All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Philippe Mathieu-Daudé" <philmd@oss.qualcomm.com>
To: qemu-devel@nongnu.org
Subject: [PULL 18/18] target/ppc: Stop vCPU thread before calling parent_unrealize
Date: Thu, 24 Sep 2026 17:23:53 +0200	[thread overview]
Message-ID: <20260924152353.36209-19-philmd@oss.qualcomm.com> (raw)
In-Reply-To: <20260924152353.36209-1-philmd@oss.qualcomm.com>

From: Shivang Upadhyay <shivangu@linux.ibm.com>

During CPU hot-unplug (e.g. via dynamic reconfiguration unplug),
ppc_cpu_unrealize() invoked pcc->parent_unrealize(dev) before calling
cpu_remove_sync(CPU(cpu)).

pcc->parent_unrealize() calls cpu_common_unrealize(), which triggers
accel_cpu_common_unrealize() -> tcg_exec_unrealizefn() -> tlb_destroy().
This immediately frees the CPU's TLB tables and structures. Because the
vCPU thread had not yet been stopped and joined via cpu_remove_sync(),
the vCPU thread was still actively running its event loop and processing
queued CPU work (such as tcg_commit_cpu / tlb_flush).

This resulted in a race where the running vCPU thread accessed and freed
already-destroyed TLB tables concurrently with tlb_destroy(), leading to
Segfault (due to heap corruption).

AddressSanitizer build reported a double-free:

=================================================================
==121930==ERROR: AddressSanitizer: attempting double-free on 0x7ef8f3438800 in thread T14:
    #0 0x7fe8f74e5beb in free.part.0 (/lib64/libasan.so.8+0xe5beb)
    #1 0x7fe8f6cb8f84 in g_free (/lib64/libglib-2.0.so.0+0x41f84)
    #2 0x558bf6a391b1 in tlb_mmu_resize_locked accel/tcg/cputlb.c:249
    #3 0x558bf6a396b5 in tlb_flush_one_mmuidx_locked accel/tcg/cputlb.c:296
    #4 0x558bf6a39f91 in tlb_flush_by_mmuidx_async_work accel/tcg/cputlb.c:390
    #5 0x558bf6a3a200 in tlb_flush_by_mmuidx accel/tcg/cputlb.c:417
    #6 0x558bf6a3a22a in tlb_flush accel/tcg/cputlb.c:422
    #7 0x558bf73f31ac in tcg_commit_cpu system/physmem.c:3068
    #8 0x558bf6987c55 in process_queued_cpu_work cpu-common.c:378
    #9 0x558bf73a9913 in qemu_process_cpu_events_common system/cpus.c:402
    #10 0x558bf73a9a46 in qemu_process_cpu_events system/cpus.c:421
    #11 0x558bf6a65974 in mttcg_cpu_thread_fn accel/tcg/tcg-accel-ops-mttcg.c:90

0x7ef8f3438800 is located 0 bytes inside of 65536-byte region [0x7ef8f3438800,0x7ef8f3448800)
freed by thread T9 here:
    #0 0x7fe8f74e5beb in free.part.0 (/lib64/libasan.so.8+0xe5beb)
    #1 0x7fe8f6cb8f84 in g_free (/lib64/libglib-2.0.so.0+0x41f84)
    #2 0x558bf6a39a91 in tlb_destroy accel/tcg/cputlb.c:345
    #3 0x558bf6a16354 in tcg_exec_unrealizefn accel/tcg/cpu-exec.c:1094
    #4 0x558bf693d073 in accel_cpu_common_unrealize accel/accel-common.c:117
    #5 0x558bf6980e37 in cpu_common_unrealize hw/core/cpu-common.c:279
    #6 0x558bf6980dfa in cpu_common_unrealizefn hw/core/cpu-common.c:267
    #7 0x558bf763ef65 in ppc_cpu_unrealize target/ppc/cpu_init.c:6965
    #8 0x558bf7872199 in device_set_realized hw/core/qdev.c:618
    #14 0x558bf756068f in spapr_unrealize_vcpu hw/ppc/spapr_cpu_core.c:209

Fix this by moving cpu_remove_sync() before pcc->parent_unrealize(dev)
in ppc_cpu_unrealize(), ensuring the vCPU thread is stopped, has
finished processing its events, and is joined before CPU resources
and accelerator state are destroyed.

Cc: qemu-stable@nongnu.org
Signed-off-by: Shivang Upadhyay <shivangu@linux.ibm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <mkchauras@gmail.com>
Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Message-ID: <20260923121444.154175-1-shivangu@linux.ibm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
---
 target/ppc/cpu_init.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/target/ppc/cpu_init.c b/target/ppc/cpu_init.c
index 6c626843c93..b711f9c0a85 100644
--- a/target/ppc/cpu_init.c
+++ b/target/ppc/cpu_init.c
@@ -6962,10 +6962,10 @@ static void ppc_cpu_unrealize(DeviceState *dev)
     PowerPCCPU *cpu = POWERPC_CPU(dev);
     PowerPCCPUClass *pcc = POWERPC_CPU_GET_CLASS(cpu);
 
-    pcc->parent_unrealize(dev);
-
     cpu_remove_sync(CPU(cpu));
 
+    pcc->parent_unrealize(dev);
+
     destroy_ppc_opcodes(cpu);
 }
 
-- 
2.53.0



  parent reply	other threads:[~2026-09-24 15:27 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 15:23 [PULL 00/18] Misc target/ patches for 2026-09-24 Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 01/18] target/mips: Fix zero in gen_mxu_d8sum Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 02/18] target/mips: Drop zero optimization in gen_mxu_s32mul Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 03/18] target/mips: Split out gen_mxu_logic Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 04/18] target/mips: Use gen_mxu_logic for gen_mxu_S32MAX_S32MIN Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 05/18] target/mips: Use gen_mxu_logic for gen_mxu_S32SLT Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 06/18] target/mips: Use gen_mxu_logic for gen_mxu_S32CPS Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 07/18] target/riscv: Stub out kvm functions Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 08/18] system: Document has_work() synchronization requirements Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 09/18] target/s390x: Use s390_cpu_get_state() consistently Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 10/18] target/s390x: Extend comment about PV cpu load state Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 11/18] target/s390x: Make s390_cpu_set_state() return void Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 12/18] target/s390x: Use S390CpuState for CPU state APIs Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 13/18] target/s390x: Access S390CpuState atomically Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 14/18] target/arm: Un-inline arm_set_cpu_power_state() Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 15/18] target/arm: Access PSCI state atomically Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 16/18] target/arm: Access halt " Philippe Mathieu-Daudé
2026-09-24 15:23 ` [PULL 17/18] target/i386: Use an acquire load for interrupt_request() Philippe Mathieu-Daudé
2026-09-24 15:23 ` Philippe Mathieu-Daudé [this message]
2026-09-25  2:35 ` [PULL 00/18] Misc target/ patches for 2026-09-24 Richard Henderson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924152353.36209-19-philmd@oss.qualcomm.com \
    --to=philmd@oss.qualcomm.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.