thebeanogamer / rpms / qemu-kvm

Forked from rpms/qemu-kvm 6 months ago
Clone

Blame SOURCES/kvm-virtio-net-don-t-handle-mq-request-in-userspace-hand.patch

1be5c7
From c9b51d54530c526f14ca0f3b9fc0bfa0b60d45ee Mon Sep 17 00:00:00 2001
1be5c7
From: Si-Wei Liu <si-wei.liu@oracle.com>
1be5c7
Date: Fri, 6 May 2022 19:28:18 -0700
1be5c7
Subject: [PATCH 20/24] virtio-net: don't handle mq request in userspace
1be5c7
 handler for vhost-vdpa
1be5c7
MIME-Version: 1.0
1be5c7
Content-Type: text/plain; charset=UTF-8
1be5c7
Content-Transfer-Encoding: 8bit
1be5c7
1be5c7
RH-Author: Jason Wang <jasowang@redhat.com>
1be5c7
RH-MergeRequest: 187: Multiqueue fixes for vhost-vDPA
1be5c7
RH-Commit: [7/7] 0e6684d12e42752deae8f5ebc56456fed174e0ed
1be5c7
RH-Bugzilla: 2069946
1be5c7
RH-Acked-by: Eugenio PĂ©rez <eperezma@redhat.com>
1be5c7
RH-Acked-by: Cindy Lu <lulu@redhat.com>
1be5c7
RH-Acked-by: Laurent Vivier <lvivier@redhat.com>
1be5c7
1be5c7
virtio_queue_host_notifier_read() tends to read pending event
1be5c7
left behind on ioeventfd in the vhost_net_stop() path, and
1be5c7
attempts to handle outstanding kicks from userspace vq handler.
1be5c7
However, in the ctrl_vq handler, virtio_net_handle_mq() has a
1be5c7
recursive call into virtio_net_set_status(), which may lead to
1be5c7
segmentation fault as shown in below stack trace:
1be5c7
1be5c7
0  0x000055f800df1780 in qdev_get_parent_bus (dev=0x0) at ../hw/core/qdev.c:376
1be5c7
1  0x000055f800c68ad8 in virtio_bus_device_iommu_enabled (vdev=vdev@entry=0x0) at ../hw/virtio/virtio-bus.c:331
1be5c7
2  0x000055f800d70d7f in vhost_memory_unmap (dev=<optimized out>) at ../hw/virtio/vhost.c:318
1be5c7
3  0x000055f800d70d7f in vhost_memory_unmap (dev=<optimized out>, buffer=0x7fc19bec5240, len=2052, is_write=1, access_len=2052) at ../hw/virtio/vhost.c:336
1be5c7
4  0x000055f800d71867 in vhost_virtqueue_stop (dev=dev@entry=0x55f8037ccc30, vdev=vdev@entry=0x55f8044ec590, vq=0x55f8037cceb0, idx=0) at ../hw/virtio/vhost.c:1241
1be5c7
5  0x000055f800d7406c in vhost_dev_stop (hdev=hdev@entry=0x55f8037ccc30, vdev=vdev@entry=0x55f8044ec590) at ../hw/virtio/vhost.c:1839
1be5c7
6  0x000055f800bf00a7 in vhost_net_stop_one (net=0x55f8037ccc30, dev=0x55f8044ec590) at ../hw/net/vhost_net.c:315
1be5c7
7  0x000055f800bf0678 in vhost_net_stop (dev=dev@entry=0x55f8044ec590, ncs=0x55f80452bae0, data_queue_pairs=data_queue_pairs@entry=7, cvq=cvq@entry=1)
1be5c7
   at ../hw/net/vhost_net.c:423
1be5c7
8  0x000055f800d4e628 in virtio_net_set_status (status=<optimized out>, n=0x55f8044ec590) at ../hw/net/virtio-net.c:296
1be5c7
9  0x000055f800d4e628 in virtio_net_set_status (vdev=vdev@entry=0x55f8044ec590, status=15 '\017') at ../hw/net/virtio-net.c:370
1be5c7
10 0x000055f800d534d8 in virtio_net_handle_ctrl (iov_cnt=<optimized out>, iov=<optimized out>, cmd=0 '\000', n=0x55f8044ec590) at ../hw/net/virtio-net.c:1408
1be5c7
11 0x000055f800d534d8 in virtio_net_handle_ctrl (vdev=0x55f8044ec590, vq=0x7fc1a7e888d0) at ../hw/net/virtio-net.c:1452
1be5c7
12 0x000055f800d69f37 in virtio_queue_host_notifier_read (vq=0x7fc1a7e888d0) at ../hw/virtio/virtio.c:2331
1be5c7
13 0x000055f800d69f37 in virtio_queue_host_notifier_read (n=n@entry=0x7fc1a7e8894c) at ../hw/virtio/virtio.c:3575
1be5c7
14 0x000055f800c688e6 in virtio_bus_cleanup_host_notifier (bus=<optimized out>, n=n@entry=14) at ../hw/virtio/virtio-bus.c:312
1be5c7
15 0x000055f800d73106 in vhost_dev_disable_notifiers (hdev=hdev@entry=0x55f8035b51b0, vdev=vdev@entry=0x55f8044ec590)
1be5c7
   at ../../../include/hw/virtio/virtio-bus.h:35
1be5c7
16 0x000055f800bf00b2 in vhost_net_stop_one (net=0x55f8035b51b0, dev=0x55f8044ec590) at ../hw/net/vhost_net.c:316
1be5c7
17 0x000055f800bf0678 in vhost_net_stop (dev=dev@entry=0x55f8044ec590, ncs=0x55f80452bae0, data_queue_pairs=data_queue_pairs@entry=7, cvq=cvq@entry=1)
1be5c7
   at ../hw/net/vhost_net.c:423
1be5c7
18 0x000055f800d4e628 in virtio_net_set_status (status=<optimized out>, n=0x55f8044ec590) at ../hw/net/virtio-net.c:296
1be5c7
19 0x000055f800d4e628 in virtio_net_set_status (vdev=0x55f8044ec590, status=15 '\017') at ../hw/net/virtio-net.c:370
1be5c7
20 0x000055f800d6c4b2 in virtio_set_status (vdev=0x55f8044ec590, val=<optimized out>) at ../hw/virtio/virtio.c:1945
1be5c7
21 0x000055f800d11d9d in vm_state_notify (running=running@entry=false, state=state@entry=RUN_STATE_SHUTDOWN) at ../softmmu/runstate.c:333
1be5c7
22 0x000055f800d04e7a in do_vm_stop (state=state@entry=RUN_STATE_SHUTDOWN, send_stop=send_stop@entry=false) at ../softmmu/cpus.c:262
1be5c7
23 0x000055f800d04e99 in vm_shutdown () at ../softmmu/cpus.c:280
1be5c7
24 0x000055f800d126af in qemu_cleanup () at ../softmmu/runstate.c:812
1be5c7
25 0x000055f800ad5b13 in main (argc=<optimized out>, argv=<optimized out>, envp=<optimized out>) at ../softmmu/main.c:51
1be5c7
1be5c7
For now, temporarily disable handling MQ request from the ctrl_vq
1be5c7
userspace hanlder to avoid the recursive virtio_net_set_status()
1be5c7
call. Some rework is needed to allow changing the number of
1be5c7
queues without going through a full virtio_net_set_status cycle,
1be5c7
particularly for vhost-vdpa backend.
1be5c7
1be5c7
This patch will need to be reverted as soon as future patches of
1be5c7
having the change of #queues handled in userspace is merged.
1be5c7
1be5c7
Fixes: 402378407db ("vhost-vdpa: multiqueue support")
1be5c7
Signed-off-by: Si-Wei Liu <si-wei.liu@oracle.com>
1be5c7
Acked-by: Jason Wang <jasowang@redhat.com>
1be5c7
Message-Id: <1651890498-24478-8-git-send-email-si-wei.liu@oracle.com>
1be5c7
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
1be5c7
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
1be5c7
(cherry picked from commit 2a7888cc3aa31faee839fa5dddad354ff8941f4c)
1be5c7
Signed-off-by: Jason Wang <jasowang@redhat.com>
1be5c7
---
1be5c7
 hw/net/virtio-net.c | 13 +++++++++++++
1be5c7
 1 file changed, 13 insertions(+)
1be5c7
1be5c7
diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c
1be5c7
index f118379bb4..7e172ef829 100644
1be5c7
--- a/hw/net/virtio-net.c
1be5c7
+++ b/hw/net/virtio-net.c
1be5c7
@@ -1373,6 +1373,7 @@ static int virtio_net_handle_mq(VirtIONet *n, uint8_t cmd,
1be5c7
 {
1be5c7
     VirtIODevice *vdev = VIRTIO_DEVICE(n);
1be5c7
     uint16_t queue_pairs;
1be5c7
+    NetClientState *nc = qemu_get_queue(n->nic);
1be5c7
 
