From nobody Fri Aug 28 00:11:56 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786614985; cv=none; d=zohomail.com; s=zohoarc; b=i53M8lRntg0lQOKZvdnqV2H9w91GFihJeSC7CUyBIGlhMuKqj7VBYDWm44tJXuDhveq1lngmwnhROXcsnmsFy71K0t1dtAe22swURVi1p12CFlmELbNnU3/Dh4EE9oMkP3LUM3xm8eQuknOsgbaGr+qhqP5W8Mwr26WQncz5QO4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786614985; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pHGjh55usKOPqSNHUu914m1Rda0mEK2+CbO6sTSHggY=; b=KWqpdSvRxYj/2pupIfB/j6WOcOV0q7UJNuGdCzTcESUgD//vC+Y/JfuPjZMf9TbWRgidz8b+MUkbxsQ2SwHG0g5FNUpyUE7aMMV1eKz0rBtMX/cZupGtAzRCvkM+9nuBYW3w9Cz94NJSkjQu2hDeT0bJ4bT+jHOKmbldq5BZIls= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178661498578292.68545514035964; Thu, 13 Aug 2026 02:56:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuSA6-0006EY-ME; Thu, 13 Aug 2026 05:55:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuS9s-0006Cb-K5 for qemu-devel@nongnu.org; Thu, 13 Aug 2026 05:55:39 -0400 Received: from [115.124.30.110] (helo=out30-110.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuS9p-0005sq-HU for qemu-devel@nongnu.org; Thu, 13 Aug 2026 05:55:32 -0400 Received: from localhost(mailfrom:guobin@linux.alibaba.com fp:SMTPD_---0X8u77Qj_1786614903 cluster:ay36) by smtp.aliyun-inc.com; Thu, 13 Aug 2026 17:55:03 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786614904; h=From:To:Subject:Date:Message-ID:MIME-Version; bh=pHGjh55usKOPqSNHUu914m1Rda0mEK2+CbO6sTSHggY=; b=aJkHkGxwsERDTcMcxy+ZHf71fms/xErlVayiVPVVQx8TD9Lwjukk5e6YvTqBnllHv9jAmg/t8V/cS+RVp0tZlnAfUV9HrqftUF1lQqH6ydoXeiXcB6nRR4zW0/U3cEithKKj4rb/PCKVKgaO3xHnv/qwPHZVh+ar/PPMJ0qJlMg= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R121e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam011083073210; MF=guobin@linux.alibaba.com; NM=1; PH=DS; RN=3; SR=0; TI=SMTPD_---0X8u77Qj_1786614903; From: Bin Guo To: qemu-devel@nongnu.org Cc: "Michael S . Tsirkin" , Stefano Garzarella Subject: [PATCH 1/2] libvhost-user: accept the postcopy client base ack in vu_add_mem_reg() Date: Thu, 13 Aug 2026 17:55:00 +0800 Message-ID: <20260813095501.20282-2-guobin@linux.alibaba.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260813095501.20282-1-guobin@linux.alibaba.com> References: <20260813095501.20282-1-guobin@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.110 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.110; envelope-from=guobin@linux.alibaba.com; helo=out30-110.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786614986885158500 Content-Type: text/plain; charset="utf-8" In postcopy mode QEMU signals that it has collected all the postcopy client bases by sending a VHOST_USER_ADD_MEM_REG message with a u64 payload of 0 and no file descriptor (see vhost_user_add_remove_regions()). vu_add_mem_reg() has a case for that message, but only reaches it after validating the fd count of a regular region, so the ack is rejected first: VHOST_USER_ADD_MEM_REG received 0 fds - only 1 fd should be sent for this message type This kills the backend during memory table setup, making postcopy unusable for any libvhost-user backend that negotiates VHOST_USER_PROTOCOL_F_CONFIGURE_MEM_SLOTS. Recognise the ack before validating the fd count. Fixes: 9f4e63491b ("libvhost-user: Add vu_add_mem_reg input validation") Signed-off-by: Bin Guo --- subprojects/libvhost-user/libvhost-user.c | 26 ++++++++++++----------- 1 file changed, 14 insertions(+), 12 deletions(-) diff --git a/subprojects/libvhost-user/libvhost-user.c b/subprojects/libvho= st-user/libvhost-user.c index a74d814bb4..248550aae1 100644 --- a/subprojects/libvhost-user/libvhost-user.c +++ b/subprojects/libvhost-user/libvhost-user.c @@ -948,6 +948,20 @@ static bool vu_add_mem_reg(VuDev *dev, VhostUserMsg *vmsg) { VhostUserMemoryRegion m =3D vmsg->payload.memreg.region, *msg_region = =3D &m; =20 + /* + * If we are in postcopy mode and we receive a u64 payload with a 0 va= lue + * we know all the postcopy client bases have been received, and we + * should start generating faults. This message carries no file + * descriptor, so it has to be recognised before the fd count of a real + * region is validated below. + */ + if (dev->postcopy_listening && + vmsg->size =3D=3D sizeof(vmsg->payload.u64) && + vmsg->payload.u64 =3D=3D 0) { + (void)generate_faults(dev); + return false; + } + if (vmsg->fd_num !