On Fri, Jul 24, 2026 at 02:09:19PM +0800, Jia Jia wrote:
> vhost-scsi translates guest response descriptors into userspace iovecs
> when commands are submitted.  Target-core completes those commands
> asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while
> an in-flight command still retains response iovecs translated through the
> old table.
> 
> If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command
> completion can write the response to an unrelated userspace object.
> 
> Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device
> ioctl.  This waits for in-flight commands that can still use the old
> response iovecs before the ioctl returns.
> 
> Changes in v2:
> - Shorten the changelog and remove investigation details.

fyi changelog should go after ---


can you pls answer mike's question on v1?
Also pls do not post v2 as response to v1

> Signed-off-by: Jia Jia <[email protected]>
> ---
>  drivers/vhost/scsi.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/vhost/scsi.c b/drivers/vhost/scsi.c
> index 9a1253b9d8c5..c3e8f1a0b2d4 100644
> --- a/drivers/vhost/scsi.c
> +++ b/drivers/vhost/scsi.c
> @@ -2424,10 +2424,11 @@ vhost_scsi_ioctl(struct file *f, unsigned int ioctl, 
> unsigned long arg)
>       default:
>               mutex_lock(&vs->dev.mutex);
>               r = vhost_dev_ioctl(&vs->dev, ioctl, argp);
> -             /* TODO: flush backend after dev ioctl. */
>               if (r == -ENOIOCTLCMD)
>                       r = vhost_vring_ioctl(&vs->dev, ioctl, argp);
> +             else
> +                     vhost_scsi_flush(vs);
>               mutex_unlock(&vs->dev.mutex);
>               return r;
>       }
>  }
> -- 
> 2.43.0


Reply via email to