From: Markus Armbruster <armbru@redhat.com>
To: "Philippe Mathieu-Daudé" <philmd@linaro.org>
Cc: qemu-devel@nongnu.org, richard.henderson@linaro.org,
Pierrick Bouvier <pierrick.bouvier@linaro.org>,
odaki@rsg.ci.i.u-tokyo.ac.jp, marcandre.lureau@redhat.com,
berrange@redhat.com, vsementsov@yandex-team.ru
Subject: Re: [PATCH v3 02/13] tcg: Fix error reporting on mprotect() failure in tcg_region_init()
Date: Tue, 23 Sep 2025 13:16:18 +0200 [thread overview]
Message-ID: <87h5wta071.fsf@pond.sub.org> (raw)
In-Reply-To: <6ebc31f0-c6cf-4e14-a87d-5b59f6c6105f@linaro.org> ("Philippe Mathieu-Daudé"'s message of "Tue, 23 Sep 2025 11:41:03 +0200")
Philippe Mathieu-Daudé <philmd@linaro.org> writes:
> On 23/9/25 11:09, Markus Armbruster wrote:
>> tcg_region_init() calls one of qemu_mprotect_rwx(),
>> qemu_mprotect_rw(), and mprotect(), then reports failure with
>> error_setg_errno(&error_fatal, errno, ...).
>>
>> The use of &error_fatal is undesirable. qapi/error.h advises:
>>
>> * Please don't error_setg(&error_fatal, ...), use error_report() and
>> * exit(), because that's more obvious.
>>
>> The use of errno is wrong. qemu_mprotect_rwx() and qemu_mprotect_rw()
>> wrap around qemu_mprotect__osdep(). qemu_mprotect__osdep() calls
>> mprotect() on POSIX, VirtualProtect() on Windows, and reports failure
>> with error_report(). VirtualProtect() doesn't set errno. mprotect()
>> does, but error_report() may clobber it.
>>
>> Fix tcg_region_init() to report errors only when it calls mprotect(),
>> and rely on qemu_mprotect_rwx()'s and qemu_mprotect_rw()'s error
>> reporting otherwise. Use error_report(), not error_setg().
>>
>> Fixes: 22c6a9938f75 (tcg: Merge buffer protection and guard page protection)
>> Fixes: 6bc144237a85 (tcg: Use Error with alloc_code_gen_buffer)
>> Cc: Richard Henderson <richard.henderson@linaro.org>
>> Signed-off-by: Markus Armbruster <armbru@redhat.com>
>> Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
>> Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
>> ---
>> tcg/region.c | 7 +++++--
>> 1 file changed, 5 insertions(+), 2 deletions(-)
>> diff --git a/tcg/region.c b/tcg/region.c
>> index 7ea0b37a84..2181267e48 100644
>> --- a/tcg/region.c
>> +++ b/tcg/region.c
>> @@ -832,13 +832,16 @@ void tcg_region_init(size_t tb_size, int splitwx, unsigned max_threads)
>> } else {
>> #ifdef CONFIG_POSIX
>> rc = mprotect(start, end - start, need_prot);
>> + if (rc) {
>> + error_report("mprotect of jit buffer: %s",
>> + strerror(errno));
>
> I'm not keen on handling errors differently in the same function.
>
> qemu_mprotect_rwx() and qemu_mprotect_rw() already print the error.
Yes: they call qemu_mprotect__osdep(), which uses error_report().
> Why not add qemu_mprotect() as a simple qemu_mprotect__osdep() alias,
> then call it here, also covering the non-POSIX case?
> (Question for Richard, after looking at commits 22c6a9938f7 and more
> importantly 97a83753c9 -- wondering about WoA).
There is no commit 97a83753c9. Do you mean a97a83753c9?
I'd like to merge this commit as is. It's a minimal fix, and it's been
reviewed. We can always improve on top.
>> + }
>> #else
>> g_assert_not_reached();
>> #endif
>> }
>> if (rc) {
>> - error_setg_errno(&error_fatal, errno,
>> - "mprotect of jit buffer");
>> + exit(1);
>> }
>> }
>> if (have_prot != 0) {
next prev parent reply other threads:[~2025-09-23 11:18 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-09-23 9:09 [PATCH v3 00/13] Error reporting cleanup, a fix, and &error_warn removal Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 01/13] monitor: Clean up HMP gdbserver error reporting Markus Armbruster
2025-09-23 9:54 ` Philippe Mathieu-Daudé
2025-09-23 11:08 ` Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 02/13] tcg: Fix error reporting on mprotect() failure in tcg_region_init() Markus Armbruster
2025-09-23 9:41 ` Philippe Mathieu-Daudé
2025-09-23 11:16 ` Markus Armbruster [this message]
2025-09-23 12:40 ` Philippe Mathieu-Daudé
2025-09-23 9:09 ` [PATCH v3 03/13] hw/cxl: Convert cxl_fmws_link() to Error Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 04/13] migration/cpr: Clean up error reporting in cpr_resave_fd() Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 05/13] hw/remote/vfio-user: Clean up error reporting Markus Armbruster
2025-09-23 9:25 ` Philippe Mathieu-Daudé
2025-09-23 10:14 ` Vladimir Sementsov-Ogievskiy
2025-09-26 6:51 ` Markus Armbruster
2025-09-30 8:02 ` Vladimir Sementsov-Ogievskiy
2025-09-30 8:21 ` Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 06/13] net/slirp: " Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 07/13] ui/spice-core: " Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 08/13] util/oslib-win32: Do not treat null @errp as &error_warn Markus Armbruster
2025-09-23 9:19 ` Philippe Mathieu-Daudé
2025-09-23 9:09 ` [PATCH v3 09/13] ui/pixman: Consistent error handling in qemu_pixman_shareable_free() Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 10/13] ui/dbus: Clean up dbus_update_gl_cb() error checking Markus Armbruster
2025-09-23 9:21 ` Philippe Mathieu-Daudé
2025-09-23 9:09 ` [PATCH v3 11/13] ui/dbus: Consistent handling of texture mutex failure Markus Armbruster
2025-09-23 9:09 ` [PATCH v3 12/13] ivshmem-flat: Mark an instance of missing error handling FIXME Markus Armbruster
2025-09-23 10:22 ` Vladimir Sementsov-Ogievskiy
2025-09-23 9:10 ` [PATCH v3 13/13] error: Kill @error_warn Markus Armbruster
2025-09-24 1:29 ` [PATCH v3 00/13] Error reporting cleanup, a fix, and &error_warn removal Akihiko Odaki
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87h5wta071.fsf@pond.sub.org \
--to=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=marcandre.lureau@redhat.com \
--cc=odaki@rsg.ci.i.u-tokyo.ac.jp \
--cc=philmd@linaro.org \
--cc=pierrick.bouvier@linaro.org \
--cc=qemu-devel@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=vsementsov@yandex-team.ru \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.