Commit 421f45d03f for qemu.org

commit 421f45d03f328267ebf77fab823a7a25ab3d6c83
Author: GuoHan Zhao <zhaoguohan@kylinos.cn>
Date:   Thu Jul 9 15:32:25 2026 +0800

    hw/virtio/vdpa-dev: pass set_config buffer to vhost backend

    vhost_vdpa_device_set_config() receives the updated config buffer, but
    forwards s->config to the vhost backend. Since s->config is refreshed by
    get_config(), it may contain stale backend state.

    Pass the supplied config buffer to vhost_dev_set_config() instead.

    Fixes: b430a2bd2303 ("vdpa: add vdpa-dev support")
    Signed-off-by: GuoHan Zhao <zhaoguohan@kylinos.cn>
    Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
    Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
    Message-ID: <20260709073225.2341642-1-zhaoguohan@kylinos.cn>

diff --git a/hw/virtio/vdpa-dev.c b/hw/virtio/vdpa-dev.c
index 089a77f4d0..6dc684ab09 100644
--- a/hw/virtio/vdpa-dev.c
+++ b/hw/virtio/vdpa-dev.c
@@ -212,7 +212,7 @@ vhost_vdpa_device_set_config(VirtIODevice *vdev, const uint8_t *config)
     VhostVdpaDevice *s = VHOST_VDPA_DEVICE(vdev);
     int ret;

-    ret = vhost_dev_set_config(&s->dev, s->config, 0, s->config_size,
+    ret = vhost_dev_set_config(&s->dev, config, 0, s->config_size,
                                VHOST_SET_CONFIG_TYPE_FRONTEND);
     if (ret) {
         error_report("set device config space failed");