From: Peter Xu <peterx@redhat.com>
To: "Dr. David Alan Gilbert" <dgilbert@redhat.com>
Cc: qemu-devel@nongnu.org, Alexey Perevalov <a.perevalov@samsung.com>,
"Daniel P . Berrange" <berrange@redhat.com>,
Juan Quintela <quintela@redhat.com>,
Andrea Arcangeli <aarcange@redhat.com>
Subject: Re: [Qemu-devel] [PATCH v4 01/32] migration: better error handling with QEMUFile
Date: Fri, 1 Dec 2017 16:39:25 +0800 [thread overview]
Message-ID: <20171201083925.GC2712@xz-mi> (raw)
In-Reply-To: <20171130102437.GA2248@work-vm>
On Thu, Nov 30, 2017 at 10:24:38AM +0000, Dr. David Alan Gilbert wrote:
> * Peter Xu (peterx@redhat.com) wrote:
> > If the postcopy down due to some reason, we can always see this on dst:
> >
> > qemu-system-x86_64: RP: Received invalid message 0x0000 length 0x0000
> >
> > However in most cases that's not the real issue. The problem is that
> > qemu_get_be16() has no way to show whether the returned data is valid or
> > not, and we are _always_ assuming it is valid. That's possibly not wise.
> >
> > The best approach to solve this would be: refactoring QEMUFile interface
> > to allow the APIs to return error if there is. However it needs quite a
> > bit of work and testing. For now, let's explicitly check the validity
> > first before using the data in all places for qemu_get_*().
> >
> > This patch tries to fix most of the cases I can see. Only if we are with
> > this, can we make sure we are processing the valid data, and also can we
> > make sure we can capture the channel down events correctly.
> >
> > Signed-off-by: Peter Xu <peterx@redhat.com>
> > ---
> > migration/migration.c | 5 +++++
> > migration/ram.c | 26 ++++++++++++++++++++++----
> > migration/savevm.c | 40 ++++++++++++++++++++++++++++++++++++++--
> > 3 files changed, 65 insertions(+), 6 deletions(-)
> >
> > diff --git a/migration/migration.c b/migration/migration.c
> > index c0206023d7..eae34d0524 100644
> > --- a/migration/migration.c
> > +++ b/migration/migration.c
> > @@ -1708,6 +1708,11 @@ static void *source_return_path_thread(void *opaque)
> > header_type = qemu_get_be16(rp);
> > header_len = qemu_get_be16(rp);
> >
> > + if (qemu_file_get_error(rp)) {
> > + mark_source_rp_bad(ms);
> > + goto out;
> > + }
> > +
> > if (header_type >= MIG_RP_MSG_MAX ||
> > header_type == MIG_RP_MSG_INVALID) {
> > error_report("RP: Received invalid message 0x%04x length 0x%04x",
> > diff --git a/migration/ram.c b/migration/ram.c
> > index 8620aa400a..960c726ff2 100644
> > --- a/migration/ram.c
> > +++ b/migration/ram.c
> > @@ -2687,7 +2687,7 @@ static int ram_load_postcopy(QEMUFile *f)
> > void *last_host = NULL;
> > bool all_zero = false;
> >
> > - while (!ret && !(flags & RAM_SAVE_FLAG_EOS)) {
> > + while (!(flags & RAM_SAVE_FLAG_EOS)) {
>
> I still think you need to keep the !ret && - see below;
> anyway, there's no harm in keeping it!
Fair enough; I'll keep it no matter what. :-)
>
> > ram_addr_t addr;
> > void *host = NULL;
> > void *page_buffer = NULL;
> > @@ -2696,6 +2696,16 @@ static int ram_load_postcopy(QEMUFile *f)
> > uint8_t ch;
> >
> > addr = qemu_get_be64(f);
> > +
> > + /*
> > + * If qemu file error, we should stop here, and then "addr"
> > + * may be invalid
> > + */
> > + ret = qemu_file_get_error(f);
> > + if (ret) {
> > + break;
> > + }
> > +
> > flags = addr & ~TARGET_PAGE_MASK;
> > addr &= TARGET_PAGE_MASK;
> >
> > @@ -2776,6 +2786,13 @@ static int ram_load_postcopy(QEMUFile *f)
> > error_report("Unknown combination of migration flags: %#x"
> > " (postcopy mode)", flags);
> > ret = -EINVAL;
[1]
> > + break;
>
> This 'break' breaks from the switch, but doesn't break the loop and
> because you remove dthe !ret && from the top, the loop keeps going when
> it shouldn't.
Ah yes I missed this one, thanks.
What I should have written here is a "goto out", and also I should add
that "out" label at the end. I think after this single change current
patch should be fine.
However I understand that you would prefer me to check the ret every
time. IMHO it's a matter of taste. I would prefer current way to do
things since I see it awkward to keep checking against (!ret) possibly
multiple times even we already know it's non-zero (especially when the
failure happens at the beginning of the loop block). But for this
patch, I can follow yours (since you asked for twice already :).
