]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
vhost-scsi: flush backend after device ioctls
authorJia Jia <physicalmtea@gmail.com>
Fri, 24 Jul 2026 06:09:19 +0000 (14:09 +0800)
committerMichael S. Tsirkin <mst@redhat.com>
Tue, 4 Aug 2026 03:08:15 +0000 (23:08 -0400)
vhost-scsi translates guest response descriptors into userspace iovecs
when commands are submitted.  Target-core completes those commands
asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while
an in-flight command still retains response iovecs translated through the
old table.

If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command
completion can write the response to an unrelated userspace object.

Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device
ioctl.  This waits for in-flight commands that can still use the old
response iovecs before the ioctl returns.

Signed-off-by: Jia Jia <physicalmtea@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260724060919.1569170-1-physicalmtea@gmail.com>

drivers/vhost/scsi.c

index c79197edb16371ce87651afcdd9fac7f5a2d2945..aae1164e1ca9e333d21db6b4acc6e6c6e26f25ed 100644 (file)
@@ -2434,9 +2434,10 @@ vhost_scsi_ioctl(struct file *f,
        default:
                mutex_lock(&vs->dev.mutex);
                r = vhost_dev_ioctl(&vs->dev, ioctl, argp);
-               /* TODO: flush backend after dev ioctl. */
                if (r == -ENOIOCTLCMD)
                        r = vhost_vring_ioctl(&vs->dev, ioctl, argp);
+               else
+                       vhost_scsi_flush(vs);
                mutex_unlock(&vs->dev.mutex);
                return r;
        }