[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL 17/41] vhost: fix cleanup on not fully initialized de
From: |
Michael S. Tsirkin |
Subject: |
[Qemu-devel] [PULL 17/41] vhost: fix cleanup on not fully initialized device |
Date: |
Fri, 29 Jul 2016 06:16:03 +0300 |
From: Marc-André Lureau <address@hidden>
If vhost_dev_init() failed, caller may still call vhost_dev_cleanup()
later. However, vhost_dev_cleanup() tries to remove the device from the
list even if it wasn't yet added, which may lead to crashes. Similarly
for the memory listener.
Signed-off-by: Marc-André Lureau <address@hidden>
Reviewed-by: Michael S. Tsirkin <address@hidden>
Signed-off-by: Michael S. Tsirkin <address@hidden>
---
hw/virtio/vhost.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c
index 8a18f9b..6b988e1 100644
--- a/hw/virtio/vhost.c
+++ b/hw/virtio/vhost.c
@@ -1033,7 +1033,6 @@ int vhost_dev_init(struct vhost_dev *hdev, void *opaque,
r = -1;
goto fail;
}
- QLIST_INSERT_HEAD(&vhost_devices, hdev, entry);
r = hdev->vhost_ops->vhost_set_owner(hdev);
if (r < 0) {
@@ -1103,6 +1102,7 @@ int vhost_dev_init(struct vhost_dev *hdev, void *opaque,
hdev->started = false;
hdev->memory_changed = false;
memory_listener_register(&hdev->memory_listener, &address_space_memory);
+ QLIST_INSERT_HEAD(&vhost_devices, hdev, entry);
return 0;
fail_busyloop:
while (--i >= 0) {
@@ -1126,7 +1126,11 @@ void vhost_dev_cleanup(struct vhost_dev *hdev)
for (i = 0; i < hdev->nvqs; ++i) {
vhost_virtqueue_cleanup(hdev->vqs + i);
}
- memory_listener_unregister(&hdev->memory_listener);
+ if (hdev->mem) {
+ /* those are only safe after successful init */
+ memory_listener_unregister(&hdev->memory_listener);
+ QLIST_REMOVE(hdev, entry);
+ }
if (hdev->migration_blocker) {
migrate_del_blocker(hdev->migration_blocker);
error_free(hdev->migration_blocker);
@@ -1135,7 +1139,6 @@ void vhost_dev_cleanup(struct vhost_dev *hdev)
g_free(hdev->mem_sections);
hdev->vhost_ops->vhost_backend_cleanup(hdev);
assert(!hdev->log);
- QLIST_REMOVE(hdev, entry);
}
/* Stop processing guest IO notifications in qemu.
--
MST
- [Qemu-devel] [PULL 07/41] hw/pci-bridge: Convert pxb initialization functions to Error, (continued)
- [Qemu-devel] [PULL 07/41] hw/pci-bridge: Convert pxb initialization functions to Error, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 08/41] apb: convert init to realize, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 09/41] hw/virtio-pci: fix virtio behaviour, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 10/41] virtio: check vring descriptor buffer length, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 11/41] misc: indentation, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 12/41] vhost-user: minor simplification, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 13/41] vhost-user: disconnect on HUP, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 15/41] vhost: make vhost_log_put() idempotent, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 14/41] vhost: don't assume opaque is a fd, use backend cleanup, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 16/41] vhost: assert the log was cleaned up, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 17/41] vhost: fix cleanup on not fully initialized device,
Michael S. Tsirkin <=
- [Qemu-devel] [PULL 18/41] vhost: make vhost_dev_cleanup() idempotent, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 19/41] vhost-net: always call vhost_dev_cleanup() on failure, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 20/41] vhost: fix calling vhost_dev_cleanup() after vhost_dev_init(), Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 22/41] vhost: add missing VHOST_OPS_DEBUG, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 21/41] vhost: do not assert() on vhost_ops failure, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 23/41] vhost: use error_report() instead of fprintf(stderr, ...), Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 24/41] qemu-char: fix qemu_chr_fe_set_msgfds() crash when disconnected, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 25/41] vhost-user: call set_msgfds unconditionally, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 26/41] vhost-user: check qemu_chr_fe_set_msgfds() return value, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 27/41] vhost-user: check vhost_user_{read, write}() return value, Michael S. Tsirkin, 2016/07/28