From nobody Thu Sep 24 16:09:27 2026 Received: from azure-sdnproxy.icoremail.net (azure-sdnproxy.icoremail.net [13.75.44.102]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 1B113422E24; Tue, 22 Sep 2026 08:14:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=13.75.44.102 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790064872; cv=none; b=mEl/0mlampLga05SFm2S2I+5TixZXUJxGAxj12/4wIwJjDozbNUnf4qqgNmQPRlc0kzgELYdu5EM/2RpEWQHkua0huwLr95lSFP3g3WLF5ai0T+WoHQh4+wNX26yu9yeFr2+xso2RU8BjXt/SBg7QjnMwizgneS0WXda3zq3tPM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790064872; c=relaxed/simple; bh=JSExzzQ/72ayZe7kT1hBIEV/iJyifsYi/u4PW4L0ufE=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=eSHT+E1XN56ZL70dkxPs2sYSTWvrY4galdLyr1+zIlLJC7vcCK2ZVs3QJU5vBJm2T6IHDIienI6R8NxesXAoU6FOUJs04dY35kgdOHdzddWC41evHu4gFB6sglNxnqG5tvy0B9X4bVDr3JyQPHqsL3/yvMEEbaB1bHb25DXbXoU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zju.edu.cn; spf=pass smtp.mailfrom=zju.edu.cn; arc=none smtp.client-ip=13.75.44.102 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zju.edu.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=zju.edu.cn Received: from zju.edu.cn (unknown [10.98.66.117]) by mtasvr (Coremail) with SMTP id _____wBHbjXWOLJqEpUtAQ--.1367S3; Tue, 22 Sep 2026 16:14:14 +0800 (CST) Received: from localhost.localdomain (unknown [10.98.66.117]) by mail-app2 (Coremail) with SMTP id zC_KCgBn1crVOLJq4b2SBA--.36365S2; Tue, 22 Sep 2026 16:14:13 +0800 (CST) From: Fan Wu To: miklos@szeredi.hu, gmaglione@redhat.com, vgoyal@redhat.com, stefanha@redhat.com Cc: eperezma@redhat.com, virtualization@lists.linux.dev, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Fan Wu , stable@vger.kernel.org, Song Li Subject: [PATCH] virtio_fs: read the vring size under virtio_fs_mutex in ->get_tree Date: Tue, 22 Sep 2026 08:13:18 +0000 Message-Id: <20260922081318.321686-1-fanwu01@zju.edu.cn> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: zC_KCgBn1crVOLJq4b2SBA--.36365S2 X-CM-SenderInfo: qrstjiaswqq6lmxovvfxof0/ X-CM-DELIVERINFO: =?B?aCLoLwXKKxbFmtjJiESix3B1w3vZ3A9ovKVTomAyoQazvoRs/NHSP8GI2EvgeEEW7R sfncGSG+szpQCInt5Y8rbJUI2t0BJcZoSB6eelYYjqAliCbwQJ+3upJMwyXmK8CBx+0EQs cpS7moAQeYMWH5swQ5up9E6mavGmQbzmcFsnzP86 X-Coremail-Antispam: 1Uk129KBj93XoWxJr4DXF1UKF1DXr1UKFW8Xwc_yoW8KrWDpr 9rtr47Gry8KFWfXFyrJ3WIg34YkrZ7CF47JryfZwn3Wrn0ywnIyryjyry8uFZ3ZrykZFWU trn5Xr4Ygr4DuFXCm3ZEXasCq-sJn29KB7ZKAUJUUUUU529EdanIXcx71UUUUU7KY7ZEXa sCq-sGcSsGvfJ3Ic02F40EFcxC0VAKzVAqx4xG6I80ebIjqfuFe4nvWSU5nxnvy29KBjDU 0xBIdaVrnRJUUU9lb4IE77IF4wAFF20E14v26r4j6ryUM7CY07I20VC2zVCF04k26cxKx2 IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28lY4IEw2IIxxk0rwA2F7IY1VAKz4vEj48v e4kI8wA2z4x0Y4vE2Ix0cI8IcVAFwI0_tr0E3s1l84ACjcxK6xIIjxv20xvEc7CjxVAFwI 0_Cr1j6rxdM28EF7xvwVC2z280aVAFwI0_GcCE3s1l84ACjcxK6I8E87Iv6xkF7I0E14v2 6rxl6s0DM2vYz4IE04k24VAvwVAKI4IrM2AIxVAIcxkEcVAq07x20xvEncxIr21l57IF6x kI12xvs2x26I8E6xACxx1l5I8CrVACY4xI64kE6c02F40Ex7xfMcIj6xIIjxv20xvE14v2 6r1Y6r17McIj6I8E87Iv67AKxVWUJVW8JwAm72CE4IkC6x0Yz7v_Jr0_Gr1lF7xvr2IYc2 Ij64vIr41lF7xvr2IYc2Ij64vIr40E4x8a64kEw24l42xK82IYc2Ij64vIr41l4I8I3I0E 4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGV WUWwC2zVAF1VAY17CE14v26r1q6r43MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_ Jr0_JF4lIxAIcVC0I7IYx2IY6xkF7I0E14v26r4j6F4UMIIF0xvE42xK8VAvwI8IcIk0rV WUJVWUCwCI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4U JbIYCTnIWIevJa73UjIFyTuYvjxU7rcfUUUUU Content-Type: text/plain; charset="utf-8" The vring size was read after virtio_fs_find_instance() had dropped virtio_fs_mutex, so a concurrent virtio_fs_remove() could free the virtqueue first. The reference from the lookup keeps the virtio_fs alive, but not its virtqueues. Hold the mutex across the lookup and the read. This issue was found by an in-house static analysis tool. Fixes: a7f0d7aab0b4 ("virtiofs: split requests that exceed virtqueue size") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6 Co-developed-by: Song Li Signed-off-by: Song Li Signed-off-by: Fan Wu --- fs/fuse/virtio_fs.c | 21 +++++++++++---------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/fs/fuse/virtio_fs.c b/fs/fuse/virtio_fs.c index df25d4fac..a3e8a64ca 100644 --- a/fs/fuse/virtio_fs.c +++ b/fs/fuse/virtio_fs.c @@ -455,26 +455,23 @@ static int virtio_fs_add_instance(struct virtio_devic= e *vdev, return ret; } =20 -/* Return the virtio_fs with a given tag, or NULL */ +/* Return the virtio_fs with a given tag, or NULL. + * Callers hold virtio_fs_mutex, which also keeps the virtqueues alive. + */ static struct virtio_fs *virtio_fs_find_instance(const char *tag) { struct virtio_fs *fs; =20 - mutex_lock(&virtio_fs_mutex); + lockdep_assert_held(&virtio_fs_mutex); =20 list_for_each_entry(fs, &virtio_fs_instances, list) { if (strcmp(fs->tag, tag) =3D=3D 0) { kobject_get(&fs->kobj); - goto found; + return fs; } } =20 - fs =3D NULL; /* not found */ - -found: - mutex_unlock(&virtio_fs_mutex); - - return fs; + return NULL; /* not found */ } =20 static void virtio_fs_free_devs(struct virtio_fs *fs) @@ -1699,13 +1696,17 @@ static int virtio_fs_get_tree(struct fs_context *fs= c) * in chan->iq->priv. Once fuse_conn is going away, it calls ->put() * to drop the reference to this object. */ + mutex_lock(&virtio_fs_mutex); fs =3D virtio_fs_find_instance(fsc->source); + if (fs) + virtqueue_size =3D virtqueue_get_vring_size(fs->vqs[VQ_REQUEST].vq); + mutex_unlock(&virtio_fs_mutex); + if (!fs) { pr_info("virtio-fs: tag <%s> not found\n", fsc->source); return -EINVAL; } =20 - virtqueue_size =3D virtqueue_get_vring_size(fs->vqs[VQ_REQUEST].vq); if (WARN_ON(virtqueue_size <=3D FUSE_HEADER_OVERHEAD)) goto out_err;