From: Jeff Cody <jcody@redhat.com>
To: Paolo Bonzini <pbonzini@redhat.com>
Cc: qemu-devel@nongnu.org, qemu-stable@nongnu.org,
qemu-block@nongnu.org, rjones@redhat.com
Subject: Re: [Qemu-devel] [PATCH 3/7] curl: avoid recursive locking of BDRVCURLState mutex
Date: Thu, 11 May 2017 16:56:11 -0400 [thread overview]
Message-ID: <20170511205611.GC19824@localhost.localdomain> (raw)
In-Reply-To: <20170510143205.32013-4-pbonzini@redhat.com>
On Wed, May 10, 2017 at 04:32:01PM +0200, Paolo Bonzini wrote:
> The curl driver has a ugly hack where, if it cannot find an empty CURLState,
> it just uses aio_poll to wait for one to be empty. This is probably
> buggy when used together with dataplane, and the simplest way to fix it
> is to use coroutines instead.
>
> A more immediate effect of the bug however is that it can cause a
> recursive call to curl_readv_bh_cb and recursively taking the
> BDRVCURLState mutex. This causes a deadlock.
>
> The fix is to unlock the mutex around aio_poll, but for cleanliness we
> should also take the mutex around all calls to curl_init_state, even if
> reaching the unlock/lock pair is impossible. The same is true for
> curl_clean_state.
>
> Reported-by: Richard W.M. Jones <rjones@redhat.com>
> Cc: jcody@redhat.com
> Cc: qemu-stable@nongnu.org
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
> ---
> block/curl.c | 13 ++++++++++++-
> 1 file changed, 12 insertions(+), 1 deletion(-)
>
> diff --git a/block/curl.c b/block/curl.c
> index 9a00fdc28e..b18e79bf54 100644
> --- a/block/curl.c
> +++ b/block/curl.c
> @@ -281,6 +281,7 @@ read_end:
> return size * nmemb;
> }
>
> +/* Called with s->mutex held. */
> static int curl_find_buf(BDRVCURLState *s, size_t start, size_t len,
> CURLAIOCB *acb)
> {
> @@ -453,6 +454,7 @@ static void curl_multi_timeout_do(void *arg)
> #endif
> }
>
> +/* Called with s->mutex held. */
> static CURLState *curl_init_state(BlockDriverState *bs, BDRVCURLState *s)
> {
> CURLState *state = NULL;
> @@ -471,7 +473,9 @@ static CURLState *curl_init_state(BlockDriverState *bs, BDRVCURLState *s)
> break;
> }
> if (!state) {
> + qemu_mutex_unlock(&s->mutex);
> aio_poll(bdrv_get_aio_context(bs), true);
> + qemu_mutex_lock(&s->mutex);
> }
> } while(!state);
>
> @@ -534,6 +538,7 @@ static CURLState *curl_init_state(BlockDriverState *bs, BDRVCURLState *s)
> return state;
> }
>
> +/* Called with s->mutex held. */
> static void curl_clean_state(CURLState *s)
> {
> int j;
> @@ -565,6 +570,7 @@ static void curl_detach_aio_context(BlockDriverState *bs)
> BDRVCURLState *s = bs->opaque;
> int i;
>
> + qemu_mutex_lock(&s->mutex);
> for (i = 0; i < CURL_NUM_STATES; i++) {
> if (s->states[i].in_use) {
> curl_clean_state(&s->states[i]);
> @@ -580,6 +586,7 @@ static void curl_detach_aio_context(BlockDriverState *bs)
> curl_multi_cleanup(s->multi);
> s->multi = NULL;
> }
> + qemu_mutex_unlock(&s->mutex);
>
> timer_del(&s->timer);
> }
> @@ -745,9 +752,12 @@ static int curl_open(BlockDriverState *bs, QDict *options, int flags,
> }
>
> DPRINTF("CURL: Opening %s\n", file);
> + qemu_mutex_init(&s->mutex);
This mutex init is now done above possible returns on error, so we should
call qemu_mutex_destroy() on errors after this point.
