From: "Marc-André Lureau" <marcandre.lureau@redhat.com>
To: qemu-devel@nongnu.org
Cc: "Michael S. Tsirkin" <mst@redhat.com>,
"Alex Bennée" <alex.bennee@linaro.org>,
"Akihiko Odaki" <odaki@rsg.ci.i.u-tokyo.ac.jp>,
"Dmitry Osipenko" <dmitry.osipenko@collabora.com>,
"Stefan Hajnoczi" <stefanha@redhat.com>,
"Kevin Wolf" <kwolf@redhat.com>,
"Hanna Reitz" <hreitz@redhat.com>,
qemu-block@nongnu.org, "Jonathan Cameron" <jic23@kernel.org>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Fam Zheng" <fam@euphon.net>,
"Daniel P. Berrangé" <berrange@redhat.com>,
"Zhao Liu" <zhao1.liu@intel.com>,
"Roman Bolshakov" <rbolshakov@ddn.com>,
"Phil Dennis-Jordan" <phil@philjordan.eu>,
"Wei Liu" <wei.liu@kernel.org>,
linux-cxl@vger.kernel.org,
"Brian Cain" <brian.cain@oss.qualcomm.com>,
"Pierrick Bouvier" <pierrick.bouvier@oss.qualcomm.com>,
"Philippe Mathieu-Daudé" <philmd@mailo.com>,
"Peter Xu" <peterx@redhat.com>, "Fabiano Rosas" <farosas@suse.de>,
"Marc-André Lureau" <marcandre.lureau@redhat.com>
Subject: [PATCH v2 12/12] qdev-monitor: drain RCU callbacks in qdev_device_add_from_qdict
Date: Mon, 27 Jul 2026 00:44:11 +0400 [thread overview]
Message-ID: <20260727-fix2-v2-12-d0c4831ed7ea@redhat.com> (raw)
In-Reply-To: <20260727-fix2-v2-0-d0c4831ed7ea@redhat.com>
qmp_device_add() and hmp_device_add() drain pending RCU callbacks after
a failed device_add, since some bus teardown (e.g. bus_remove_child())
is deferred to call_rcu(). -device on the command line reaches the same
qdev_device_add_from_qdict() with errp pointing at error_fatal, whose
ERRP_GUARD() exits before control returns to the caller, so the caller's
drain_call_rcu() never runs.
Move the drain into qdev_device_add_from_qdict()'s own err_del_dev path
and drop the now-redundant calls in qmp_device_add() and
hmp_device_add(). Gate it behind a new drain_rcu parameter, because
virtio-net failover can reach qdev_device_add_from_qdict() from an MMIO
write dispatched under address_space_write()'s RCU read lock.
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
---
include/monitor/qdev.h | 3 ++-
hw/audio/intel-hda.c | 2 +-
hw/net/virtio-net.c | 2 +-
system/qdev-monitor.c | 42 ++++++++++++++++--------------------------
4 files changed, 20 insertions(+), 29 deletions(-)
diff --git a/include/monitor/qdev.h b/include/monitor/qdev.h
index f85f25738d58..72d2fa4654d3 100644
--- a/include/monitor/qdev.h
+++ b/include/monitor/qdev.h
@@ -12,7 +12,8 @@ void qmp_device_add(QDict *qdict, QObject **ret_data, Error **errp);
int qdev_device_help(QemuOpts *opts);
DeviceState *qdev_device_add(QemuOpts *opts, Error **errp);
DeviceState *qdev_device_add_from_qdict(const QDict *opts,
- bool from_json, Error **errp);
+ bool from_json, bool drain_rcu,
+ Error **errp);
BusState *qdev_find_default_bus(DeviceClass *dc, Error **errp);
/**
diff --git a/hw/audio/intel-hda.c b/hw/audio/intel-hda.c
index 3d361a4976c6..128c5ee612ce 100644
--- a/hw/audio/intel-hda.c
+++ b/hw/audio/intel-hda.c
@@ -1313,7 +1313,7 @@ static void intel_hda_and_codec_init(const char *audiodev)
