Re: [PATCH v7 03/12] PCI: liveupdate: Track incoming preserved PCI devices
Pasha Tatashin <[email protected]> Fri, 17 Jul 2026 21:46:52 +0000
| Newsgroups | org.infradead.lists.kexec,org.kernel.vger.linux-doc,org.kernel.vger.linux-kernel,org.kernel.vger.linux-pci,org.kvack.linux-mm |
|---|---|
| Message-ID | <178432481253.189683.3297727348836286619.b4-review@b4> |
On Fri, 10 Jul 2026 21:26:06 +0000, David Matlack <[email protected]> wrote: > diff --git a/drivers/pci/liveupdate.c b/drivers/pci/liveupdate.c > index 03075ce06ac9..df6a02240aa4 100644 > --- a/drivers/pci/liveupdate.c > +++ b/drivers/pci/liveupdate.c > @@ -298,6 +377,87 @@ void pci_liveupdate_unpreserve(struct pci_dev *dev) > [ ... skip 76 lines ... ] > + /* > + * Hold the ref on the incoming FLB until pci_liveupdate_finish() so > + * that dev->liveupdate.incoming cannot get freed while the PCI core > + * has a pointer to it. It's better to leak the incoming FLB than do a > + * use-after-free if driver does not call pci_liveupdate_finish(). > + */ I am confused by this. Each preserved PCI device must have an associated FD preserved with it via LUO. I.e., vfiofd would need to be preserved. If the vfiofd was not reclaimed, and finish is not possible, that vfiofd would still be owned by LUO, and therefore PCI FLB refcount would stay positive. However, if finish is possible, and this is the last vfiofd that is finished, FLB will be freed as soon as the reference count reaches zero, which I would think is the expected behavior. What is the point of holding a reference here, instead of only for the duration of FLB access, i.e. to make sure we are accessing a valid data? -- Pasha Tatashin <[email protected]>