* [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown
@ 2026-07-29 18:58 Weiming Shi
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
0 siblings, 1 reply; 4+ messages in thread
From: Weiming Shi @ 2026-07-29 18:58 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Virtio-vsock workers can remain queued while freeze deletes the
virtqueues. This series prevents workers delayed across freeze and
restore from retaining pointers to deleted queues, and prevents the RX
worker from refilling its queue after teardown.
Changes in v2:
- Split the worker pointer changes from the RX refill fix because they
fix different commits.
- Use bd50c5dc182b as the Fixes tag for the worker pointer changes.
- Keep b917507e5ad9 as the Fixes tag for the RX refill fix.
- Use the suggested out_nofill label when rx_run is clear.
Weiming Shi (2):
vsock/virtio: read virtqueues under worker locks
vsock/virtio: avoid refilling the RX queue after teardown
net/vmw_vsock/virtio_transport.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
base-commit: 51b093a7ba27476e1f639455f005e8d2e75390e4
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v3 0/2] vsock/virtio: fix worker access after virtqueue teardown
2026-07-29 18:58 [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown Weiming Shi
@ 2026-07-29 19:16 ` Weiming Shi
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
0 siblings, 2 replies; 4+ messages in thread
From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Virtio-vsock workers can remain queued while freeze deletes the
virtqueues. This series prevents workers delayed across freeze and
restore from retaining pointers to deleted queues, and prevents the RX
worker from refilling its queue after teardown.
Changes in v3:
- Resend the series with proper email threading; no code changes.
Changes in v2:
- Split the worker pointer changes from the RX refill fix because they
fix different commits.
- Use bd50c5dc182b as the Fixes tag for the worker pointer changes.
- Keep b917507e5ad9 as the Fixes tag for the RX refill fix.
- Use the suggested out_nofill label when rx_run is clear.
Weiming Shi (2):
vsock/virtio: read virtqueues under worker locks
vsock/virtio: avoid refilling the RX queue after teardown
net/vmw_vsock/virtio_transport.c | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
base-commit: 51b093a7ba27476e1f639455f005e8d2e75390e4
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
@ 2026-07-29 19:16 ` Weiming Shi
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
1 sibling, 0 replies; 4+ messages in thread
From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Commit bd50c5dc182b ("vsock/virtio: add support for device
suspend/resume") made the *_run flags transition from false to true when
restore installs replacement virtqueues. The RX, TX and event workers
read their virtqueue before locking and checking the corresponding flag,
so a worker delayed across freeze and restore can observe the replacement
queue's running state while retaining a pointer to the deleted queue.
Read each virtqueue under its mutex after checking the run flag, keeping
the pointer and state in the same queue generation.
Fixes: bd50c5dc182b ("vsock/virtio: add support for device suspend/resume")
Cc: stable@vger.kernel.org
Reported-by: Xiang Mei <xmei5@asu.edu>
Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
Assisted-by: OpenAI-Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
---
net/vmw_vsock/virtio_transport.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
index 57f2d6ec3ffc..a8e1dd95ba8c 100644
--- a/net/vmw_vsock/virtio_transport.c
+++ b/net/vmw_vsock/virtio_transport.c
@@ -346,12 +346,13 @@ static void virtio_transport_tx_work(struct work_struct *work)
struct virtqueue *vq;
bool added = false;
- vq = vsock->vqs[VSOCK_VQ_TX];
mutex_lock(&vsock->tx_lock);
if (!vsock->tx_run)
goto out;
+ vq = vsock->vqs[VSOCK_VQ_TX];
+
do {
struct sk_buff *skb;
unsigned int len;
@@ -451,13 +452,13 @@ static void virtio_transport_event_work(struct work_struct *work)
container_of(work, struct virtio_vsock, event_work);
struct virtqueue *vq;
- vq = vsock->vqs[VSOCK_VQ_EVENT];
-
mutex_lock(&vsock->event_lock);
if (!vsock->event_run)
goto out;
+ vq = vsock->vqs[VSOCK_VQ_EVENT];
+
do {
struct virtio_vsock_event *event;
unsigned int len;
@@ -634,13 +635,13 @@ static void virtio_transport_rx_work(struct work_struct *work)
container_of(work, struct virtio_vsock, rx_work);
struct virtqueue *vq;
- vq = vsock->vqs[VSOCK_VQ_RX];
-
mutex_lock(&vsock->rx_lock);
if (!vsock->rx_run)
goto out;
+ vq = vsock->vqs[VSOCK_VQ_RX];
+
do {
virtqueue_disable_cb(vq);
for (;;) {
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
@ 2026-07-29 19:16 ` Weiming Shi
1 sibling, 0 replies; 4+ messages in thread
From: Weiming Shi @ 2026-07-29 19:16 UTC (permalink / raw)
To: Michael S. Tsirkin, Jason Wang, Xuan Zhuo, Eugenio Pérez,
Stefan Hajnoczi, Stefano Garzarella, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman
Cc: virtualization, kvm, netdev, linux-kernel, Xiang Mei,
Bobby Eshleman
Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
made the RX worker jump to its common exit when rx_run is clear. That
exit still refills the RX queue when the buffer count is low, so work
queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
have been deleted.
BUG: KASAN: slab-use-after-free in virtqueue_add_sgs
Read of size 4 by task kworker/0:1
Workqueue: virtio_vsock virtio_transport_rx_work
Call Trace:
virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)
virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)
virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3478)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
...
Freed by task 141:
kfree (mm/slub.c:6566)
vp_del_vq (drivers/virtio/virtio_pci_common.c:259)
vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)
virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)
virtio_device_freeze (drivers/virtio/virtio.c:658)
virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)
pci_pm_freeze (drivers/pci/pci-driver.c:1098)
device_suspend (drivers/base/power/main.c:1968)
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Jump to a no-refill exit when rx_run is clear, leaving the normal exit
to replenish a running queue.
Fixes: b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
Cc: stable@vger.kernel.org
Reported-by: Xiang Mei <xmei5@asu.edu>
Link: https://lore.kernel.org/r/20260727035804.1860862-1-bestswngs@gmail.com
Suggested-by: Stefano Garzarella <sgarzare@redhat.com>
Assisted-by: OpenAI-Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
---
net/vmw_vsock/virtio_transport.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
index a8e1dd95ba8c..96c9fe8d357c 100644
--- a/net/vmw_vsock/virtio_transport.c
+++ b/net/vmw_vsock/virtio_transport.c
@@ -638,7 +638,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
mutex_lock(&vsock->rx_lock);
if (!vsock->rx_run)
- goto out;
+ goto out_nofill;
vq = vsock->vqs[VSOCK_VQ_RX];
@@ -692,6 +692,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
out:
if (vsock->rx_buf_nr < vsock->rx_buf_max_nr / 2)
virtio_vsock_rx_fill(vsock);
+out_nofill:
mutex_unlock(&vsock->rx_lock);
}
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-07-29 19:17 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 18:58 [PATCH v2 0/2] vsock/virtio: fix worker access after virtqueue teardown Weiming Shi
2026-07-29 19:16 ` [PATCH v3 " Weiming Shi
2026-07-29 19:16 ` [PATCH v3 1/2] vsock/virtio: read virtqueues under worker locks Weiming Shi
2026-07-29 19:16 ` [PATCH v3 2/2] vsock/virtio: avoid refilling the RX queue after teardown Weiming Shi
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox