Skip to content

Commit 5d72720

Browse files
peaktwilightaxboe
authored andcommitted
xen-blkfront: fix double completion of split requests on resume
When a block request is too large for a single ring entry and the backend does not support indirect descriptors, blkfront splits it across two ring requests. This only happens when the frontend runs on a 64K-page kernel (e.g. arm64): there, even a single-page request may not fit in one ring slot and must be split. blkif_ring_get_request() is called twice and both shadow slots (shadow[id] and shadow[extra_id]) point at the *same* struct request, linked through associated_id. blkif_completion() collapses the pair on the normal completion path, recycling the second slot and completing the request once. The suspend/resume walk in blkfront_resume() does not: it visits every shadow slot with ->request set and calls blk_mq_end_request() or re-queues ->request. For an in-flight split request it therefore processes the shared struct request twice on resume/migration -- a double completion. Skip the secondary slot of a split request in the resume walk so each logical request is processed exactly once. The secondary slot is the linked one (associated_id != NO_ASSOCIATED_ID) that carries no scatter-gather list (num_sg == 0); the first slot always keeps the sg list. The bug is only reachable on suspend/resume or live migration of such a guest, so it has no local reproducer. Fixes: 6cc5683 ("xen/blkfront: Handle non-indirect grant with 64KB pages") Assisted-by: 0sec:claude-opus-4-8 Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai> Acked-by: Roger Pau Monné <roger.pau@citrix.com> Link: https://patch.msgid.link/20260709100853.7489-1-doruk@0sec.ai Signed-off-by: Jens Axboe <axboe@kernel.dk>
1 parent f01f527 commit 5d72720

1 file changed

Lines changed: 9 additions & 0 deletions

File tree

drivers/block/xen-blkfront.c

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2079,6 +2079,15 @@ static int blkfront_resume(struct xenbus_device *dev)
20792079
if (!shadow[j].request)
20802080
continue;
20812081

2082+
/*
2083+
* For requests split across multiple slots, process the
2084+
* underlying request only once: skip the linked, sg-less
2085+
* secondary slot.
2086+
*/
2087+
if (shadow[j].associated_id != NO_ASSOCIATED_ID &&
2088+
shadow[j].num_sg == 0)
2089+
continue;
2090+
20822091
/*
20832092
* Get the bios in the request so we can re-queue them.
20842093
*/

0 commit comments

Comments
 (0)