> s->aio_context = bdrv_get_aio_context(bs);
> s->url = g_strdup(file);
> + qemu_mutex_lock(&s->mutex);
> state = curl_init_state(bs, s);
> + qemu_mutex_unlock(&s->mutex);
> if (!state)
> goto out_noclean;
>
> @@ -791,11 +801,12 @@ static int curl_open(BlockDriverState *bs, QDict *options, int flags,
> }
> DPRINTF("CURL: Size = %zd\n", s->len);
>
> + qemu_mutex_lock(&s->mutex);
> curl_clean_state(state);
> + qemu_mutex_unlock(&s->mutex);
> curl_easy_cleanup(state->curl);
> state->curl = NULL;
>
> - qemu_mutex_init(&s->mutex);
> curl_attach_aio_context(bs, bdrv_get_aio_context(bs));
>
> qemu_opts_del(opts);
> --
> 2.12.2
>
>
next prev parent reply other threads:[~2017-05-11 20:56 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-05-10 14:31 [Qemu-devel] [PATCH v2 0/7] curl: locking cleanups/fixes, coroutine conversion, remove aio_poll Paolo Bonzini
2017-05-10 14:31 ` [Qemu-devel] [PATCH 1/7] curl: strengthen assertion in curl_clean_state Paolo Bonzini
2017-05-10 16:33 ` [Qemu-devel] [Qemu-block] " Max Reitz
2017-05-11 20:35 ` [Qemu-devel] " Jeff Cody
2017-05-10 14:32 ` [Qemu-devel] [PATCH 2/7] curl: never invoke callbacks with s->mutex held Paolo Bonzini
2017-05-10 16:33 ` [Qemu-devel] [Qemu-block] " Max Reitz
2017-05-11 20:40 ` [Qemu-devel] " Jeff Cody
2017-05-10 14:32 ` [Qemu-devel] [PATCH 3/7] curl: avoid recursive locking of BDRVCURLState mutex Paolo Bonzini
2017-05-10 16:38 ` [Qemu-devel] [Qemu-block] " Max Reitz
2017-05-11 20:56 ` Jeff Cody [this message]
2017-05-12 14:48 ` [Qemu-devel] " Paolo Bonzini
2017-05-10 14:32 ` [Qemu-devel] [PATCH 4/7] curl: split curl_find_state/curl_init_state Paolo Bonzini
2017-05-10 17:26 ` [Qemu-devel] [Qemu-block] " Max Reitz
2017-05-11 13:49 ` [Qemu-devel] " Paolo Bonzini
2017-05-12 21:38 ` Jeff Cody
2017-05-10 14:32 ` [Qemu-devel] [PATCH 5/7] curl: convert CURLAIOCB to byte values Paolo Bonzini
2017-05-10 17:36 ` [Qemu-devel] [Qemu-block] " Max Reitz
2017-05-10 18:37 ` Eric Blake
2017-05-12 21:38 ` [Qemu-devel] " Jeff Cody
2017-05-10 14:32 ` [Qemu-devel] [PATCH 6/7] curl: convert readv to coroutines Paolo Bonzini
2017-05-12 21:40 ` Jeff Cody
2017-05-10 14:32 ` [Qemu-devel] [PATCH 7/7] curl: do not do aio_poll when waiting for a free CURLState Paolo Bonzini
2017-05-10 17:54 ` [Qemu-devel] [Qemu-block] " Max Reitz
2017-05-12 21:41 ` [Qemu-devel] " Jeff Cody
2017-05-10 15:11 ` [Qemu-devel] [PATCH v2 0/7] curl: locking cleanups/fixes, coroutine conversion, remove aio_poll no-reply
2017-05-10 15:57 ` Richard W.M. Jones
2017-05-15 19:12 ` [Qemu-devel] [Qemu-block] " Max Reitz
2017-05-15 20:30 ` Richard W.M. Jones
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170511205611.GC19824@localhost.localdomain \
--to=jcody@redhat.com \
--cc=pbonzini@redhat.com \
--cc=qemu-block@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=qemu-stable@nongnu.org \
--cc=rjones@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.