Re: [PATCH RFC 09/15] hw/virtio/vhost-shadow-virtqueue: specified vring placement
Akihiko Odaki <[email protected]>
| Newsgroups | gmane.comp.emulators.qemu.block,gmane.comp.emulators.qemu |
|---|---|
| Message-ID | <[email protected]> |
On 2026/08/07 0:29, Connor Kite wrote: > On Fri, Jul 24, 2026 at 5:19 AM Akihiko Odaki > <[email protected]> wrote: > ... >> >> Nit: please remove the whitespace between (void *) and svq->base_addr. >> > > Removing the whitespace! > >>> + svq->vring.avail = (void *)((char *)svq->vring.desc + desc_size); >>> + svq->vring.used = (void *)((char *)svq->base_addr + >>> + vhost_svq_driver_area_size(svq)); >>> + } >> >> Unmapping svq here can lead to use-after-unmapping because the ring is >> not stopped yet. do_vhost_dev_stop() calls do_vhost_virtqueue_stop() >> only after calling hdev->vhost_ops->vhost_dev_start(hdev, false). >> > > I am afraid I don't quite understand, as this patch does not introduce > any unmapping. > Was this comment meant for a different patch? Yes, sorry, this comment was meant for "[PATCH RFC 14/15] hw/virtio/vhost-user: handle data movement with shadow vqs". vhost_user_dev_start(dev, false) calls vhost_user_svqs_stop(), which calls vhost_svq_stop() and unmaps the shadow vring. However, do_vhost_dev_stop() calls do_vhost_virtqueue_stop() only after the callback returns. The backend vring therefore remains active until VHOST_USER_GET_VRING_BASE, so it may still access the unmapped memory. Regards, Akihiko Odaki