<div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Fri, Jul 31, 2026 at 10:10 AM <<a href="mailto:pravin.bathija@dell.com">pravin.bathija@dell.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">From: Pravin M Bathija <<a href="mailto:pravin.bathija@dell.com" target="_blank">pravin.bathija@dell.com</a>><br>
<br>
The vhost-user specification (vhost-user.rst) states that no file<br>
descriptors SHOULD be passed with VHOST_USER_REM_MEM_REG.  However,<br>
it also says: "For compatibility with existing incorrect<br>
implementations, the back-end MAY accept messages with one file<br>
descriptor.  If a file descriptor is passed, the back-end MUST close<br>
it without using it otherwise."<br>
<br>
Some front-ends, notably libblkio, reuse the same message-building<br>
helper for both ADD_MEM_REG and REM_MEM_REG and unconditionally attach<br>
the mapping fd.  The previous implementation rejected any<br>
REM_MEM_REG carrying a file descriptor with the error:<br>
<br>
        expect 0 FDs for request VHOST_USER_REM_MEM_REG, received 1<br>
<br>
This broke teardown and memory region hot-swap with these front-ends.<br>
<br>
To reproduce, run any libblkio (v1.5.0) application using the<br>
virtio-blk-vhost-user driver against a DPDK vhost back-end.  The<br>
connection is dropped during cleanup or whenever a memory region is<br>
unmapped and remapped.<br>
<br>
QEMU's libvhost-user reference back-end (vu_rem_mem_reg) already<br>
tolerates zero or one fd in this message.  Align DPDK's behavior<br>
with both the specification's compatibility clause and the reference<br>
implementation by accepting the message and closing any unexpected fd.<br>
<br>
Tested with:<br>
 - QEMU VM bring-up with runtime add/remove memory regions via<br>
   QEMU monitor<br>
 - QEMU post-copy live migration between source and destination<br>
 - SPDK vhost-blk with libblkio (fio libblkio engine, write + md5<br>
   verify)<br>
 - libblkio alloc-mem-region and map-mem-region tests exercising<br>
   ADD_MEM_REG / REM_MEM_REG / ADD_MEM_REG cycles against SPDK<br>
   vhost-blk<br>
<br>
Fixes: 1d730eea6a42 ("vhost: add memory region handlers")<br>
Cc: <a href="mailto:stable@dpdk.org" target="_blank">stable@dpdk.org</a><br>
<br>
Signed-off-by: Pravin M Bathija <<a href="mailto:pravin.bathija@dell.com" target="_blank">pravin.bathija@dell.com</a>><br>
---<br>
 lib/vhost/vhost_user.c | 9 ++++++++-<br>
 1 file changed, 8 insertions(+), 1 deletion(-)<br>
<br>
diff --git a/lib/vhost/vhost_user.c b/lib/vhost/vhost_user.c<br>
index 020c993b29..82c62f2f64 100644<br>
--- a/lib/vhost/vhost_user.c<br>
+++ b/lib/vhost/vhost_user.c<br>
@@ -73,7 +73,7 @@ VHOST_MESSAGE_HANDLER(VHOST_USER_RESET_OWNER, vhost_user_reset_owner, false, fal<br>
 VHOST_MESSAGE_HANDLER(VHOST_USER_SET_MEM_TABLE, vhost_user_set_mem_table, true, true) \<br>
 VHOST_MESSAGE_HANDLER(VHOST_USER_GET_MAX_MEM_SLOTS, vhost_user_get_max_mem_slots, false, false) \<br>
 VHOST_MESSAGE_HANDLER(VHOST_USER_ADD_MEM_REG, vhost_user_add_mem_reg, true, true) \<br>
-VHOST_MESSAGE_HANDLER(VHOST_USER_REM_MEM_REG, vhost_user_rem_mem_reg, false, true) \<br>
+VHOST_MESSAGE_HANDLER(VHOST_USER_REM_MEM_REG, vhost_user_rem_mem_reg, true, true) \<br>
 VHOST_MESSAGE_HANDLER(VHOST_USER_SET_LOG_BASE, vhost_user_set_log_base, true, true) \<br>
 VHOST_MESSAGE_HANDLER(VHOST_USER_SET_LOG_FD, vhost_user_set_log_fd, true, true) \<br>
 VHOST_MESSAGE_HANDLER(VHOST_USER_SET_VRING_NUM, vhost_user_set_vring_num, false, true) \<br>
@@ -1811,6 +1811,13 @@ vhost_user_rem_mem_reg(struct virtio_net **pdev,<br>
        struct virtio_net *dev = *pdev;<br>
        uint32_t i;<br>
<br>
+       /*<br>
+        * The specification says no file descriptor should be passed with<br>
+        * this message, but some front-ends send one anyway. Tolerate it and<br>
+        * close it without using it, as the specification requires.<br>
+        */<br>
+       close_msg_fds(ctx);<br>
+<br>
        if (dev->mem == NULL || dev->mem->nregions == 0) {<br>
                VHOST_CONFIG_LOG(dev->ifname, ERR, "no memory regions to remove");<br>
                return RTE_VHOST_MSG_RESULT_ERR;<br>
-- <br>
2.43.0<br>
<br></blockquote><div><br></div><div>Reviewed-by: Maxime Coquelin <<a href="mailto:maxime.coquelin@redhat.com">maxime.coquelin@redhat.com</a>></div><div><br></div><div>Thanks,</div><div>Maxime </div></div></div>