From: Stefano Garzarella <sgarzare@redhat.com>
To: Polina Vishneva <polina.vishneva@virtuozzo.com>
Cc: linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
virtualization@lists.linux.dev, kvm@vger.kernel.org,
"Eugenio Pérez" <eperezma@redhat.com>,
"Jason Wang" <jasowang@redhat.com>,
"Michael S. Tsirkin" <mst@redhat.com>,
"Stefan Hajnoczi" <stefanha@redhat.com>,
"Denis V . Lunev" <den@openvz.org>
Subject: Re: [PATCH] vhost/vsock: Refuse the connection immediately when guest isn't ready
Date: Mon, 11 May 2026 17:56:41 +0200 [thread overview]
Message-ID: <agH3WvJtAsQ_5zx4@sgarzare-redhat> (raw)
In-Reply-To: <20260511145610.413210-1-polina.vishneva@virtuozzo.com>
On Mon, May 11, 2026 at 04:56:10PM +0200, Polina Vishneva wrote:
>From: "Denis V. Lunev" <den@openvz.org>
>
>When the host initiates an AF_VSOCK connect() to a guest that has not
>yet loaded the virtio-vsock transport (i.e. still booting), the caller
>blocks for VSOCK_DEFAULT_CONNECT_TIMEOUT (2 seconds), because
>vhost_transport_do_send_pkt() silently exits when
>vhost_vq_get_backend(vq) returns NULL.
Can SO_VM_SOCKETS_CONNECT_TIMEOUT helps on this?
>
>If the guest doesn't start listening within this timeout, connect()
>returns ETIMEDOUT.
>
>This delay is usually pointless and it doesn't well align with our
>behavior at other initialization stages: for example, if a connection is
>attempted when the guest driver is already loaded, but when nothing is
>listening yet, it returns ECONNRESET immediately without any wait.
>
>Fix this by checking the RX virtqueue backend in
>vhost_transport_send_pkt() before queuing. If the backend is NULL,
>return -ECONNREFUSED immediately.
>
>Signed-off-by: Denis V. Lunev <den@openvz.org>
>Co-developed-by: Polina Vishneva <polina.vishneva@virtuozzo.com>
>Signed-off-by: Polina Vishneva <polina.vishneva@virtuozzo.com>
>---
> drivers/vhost/vsock.c | 10 ++++++++++
> 1 file changed, 10 insertions(+)
>
>diff --git a/drivers/vhost/vsock.c b/drivers/vhost/vsock.c
>index 1d8ec6bed53e..a3f218292c3a 100644
>--- a/drivers/vhost/vsock.c
>+++ b/drivers/vhost/vsock.c
>@@ -302,6 +302,16 @@ vhost_transport_send_pkt(struct sk_buff *skb, struct net *net)
> return -ENODEV;
> }
>
>+ /* Fast-fail if the guest hasn't enabled the RX vq yet. Reading
>+ * private_data without vq->mutex is deliberate: even if the backend becomes
>+ * NULL right after that check, do_send_pkt() checks it under the mutex.
>+ */
>+ if (!data_race(READ_ONCE(vsock->vqs[VSOCK_VQ_RX].private_data)))
Why not using vhost_vq_get_backend() ?
Also is READ_ONCE() okay without WRITE_ONCE() where it is set ?
>{
>+ rcu_read_unlock();
>+ kfree_skb(skb);
>+ return -ECONNREFUSED;
This is a generic send_pkt, is it okay to return ECONNREFUSED in any
case?
Thanks,
Stefano
>+ }
>+
> if (virtio_vsock_skb_reply(skb))
> atomic_inc(&vsock->queued_replies);
>
>
>base-commit: 8ab992f815d6736b5c7a6f5fd7bfe7bc106bb3dc
>--
>2.53.0
>
prev parent reply other threads:[~2026-05-11 15:56 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-11 14:56 [PATCH] vhost/vsock: Refuse the connection immediately when guest isn't ready Polina Vishneva
2026-05-11 15:56 ` Stefano Garzarella [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=agH3WvJtAsQ_5zx4@sgarzare-redhat \
--to=sgarzare@redhat.com \
--cc=den@openvz.org \
--cc=eperezma@redhat.com \
--cc=jasowang@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mst@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=polina.vishneva@virtuozzo.com \
--cc=stefanha@redhat.com \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox