[Devel] [PATCH RHEL10 COMMIT] drivers/vhost/blk: report correct used-ring lengths

Konstantin Khorenko khorenko at virtuozzo.com
Tue Aug 25 16:56:58 MSK 2026


The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git at bitbucket.org:openvz/vzkernel.git
after rh10-6.12.0-211.39.1.16.9.vz10
------>
commit 35b08c53bf488c7991dba12f966d3030d1328d4f
Author: Andrey Zhadchenko <andrey.zhadchenko at virtuozzo.com>
Date:   Tue Aug 25 15:51:49 2026 +0300

    drivers/vhost/blk: report correct used-ring lengths
    
    We are expected to return amount of bytes written to the guest,
    which also includes status.
    
    https://virtuozzo.atlassian.net/browse/VSTOR-138640
    Fixes: d8722ff88c5d ("drivers/vhost: vhost-blk accelerator for virtio-blk guests")
    Feature: vhost-blk: in-kernel accelerator for virtio-blk guests
    Signed-off-by: Andrey Zhadchenko <andrey.zhadchenko at virtuozzo.com>
    Reviewed-by: Vasileios Almpanis <vasileios.almpanis at virtuozzo.com>
    Reviewed-by: Konstantin Khorenko <khorenko at virtuozzo.com>
---
 drivers/vhost/blk.c | 20 ++++++++++++++------
 1 file changed, 14 insertions(+), 6 deletions(-)

diff --git a/drivers/vhost/blk.c b/drivers/vhost/blk.c
index edd3e75873ff5..2c41a073004bc 100644
--- a/drivers/vhost/blk.c
+++ b/drivers/vhost/blk.c
@@ -445,12 +445,14 @@ static int vhost_blk_req_submit(struct vhost_blk_req *req)
 
 static int vhost_blk_req_handle(struct vhost_virtqueue *vq,
 				struct virtio_blk_outhdr *hdr,
-				u16 head, u16 total_iov_nr)
+				u16 head, u16 out, u16 in)
 {
 	struct vhost_blk *blk = container_of(vq->dev, struct vhost_blk, dev);
 	struct vhost_blk_vq *blk_vq = container_of(vq, struct vhost_blk_vq, vq);
 	struct vhost_blk_req *req;
+	u16 total_iov_nr = out + in;
 	struct iov_iter iter;
+	size_t in_len;
 	int ret, len;
 	u8 status;
 
@@ -461,8 +463,9 @@ static int vhost_blk_req_handle(struct vhost_virtqueue *vq,
 	req->sector	= hdr->sector;
 	req->iov	= blk_vq->iov;
 	req->bio_err	= 0;
+	in_len		= iov_length(vq->iov + out, in);
 
-	if (iov_length(vq->iov, total_iov_nr) < sizeof(status))
+	if (in_len < sizeof(status) || in_len > INT_MAX)
 		return -EINVAL;
 
 	req->len	= iov_length(vq->iov, total_iov_nr) - sizeof(status);
@@ -498,14 +501,14 @@ static int vhost_blk_req_handle(struct vhost_virtqueue *vq,
 		ret = vhost_blk_set_status(req, status);
 		if (ret)
 			break;
-		vhost_add_used_and_signal(&blk->dev, vq, head, len);
+		vhost_add_used_and_signal(&blk->dev, vq, head, in_len);
 		break;
 	default:
 		status = VIRTIO_BLK_S_UNSUPP;
 		ret = vhost_blk_set_status(req, status);
 		if (ret)
 			break;
-		vhost_add_used_and_signal(&blk->dev, vq, head, 0);
+		vhost_add_used_and_signal(&blk->dev, vq, head, sizeof(status));
 	}
 
 	return ret;
@@ -561,7 +564,7 @@ static void vhost_blk_handle_guest_kick(struct vhost_work *work)
 			break;
 		}
 
-		ret = vhost_blk_req_handle(vq, &hdr, head, out + in);
+		ret = vhost_blk_req_handle(vq, &hdr, head, out, in);
 		if (ret == -EAGAIN || ret == -ENOMEM) {
 			vhost_discard_vq_desc(vq, 1);
 			vhost_poll_queue(&vq->poll);
@@ -610,7 +613,12 @@ static void vhost_blk_handle_host_kick(struct vhost_work *work)
 		if (vhost_blk_set_status(req, status)) {
 			vhostblk_vq_err(blk, vq, "Failed to write status");
 		} else {
-			vhost_add_used(vq, req->head, req->len);
+			int used_len = sizeof(status);
+
+			if (req->bi_opf == REQ_OP_READ)
+				used_len += req->len;
+
+			vhost_add_used(vq, req->head, used_len);
 			added = true;
 		}
 


More information about the Devel mailing list