From nobody Tue Apr 7 21:27:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1773258073; cv=none; d=zohomail.com; s=zohoarc; b=K3HxTBxonEMqxP9Gt6vLrlvKSco6IAgUQhC/c1jPjjoFlhndQeGiJusMWiu1f0Y0t0syRURFyh1PEE8x2tWz6rZd5Hp8ipqIZP068sh6L8ZS03Ii6tMZ/PfPpvsOV4l473NYiH2MYMLT5i2WhbfkemXe4x6RynxGi87pcf3PwNk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1773258073; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=M2r2K9VEYfGxaXGJFWGv3pROfWCj0wz20W+1sB4QYVs=; b=MrNMIBJFh64Q79/pQY8f03aRyv79J6enwBTzoYuYBxfYoCw7OwgQQxReFm7AkjlQuM6Trrz4A46ZGdAvRSFNTFDiiFg7epj4LW5gYTXjbg6Vilb1VoqK60UXtOLu2mhlDKwmuYT8SrPJn5SbkO3KrnymDJe8LIwic8jl4Gb3Ky4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 177325807301740.13898435608962; Wed, 11 Mar 2026 12:41:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1w0PMr-0002Oh-Cl; Wed, 11 Mar 2026 15:37:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1w0PMY-00021G-8c; Wed, 11 Mar 2026 15:37:01 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1w0PMU-0000Lk-Br; Wed, 11 Mar 2026 15:36:55 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 106C1192100; Wed, 11 Mar 2026 22:34:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 541F737C465; Wed, 11 Mar 2026 22:35:06 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1773257668; bh=rLUHziL3XRMnonK+0RGs8f/A9GwPWYXX7CuCsGPXpRA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=P4Bzm4cbfotdXlvLCWe5QrwNLaNCUyQF1PKceKGXcy0WqXWuHwm6gaDj6e9tHfCLj zsD4tS/P5wWnQTuzhF0IbPapSb2NbBJxMQazyw2IFWcrvvCTUB2nfsP28VBdZN8zgp Q+fLhI7lqalXJH2Le5zHhL8B2YkcPf2YMEDLzzJcnmjuUVGlqDaiU9GKTNjT5i5fTI Hzx4GMc6P+6daqkwX0a0xe1XoLMy+aAjahgJr0sMxpRDbeRxVmOa1ve1AnfVHqPbV/ aqwcNqHgPS8fai+0kOwIzFURaUpg+aZ+1EFYqTqJ0Hl79jC/Ar7ZzfvKzQG750gaVP LZS25EUjowZpg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richie Buturla , Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.2.2 24/53] hw/9pfs: fix data race in v9fs_mark_fids_unreclaim() Date: Wed, 11 Mar 2026 22:34:17 +0300 Message-ID: <20260311193449.1096110-24-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.819, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.903, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1773258074816154100 Content-Type: text/plain; charset="utf-8" From: Richie Buturla A data race between v9fs_mark_fids_unreclaim() and v9fs_path_copy() causes an inconsistent read of fidp->path. In v9fs_path_copy(), the path size is set before the data pointer is allocated, creating a window where size is non-zero but data is NULL. v9fs_co_open2() holds a write lock during path modifications, but v9fs_mark_fids_unreclaim() was not acquiring a read lock, allowing it to race. Fix by holding the path read lock during FID table iteration. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3300 Signed-off-by: Richie Buturla Link: https://lore.kernel.org/qemu-devel/20260211154450.254338-1-richie@lin= ux.ibm.com/ Fixes: 7a46274529 ("hw/9pfs: Add file descriptor reclaim support") Signed-off-by: Christian Schoenebeck (cherry picked from commit c96f6d2398a9dc068fa82088ea43020a52e2b26d) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index bc4a016ee3..127e02a077 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -560,6 +560,7 @@ static int coroutine_fn v9fs_mark_fids_unreclaim(V9fsPD= U *pdu, V9fsPath *path) sizeof(V9fsFidState *), 1); gint i; =20 + v9fs_path_read_lock(s); g_hash_table_iter_init(&iter, s->fids); =20 /* @@ -580,6 +581,7 @@ static int coroutine_fn v9fs_mark_fids_unreclaim(V9fsPD= U *pdu, V9fsPath *path) g_array_append_val(to_reopen, fidp); } } + v9fs_path_unlock(s); =20 for (i =3D 0; i < to_reopen->len; i++) { fidp =3D g_array_index(to_reopen, V9fsFidState*, i); --=20 2.47.3