From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:54022) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TU7hg-0005nn-4r for qemu-devel@nongnu.org; Thu, 01 Nov 2012 23:13:54 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TU7he-0001vT-R3 for qemu-devel@nongnu.org; Thu, 01 Nov 2012 23:13:52 -0400 Received: from e23smtp03.au.ibm.com ([202.81.31.145]:50445) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TU7he-0001uX-4y for qemu-devel@nongnu.org; Thu, 01 Nov 2012 23:13:50 -0400 Received: from /spool/local by e23smtp03.au.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Fri, 2 Nov 2012 13:10:47 +1000 Received: from d23av04.au.ibm.com (d23av04.au.ibm.com [9.190.235.139]) by d23relay03.au.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id qA23DfOE62390354 for ; Fri, 2 Nov 2012 14:13:41 +1100 Received: from d23av04.au.ibm.com (loopback [127.0.0.1]) by d23av04.au.ibm.com (8.14.4/8.13.1/NCO v10.0 AVout) with ESMTP id qA23DfcD019735 for ; Fri, 2 Nov 2012 14:13:41 +1100 Date: Fri, 2 Nov 2012 14:15:08 +1100 From: David Gibson Message-ID: <20121102031508.GN27695@truffula.fritz.box> References: <1351654988-13165-1-git-send-email-david@gibson.dropbear.id.au> <509106A0.7020400@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <509106A0.7020400@redhat.com> Subject: Re: [Qemu-devel] [PATCH] Fix off-by-1 error in RAM migration code List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Orit Wasserman Cc: aliguori@us.ibm.com, qemu-devel@nongnu.org, quintela@redhat.com On Wed, Oct 31, 2012 at 01:08:16PM +0200, Orit Wasserman wrote: > On 10/31/2012 05:43 AM, David Gibson wrote: > > The code for migrating (or savevm-ing) memory pages starts off by creating > > a dirty bitmap and filling it with 1s. Except, actually, because bit > > addresses are 0-based it fills every bit except bit 0 with 1s and puts an > > extra 1 beyond the end of the bitmap, potentially corrupting unrelated > > memory. Oops. This patch fixes it. > > > > Signed-off-by: David Gibson > > --- > > arch_init.c | 2 +- > > 1 file changed, 1 insertion(+), 1 deletion(-) > > > > diff --git a/arch_init.c b/arch_init.c > > index e6effe8..b75a4c5 100644 > > --- a/arch_init.c > > +++ b/arch_init.c > > @@ -568,7 +568,7 @@ static int ram_save_setup(QEMUFile *f, void *opaque) > > int64_t ram_pages = last_ram_offset() >> TARGET_PAGE_BITS; > > > > migration_bitmap = bitmap_new(ram_pages); > > - bitmap_set(migration_bitmap, 1, ram_pages); > > + bitmap_set(migration_bitmap, 0, ram_pages); > > migration_dirty_pages = ram_pages; > > > > bytes_transferred = 0; > > > You are correct, good catch. > Reviewed-by: Orit Wasserman Juan, Sorry, forgot to CC you on the original mailing here, which I should have done. This is a serious bug in the migration code and we should apply to mainline ASAP. -- David Gibson | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_ | _way_ _around_! http://www.ozlabs.org/~dgibson