From nobody Tue Apr 7 21:48:16 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1773241544; cv=none; d=zohomail.com; s=zohoarc; b=aFzwTDq3yke5C7DcrBQILBTHW6Cg6AARvve8dCLlhY84dPUhcA1MHnviuQdoUx3DA0OGU/7pvn5mXE1VX5vlvmlNUHGtRIAtyIPy4v8JkuPcgnzgeP7wepudu5HM7nl3wktNTsIBRvcdvlL2Hqb0f76LBTufTjD5ut0fs7aHYGY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1773241544; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=AQs7/4punjlP9TA6Q2iVY1apioyB9jmj7ZofebP76/A=; b=ceePsmwqkGX4wTAMUSJ+mKdNkLzW7+5f6K8iWROlNXdU78MRDD/VuzvVKnqCJp/QBh9y1AcBdpw2F8QsKyYBU/xx1nLLcsXrm/bZA5/9xTVHWD6W93FQrdSBlqzfAWb93a0wWrt/x1U4Reu3ELCqxVwMjfnVCawhzQgKUi6pCUs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1773241544332766.5824468865691; Wed, 11 Mar 2026 08:05:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1w0L7l-00004t-SN; Wed, 11 Mar 2026 11:05:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1w0L6F-0005Sb-Hp; Wed, 11 Mar 2026 11:03:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1w0L6D-00049j-NT; Wed, 11 Mar 2026 11:03:51 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DAE29191E53; Wed, 11 Mar 2026 18:01:44 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C7E8C37C2A5; Wed, 11 Mar 2026 18:02:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1773241304; bh=Jyh1Fr9LA2lKwnx5fFYLqhpftjyZTAdmbu/4IxxV/iw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=sPRDnU0JKjEYyUj/15eOZlWHDhv5WCwz2oMtHx/dr5ULxRWLn5QJwxNe9rudtE+No pDJawd0PWg+654w9/eZxRQu1AZE9sZFOy7tZ/yY+1Yt7uExXdaMPs40kGmHoPtj9Ep O0Dbtfj2Co5h59gWMBBQjmPmmMFr2NDiC+IcxeLVnMkIeTMohPfoLSuljI5whb+mL8 ruifGisdqg6yv94V3M6TfFKymMdgYARKvQ5bclxMHyQTU2sho63nOirXiE7XJNuYp9 oediSeKlVOKJQaizupm4htzPvTQVZrV2T1KANEmv1/i2HS+07eIa3uyPtHlntrHoGF uVccsh3W6UYxQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richie Buturla , Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.9 21/44] hw/9pfs: fix data race in v9fs_mark_fids_unreclaim() Date: Wed, 11 Mar 2026 18:01:53 +0300 Message-ID: <20260311150221.1084186-21-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.819, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.903, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1773241546361154100 Content-Type: text/plain; charset="utf-8" From: Richie Buturla A data race between v9fs_mark_fids_unreclaim() and v9fs_path_copy() causes an inconsistent read of fidp->path. In v9fs_path_copy(), the path size is set before the data pointer is allocated, creating a window where size is non-zero but data is NULL. v9fs_co_open2() holds a write lock during path modifications, but v9fs_mark_fids_unreclaim() was not acquiring a read lock, allowing it to race. Fix by holding the path read lock during FID table iteration. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3300 Signed-off-by: Richie Buturla Link: https://lore.kernel.org/qemu-devel/20260211154450.254338-1-richie@lin= ux.ibm.com/ Fixes: 7a46274529 ("hw/9pfs: Add file descriptor reclaim support") Signed-off-by: Christian Schoenebeck (cherry picked from commit c96f6d2398a9dc068fa82088ea43020a52e2b26d) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 80b190ff5b..b1fcda574d 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -551,6 +551,7 @@ static int coroutine_fn v9fs_mark_fids_unreclaim(V9fsPD= U *pdu, V9fsPath *path) sizeof(V9fsFidState *), 1); gint i; =20 + v9fs_path_read_lock(s); g_hash_table_iter_init(&iter, s->fids); =20 /* @@ -571,6 +572,7 @@ static int coroutine_fn v9fs_mark_fids_unreclaim(V9fsPD= U *pdu, V9fsPath *path) g_array_append_val(to_reopen, fidp); } } + v9fs_path_unlock(s); =20 for (i =3D 0; i < to_reopen->len; i++) { fidp =3D g_array_index(to_reopen, V9fsFidState*, i); --=20 2.47.3