From nobody Sat Sep 26 22:14:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=seu.edu.cn ARC-Seal: i=1; a=rsa-sha256; t=1788496406; cv=none; d=zohomail.com; s=zohoarc; b=FuZ5OaW3kEGSzb2qNH0cuEef6bpNWNura8u9G+zap/BOl/CGI08+x5yKn/VdlxhC31MmB/8wEsNeBoCT/CW67EsMg9abimwuqZYKPokVHALgZQ7D1z5ya9v1TYP9E2tU4V/5qPhmhZiPduO4NB7IoOs9gx+RmP25wyeH4P6Heyc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788496406; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6pPjq38Rl1B06uwZRdHLtZfA+MlrG39TWGjcdYU28xg=; b=hihaiCjiQhn+tleDcErbktuaoCUTVElTWEvaCCatvApyjx2bxUEaFu0hLx7+dlgR9m4SdCQKmq+dpKbrp5OEitNHCl2WJ7xCk5suIdkK9c0SR2wtFxkUPWJqOnNTmxfJQFP445A6Ut4hZiAm98Y7S/8OucQPufRmg7oLYzTtyhU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788496406502419.8639907366686; Thu, 3 Sep 2026 21:33:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2LbF-0001Cr-HV; Fri, 04 Sep 2026 00:32:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2Kn6-0004UD-UY for qemu-devel@nongnu.org; Thu, 03 Sep 2026 23:40:36 -0400 Received: from mail-m49198.qiye.163.com ([45.254.49.198]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2Kn2-0003BY-Nu for qemu-devel@nongnu.org; Thu, 03 Sep 2026 23:40:36 -0400 Received: from LAPTOP-99KJFSET (unknown [36.153.54.56]) by smtp.qiye.163.com (Hmail) with ESMTP id 4c7fb7a3b; Fri, 4 Sep 2026 11:33:24 +0800 (GMT+08:00) From: Hongyan Xu To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Alex=20Benn=C3=A9e?= , Akihiko Odaki , Hongyan Xu Subject: [RFC PATCH] virtio-gpu: guard BH scheduling against a late hostmem region finalize Date: Fri, 4 Sep 2026 11:33:24 +0800 Message-ID: <20260904033324.1754-1-getshell@seu.edu.cn> X-Mailer: git-send-email 2.50.1.windows.1 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-HM-Tid: 0aa06a7a6de203a1kunmc8190e32241bb X-HM-MType: 10 X-HM-Spam-Status: e1kfGhgUHx5ZQUpXWQgPGg8OCBgUHx5ZQUlOS1dZFg8aDwILHllBWSg2Ly tZV1koWUFITzdXWRgWCB1ZQUpXWS1ZQUlXWQ8JGhUIEh9ZQVlCT0tLVh0eSR5DGRpLSU1IS1YeHw 5VEwETFhoSFyQUDg9ZV1kYEgtZQVlITVVKTkhVTk9VTk1ZV1kWGg8SFR0UWUFZT0tIVUpLSEpOTE 5VSktLVUpCS0tZBg++ DKIM-Signature: a=rsa-sha256; b=mHL8TOENSGooDIHHXUShT9dN9sEGAN9V8i+HIN2voRIrERQh+pQdIMAHLFI43a0hDyEHazRsnniZNK5wuzK7aV8kZeWaDKE5PLQmS1HMMOFR3PI6Lic/osAVVk4MPz7UWbQ1Z2eH/g5u8rKBYNDxsX0/m14aB+MtglLwcUffuJs=; c=relaxed/relaxed; s=default; d=seu.edu.cn; v=1; bh=6pPjq38Rl1B06uwZRdHLtZfA+MlrG39TWGjcdYU28xg=; h=date:mime-version:subject:message-id:from; Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=45.254.49.198; envelope-from=getshell@seu.edu.cn; helo=mail-m49198.qiye.163.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 04 Sep 2026 00:32:22 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @seu.edu.cn) X-ZM-MESSAGEID: 1788496407868158500 Content-Type: text/plain; charset="utf-8" virtio_gpu_gl_device_unrealize() deletes gl->cmdq_resume_bh (and, when present, gl->async_fence_bh). As the comment in that function notes, hostmem memory regions are not guaranteed to be finalized during unrealize(): their finalize may be deferred (e.g. through an RCU / object reference lifetime) until after unrealize() has returned. virtio_gpu_virgl_hostmem_region_finalize() runs on that deferred path and calls qemu_bh_schedule(gl->cmdq_resume_bh). If the finalize lands after unrealize() has deleted the BH, this schedules a deleted BH (a use-after-free / use-after-delete window on the BH object). NULL out both BHs after deleting them in unrealize(), and guard the two schedule sites in virtio-gpu-virgl.c with a NULL check so a late finalize (or a late async-fence callback) simply skips the wake-up instead of touching a deleted BH. This is an RFC: this area overlaps Akihiko Odaki's "Fix memory region use-after-finalization" discussion series; if that series lands first this patch should be reworked to fit its lifetime model. Signed-off-by: Hongyan Xu --- hw/display/virtio-gpu-gl.c | 8 ++++++++ hw/display/virtio-gpu-virgl.c | 8 ++++++-- 2 files changed, 14 insertions(+), 2 deletions(-) diff --git a/hw/display/virtio-gpu-gl.c b/hw/display/virtio-gpu-gl.c index 2b7a41c466..2fd3f84a91 100644 --- a/hw/display/virtio-gpu-gl.c +++ b/hw/display/virtio-gpu-gl.c @@ -180,10 +180,18 @@ static void virtio_gpu_gl_device_unrealize(DeviceStat= e *qdev) if (gl->renderer_state >=3D RS_INITED) { #if VIRGL_VERSION_MAJOR >=3D 1 qemu_bh_delete(gl->cmdq_resume_bh); + /* + * hostmem memory regions can be finalized after unrealize() + * returns (see below); their finalize path schedules + * cmdq_resume_bh, so NULL it out to let them detect that the + * BH is gone instead of touching a deleted BH. + */ + gl->cmdq_resume_bh =3D NULL; =20 if (gl->async_fence_bh) { virtio_gpu_virgl_reset_async_fences(g); qemu_bh_delete(gl->async_fence_bh); + gl->async_fence_bh =3D NULL; } #endif if (virtio_gpu_stats_enabled(g->parent_obj.conf)) { diff --git a/hw/display/virtio-gpu-virgl.c b/hw/display/virtio-gpu-virgl.c index 9bda572426..d38d8fe995 100644 --- a/hw/display/virtio-gpu-virgl.c +++ b/hw/display/virtio-gpu-virgl.c @@ -134,7 +134,9 @@ static void virtio_gpu_virgl_hostmem_region_finalize(Ob= ject *obj) * context. */ gl =3D VIRTIO_GPU_GL(vmr->g); - qemu_bh_schedule(gl->cmdq_resume_bh); + if (gl->cmdq_resume_bh) { + qemu_bh_schedule(gl->cmdq_resume_bh); + } } =20 static const TypeInfo virtio_gpu_virgl_hostmem_region_info =3D { @@ -1294,7 +1296,9 @@ virtio_gpu_virgl_push_async_fence(VirtIOGPU *g, uint3= 2_t ctx_id, =20 QSLIST_INSERT_HEAD_ATOMIC(&gl->async_fenceq, f, next); =20 - qemu_bh_schedule(gl->async_fence_bh); + if (gl->async_fence_bh) { + qemu_bh_schedule(gl->async_fence_bh); + } } =20 static void virgl_write_async_fence(void *opaque, uint32_t fence) --=20 2.50.1.windows.1