From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E462C39BFE5 for ; Thu, 4 Jun 2026 10:55:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780570562; cv=none; b=hQ3I78KaZBBDsHGE0F1NetaLUhRa5rQX+8wKQkT1lbrXZ53gufink2U1Gk1Bb4vc/R0rByP46Exj3gZTgoYkG7lXgrdBUnOP8WcuSRbrdusj7piD3BTJnAozGW8b/7qVDAJnLcnOB3wm9YUXjTGRPE5cOYM5jxlU4C23hX5gWcs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780570562; c=relaxed/simple; bh=7PDVjOFFBvB62jh1T+5fxxeccqZf3wobQfN0ejWBl+k=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=OtGyBAt034B5qn7eJOpE+lKrhkdRQ0CIQ3x83Tk2TtwAhY+98c7LOnWQjFBvo/NcEq1NWc85VVLY1aasOMpyhEb+zVcP2C6nVHi88GE4cEvO6LnpLfO3dQOHhJ9BDTaCt774VNeZ7M56vMpb/9Ac0P270eRNXk00jwMjM6vImkg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=I4cyXq2j; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=MI9EvFI5; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="I4cyXq2j"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="MI9EvFI5" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780570558; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=7wklQVRsViMBNiTmJy4yFl6j2hWwlYVgd/9iVl7uSjw=; b=I4cyXq2j1MXxWa4MHZi8HHFkB55NiitQqhTwRK5EjBbkwwV6XqzEMuAI298hIw7j+IeA4D xN0CLLEqM1DAo4dX8xFUoRN5kgi0UEhnlkfDiaMvxJ9aIBukniBT0HuoFAYmpX/JfxOjOV Szye3FORi5arkASpFok5Fj+jXOr/Bgk= Received: from mail-wr1-f69.google.com (mail-wr1-f69.google.com [209.85.221.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-352-j35v9FpqOuiQnRubFSvJgw-1; Thu, 04 Jun 2026 06:55:56 -0400 X-MC-Unique: j35v9FpqOuiQnRubFSvJgw-1 X-Mimecast-MFC-AGG-ID: j35v9FpqOuiQnRubFSvJgw_1780570552 Received: by mail-wr1-f69.google.com with SMTP id ffacd0b85a97d-45eef10d5ebso295358f8f.0 for ; Thu, 04 Jun 2026 03:55:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1780570552; x=1781175352; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=7wklQVRsViMBNiTmJy4yFl6j2hWwlYVgd/9iVl7uSjw=; b=MI9EvFI5CC492CNU1fnOZp0eV9EwEJ3muBcXeBfSLBLuG7XJFSapj1Za9v8hw6SiVZ bFoTynRh2bExwPgVOiOic52NPaeBITTOJsOJs9F+T0mSuI5LYPAbetIBCcAcXyZHlTYE 2iM6zJwUYnPVOPtRnx2w1afksrn1P/NAe70hyHoEml68K5ap0j1aObZHaje9LViTQq/h Gcb8UeA2YppKS+vRg8w2PGfVmwwSSk4vbpZ3z03JquRN2rl/yeYZFjVSknUajYrdMGrh 8PJzYqfbYcT6ZgbajW2ChvKV9os/h2XAvI/6hbLR9DGIJW4m0pYsz1nbO0VklJoDAxfN 3UQg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780570552; x=1781175352; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=7wklQVRsViMBNiTmJy4yFl6j2hWwlYVgd/9iVl7uSjw=; b=j1bqObq1YrnNK97wYoWTWZqk+cG/G5icFdaxYQSatoN1tuvGmKYH477WaZWeUYyty2 y1i4sPpRHyLY6KUkQXQ+tzWaJJwTJ/cIBAheZqZjNJE/o8I3Ok2swBEZ8R5DUh6NJila IoSfHwJCoG0E/pUpKw58eO0CaNpK6vbCDHXcXicme3L3mE9noeIvl31h5eGseIxnGwRe nGu3EZqgsq7q0NiDUnb2z1TA/ZvotlOQ6pOSfnXUmX085ARELT1KcvhFdZGhYWVxzlWH Y1VLKo/4xMY1dUUfGX6ebzgtZ62Cg0O9hapTh8DuiJwns7AytXe/wHxhC/cZBZ8Qh3Uf oPrw== X-Forwarded-Encrypted: i=1; AFNElJ98XILrw1qrSkrCiUGPNDmIxs1dYQuRJEgXpCAN0bR6IwBzG3NCB6Vb+tm8yUA37oqfExsOPvGlC3ScVTY=@vger.kernel.org X-Gm-Message-State: AOJu0YzddEwxjVXe9ShAJHuvpuJAdbFA/JIS/mrZt6lSEusONn3zOg18 iRk/CyNtWqhhi5r4D9lgPFVMOab8RmrY7WXlFzuKcxoc/iqv6IY+rGtrBye0WqJvGn8OGLbsBcW rTphzVCcKAjmnQ++CYFGUnFMHL9kXOB75K7r/WWg6/xc+YUTboKrpBZGrnkmhEjmUsQ== X-Gm-Gg: Acq92OFWipdxSQL6i+/5QcCwRQkY9l27ScZ6n9/6nYTPgkUY84E1TI52eRGTvlI9fa1 