Two issues with virtio device reset:
1. Karl Mehltretter reported that virtio_reset_device() promises
callbacks are not in progress after reset, but only PCI transports
actually synchronize callbacks - other transports leave a window
where a handler already executing keeps running while the driver
tears down state.
2. sashiko reported a race in virtio_pci_modern: the avq interrupt
handler calls virtqueue_get_buf concurrently with
virtqueue_detach_unused_buf in vp_modern_avq_cleanup, and there
is no synchronize_irq between reset and cleanup.
Fix 1 by adding virtio_synchronize_cbs in the core after reset,
then dropping the now-redundant per-transport sync calls. Fix 2 by
moving avq cleanup from vp_reset to vp_del_vqs, which runs after
callbacks have been synchronized - and is where buffer teardown
conceptually belongs.
Changes v2->v3:
patch 1: unchanged
patch 2: split from v2 patch 2 - legacy part only
patch 3: new - v2 just dropped the sync from modern vp_reset,
leaving avq_cleanup there before the removed sync. v3
moves avq_cleanup out of vp_reset entirely into vp_del_vqs,
fixing the race. Adds NULL check for admin_vq.info needed
because find_vqs error paths call vp_del_vqs before it is
allocated.
Michael S. Tsirkin (3):
virtio: synchronize callbacks after device reset
virtio_pci_legacy: drop callback sync on reset
virtio_pci_modern: move avq cleanup from reset to del_vqs
drivers/virtio/virtio.c | 2 ++
drivers/virtio/virtio_pci_common.c | 2 ++
drivers/virtio/virtio_pci_common.h | 1 +
drivers/virtio/virtio_pci_legacy.c | 2 --
drivers/virtio/virtio_pci_modern.c | 10 ++++------
5 files changed, 9 insertions(+), 8 deletions(-)
--
MST