qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Subject: [Qemu-devel] [PULL 14/15] cpus: fix deadlock and segfault in qemu_mutex_lock_iothread
Date: Mon,  2 Mar 2015 11:08:53 +0100	[thread overview]
Message-ID: <1425290934-60872-15-git-send-email-pbonzini@redhat.com> (raw)
In-Reply-To: <1425290934-60872-1-git-send-email-pbonzini@redhat.com>

When two threads (other than the low-priority TCG VCPU thread)
are competing for the iothread lock, a deadlock can happen.  This
is because iothread_requesting_mutex is set to false by the first
thread that gets the mutex, and then the VCPU thread might never
yield from the execution loop.  If iothread_requesting_mutex is
changed from a bool to a counter, the deadlock is fixed.

However, there is another bug in qemu_mutex_lock_iothread that
can be triggered by the new call_rcu thread.  The bug happens
if qemu_mutex_lock_iothread is called before the CPUs are
created.  In that case, first_cpu is NULL and the caller
segfaults in qemu_mutex_lock_iothread.  To fix this, just
do not do the kick if first_cpu is NULL.

Reported-by: Leon Alrae <leon.alrae@imgtec.com>
Reported-by: Andreas Gustafsson <gson@gson.org>
Tested-by: Leon Alrae <leon.alrae@imgtec.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 cpus.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/cpus.c b/cpus.c
index 1cd9867..83c078e 100644
--- a/cpus.c
+++ b/cpus.c
@@ -778,7 +778,7 @@ static void qemu_tcg_init_cpu_signals(void)
 
 static QemuMutex qemu_global_mutex;
 static QemuCond qemu_io_proceeded_cond;
-static bool iothread_requesting_mutex;
+static unsigned iothread_requesting_mutex;
 
 static QemuThread io_thread;
 
@@ -1115,15 +1115,15 @@ bool qemu_in_vcpu_thread(void)
 
 void qemu_mutex_lock_iothread(void)
 {
-    if (!tcg_enabled()) {
+    if (!tcg_enabled() || !first_cpu) {
         qemu_mutex_lock(&qemu_global_mutex);
     } else {
-        iothread_requesting_mutex = true;
+        atomic_inc(&iothread_requesting_mutex);
         if (qemu_mutex_trylock(&qemu_global_mutex)) {
             qemu_cpu_kick_thread(first_cpu);
             qemu_mutex_lock(&qemu_global_mutex);
         }
-        iothread_requesting_mutex = false;
+        atomic_dec(&iothread_requesting_mutex);
         qemu_cond_broadcast(&qemu_io_proceeded_cond);
     }
 }
-- 
2.3.0

  parent reply	other threads:[~2015-03-02 10:09 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-03-02 10:08 [Qemu-devel] [PULL 00/15] Misc changes for 2015-03-02 Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 01/15] scsi: give device a parent before setting properties Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 02/15] block: Forbid bdrv_set_aio_context outside BQL Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 03/15] virtio-scsi-dataplane: Call blk_set_aio_context within BQL Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 04/15] timer: replace time() with QEMU_CLOCK_HOST Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 05/15] bootdevice: fix segment fault when booting guest with '-kernel' and '-initrd' Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 06/15] Add specific config options for PCI-E bridges Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 07/15] Create specific config option for "platform-bus" Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 08/15] Give ivshmem its own config option Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 09/15] iscsi: Handle write protected case in reopen Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 10/15] Makefile: fix up parallel building under MSYS+MinGW Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 11/15] Makefile: don't silence mak file test with V=1 Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 12/15] Makefile.target: binary depends on config-devices Paolo Bonzini
2015-03-02 10:08 ` [Qemu-devel] [PULL 13/15] virtio-scsi: Allocate op blocker reason before blocking Paolo Bonzini
2015-03-02 10:08 ` Paolo Bonzini [this message]
2015-03-02 10:08 ` [Qemu-devel] [PULL 15/15] cpus: be more paranoid in avoiding deadlocks Paolo Bonzini
2015-03-02 16:09 ` [Qemu-devel] [PULL 00/15] Misc changes for 2015-03-02 Eric Blake
2015-03-02 16:23   ` Paolo Bonzini
2015-03-02 17:15     ` Eric Blake
2015-03-03 13:09 ` Peter Maydell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1425290934-60872-15-git-send-email-pbonzini@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).