>
> > + }
> > +
> > + /* Detect for any possible file errors */
> > + if (qemu_file_get_error(f)) {
> > + ret = qemu_file_get_error(f);
> > + break;
> > }
>
> This is all simpler if you just leave the !ret && at the top, and then
> make this:
> if (!ret) {
> ret = qemu_file_get_error(f);
> }
Sure.
(So to show what I meant: if we failed at [1] above we still need to
check this, which is unecessary imho)
>
> >
> > if (place_needed) {
>
> Make that
>
> if (!ret && place_needed) {
Will do.
(same here if we failed at [1], actually we don't need to check the
ret value so many times)
>
> > @@ -2789,9 +2806,10 @@ static int ram_load_postcopy(QEMUFile *f)
> > ret = postcopy_place_page(mis, place_dest,
> > place_source, block);
> > }
> > - }
> > - if (!ret) {
> > - ret = qemu_file_get_error(f);
> > +
> > + if (ret) {
> > + break;
> > + }
>
> And with the !ret check at the top this goes again.
Yes, will remove it. Thanks!
--
Peter Xu
next prev parent reply other threads:[~2017-12-01 15:50 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-11-08 6:00 [Qemu-devel] [PATCH v4 00/32] Migration: postcopy failure recovery Peter Xu
2017-11-08 6:00 ` [Qemu-devel] [PATCH v4 01/32] migration: better error handling with QEMUFile Peter Xu
2017-11-30 10:24 ` Dr. David Alan Gilbert
2017-12-01 8:39 ` Peter Xu [this message]
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 02/32] migration: reuse mis->userfault_quit_fd Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 03/32] migration: provide postcopy_fault_thread_notify() Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 04/32] migration: new postcopy-pause state Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 05/32] migration: implement "postcopy-pause" src logic Peter Xu
2017-11-30 10:49 ` Dr. David Alan Gilbert
2017-12-01 8:56 ` Peter Xu
2017-12-01 10:49 ` Dr. David Alan Gilbert
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 06/32] migration: allow dst vm pause on postcopy Peter Xu
2017-11-30 11:17 ` Dr. David Alan Gilbert
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 07/32] migration: allow src return path to pause Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 08/32] migration: allow send_rq to fail Peter Xu
2017-11-30 12:13 ` Dr. David Alan Gilbert
2017-12-01 9:30 ` Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 09/32] migration: allow fault thread to pause Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 10/32] qmp: hmp: add migrate "resume" option Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 11/32] migration: pass MigrationState to migrate_init() Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 12/32] migration: rebuild channel on source Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 13/32] migration: new state "postcopy-recover" Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 14/32] migration: wakeup dst ram-load-thread for recover Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 15/32] migration: new cmd MIG_CMD_RECV_BITMAP Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 16/32] migration: new message MIG_RP_MSG_RECV_BITMAP Peter Xu
2017-11-30 17:21 ` Dr. David Alan Gilbert
2017-12-01 9:37 ` Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 17/32] migration: new cmd MIG_CMD_POSTCOPY_RESUME Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 18/32] migration: new message MIG_RP_MSG_RESUME_ACK Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 19/32] migration: introduce SaveVMHandlers.resume_prepare Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 20/32] migration: synchronize dirty bitmap for resume Peter Xu
2017-11-30 18:40 ` Dr. David Alan Gilbert
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 21/32] migration: setup ramstate " Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 22/32] migration: final handshake for the resume Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 23/32] migration: free SocketAddress where allocated Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 24/32] migration: return incoming task tag for sockets Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 25/32] migration: return incoming task tag for exec Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 26/32] migration: return incoming task tag for fd Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 27/32] migration: store listen task tag Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 28/32] migration: allow migrate_incoming for paused VM Peter Xu
2017-12-01 17:21 ` Dr. David Alan Gilbert
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 29/32] migration: init dst in migration_object_init too Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 30/32] migration: delay the postcopy-active state switch Peter Xu
2017-12-01 12:34 ` Dr. David Alan Gilbert
2017-12-04 4:14 ` Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 31/32] migration, qmp: new command "migrate-pause" Peter Xu
2017-12-01 16:53 ` Dr. David Alan Gilbert
2017-12-04 4:48 ` Peter Xu
2017-12-04 17:10 ` Dr. David Alan Gilbert
2017-12-05 2:52 ` Peter Xu
2017-11-08 6:01 ` [Qemu-devel] [PATCH v4 32/32] migration, hmp: new command "migrate_pause" Peter Xu
2017-11-30 20:00 ` [Qemu-devel] [PATCH v4 00/32] Migration: postcopy failure recovery Dr. David Alan Gilbert
2017-12-01 10:23 ` Peter Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20171201083925.GC2712@xz-mi \
--to=peterx@redhat.com \
--cc=a.perevalov@samsung.com \
--cc=aarcange@redhat.com \
--cc=berrange@redhat.com \
--cc=dgilbert@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=quintela@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.