From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f181.google.com (mail-qt1-f181.google.com [209.85.160.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E35E827B35F for ; Wed, 3 Jun 2026 01:05:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780448753; cv=none; b=S4ZPGQTQu4DB+UE1+16T2dG0MWyIrTcTBCq7fSwHlKOPG8ZtIEwNVoJ0t0RQ3G3MrYFd3wqtRrHPOcO2CrfdG68TS2ZsCy3zUThqyU4DxPDVmpZYSvSKRktSyAw4CGLzMwAmzJQTHTbQYa9tILn/sFD/O+wuNrqCxCsNzDnXJ8E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780448753; c=relaxed/simple; bh=u4ZwvdtqyKkvqfZ4xOXnUQfX+M6r5bs1mqg9vWH4izY=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=RGzTXOaPIBVJFg/qPuMbksmnljuguhtkbz9djeZWlNC/v5tnBB4EAdhWTrlNm5BCpSFswS5FiAOj7jlGGoi0QlTqYOTdsyGMzvlYjVJmpz+E94KZkJpkSoRWu5y9Kk/cxwzTn63SCUPxY/guPMXX5ILySVlZi5EGabJc9kKdHEg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca; spf=pass smtp.mailfrom=ziepe.ca; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b=Vb/IqGD9; arc=none smtp.client-ip=209.85.160.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b="Vb/IqGD9" Received: by mail-qt1-f181.google.com with SMTP id d75a77b69052e-5174a1da4b2so28817621cf.2 for ; Tue, 02 Jun 2026 18:05:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; t=1780448750; x=1781053550; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=nF9EObNDEmryj31PflampZ0Pq/iKEgkudnP3BX3S/AU=; b=Vb/IqGD9/62/BIaKGrIR97P2I/GXAC662Sggs9S78HDf0fobGJc2/vEkpLplHqBWoB xCMzsdzLXXiBVsPblWOR5W/XfIElIfei8vaUSCFIsr90zkcd6jtLr1h70i5l4t2J7DAT 4O4xbWrrfMMfI1vU0fpwMLEzojfBK1DmxbFeoPvJQ/fa40QsQuYk4h9oaLj/G7Bn1/Fn 06XMVTzgL9VgtH37FyPgDXp223hu5PfyqJyVlZc7H3JTfQKt1oX2vRbADp1F7/ZJEQ9f 2SeskE4cOCA7RZ9toCEx8LE7BnROL8gXECEbv41grH/51KjrRrnYeaoy41DPHV1CcoZm LZkg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780448750; x=1781053550; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=nF9EObNDEmryj31PflampZ0Pq/iKEgkudnP3BX3S/AU=; b=aooxWOJtab5ixdFlKfQP8HZVNY6ASsoMngrKX1oZnLEqgwPEWKmUIdZd4bWmjHJbhk jP0GMXqiF1Y3q5QlEqfMnFOv/UE9kZx6ohWvwUszG1eT+FwuwcTf0ysRvjC2J3jkwMyy MWTWapb/FN5dw5/qi9k7s++FtiSSz1ynqOAR1FoKmdPHvkjQeibzegp3cUdDBH+P6h++ NaxGfSuh1mwNqh3OrZG4dMpK2Vf71mHGIi47H9JHa+cSB6sIELpGryxqbUItrlMY/aA6 8/rsLKuSNHenE5inOlHyHDqEw0MdswAWFhOeYmPlSJ4GkFe/+lSykSFQjFb60UxYhCU3 Uydg== X-Forwarded-Encrypted: i=1; AFNElJ/j+4i6uo6aiLdHq0l+luWEjm6r8rstfVFvjLUFVBc1cAddjti9MbfeJCAyeFUGfpu6GoHJnzlw+2P+M/o=@vger.kernel.org X-Gm-Message-State: AOJu0Yxwr7qGLyRmVVz8C3L/sshV04NmdqTxA/mHCPhi8K9OQpD0/iKv NJ22s9TFdqmJw+88Z7fVXknJSwllT2XXcXQ2C8SRP5tBIXtX8xtAb1YtkOrxe7DPXds= X-Gm-Gg: Acq92OGRmviX70gvqUeVBxL/XA4Jbk6xQcv8gucGOSKkh97zT1Xxn+ve9pKdn/ydcVA P5fZK/Emg/IzvMio1Nrovb+g6EyaOkOJSVW64dId4A6UqDBusHj9VfDYAuT6cvOm7E5cmHLDVsg