Internal Use - Confidential
> -----Original Message-----
> From: David Marchand <[email protected]>
> Sent: Thursday, July 30, 2026 11:22 PM
> To: Bathija, Pravin <[email protected]>; [email protected]
> Cc: [email protected]; [email protected];
> [email protected]; [email protected]; [email protected]
> Subject: Re: [PATCH v2 1/1] vhost: tolerate file descriptor in REM_MEM_REG
> msg
>
>
> [EXTERNAL EMAIL]
>
> On Fri, 31 Jul 2026 at 05:14, <[email protected]> wrote:
> >
> > From: Pravin M Bathija <[email protected]>
> >
> > The vhost-user specification (vhost-user.rst) states that no file
> > descriptors SHOULD be passed with VHOST_USER_REM_MEM_REG.
> However, it
> > also says: "For compatibility with existing incorrect implementations,
> > the back-end MAY accept messages with one file descriptor. If a file
> > descriptor is passed, the back-end MUST close it without using it
> > otherwise."
> >
> > Some front-ends, notably libblkio, reuse the same message-building
> > helper for both ADD_MEM_REG and REM_MEM_REG and unconditionally
> attach
> > the mapping fd. The previous implementation rejected any REM_MEM_REG
> > carrying a file descriptor with the error:
> >
> > expect 0 FDs for request VHOST_USER_REM_MEM_REG, received 1
> >
> > This broke teardown and memory region hot-swap with these front-ends.
> >
> > To reproduce, run any libblkio (v1.5.0) application using the
> > virtio-blk-vhost-user driver against a DPDK vhost back-end. The
> > connection is dropped during cleanup or whenever a memory region is
> > unmapped and remapped.
>
> Is libblkio fixed now?
>
> I am not a fan of such compatibility fix, having to accept one buggy client...
>
Yes, the libblkio fix is ready and will be submitted upstream within a day or
so.
It stops sending the fd with REM_MEM_REG.
That said, this DPDK fix stands on its own regardless of libblkio. The
vhost-user
specification explicitly anticipates this situation and requires back-ends to
handle it:
"For compatibility with existing incorrect implementations, the back-end MAY
accept messages
with one file descriptor. If a file descriptor is passed, the back-end MUST
close it without
using it otherwise."
While the immediate motivation was libblkio, the spec's compatibility clause
was written for
exactly this situation — any front-end could make the same mistake. QEMU's
libvhost-user
reference implementation already tolerates it (see vu_rem_mem_reg).
The fix is 2 lines with no downside: accept the message, close the fd.
Rejecting it drops the
connection entirely, which is a disproportionate response to a harmless extra
fd.
> >
> > QEMU's libvhost-user reference back-end (vu_rem_mem_reg) already
> > tolerates zero or one fd in this message. Align DPDK's behavior with
> > both the specification's compatibility clause and the reference
> > implementation by accepting the message and closing any unexpected fd.
> >
> > Tested with:
> > - QEMU VM bring-up with runtime add/remove memory regions via
> > QEMU monitor
> > - QEMU post-copy live migration between source and destination
> > - SPDK vhost-blk with libblkio (fio libblkio engine, write + md5
> > verify)
> > - libblkio alloc-mem-region and map-mem-region tests exercising
> > ADD_MEM_REG / REM_MEM_REG / ADD_MEM_REG cycles against SPDK
> > vhost-blk
> >
> > Fixes: 1d730eea6a42 ("vhost: add memory region handlers")
> > Cc: [email protected]
> >
> > Signed-off-by: Pravin M Bathija <[email protected]>
> > ---
> > doc/guides/rel_notes/release_26_07.rst | 8 ++++++++
> > lib/vhost/vhost_user.c | 9 ++++++++-
> > 2 files changed, 16 insertions(+), 1 deletion(-)
> >
> > diff --git a/doc/guides/rel_notes/release_26_07.rst
> > b/doc/guides/rel_notes/release_26_07.rst
> > index 3d18ba2dd0..86042bd5e3 100644
> > --- a/doc/guides/rel_notes/release_26_07.rst
> > +++ b/doc/guides/rel_notes/release_26_07.rst
>
> We are working on 26.*11* ...
>
>
> > @@ -85,6 +85,14 @@ New Features
> > to support adding and removing memory regions without resetting
> > the whole guest memory map.
> >
> > +* **Fixed vhost REM_MEM_REG compatibility with front-ends sending
> > +file descriptors.**
> > +
> > + The vhost-user ``REM_MEM_REG`` message handler now tolerates an
> > + unexpected file descriptor sent by the front-end, closing it
> > + without use as permitted by the vhost-user specification.
> > + This fixes interoperability with front-ends such as libblkio that
> > + unconditionally attach a file descriptor to the message.
> > +
>
> ... and regardless of the version this was put in, this is not a feature.
>
> We usually don't put Fixes: in RN.
> The AI bot nags too much.
>
>
> --
> David Marchand