Re: [PATCH RFC 09/15] hw/virtio/vhost-shadow-virtqueue: specified vring placement

Akihiko Odaki <[email protected]>
Newsgroups dev.linux.lists.virtio-fs,org.nongnu.qemu-devel
Message-ID <[email protected]>
On 2026/08/07 0:29, Connor Kite wrote:
> On Fri, Jul 24, 2026 at 5:19 AM Akihiko Odaki
> <[email protected]> wrote:
> ...
>>
>> Nit: please remove the whitespace between (void *) and svq->base_addr.
>>
> 
> Removing the whitespace!
> 
>>> +        svq->vring.avail = (void *)((char *)svq->vring.desc + desc_size);
>>> +        svq->vring.used = (void *)((char *)svq->base_addr +
>>> +                          vhost_svq_driver_area_size(svq));
>>> +    }
>>
>> Unmapping svq here can lead to use-after-unmapping because the ring is
>> not stopped yet. do_vhost_dev_stop() calls do_vhost_virtqueue_stop()
>> only after calling hdev->vhost_ops->vhost_dev_start(hdev, false).
>>
> 
> I am afraid I don't quite understand, as this patch does not introduce
> any unmapping.
> Was this comment meant for a different patch?

Yes, sorry, this comment was meant for "[PATCH RFC 14/15] 
hw/virtio/vhost-user: handle data movement with shadow vqs".

vhost_user_dev_start(dev, false) calls vhost_user_svqs_stop(), which 
calls vhost_svq_stop() and unmaps the shadow vring. However, 
do_vhost_dev_stop() calls do_vhost_virtqueue_stop() only after the 
callback returns. The backend vring therefore remains active until 
VHOST_USER_GET_VRING_BASE, so it may still access the unmapped memory.

Regards,
Akihiko Odaki
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.