KmV5pXsmJFYWPlgb6W3LVYv2YTaBHPtPqgU63JU54ri/H4FMqXiNM7ZnCINyQM13KOLNUOr6Nx5 BYwWli5CFM5LFGLRPFrU6e9WonWMDOUGEgHgICAVf5NFMhzMQoYKVOcgZmzecEsn+ptfmvihL5F OhLPUnxaaVvG12qFUjc/UXxiSRH2JGIcmjJvvCPgPBOGJJ9aP9iLKByKPIhknDjgaH4xhdWNS1B A6EuCKLcpZtdi2uA1yqy1z1ACIFPIHL9YSoATtNOGHHq4mNuZyJp6HRTtyvE5XTJaBMDtEtSSXf nDcQ/zCyEZZw7+5JCVn+qQeu+w2XotIXX6KnytPdLrmztbMon0IOPBlznc1gNRPz82AzVoVWhM0 luY6IsbDdyZfW732AbySPCa2nc= X-Received: by 2002:ac8:7dd6:0:b0:50f:b257:9301 with SMTP id d75a77b69052e-5177877c12cmr23156881cf.52.1780448749904; Tue, 02 Jun 2026 18:05:49 -0700 (PDT) Received: from ziepe.ca (crbknf0213w-47-54-130-67.pppoe-dynamic.high-speed.nl.bellaliant.net. [47.54.130.67]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51775c297a8sm12256991cf.8.2026.06.02.18.05.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 18:05:49 -0700 (PDT) Received: from jgg by wakko with local (Exim 4.97) (envelope-from ) id 1wUa3I-00000004y36-1UNk; Tue, 02 Jun 2026 22:05:48 -0300 Date: Tue, 2 Jun 2026 22:05:48 -0300 From: Jason Gunthorpe To: Junrui Luo Cc: Alex Williamson , Shameer Kolothum , Yishai Hadas , Shay Drory , Kevin Tian , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yuhao Jiang , stable@vger.kernel.org Subject: Re: [PATCH] vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc Message-ID: <20260603010548.GP2487554@ziepe.ca> References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: On Tue, Jun 02, 2026 at 04:58:48PM +0800, Junrui Luo wrote: > vfio_mig_get_next_state() walks vfio_from_fsm_table[] one step at a time, > looping to skip optional states the device does not support until > *next_fsm is supported. A blocked transition is encoded as > VFIO_DEVICE_STATE_ERROR, which the trailing return reports as -EINVAL. > > The skip loop does not account for the ERROR sentinel. > state_flags_table[ERROR] is ~0U and vfio_from_fsm_table[ERROR][*] is > ERROR, so once *next_fsm becomes ERROR the loop condition stays true and > *next_fsm never changes. The blocked arcs STOP_COPY -> PRE_COPY and > STOP_COPY -> PRE_COPY_P2P map to ERROR yet pass the support check on a > precopy-capable device, causing the loop to spin forever while holding > the driver state mutex. This can result in a soft lockup, and a panic > with softlockup_panic set. > > Terminate the skip loop on the ERROR sentinel so a blocked transition > falls through to the existing return and reports -EINVAL. > > Fixes: 4db52602a607 ("vfio: Extend the device migration protocol with PRE_COPY") > Reported-by: Yuhao Jiang > Cc: stable@vger.kernel.org > Signed-off-by: Junrui Luo > --- > drivers/vfio/vfio_main.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) Reviewed-by: Jason Gunthorpe Jason