Re: [PATCH v2] xen-blkfront: fix double completion of split requests on resume

From: Roger Pau Monné

Date: Thu Jul 09 2026 - 06:28:15 EST


On Thu, Jul 09, 2026 at 12:08:53PM +0200, Doruk Tan Ozturk wrote:
> When a block request is too large for a single ring entry and the
> backend does not support indirect descriptors, blkfront splits it across
> two ring requests. This only happens when the frontend runs on a
> 64K-page kernel (e.g. arm64): there, even a single-page request may not
> fit in one ring slot and must be split. blkif_ring_get_request() is
> called twice and both shadow slots (shadow[id] and shadow[extra_id])
> point at the *same* struct request, linked through associated_id.
>
> blkif_completion() collapses the pair on the normal completion path,
> recycling the second slot and completing the request once. The
> suspend/resume walk in blkfront_resume() does not: it visits every
> shadow slot with ->request set and calls blk_mq_end_request() or
> re-queues ->request. For an in-flight split request it therefore
> processes the shared struct request twice on resume/migration -- a
> double completion.
>
> Skip the secondary slot of a split request in the resume walk so each
> logical request is processed exactly once. The secondary slot is the
> linked one (associated_id != NO_ASSOCIATED_ID) that carries no
> scatter-gather list (num_sg == 0); the first slot always keeps the sg
> list. The bug is only reachable on suspend/resume or live migration of
> such a guest, so it has no local reproducer.
>
> Fixes: 6cc568339047 ("xen/blkfront: Handle non-indirect grant with 64KB pages")
> Assisted-by: 0sec:claude-opus-4-8
> Signed-off-by: Doruk Tan Ozturk <doruk@xxxxxxx>

Acked-by: Roger Pau Monné <roger.pau@xxxxxxxxxx>

Thanks, Roger.