From: GuoHan Zhao <[email protected]>

On Thu, Jul 09, 2026 at 03:35:16AM -0400, Michael S. Tsirkin wrote:
> On Thu, Jul 09, 2026 at 03:32:25PM +0800, [email protected] wrote:
>> From: GuoHan Zhao <[email protected]>
>> 
>> vhost_vdpa_device_set_config() receives the updated config buffer, but
>> forwards s->config to the vhost backend. Since s->config is refreshed by
>> get_config(), it may contain stale backend state.
>>
> 
> could you be a bit more specific pls? a real scenario where you
> see an issue? thanks!
>  
>> Pass the supplied config buffer to vhost_dev_set_config() instead.
>> 
>> Fixes: b430a2bd2303 ("vdpa: add vdpa-dev support")
>> Signed-off-by: GuoHan Zhao <[email protected]>
>> ---
>>  hw/virtio/vdpa-dev.c | 2 +-
>>  1 file changed, 1 insertion(+), 1 deletion(-)
>> 
>> diff --git a/hw/virtio/vdpa-dev.c b/hw/virtio/vdpa-dev.c
>> index 089a77f4d0b9..6dc684ab096a 100644
>> --- a/hw/virtio/vdpa-dev.c
>> +++ b/hw/virtio/vdpa-dev.c
>> @@ -212,7 +212,7 @@ vhost_vdpa_device_set_config(VirtIODevice *vdev, const 
>> uint8_t *config)
>>      VhostVdpaDevice *s = VHOST_VDPA_DEVICE(vdev);
>>      int ret;
>>  
>> -    ret = vhost_dev_set_config(&s->dev, s->config, 0, s->config_size,
>> +    ret = vhost_dev_set_config(&s->dev, config, 0, s->config_size,
>>                                 VHOST_SET_CONFIG_TYPE_FRONTEND);
>>      if (ret) {
>>          error_report("set device config space failed");
>> -- 
>> 2.43.0

Sure. I hit this with a generic vhost-vdpa virtio-blk device when
changing the write cache mode.

For virtio-blk, the guest updates virtio_blk_config.wce when switching
between write through and write back. Without this patch, QEMU still
passes the old s->config buffer to VHOST_VDPA_SET_CONFIG, so the backend
does not see the new wce value.

I reproduced it with vdpa_sim_blk. After writing wce=1 and then wce=0,
the byte corresponding to virtio_blk_config.wce in the buffer passed to
VHOST_VDPA_SET_CONFIG remained unchanged without this patch:

guest writes wce=1:
0x0020: 00 00 01 00 ...
guest writes wce=0:
0x0020: 00 00 01 00 ...

With this patch, the same writes are passed down correctly:

guest writes wce=1:
0x0020: 01 00 00 00 ...
guest writes wce=0:
0x0020: 00 00 00 00 ...

So from the guest's perspective the write cache mode change appears to
succeed, but the updated value never reaches the vDPA backend because
VHOST_VDPA_SET_CONFIG receives stale configuration data.

Reply via email to