cXqi9LS64LkKTYivg5cOSGVihwDm+o4t4cDg8cSEPdkPntJ0+HKeRMUSkueWYs5dGQ/UsVqsiJd JYAAAa9NI21aX+84/90ljobKrvIv1rA9g+95PJ8iVhpLIUd8kr0+L2GsbYN/+FuSeqEyBdihZ8x iM2U4ofBlwuk7CKj3JMg59M6prn3F5dFCckQiHAbnTNhL3onLERQ1DdCojBl6mj8ydCpd3WiLoH 3Rv/Yek1gaE/bBr3rvjLbHs1l9it+pXqNN3pcosxl5wW4rzM9O23aQTOw4t82beevapGSjmscSR DaM4ptZCxgfnqsIQejEckJTZfpAOMpAO1ZUlta1gglt2zs7l2DlKp+W2eWNC+FiRSJB8= X-Received: by 2002:adf:fb85:0:b0:45e:fa38:c899 with SMTP id ffacd0b85a97d-46021783cecmr8984904f8f.4.1780570551759; Thu, 04 Jun 2026 03:55:51 -0700 (PDT) X-Received: by 2002:adf:fb85:0:b0:45e:fa38:c899 with SMTP id ffacd0b85a97d-46021783cecmr8984861f8f.4.1780570551302; Thu, 04 Jun 2026 03:55:51 -0700 (PDT) Received: from [192.168.88.32] ([212.105.155.59]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4601f3529e0sm15330789f8f.28.2026.06.04.03.55.50 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 04 Jun 2026 03:55:50 -0700 (PDT) Message-ID: Date: Thu, 4 Jun 2026 12:55:49 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH net] vhost/net: complete zerocopy ubufs only once To: Qing Ming , "Michael S. Tsirkin" , Jason Wang Cc: =?UTF-8?Q?Eugenio_P=C3=A9rez?= , Shirley , "David S. Miller" , kvm@vger.kernel.org, virtualization@lists.linux.dev, netdev@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260601104300.197210-1-a0yami@mailbox.org> From: Paolo Abeni Content-Language: en-US In-Reply-To: <20260601104300.197210-1-a0yami@mailbox.org> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 6/1/26 12:43 PM, Qing Ming wrote: > vhost-net initializes one ubuf_info per outstanding zerocopy TX > descriptor and hands it to the backend socket. The networking stack may > then clone a zerocopy skb before all skb references are released. For > example, batman-adv fragmentation reaches skb_split(), which calls > skb_zerocopy_clone() and increments the same ubuf_info refcount. > > vhost_zerocopy_complete() currently treats every ubuf callback as a > completed vhost descriptor. It dereferences ubuf->ctx, writes the > descriptor completion state, and drops the vhost_net_ubuf_ref even when > the callback only releases a cloned skb reference. A backend reset can > therefore wait for and free the vhost_net_ubuf_ref while another cloned > skb still carries the same ubuf_info. A later completion then > dereferences the freed ubufs pointer. > > KASAN reports the stale completion as: > > BUG: KASAN: slab-use-after-free in vhost_zerocopy_complete+0x1d7/0x1f0 > BUG: KASAN: slab-use-after-free in vhost_zerocopy_complete+0x101/0x1f0 > vhost_zerocopy_complete > skb_copy_ubufs > __dev_forward_skb2 > veth_xmit > > The freed object was allocated from vhost_net_ioctl() while setting the > backend and freed through kfree_rcu()/kvfree_rcu_bulk after backend > removal, while delayed skb completion still reached > vhost_zerocopy_complete(). > > Honor the generic ubuf_info refcount before touching vhost state, and run > the vhost descriptor completion only for the final ubuf reference. This > matches the msg_zerocopy_complete() ownership rule for cloned zerocopy > skbs. > > Fixes: bab632d69ee4 ("vhost: vhost TX zero-copy support") > Signed-off-by: Qing Ming The patch LGTM. @Michael: to you want to take it via your tree? /P