel.org > Reported-by: Xiang Mei <xmei5@asu.edu> > Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com > Assisted-by: OpenAI-Codex:gpt-5 > Signed-off-by: Weiming Shi <bestswngs@gmail.com> > --- > net/vmw_vsock/virtio_transport.c | 11 ++++++----- > 1 file changed, 6 insertions(+), 5 deletions(-) > > diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c > index 57f2d6ec3ffc..a8e1dd95ba8c 100644 > --- a/net/vmw_vsock/virtio_transport.c > +++ b/net/vmw_vsock/virtio_transport.c > @@ -346,12 +346,13 @@ static void virtio_transport_tx_work(struct work_struct *work) > struct virtqueue *vq; > bool added = false; > > - vq = vsock->vqs[VSOCK_VQ_TX]; > mutex_lock(&vsock->tx_lock); > > if (!vsock->tx_run) > goto out; > > + vq = vsock->vqs[VSOCK_VQ_TX]; > + > do { > struct sk_buff *skb; > unsigned int len; > @@ -451,13 +452,13 @@ static void virtio_transport_event_work(struct work_struct *work) > container_of(work, struct virtio_vsock, event_work); > struct virtqueue *vq; > > - vq = vsock->vqs[VSOCK_VQ_EVENT]; > - > mutex_lock(&vsock->event_lock); > > if (!vsock->event_run) > goto out; > > + vq = vsock->vqs[VSOCK_VQ_EVENT]; > + > do { > struct virtio_vsock_event *event; > unsigned int len; > @@ -634,13 +635,13 @@ static void virtio_transport_rx_work(struct work_struct *work) > container_of(work, struct virtio_vsock, rx_work); > struct virtqueue *vq; > > - vq = vsock->vqs[VSOCK_VQ_RX]; > - > mutex_lock(&vsock->rx_lock); > > if (!vsock->rx_run) > goto out; > > + vq = vsock->vqs[VSOCK_VQ_RX]; > + > do { > virtqueue_disable_cb(vq); > for (;;) { > -- > 2.55.0 > Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com> ^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown 2026-07-29 19:16 ` [PATCH v3 " Weiming Shi 2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi @ 2026-07-29 19:16 ` Weiming Shi 2026-07-30 19:17 ` sashiko-bot 2026-07-30 21:46 ` Bobby Eshleman 1 sibling, 2 replies; 7+ messages in thread From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw) To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez, Stefan Hajnoczi, Stefano Garzarella, David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei, Bobby Eshleman Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()") made the RX worker jump to its common exit when rx_run is clear. That exit still refills the RX queue when the buffer count is low, so work queued across virtio_vsock_vqs_del() can add buffers after the virtqueues have been deleted. BUG: KASAN: slab-use-after-free in virtqueue_add_sgs Read of size 4 by task kworker/0:1 Workqueue: virtio_vsock virtio_transport_rx_work Call Trace: virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796) virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332) virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701) process_one_work (kernel/workqueue.c:3314) worker_thread (kernel/workqueue.c:3478) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) ... Freed by task 141: kfree (mm/slub.c:6566) vp_del_vq (drivers/virtio/virtio_pci_common.c:259) vp_del_vqs (drivers/virtio/virtio_pci_common.c:285) virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912) virtio_device_freeze (drivers/virtio/virtio.c:658) virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601) pci_pm_freeze (drivers/pci/pci-driver.c:1098) device_suspend (drivers/base/power/main.c:1968) Kernel panic - not syncing: KASAN: panic_on_warn set ... Jump to a no-refill exit when rx_run is clear, leaving the normal exit to replenish a running queue. Fixes: b917507e5ad9 ("vsock/virtio: stop workers during the .remove()") Cc: stable@vger.kernel.org Reported-by: Xiang Mei <xmei5@asu.edu> Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com Suggested-by: Stefano Garzarella <sgarzare@redhat.com> Assisted-by: OpenAI-Codex:gpt-5 Signed-off-by: Weiming Shi <bestswngs@gmail.com> --- net/vmw_vsock/virtio_transport.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c index a8e1dd95ba8c..96c9fe8d357c 100644 --- a/net/vmw_vsock/virtio_transport.c +++ b/net/vmw_vsock/virtio_transport.c @@ -638,7 +638,7 @@ static void virtio_transport_rx_work(struct work_struct *work) mutex_lock(&vsock->rx_lock); if (!vsock->rx_run) - goto out; + goto out_nofill; vq = vsock->vqs[VSOCK_VQ_RX]; @@ -692,6 +692,7 @@ static void virtio_transport_rx_work(struct work_struct *work) out: if (vsock->rx_buf_nr < vsock->rx_buf_max_nr / 2) virtio_vsock_rx_fill(vsock); +out_nofill: mutex_unlock(&vsock->rx_lock); } -- 2.55.0 ^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown 2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi @ 2026-07-30 19:17 ` sashiko-bot 2026-07-30 21:46 ` Bobby Eshleman 1 sibling, 0 replies; 7+ messages in thread From: sashiko-bot @ 2026-07-30 19:17 UTC (permalink / raw) To: Weiming Shi; +Cc: kvm Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: Pre-existing issues: - [High] Incorrect `flush_work` ordering in `virtio_vsock_remove()` allows `virtio_transport_rx_work` to execute after the `vsock` object has been freed. -- --- Patch [2]: [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown --- commit e28975cab51c80e977d0774ef653bc9c4660fff0 Author: Weiming Shi <bestswngs@gmail.com> vsock/virtio: avoid refilling the RX queue after teardown Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()") made the RX worker jump to its common exit when rx_run is clear. That exit still refills the RX queue when the buffer count is low, so work queued across virtio_vsock_vqs_del() can add buffers after the virtqueues have been deleted. Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com > diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c > index 57f2d6ec3ffc6..96c9fe8d357c6 100644 > --- a/net/vmw_vsock/virtio_transport.c > +++ b/net/vmw_vsock/virtio_transport.c [ ... ] > @@ -634,12 +635,12 @@ static void virtio_transport_rx_work(struct work_struct *work) > container_of(work, struct virtio_vsock, rx_work); > struct virtqueue *vq; > > - vq = vsock->vqs[VSOCK_VQ_RX]; > - > mutex_lock(&vsock->rx_lock); > > if (!vsock->rx_run) > - goto out; > + goto out_nofill; [Severity: High] This is a pre-existing issue, but I have a question about the workqueue teardown logic that can still trigger a use-after-free for vsock. In virtio_vsock_remove(), the workqueues are flushed in this order: net/vmw_vsock/virtio_transport.c:virtio_vsock_remove() { ... flush_work(&vsock->rx_work); flush_work(&vsock->tx_work); flush_work(&vsock->event_work); flush_work(&vsock->send_pkt_work); ... } However, virtio_transport_send_pkt_work() can queue rx_work without holding locks if restart_rx is true: net/vmw_vsock/virtio_transport.c:virtio_transport_send_pkt_work() { ... out: mutex_unlock(&vsock->tx_lock); if (restart_rx) queue_work(virtio_vsock_workqueue, &vsock->rx_work); } If a worker executing virtio_transport_send_pkt_work() is preempted just before calling queue_work(), and a concurrent virtio_vsock_remove() flushes rx_work and then blocks flushing send_pkt_work, couldn't the preempted worker then resume and queue a new rx_work? This newly queued rx_work would be left pending after virtio_vsock_remove() completes, causing a use-after-free when the vsock structure is freed. Should virtio_vsock_remove() flush send_pkt_work before rx_work to prevent this race? > + > + vq = vsock->vqs[VSOCK_VQ_RX]; > > do { > virtqueue_disable_cb(vq); -- Sashiko AI review · https://sashiko.dev/#/patchset/cover.1785352330.git.bestswngs@gmail.com?part=2 ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown 2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi 2026-07-30 19:17 ` sashiko-bot @ 2026-07-30 21:46 ` Bobby Eshleman 1 sibling, 0 replies; 7+ messages in thread From: Bobby Eshleman @ 2026-07-30 21:46 UTC (permalink / raw) To: Weiming Shi Cc: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez, Stefan Hajnoczi, Stefano Garzarella, David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman, virtualization, kvm, netdev, linux-kernel, Xiang Mei, Bobby Eshleman On Wed, Jul 29, 2026 at 12:16:55PM -0700, Weiming Shi wrote: > Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()") > made the RX worker jump to its common exit when rx_run is clear. That > exit still refills the RX queue when the buffer count is low, so work > queued across virtio_vsock_vqs_del() can add buffers after the virtqueues > have been deleted. > > BUG: KASAN: slab-use-after-free in virtqueue_add_sgs > Read of size 4 by task kworker/0:1 > Workqueue: virtio_vsock virtio_transport_rx_work > Call Trace: > virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796) > virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332) > virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701) > process_one_work (kernel/workqueue.c:3314) > worker_thread (kernel/workqueue.c:3478) > kthread (kernel/kthread.c:436) > ret_from_fork (arch/x86/kernel/process.c:158) > ret_from_fork_asm (arch/x86/entry/entry_64.S:245) > ... > Freed by task 141: > kfree (mm/slub.c:6566) > vp_del_vq (drivers/virtio/virtio_pci_common.c:259) > vp_del_vqs (drivers/virtio/virtio_pci_common.c:285) > virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912) > virtio_device_freeze (drivers/virtio/virtio.c:658) > virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601) > pci_pm_freeze (drivers/pci/pci-driver.c:1098) > device_suspend (drivers/base/power/main.c:1968) > Kernel panic - not syncing: KASAN: panic_on_warn set ... > > Jump to a no-refill exit when rx_run is clear, leaving the normal exit > to replenish a running queue. > > Fixes: b917507e5ad9 ("vsock/virtio: stop workers during the .remove()") > Cc: stable@vger.kernel.org > Reported-by: Xiang Mei <xmei5@asu.edu> > Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com > Suggested-by: Stefano Garzarella <sgarzare@redhat.com> > Assisted-by: OpenAI-Codex:gpt-5 > Signed-off-by: Weiming Shi <bestswngs@gmail.com> > --- > net/vmw_vsock/virtio_transport.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c > index a8e1dd95ba8c..96c9fe8d357c 100644 > --- a/net/vmw_vsock/virtio_transport.c > +++ b/net/vmw_vsock/virtio_transport.c > @@ -638,7 +638,7 @@ static void virtio_transport_rx_work(struct work_struct *work) > mutex_lock(&vsock->rx_lock); > > if (!vsock->rx_run) > - goto out; > + goto out_nofill; > > vq = vsock->vqs[VSOCK_VQ_RX]; > > @@ -692,6 +692,7 @@ static void virtio_transport_rx_work(struct work_struct *work) > out: > if (vsock->rx_buf_nr < vsock->rx_buf_max_nr / 2) > virtio_vsock_rx_fill(vsock); > +out_nofill: > mutex_unlock(&vsock->rx_lock); > } > > -- > 2.55.0 > Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com> ^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-07-30 21:47 UTC | newest] Thread overview: 7+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-07-29 18:58 [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown Weiming Shi 2026-07-29 19:16 ` [PATCH v3 " Weiming Shi 2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi 2026-07-30 21:46 ` Bobby Eshleman 2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi 2026-07-30 19:17 ` sashiko-bot 2026-07-30 21:46 ` Bobby Eshleman
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox