From: "Dr. David Alan Gilbert" <dgilbert@redhat.com>
To: Peter Xu <peterx@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>,
Lukas Straub <lukasstraub2@web.de>,
"Daniel P . Berrange" <berrange@redhat.com>,
Juan Quintela <quintela@redhat.com>,
qemu-devel@nongnu.org,
Leonardo Bras Soares Passos <lsoaresp@redhat.com>
Subject: Re: [PATCH v2 2/5] migration: Make from_dst_file accesses thread-safe
Date: Thu, 22 Jul 2021 16:19:28 +0100 [thread overview]
Message-ID: <YPmMgEqXDxKxNCNo@work-vm> (raw)
In-Reply-To: <20210721193409.910462-3-peterx@redhat.com>
* Peter Xu (peterx@redhat.com) wrote:
> Accessing from_dst_file is potentially racy in current code base like below:
>
> if (s->from_dst_file)
> do_something(s->from_dst_file);
>
> Because from_dst_file can be reset right after the check in another
> thread (rp_thread). One example is migrate_fd_cancel().
>
> Use the same qemu_file_lock to protect it too, just like to_dst_file.
>
> When it's safe to access without lock, comment it.
>
> There's one special reference in migration_thread() that can be replaced by
> the newly introduced rp_thread_created flag.
>
> Reported-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
> Signed-off-by: Peter Xu <peterx@redhat.com>
Yep, with Eric's comments
Reviewed-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
> ---
> migration/migration.c | 32 +++++++++++++++++++++++++-------
> migration/migration.h | 8 +++++---
> migration/ram.c | 1 +
> 3 files changed, 31 insertions(+), 10 deletions(-)
>
> diff --git a/migration/migration.c b/migration/migration.c
> index 21b94f75a3..fa70400f98 100644
> --- a/migration/migration.c
> +++ b/migration/migration.c
> @@ -1879,10 +1879,12 @@ static void migrate_fd_cancel(MigrationState *s)
> QEMUFile *f = migrate_get_current()->to_dst_file;
> trace_migrate_fd_cancel();
>
> + qemu_mutex_lock(&s->qemu_file_lock);
> if (s->rp_state.from_dst_file) {
> /* shutdown the rp socket, so causing the rp thread to shutdown */
> qemu_file_shutdown(s->rp_state.from_dst_file);
> }
> + qemu_mutex_unlock(&s->qemu_file_lock);
>
> do {
> old_state = s->state;
> @@ -2686,6 +2688,22 @@ static int migrate_handle_rp_resume_ack(MigrationState *s, uint32_t value)
> return 0;
> }
>
> +/* Release ms->rp_state.from_dst_file in a safe way */
> +static void migration_release_from_dst_file(MigrationState *ms)
> +{
> + QEMUFile *file = ms->rp_state.from_dst_file;
> +
> + qemu_mutex_lock(&ms->qemu_file_lock);
> + /*
> + * Reset the from_dst_file pointer first before releasing it, as we can't
> + * block within lock section
> + */
> + ms->rp_state.from_dst_file = NULL;
> + qemu_mutex_unlock(&ms->qemu_file_lock);
> +
> + qemu_fclose(file);
> +}
> +
> /*
> * Handles messages sent on the return path towards the source VM
> *
> @@ -2827,11 +2845,13 @@ out:
> * Maybe there is something we can do: it looks like a
> * network down issue, and we pause for a recovery.
> */
> - qemu_fclose(rp);
> - ms->rp_state.from_dst_file = NULL;
> + migration_release_from_dst_file(ms);
> rp = NULL;
> if (postcopy_pause_return_path_thread(ms)) {
> - /* Reload rp, reset the rest */
> + /*
> + * Reload rp, reset the rest. Referencing it is save since
> + * it's reset only by us above, or when migration completes
> + */
> rp = ms->rp_state.from_dst_file;
> ms->rp_state.error = false;
> goto retry;
> @@ -2843,8 +2863,7 @@ out:
> }
>
> trace_source_return_path_thread_end();
> - ms->rp_state.from_dst_file = NULL;
> - qemu_fclose(rp);
> + migration_release_from_dst_file(ms);
> rcu_unregister_thread();
> return NULL;
> }
> @@ -2852,7 +2871,6 @@ out:
> static int open_return_path_on_source(MigrationState *ms,
> bool create_thread)
> {
> -
> ms->rp_state.from_dst_file = qemu_file_get_return_path(ms->to_dst_file);
> if (!ms->rp_state.from_dst_file) {
> return -1;
> @@ -3746,7 +3764,7 @@ static void *migration_thread(void *opaque)
> * If we opened the return path, we need to make sure dst has it
> * opened as well.
> */
> - if (s->rp_state.from_dst_file) {
> + if (s->rp_state.rp_thread_created) {
> /* Now tell the dest that it should open its end so it can reply */
> qemu_savevm_send_open_return_path(s->to_dst_file);
>
> diff --git a/migration/migration.h b/migration/migration.h
> index c302879fad..7a5aa8c2fd 100644
> --- a/migration/migration.h
> +++ b/migration/migration.h
> @@ -154,12 +154,13 @@ struct MigrationState {
> QemuThread thread;
> QEMUBH *vm_start_bh;
> QEMUBH *cleanup_bh;
> + /* Protected by qemu_file_lock */
> QEMUFile *to_dst_file;
> QIOChannelBuffer *bioc;
> /*
> - * Protects to_dst_file pointer. We need to make sure we won't
> - * yield or hang during the critical section, since this lock will
> - * be used in OOB command handler.
> + * Protects to_dst_file/from_dst_file pointers. We need to make sure we
> + * won't yield or hang during the critical section, since this lock will be
> + * used in OOB command handler.
> */
> QemuMutex qemu_file_lock;
>
> @@ -192,6 +193,7 @@ struct MigrationState {
>
> /* State related to return path */
> struct {
> + /* Protected by qemu_file_lock */
> QEMUFile *from_dst_file;
> QemuThread rp_thread;
> bool error;
> diff --git a/migration/ram.c b/migration/ram.c
> index b5fc454b2f..f728f5072f 100644
> --- a/migration/ram.c
> +++ b/migration/ram.c
> @@ -4012,6 +4012,7 @@ static void ram_dirty_bitmap_reload_notify(MigrationState *s)
> int ram_dirty_bitmap_reload(MigrationState *s, RAMBlock *block)
> {
> int ret = -EINVAL;
> + /* from_dst_file is always valid because we're within rp_thread */
> QEMUFile *file = s->rp_state.from_dst_file;
> unsigned long *le_bitmap, nbits = block->used_length >> TARGET_PAGE_BITS;
> uint64_t local_size = DIV_ROUND_UP(nbits, 8);
> --
> 2.31.1
>
--
Dr. David Alan Gilbert / dgilbert@redhat.com / Manchester, UK
next prev parent reply other threads:[~2021-07-22 15:20 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-07-21 19:34 [PATCH v2 0/5] migrations: Fix potential rare race of migration-test after yank Peter Xu
2021-07-21 19:34 ` [PATCH v2 1/5] migration: Fix missing join() of rp_thread Peter Xu
2021-07-21 19:34 ` [PATCH v2 2/5] migration: Make from_dst_file accesses thread-safe Peter Xu
2021-07-21 21:15 ` Eric Blake
2021-07-22 14:44 ` Peter Xu
2021-07-22 15:19 ` Dr. David Alan Gilbert [this message]
2021-07-21 19:34 ` [PATCH v2 3/5] migration: Introduce migration_ioc_[un]register_yank() Peter Xu
2021-07-21 19:34 ` [PATCH v2 4/5] migration: Teach QEMUFile to be QIOChannel-aware Peter Xu
2021-07-22 15:21 ` Dr. David Alan Gilbert
2021-07-21 19:34 ` [PATCH v2 5/5] migration: Move the yank unregister of channel_close out Peter Xu
2021-07-22 15:27 ` Dr. David Alan Gilbert
2021-07-22 16:19 ` Peter Xu
2021-07-22 17:09 ` Dr. David Alan Gilbert
2021-07-22 17:35 ` Peter Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=YPmMgEqXDxKxNCNo@work-vm \
--to=dgilbert@redhat.com \
--cc=berrange@redhat.com \
--cc=lsoaresp@redhat.com \
--cc=lukasstraub2@web.de \
--cc=peter.maydell@linaro.org \
--cc=peterx@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=quintela@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.