vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value
into v->config_ctx before checking it, so on failure the field briefly
holds an ERR_PTR:

        ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd);
        swap(ctx, v->config_ctx);

        if (!IS_ERR_OR_NULL(ctx))
                eventfd_ctx_put(ctx);

        if (IS_ERR(v->config_ctx)) {
                long ret = PTR_ERR(v->config_ctx);

                v->config_ctx = NULL;
                return ret;
        }

Commit 0bde59c1723a ("vhost-vdpa: set v->config_ctx to NULL if
eventfd_ctx_fdget() fails") added that clearing, and spelled out the
invariant the rest of the file relies on: "we consider 'v->config_ctx'
valid if it is not NULL".  The window between the swap and the clearing
still breaks it.  vhost_vdpa_config_cb() only tests for NULL, so a config
interrupt delivered inside the window hands the ERR_PTR to
eventfd_signal().

Check the fd before installing it instead.  That closes the window and
matches how vhost_vring_ioctl() handles the same failure for the vq call
fd.

It also stops a rejected fd from tearing down a config interrupt that was
working: until now the swap replaced the live context and put it, so
after an EBADF the device silently stopped delivering config interrupts
until userspace installed a new fd.

Fixes: 776f395004d8 ("vhost_vdpa: Support config interrupt in vdpa")
Signed-off-by: Yu Zhang <[email protected]>
---
 drivers/vhost/vdpa.c | 12 ++++--------
 1 file changed, 4 insertions(+), 8 deletions(-)

diff --git a/drivers/vhost/vdpa.c b/drivers/vhost/vdpa.c
index ac55275..e5e47f6 100644
--- a/drivers/vhost/vdpa.c
+++ b/drivers/vhost/vdpa.c
@@ -529,18 +529,14 @@ static long vhost_vdpa_set_config_call(struct vhost_vdpa 
*v, u32 __user *argp)
                return  -EFAULT;
 
        ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd);
+       if (IS_ERR(ctx))
+               return PTR_ERR(ctx);
+
        swap(ctx, v->config_ctx);
 
-       if (!IS_ERR_OR_NULL(ctx))
+       if (ctx)
                eventfd_ctx_put(ctx);
 
-       if (IS_ERR(v->config_ctx)) {
-               long ret = PTR_ERR(v->config_ctx);
-
-               v->config_ctx = NULL;
-               return ret;
-       }
-
        v->vdpa->config->set_config_cb(v->vdpa, &cb);
 
        return 0;
-- 
2.43.0


Reply via email to