1be5c7
     virtio_net_disable_rss(n);
1be5c7
     if (cmd == VIRTIO_NET_CTRL_MQ_HASH_CONFIG) {
1be5c7
@@ -1404,6 +1405,18 @@ static int virtio_net_handle_mq(VirtIONet *n, uint8_t cmd,
1be5c7
         return VIRTIO_NET_ERR;
1be5c7
     }
1be5c7
 
1be5c7
+    /* Avoid changing the number of queue_pairs for vdpa device in
1be5c7
+     * userspace handler. A future fix is needed to handle the mq
1be5c7
+     * change in userspace handler with vhost-vdpa. Let's disable
1be5c7
+     * the mq handling from userspace for now and only allow get
1be5c7
+     * done through the kernel. Ripples may be seen when falling
1be5c7
+     * back to userspace, but without doing it qemu process would
1be5c7
+     * crash on a recursive entry to virtio_net_set_status().
1be5c7
+     */
1be5c7
+    if (nc->peer && nc->peer->info->type == NET_CLIENT_DRIVER_VHOST_VDPA) {
1be5c7
+        return VIRTIO_NET_ERR;
1be5c7
+    }
1be5c7
+
1be5c7
     n->curr_queue_pairs = queue_pairs;
1be5c7
     /* stop the backend before changing the number of queue_pairs to avoid handling a
1be5c7
      * disabled queue */
1be5c7
-- 
1be5c7
2.35.3
1be5c7