BusState *hdabus;
qdict_put_str(props, "driver", "intel-hda");
- intel_hda = qdev_device_add_from_qdict(props, false, &error_fatal);
+ intel_hda = qdev_device_add_from_qdict(props, false, true, &error_fatal);
hdabus = QLIST_FIRST(&intel_hda->child_bus);
codec = qdev_new("hda-duplex");
diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c
index f0e3beb29032..0c5da8cb71af 100644
--- a/hw/net/virtio-net.c
+++ b/hw/net/virtio-net.c
@@ -916,7 +916,7 @@ static void failover_add_primary(VirtIONet *n, Error **errp)
dev = qdev_device_add_from_qdict(n->primary_opts,
n->primary_opts_from_json,
- &err);
+ false, &err);
if (err) {
qobject_unref(n->primary_opts);
n->primary_opts = NULL;
diff --git a/system/qdev-monitor.c b/system/qdev-monitor.c
index 00fed791cce1..77508bb1c3f1 100644
--- a/system/qdev-monitor.c
+++ b/system/qdev-monitor.c
@@ -650,7 +650,8 @@ BusState *qdev_find_default_bus(DeviceClass *dc, Error **errp)
}
DeviceState *qdev_device_add_from_qdict(const QDict *opts,
- bool from_json, Error **errp)
+ bool from_json, bool drain_rcu,
+ Error **errp)
{
ERRP_GUARD();
DeviceClass *dc;
@@ -746,6 +747,18 @@ err_del_dev:
object_unparent(OBJECT(dev));
object_unref(OBJECT(dev));
+ /*
+ * Some bus teardown (e.g. bus_remove_child()) is deferred via
+ * call_rcu(). When safe, drain those callbacks so the failed
+ * device is fully torn down before we return. Callers that are
+ * already inside an RCU read-side critical section (e.g. MMIO
+ * dispatch during virtio-net failover) must pass drain_rcu=false
+ * to avoid deadlocking on the grace period.
+ */
+ if (drain_rcu) {
+ drain_call_rcu();
+ }
+
return NULL;
}
@@ -755,7 +768,7 @@ DeviceState *qdev_device_add(QemuOpts *opts, Error **errp)
QDict *qdict = qemu_opts_to_qdict(opts, NULL);
DeviceState *ret;
- ret = qdev_device_add_from_qdict(qdict, false, errp);
+ ret = qdev_device_add_from_qdict(qdict, false, true, errp);
if (ret) {
qemu_opts_del(opts);
}
@@ -869,19 +882,7 @@ void qmp_device_add(QDict *qdict, QObject **ret_data, Error **errp)
{
DeviceState *dev;
- dev = qdev_device_add_from_qdict(qdict, true, errp);
- if (!dev) {
- /*
- * Drain all pending RCU callbacks. This is done because
- * some bus related operations can delay a device removal
- * (in this case this can happen if device is added and then
- * removed due to a configuration error)
- * to a RCU callback, but user might expect that this interface
- * will finish its job completely once qmp command returns result
- * to the user
- */
- drain_call_rcu();
- }
+ dev = qdev_device_add_from_qdict(qdict, true, true, errp);
object_unref(OBJECT(dev));
}
@@ -1017,17 +1018,6 @@ void hmp_device_add(Monitor *mon, const QDict *qdict)
}
dev = qdev_device_add(opts, &err);
if (!dev) {
- /*
- * Drain all pending RCU callbacks. This is done because
- * some bus related operations can delay a device removal
- * (in this case this can happen if device is added and then
- * removed due to a configuration error)
- * to a RCU callback, but user might expect that this interface