=3D 1) { vmsg_close_fds(vmsg); vu_panic(dev, "VHOST_USER_ADD_MEM_REG received %d fds - only 1 fd " @@ -971,18 +985,6 @@ vu_add_mem_reg(VuDev *dev, VhostUserMsg *vmsg) { return false; } =20 - /* - * If we are in postcopy mode and we receive a u64 payload with a 0 va= lue - * we know all the postcopy client bases have been received, and we - * should start generating faults. - */ - if (dev->postcopy_listening && - vmsg->size =3D=3D sizeof(vmsg->payload.u64) && - vmsg->payload.u64 =3D=3D 0) { - (void)generate_faults(dev); - return false; - } - _vu_add_mem_reg(dev, msg_region, vmsg->fds[0]); close(vmsg->fds[0]); =20 --=20 2.50.1 (Apple Git-155) From nobody Fri Aug 28 00:11:56 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786614986; cv=none; d=zohomail.com; s=zohoarc; b=jvdwBf22AGWsd2v0oe93B/gKkTwfdKEXnkNjVt6d5sLZAGdzM/HmagQ4VWEjzTkTYoI6u1btNaDprsXfTd59mx8JBnAgTdQN+AolHMwd1Sheg4bb+eHxYTDP9uqBDgoci58Yvjnra6IrtNAPmflhcxh9Ik33tuu0nBm4vJHASSc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786614986; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=40y1RV1ifjLY5kLqdvBtOkbrea1HokAB7lurYvj6RQE=; b=Whd3lDr8LjTKlApC3ljxnN8DuGcMN0ntisND2h0RRsrpPxf73reHIKcerTsf74s3bjn9jzoabLqyrQqFuBfwLZxoX0pEQh96NtzOEBGydxrmGA6Xb0DVwAhHLObcjm+Dfh6f7oOa5f/GD0mLZLcP7X3BUBpKQGh6OgaL8SxvDSY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786614985932607.8199323862143; Thu, 13 Aug 2026 02:56:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuSA5-0006EM-KX; Thu, 13 Aug 2026 05:55:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuS9u-0006Cm-EU for qemu-devel@nongnu.org; Thu, 13 Aug 2026 05:55:39 -0400 Received: from [115.124.30.112] (helo=out30-112.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuS9r-0005sx-OL for qemu-devel@nongnu.org; Thu, 13 Aug 2026 05:55:34 -0400 Received: from localhost(mailfrom:guobin@linux.alibaba.com fp:SMTPD_---0X8u77R7_1786614904 cluster:ay36) by smtp.aliyun-inc.com; Thu, 13 Aug 2026 17:55:04 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786614904; h=From:To:Subject:Date:Message-ID:MIME-Version; bh=40y1RV1ifjLY5kLqdvBtOkbrea1HokAB7lurYvj6RQE=; b=fxYpCTLknncvUeY2NlODFO4XpocdKITcjKUIhtQi/KHkyS7QBCuO56V9NVUrlINgYXyYcMX0S0D4FCkS7UgEPqLIPB4vUOVHFlX4l/a5UE/6qmiHZKbpAk6gXMFe96oewEBxzKgSaRZj7TFBTYJsmJV28Ot4sUF6Phy+p6Q1Hcc= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R121e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045133197; MF=guobin@linux.alibaba.com; NM=1; PH=DS; RN=3; SR=0; TI=SMTPD_---0X8u77R7_1786614904; From: Bin Guo To: qemu-devel@nongnu.org Cc: "Michael S . Tsirkin" , Stefano Garzarella Subject: [PATCH 2/2] libvhost-user: return the backend mapping address for added regions Date: Thu, 13 Aug 2026 17:55:01 +0800 Message-ID: <20260813095501.20282-3-guobin@linux.alibaba.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260813095501.20282-1-guobin@linux.alibaba.com> References: <20260813095501.20282-1-guobin@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.112 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.112; envelope-from=guobin@linux.alibaba.com; helo=out30-112.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786614988253158500 Content-Type: text/plain; charset="utf-8" In postcopy mode the backend must tell QEMU where it mapped a region, so that QEMU can translate the backend's fault addresses back into a RAMBlock and offset. vu_add_mem_reg() works on a copy of the region and lets _vu_add_mem_reg() fill the mapping address into that copy, but never writes it back into the reply payload. QEMU then stores its own address as the postcopy client base, so fault resolution fails: vhost_user_postcopy_fault_handler: Failed to find region for fault ... The VHOST_USER_SET_MEM_TABLE path is unaffected, it fills the payload directly. Put the updated region back into the payload before replying; a pointer into the payload cannot be used instead, as VhostUserMsg is packed. Fixes: ec94c8e621 ("Support adding individual regions in libvhost-user") Signed-off-by: Bin Guo --- subprojects/libvhost-user/libvhost-user.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/subprojects/libvhost-user/libvhost-user.c b/subprojects/libvho= st-user/libvhost-user.c index 248550aae1..2fed792e85 100644 --- a/subprojects/libvhost-user/libvhost-user.c +++ b/subprojects/libvhost-user/libvhost-user.c @@ -989,7 +989,13 @@ vu_add_mem_reg(VuDev *dev, VhostUserMsg *vmsg) { close(vmsg->fds[0]); =20 if (dev->postcopy_listening) { - /* Send the message back to qemu with the addresses filled in. */ + /* + * Send the message back to qemu with the addresses filled in. + * _vu_add_mem_reg() worked on our copy of the region, so it has t= o be + * put back into the message payload. A pointer into the payload + * cannot be handed out instead, VhostUserMsg is packed. + */ + vmsg->payload.memreg.region =3D m; vmsg->fd_num =3D 0; DPRINT("Successfully added new region in postcopy\n"); return true; --=20 2.50.1 (Apple Git-155)