From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A448843E083 for ; Thu, 30 Jul 2026 14:48:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785422942; cv=none; b=TuISOGVCFsQC4JwNyn1Z2npSt27ikY9Q5kr0FHndfxRkoHkTaKlqJdeKfD1jD3nBZHIvAC9eZbpyotevRohr93C+7FWaOJGX3WsmK+UceP9+lOO+MTz3VD0YPw0dusiRjTXPv0zr/OsSS7DXvKJTjdgkEHcu7Q7saire10rRQqM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785422942; c=relaxed/simple; bh=xT+59zrSNXgZSX292AF0H2w7CA1Unv3yXaYCM8QYlXA=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=mBSk1O8eg5mFFGry6ZDsZMTh9hY8Ah+cQH8RkuGtFSCkfUs5O1NxHEVXBzrtEdqPxapyulP4qkctMzMZSMuNgCZ0YXxJ4GqEyjUHEXuG3CNhy5Rp9wYrJX0Wfgq1B8B4c0lc0+cPwN6x2SOaXgKlXImmrC8m/LBX3wBqhaeeoM0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=WDPQsKK2; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=p2T5t0fg; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="WDPQsKK2"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="p2T5t0fg" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785422938; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=icEaXTibKrUroRnU8otVcNfABM2uS6NaLhn91NMFBqw=; b=WDPQsKK2LeKdPU2iKUJDXXb0BSQaoFX2hRc/DnX4+cN6+LeZ+c6gePg7tGGQJdDqa0+5s4 9CsAbCGOEwpNj+D6ClHvngkbLRIlj3ZlEpXm5hPWWfcsumX71sr8BXxbixMTC+gyG4dFUZ SDYdrcbY05ZWPfU64XTf/GsfKLGZXPk= Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-561-rnVNCxK1NL-9sRd2Ya0Sfg-1; Thu, 30 Jul 2026 10:48:56 -0400 X-MC-Unique: rnVNCxK1NL-9sRd2Ya0Sfg-1 X-Mimecast-MFC-AGG-ID: rnVNCxK1NL-9sRd2Ya0Sfg_1785422936 Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-492488f8583so19480815e9.2 for ; Thu, 30 Jul 2026 07:48:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785422935; x=1786027735; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=icEaXTibKrUroRnU8otVcNfABM2uS6NaLhn91NMFBqw=; b=p2T5t0fgUPlRjhQhk2cVh0buhKTyE1lw6quG8mrXjmDMNHXodcEUIChQ2G0nSlrGYa VreZDs8HWs6Mokvtw8YNbXUZmds7HjXQcZXIxE/cI2frIPKITz/jwG8S/lkbeXWY4sQI 6vXsCBcRRpF6R06y7pWOKBRFKJJKfSSKC74xbbn2sa2A9r78MqfyYCWjwgHJwaI01LlJ g+jl8pOPSG6SrudU+d3zEvT2dk5kkAhJOV4kBEJJ5Wot7q5YGO350yJAJUghwZnIoH4J SkTqT41KbYvzzVE9N/T7wjSv0Y1KOHVcZtsKtXdwct5GZTAXEen+sayCeMZ/jMCpxk15 xHEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785422935; x=1786027735; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=icEaXTibKrUroRnU8otVcNfABM2uS6NaLhn91NMFBqw=; b=sKCxgEFxtURfw0jBnk0k5/qC1QvtT+EAWayL4DTU0t99OtTRSmg4s0rfxMuxcrGElz nUANkHPrXmyAiPf/f3yYh4bjUgMFsvUVly45kzC8cg9KgfMoW3IPSMd2MO1hDnBuW/xA uhzm8l8dAwxBFqTIKFIspX8WUG0KsFASPUJ8+Bx0bPpBp8JQlkvfWv93ZSfIUjzg1qpw g8I1g9pfaL1T7EZLyS3tjMzn1Mn6/o2WBaUaadvZRjMenlDkUJTZrdam8tZA0EaUl/2A q0pjeapG57lhrNC4LP+2JJQunhOdG+S0a367pS/Z6sNgGOXMS5BfUq5wmYyhSo4ii/Xl UUkQ== X-Forwarded-Encrypted: i=1; AHgh+RqtdfbZ8hTyHYLnA/oe+ZAFPJTB9FXLKrpXlYWKWTSeERldKjC0UjWmKU/MBJDXn4JA/oIL0FpibPVMgBw=@vger.kernel.org X-Gm-Message-State: AOJu0YzzOdob0EYiB2ciB5aaN7Yl1USONCNW3TaGoigxXfWSF8HFivKe IMQ3myuD26nOx4f2QrH0MPO6e3hKUQcgZMCErz/saQnEcFmtQRHFRsds1xLVBEz2dEtNlfxcF/+ Ibh7NN5gNcNHyiKUgYlo3kIaDoE5C0rQqHdkUF4/w56WpqeBJJoDy/00zHo182WQy0Q== X-Gm-Gg: AR+sD107amRg2nlH50CzrZGMQqs9ADJEngIiYtdQVdxvP9Qp8WkUDwfTq6iiJ1Asl4R rDSfFWCNUOn8RXytmZ7kBGyH8mAVos5d1eM4E9Am1DsCnNVDJBM2m1XIaI19A2AoUZZXpEg6K2h l2eu28ZcTsKM+6BDU9YOuKcgStRBrCAigMQuJsi+5JxPjlbejFokFrCeQoVVnNUD/kl81jFkc3r zXwUYVqui1HNPMv3BzWSRY9gKu1Y/NfMFctDt0GpixhePxoq82Oi9N/+K4HNur/mee28A+7yF6C +HoFe7QwQ8Al+MVVRDhbadngy7R5hQ9KOugK+71F6T9AbyDBNcfTbZt88sFiNseJIVTzLuOQOOe ED/E4YETsUycXT4bz8flpZO4= X-Received: by 2002:a05:600c:e557:10b0:493:f140:c3fb with SMTP id 5b1f17b1804b1-49800e898e4mr29774725e9.7.1785422935581; Thu, 30 Jul 2026 07:48:55 -0700 (PDT) X-Received: by 2002:a05:600c:e557:10b0:493:f140:c3fb with SMTP id 5b1f17b1804b1-49800e898e4mr29774385e9.7.1785422935051; Thu, 30 Jul 2026 07:48:55 -0700 (PDT) Received: from redhat.com (ppp-94-66-118-61.home.otenet.gr. [94.66.118.61]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-498011fd5fesm60785515e9.7.2026.07.30.07.48.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 07:48:54 -0700 (PDT) Date: Thu, 30 Jul 2026 10:48:51 -0400 From: "Michael S. Tsirkin" To: Stefan Hajnoczi Cc: Jia Jia , sgarzare@redhat.com, jasowang@gmail.com, eperezma@redhat.com, kvm@vger.kernel.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org Subject: Re: [PATCH] vhost/vsock: prevent stale IOTLB after ACCESS_PLATFORM changes Message-ID: <20260730104811-mutt-send-email-mst@kernel.org> References: <20260730040938.1725757-1-physicalmtea@gmail.com> <20260730135508.GC1442692@fedora> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260730135508.GC1442692@fedora> On Thu, Jul 30, 2026 at 09:55:08AM -0400, Stefan Hajnoczi wrote: > On Thu, Jul 30, 2026 at 12:09:38PM +0800, Jia Jia wrote: > > vhost_vsock_set_features() initializes dev->iotlb when > > VIRTIO_F_ACCESS_PLATFORM is enabled. It does not remove that IOTLB > > when the feature is later cleared. The virtqueue still points at the > > old IOTLB, and vhost_vsock_handle_tx_kick() passes descriptors to > > vhost_get_vq_desc(), which translates them through that mapping. > > > > A userspace backend can enable ACCESS_PLATFORM, install an IOTLB entry > > for a payload GPA, start the device, clear ACCESS_PLATFORM, replace the > > memory table, and reuse the old HVA before submitting the same GPA > > again. The feature state then says direct memory access is in use > > while the TX path still uses the old IOTLB HVA. > > > > Reject clearing ACCESS_PLATFORM while the device IOTLB exists. Also > > keep the existing IOTLB when a feature update leaves ACCESS_PLATFORM > > enabled; VHOST_SET_FEATURES is used for runtime log updates and must > > not discard the current translations by allocating an empty IOTLB. > > > > Fixes: e13a6915a03f ("vhost/vsock: add IOTLB API support") > > Signed-off-by: Jia Jia > > --- > > drivers/vhost/vsock.c | 12 ++++++++++-- > > 1 file changed, 10 insertions(+), 2 deletions(-) > > > > diff --git a/drivers/vhost/vsock.c b/drivers/vhost/vsock.c > > index ae01457ea2cd..57e8fd1eb670 100644 > > --- a/drivers/vhost/vsock.c > > +++ b/drivers/vhost/vsock.c > > @@ -798,6 +798,7 @@ static int vhost_vsock_set_cid(struct vhost_vsock *vsock, u64 guest_cid) > > static int vhost_vsock_set_features(struct vhost_vsock *vsock, u64 features) > > { > > struct vhost_virtqueue *vq; > > + int ret = -EFAULT; > > int i; > > > > if (features & ~VHOST_VSOCK_FEATURES) > > @@ -809,7 +810,14 @@ static int vhost_vsock_set_features(struct vhost_vsock *vsock, u64 features) > > goto err; > > } > > > > - if ((features & (1ULL << VIRTIO_F_ACCESS_PLATFORM))) { > > + if (!(features & (1ULL << VIRTIO_F_ACCESS_PLATFORM)) && > > + vsock->dev.iotlb) { > > + ret = -EBUSY; > > + goto err; > > + } > > This prevents one problem but there are still other issues with how > feature bit negotiation and the IOTLB are implemented: > > 1. VIRTIO_F_ACCESS_PLATFORM is defined by the VIRTIO spec and must not > be change after feature bit negotiation. Please reject all feature > bit updates except VHOST_F_LOG_ALL to comply with the VIRTIO spec and > eliminate potential bugs in drivers/vhost/vsock.c. Unfortunately, vhost does not expose the feature negotiation to the kernel. > 2. When the device is reset, the iotlb cannot be left initialized > because there is no guarantee that VIRTIO_F_ACCESS_PLATFORM will be > negotiated again. > > > + if ((features & (1ULL << VIRTIO_F_ACCESS_PLATFORM)) && > > + !vsock->dev.iotlb) { > > if (vhost_init_device_iotlb(&vsock->dev)) > > goto err; > > } > > @@ -827,7 +835,7 @@ static int vhost_vsock_set_features(struct vhost_vsock *vsock, u64 features) > > > > err: > > mutex_unlock(&vsock->dev.mutex); > > - return -EFAULT; > > + return ret; > > } > > > > static long vhost_vsock_dev_ioctl(struct file *f, unsigned int ioctl, > > -- > > 2.34.1 > >