The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH 0/2] virtio_pci_modern: fix vp_reset() hang on unresponsive device
@ 2026-08-02 17:40 Abhin Parekadan Jose
  2026-08-02 17:40 ` [PATCH 1/2] virtio_pci_modern_dev: warn once on invalid status Abhin Parekadan Jose
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Abhin Parekadan Jose @ 2026-08-02 17:40 UTC (permalink / raw)
  To: mst, jasowangio, xuanzhuo, eperezma
  Cc: virtualization, linux-kernel, Abhin Parekadan Jose

While investigating a syzbot report of a WARN_ON_ONCE firing in
virtio_dev_remove() [1], I found a related but more serious issue:
vp_reset() in the modern virtio-pci transport can hang indefinitely
if PCI_COMMAND memory-space decode is disabled while the device is
bound (e.g. surprise removal, hardware fault, or -- as reproduced
here -- a direct write to the PCI_COMMAND register). The status
register poll loop has no way to distinguish "device still resetting"
from "device unreachable," so it never terminates.

Patch 1 adds a VIRTIO_STATUS_ERROR() check that recognizes an
all-ones status read as invalid (per spec, bits 4-5 are reserved and
can never legitimately be set) and warns once at the point the bad
read actually happens.

Patch 2 uses that check to break out of vp_reset()'s poll loop
instead of spinning forever.

Reproduced on a modern-transport virtio-blk-pci device:

  # printf '\x00\x00' | dd of=/sys/bus/pci/devices/0000:01:00.0/config \
    bs=1 seek=4 count=2 conv=notrunc
  # echo 1 > /sys/bus/pci/devices/0000:01:00.0/remove

The second command hangs indefinitely without this series; gdb
confirms the CPU is stuck in vp_reset()'s status-polling loop, with
vp_modern_get_status() consistently returning 0xff.

[1] https://syzbot.org/bug?extid=a1c8effc62c569d4bd25

Abhin Parekadan Jose (2):
  virtio_pci_modern_dev: warn once on invalid status
  virtio_pci_modern: avoid infinite loop in vp_reset() on invalid status

 drivers/virtio/virtio_pci_modern.c     |  6 +++++-
 drivers/virtio/virtio_pci_modern_dev.c |  8 +++++++-
 include/uapi/linux/virtio_config.h     | 16 ++++++++++++++++
 3 files changed, 28 insertions(+), 2 deletions(-)

--
2.51.1

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-08-02 19:54 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-02 17:40 [PATCH 0/2] virtio_pci_modern: fix vp_reset() hang on unresponsive device Abhin Parekadan Jose
2026-08-02 17:40 ` [PATCH 1/2] virtio_pci_modern_dev: warn once on invalid status Abhin Parekadan Jose
2026-08-02 18:10   ` Michael S. Tsirkin
2026-08-02 17:40 ` [PATCH 2/2] virtio_pci_modern: avoid infinite loop in vp_reset() " Abhin Parekadan Jose
2026-08-02 18:06   ` Michael S. Tsirkin
2026-08-02 17:47 ` [PATCH 0/2] virtio_pci_modern: fix vp_reset() hang on unresponsive device Michael S. Tsirkin
2026-08-02 18:28   ` Abhin Parekadan Jose
2026-08-02 19:08     ` Michael S. Tsirkin
2026-08-02 19:48       ` Abhin Parekadan Jose
2026-08-02 19:54         ` Michael S. Tsirkin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox