From: Eric Blake <eblake@redhat.com>
To: Luiz Capitulino <lcapitulino@redhat.com>
Cc: qemu-devel <qemu-devel@nongnu.org>, mdroth@linux.vnet.ibm.com
Subject: Re: [Qemu-devel] [PATCH] qemu-ga: guest-shutdown: use only async-signal-safe functions
Date: Mon, 14 May 2012 11:51:13 -0600 [thread overview]
Message-ID: <4FB14611.7090808@redhat.com> (raw)
In-Reply-To: <20120514144058.2ffac223@doriath.home>
[-- Attachment #1: Type: text/plain, Size: 2630 bytes --]
On 05/14/2012 11:40 AM, Luiz Capitulino wrote:
> POSIX mandates[1] that a child process of a multi-thread program uses
> only async-signal-safe functions before exec(). We consider qemu-ga
> to be multi-thread, because it uses glib.
>
> However, qmp_guest_shutdown() uses functions that are not
> async-signal-safe. Fix it the following way:
>
> - fclose() -> reopen_fd_to_null()
> - execl() -> execle()
> - exit() -> _exit()
> - drop slog() usage (which is not safe)
>
> [1] http://pubs.opengroup.org/onlinepubs/009695399/functions/fork.html
>
> # @guest-shutdown:
> #
> # Initiate guest-activated shutdown. Note: this is an asynchronous
> -# shutdown request, with no guaruntee of successful shutdown. Errors
> -# will be logged to guest's syslog.
> +# shutdown request, with no guaruntee of successful shutdown.
As long as you are changing docs, fix the typo:
s/guaruntee/guarantee/
> +++ b/qga/commands-posix.c
> @@ -57,16 +57,13 @@ void qmp_guest_shutdown(bool has_mode, const char *mode, Error **err)
> if (pid == 0) {
> /* child, start the shutdown */
> setsid();
> - fclose(stdin);
> - fclose(stdout);
> - fclose(stderr);
> -
> - ret = execl("/sbin/shutdown", "shutdown", shutdown_flag, "+0",
> - "hypervisor initiated shutdown", (char*)NULL);
> - if (ret) {
> - slog("guest-shutdown failed: %s", strerror(errno));
> - }
> - exit(!!ret);
> + reopen_fd_to_null(0);
> + reopen_fd_to_null(1);
> + reopen_fd_to_null(2);
I prefer the POSIX-mandated macros STDIN_FILENO, STDOUT_FILENO, and
STDERR_FILENO, but don't know if qemu intends to rely on them (according
to gnulib, at least older mingw lacked those macro names from
<unistd.h>). So I won't make you change this.
> +
> + ret = execle("/sbin/shutdown", "shutdown", shutdown_flag, "+0",
> + "hypervisor initiated shutdown", (char*)NULL, environ);
Where was 'environ' declared? POSIX says that environ must exist, but
that it is the one variable where you must declare it yourself rather
than getting it from a public header. (For convenience, glibc declares
environ in <unistd.h> when using _GNU_SOURCE, but when you are asking
for strict standards namespace compliance, it disappears.)
> + _exit(!!ret);
Why are we even bothering with ret? If execle() returns, we _know_ we
had a failure, and !!ret will always be 1.
--
Eric Blake eblake@redhat.com +1-919-301-3266
Libvirt virtualization library http://libvirt.org
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 620 bytes --]
next prev parent reply other threads:[~2012-05-14 17:51 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-05-14 17:40 [Qemu-devel] [PATCH] qemu-ga: guest-shutdown: use only async-signal-safe functions Luiz Capitulino
2012-05-14 17:51 ` Eric Blake [this message]
2012-05-14 18:01 ` Luiz Capitulino
2012-05-14 18:03 ` Luiz Capitulino
2012-05-14 18:41 ` Eric Blake
2012-05-14 19:59 ` Luiz Capitulino
2012-05-14 20:01 ` Eric Blake
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4FB14611.7090808@redhat.com \
--to=eblake@redhat.com \
--cc=lcapitulino@redhat.com \
--cc=mdroth@linux.vnet.ibm.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.