From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from [140.186.70.92] (port=58546 helo=eggs.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1PDemU-0003wD-8k for qemu-devel@nongnu.org; Wed, 03 Nov 2010 10:57:43 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1PDemS-0001rZ-Sk for qemu-devel@nongnu.org; Wed, 03 Nov 2010 10:57:41 -0400 Received: from mail-qy0-f180.google.com ([209.85.216.180]:52120) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1PDemS-0001rL-QV for qemu-devel@nongnu.org; Wed, 03 Nov 2010 10:57:40 -0400 Received: by qyk34 with SMTP id 34so19246qyk.4 for ; Wed, 03 Nov 2010 07:57:39 -0700 (PDT) Message-ID: <4CD17861.2060806@codemonkey.ws> Date: Wed, 03 Nov 2010 09:57:37 -0500 From: Anthony Liguori MIME-Version: 1.0 Subject: Re: [Qemu-devel] [PATCH] Delete IOHandlers after potentially running them References: <1288794584-6099-1-git-send-email-stefanha@linux.vnet.ibm.com> In-Reply-To: <1288794584-6099-1-git-send-email-stefanha@linux.vnet.ibm.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Stefan Hajnoczi Cc: qemu-devel@nongnu.org, Juan Quintela On 11/03/2010 09:29 AM, Stefan Hajnoczi wrote: > Since commit 4bed9837309e58d208183f81d8344996744292cf an .fd_read() > handler that deletes its IOHandler is exposed to .fd_write() being > called on the deleted IOHandler. > > This patch fixes deletion so that .fd_read() and .fd_write() are never > called on an IOHandler that is marked for deletion. > > Signed-off-by: Stefan Hajnoczi > --- > vl.c | 15 ++++++++------- > 1 files changed, 8 insertions(+), 7 deletions(-) > > diff --git a/vl.c b/vl.c > index 7038952..6f56123 100644 > --- a/vl.c > +++ b/vl.c > @@ -1252,17 +1252,18 @@ void main_loop_wait(int nonblocking) > IOHandlerRecord *pioh; > > QLIST_FOREACH_SAFE(ioh,&io_handlers, next, pioh) { > - if (ioh->deleted) { > - QLIST_REMOVE(ioh, next); > - qemu_free(ioh); > - continue; > - } > - if (ioh->fd_read&& FD_ISSET(ioh->fd,&rfds)) { > + if (!ioh->deleted&& ioh->fd_read&& FD_ISSET(ioh->fd,&rfds)) { > ioh->fd_read(ioh->opaque); > } > - if (ioh->fd_write&& FD_ISSET(ioh->fd,&wfds)) { > + if (!ioh->deleted&& ioh->fd_write&& FD_ISSET(ioh->fd,&wfds)) { > ioh->fd_write(ioh->opaque); > } > + > + /* Do this last in case read/write handlers marked it for deletion */ > + if (ioh->deleted) { > + QLIST_REMOVE(ioh, next); > + qemu_free(ioh); > + } > } > This isn't enough. If you end up with a handler deleting the next pointer and the current pointer, you'll end up running off the end of the list. The original commit should be reverted. Regards, Anthony Liguori > } > >