- * will finish its job completely once qmp command returns result
- * to the user
- */
- drain_call_rcu();
-
qemu_opts_del(opts);
}
object_unref(dev);
--
2.55.0
next prev parent reply other threads:[~2026-07-26 20:45 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-26 20:43 [PATCH v2 00/12] Fixes for 11.1 Marc-André Lureau
2026-07-26 20:44 ` [PATCH v2 01/12] hw/display/virtio-gpu-rutabaga: zero-init capset info response Marc-André Lureau
2026-07-26 20:44 ` [PATCH v2 02/12] block/blkio: fix error return value on getlength() Marc-André Lureau
2026-07-26 20:44 ` [PATCH v2 03/12] block/blkio: fix compiler false-positive warning Marc-André Lureau
2026-07-27 7:34 ` Philippe Mathieu-Daudé
2026-07-26 20:44 ` [PATCH v2 04/12] include/qemu: adjust LOCK_GUARD macros to avoid potential warning Marc-André Lureau
2026-07-26 20:44 ` [PATCH v2 05/12] hw/cxl: fix invalid free on early return Marc-André Lureau
2026-07-26 20:49 ` Michael S. Tsirkin
2026-07-26 21:09 ` Marc-André Lureau
2026-07-27 4:40 ` Akihiko Odaki
2026-07-27 7:35 ` Philippe Mathieu-Daudé
2026-07-27 8:30 ` Michael S. Tsirkin
2026-07-26 20:44 ` [PATCH v2 06/12] hw/i3c: fix default return value of d2_i3c_send() Marc-André Lureau
2026-07-27 7:40 ` Philippe Mathieu-Daudé
2026-07-26 20:44 ` [PATCH v2 07/12] Fix some -Werror=maybe-uninitialized Marc-André Lureau
2026-07-26 20:52 ` Michael S. Tsirkin
2026-07-26 21:07 ` Marc-André Lureau
2026-07-27 5:25 ` Akihiko Odaki
2026-07-27 8:56 ` Daniel P. Berrangé
2026-07-27 8:49 ` Michael S. Tsirkin
2026-07-26 20:44 ` [PATCH v2 08/12] hw/hexagon: fix machine->fdt leak in qom-test Marc-André Lureau
2026-07-27 7:21 ` Philippe Mathieu-Daudé
2026-07-26 20:44 ` [PATCH v2 09/12] hw/ppc: fix dangling fdt reference Marc-André Lureau
2026-07-26 20:44 ` [PATCH v2 10/12] hw/core/machine: free machine->fdt in machine_finalize() Marc-André Lureau
2026-07-26 20:44 ` [PATCH v2 11/12] migration/multifd: fix Error leak in multifd_recv_terminate_threads() Marc-André Lureau
2026-07-26 20:44 ` Marc-André Lureau [this message]
2026-07-26 20:49 ` [PATCH v2 00/12] Fixes for 11.1 Michael S. Tsirkin
2026-07-26 21:08 ` Marc-André Lureau
2026-07-27 8:51 ` Michael S. Tsirkin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260727-fix2-v2-12-d0c4831ed7ea@redhat.com \
--to=marcandre.lureau@redhat.com \
--cc=alex.bennee@linaro.org \
--cc=berrange@redhat.com \
--cc=brian.cain@oss.qualcomm.com \
--cc=dmitry.osipenko@collabora.com \
--cc=fam@euphon.net \
--cc=farosas@suse.de \
--cc=hreitz@redhat.com \
--cc=jic23@kernel.org \
--cc=kwolf@redhat.com \
--cc=linux-cxl@vger.kernel.org \
--cc=mst@redhat.com \
--cc=odaki@rsg.ci.i.u-tokyo.ac.jp \
--cc=pbonzini@redhat.com \
--cc=peterx@redhat.com \
--cc=phil@philjordan.eu \
--cc=philmd@mailo.com \
--cc=pierrick.bouvier@oss.qualcomm.com \
--cc=qemu-block@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=rbolshakov@ddn.com \
--cc=stefanha@redhat.com \
--cc=wei.liu@kernel.org \
--cc=zhao1.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox