From: Eduardo Habkost <ehabkost@redhat.com>
To: Igor Mammedov <imammedo@redhat.com>
Cc: qemu-devel@nongnu.org, ldoktor@redhat.com, mreitz@redhat.com,
pbonzini@redhat.com, Eric Blake <eblake@redhat.com>,
"Daniel P. Berrange" <berrange@redhat.com>,
Markus Armbruster <armbru@redhat.com>
Subject: Re: [Qemu-devel] [PATCH v6 2/2] vl: fix use of --daemonize with --preconfig
Date: Mon, 11 Jun 2018 16:06:07 -0300 [thread overview]
Message-ID: <20180611190607.GU7451@localhost.localdomain> (raw)
In-Reply-To: <20180611151625.4b2420b8@redhat.com>
On Mon, Jun 11, 2018 at 03:16:25PM +0200, Igor Mammedov wrote:
> On Fri, 8 Jun 2018 10:21:05 -0300
> Eduardo Habkost <ehabkost@redhat.com> wrote:
>
> > On Thu, Jun 07, 2018 at 02:00:09PM +0200, Igor Mammedov wrote:
> > > When using --daemonize, the initial lead process will fork a child and
> > > then wait to be notified that setup is complete via a pipe, before it
> > > exits. When using --preconfig there is an extra call to main_loop()
> > > before the notification is done from os_setup_post(). Thus the parent
> > > process won't exit until the mgmt application connects to the monitor
> > > and tells QEMU to leave the RUN_STATE_PRECONFIG. The mgmt application
> > > won't connect to the monitor until daemonizing has completed though.
> > >
> > > This is a chicken and egg problem, leading to deadlock at startup.
> > >
> > > The only viable way to fix this is to call os_setup_post() before
> > > the early main_loop() call when --preconfig is used. This has the
> > > downside that any errors from this point onwards won't be handled
> > > well by the mgmt application, because it will think QEMU has started
> > > successfully, so not be expecting an abrupt exit. Moving as much user
> > > input validation as possible to before the main_loop() call might help,
> > > but mgmt application should stop assuming that QEMU has started
> > > successfuly and use other means to collect errors from QEMU (logfile).
> > >
> > > Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
> > > Signed-off-by: Igor Mammedov <imammedo@redhat.com>
> > > ---
> > > v5:
> > > * use original Daniel's patch [1], but addapt it to apply on top of
> > > "[PATCH v3 1/2] cli: Don't run early event loop if no --preconfig was specified"
> > > with extra comment and massage commit message a little bit.
> > > v6:
> > > * hide os_setup_post_done flag inside of os_setup_post() as it was in v4
> > >
> > > CC: berrange@redhat.com
> > > CC: mreitz@redhat.com
> > > CC: pbonzini@redhat.com
> > > CC: ehabkost@redhat.com
> > > CC: ldoktor@redhat.com
> > > CC: eblake@redhat.com
> > > ---
> > > os-posix.c | 6 ++++++
> > > vl.c | 6 ++++++
> > > 2 files changed, 12 insertions(+)
> > >
> > > diff --git a/os-posix.c b/os-posix.c
> > > index 9ce6f74..0246195 100644
> > > --- a/os-posix.c
> > > +++ b/os-posix.c
> > > @@ -309,8 +309,14 @@ void os_daemonize(void)
> > >
> > > void os_setup_post(void)
> > > {
> > > + static bool os_setup_post_done;
> > > int fd = 0;
> > >
> > > + if (os_setup_post_done) {
> > > + return;
> > > + }
> > > + os_setup_post_done = true;
> > > +
> > > if (daemonize) {
> > > if (chdir("/")) {
> > > error_report("not able to chdir to /: %s", strerror(errno));
> > > diff --git a/vl.c b/vl.c
> > > index fa44138..457ff2a 100644
> > > --- a/vl.c
> > > +++ b/vl.c
> > > @@ -4578,6 +4578,12 @@ int main(int argc, char **argv, char **envp)
> > > parse_numa_opts(current_machine);
> > >
> > > /* do monitor/qmp handling at preconfig state if requested */
> > > + if (!preconfig_exit_requested && is_daemonized()) {
> > > + /* signal parent QEMU to exit, libvirt treats it as a sign
> > > + * that monitor socket is ready to accept connections
> > > + */
> > > + os_setup_post();
> > > + }
> >
> > I was looking at the daemonize logic, and noticed it we have a
> > huge amount of code between this line and the next
> > os_setup_post() call that could either:
> >
> > * call exit() and/or error_report(); or
> logging would work to the extent mentioned in commit message,
> i.e. it' would work fine when log file is used otherwise it
> errors will go to /dev/null
>
> so it should be more or less fine on this point
My worry is that most users of error_report() involve an exit()
call too.
Once we have an active monitor, we must never call exit()
directly. Even qmp_quit() doesn't call exit() directly.
>
> > * be unable to finish machine initialization because of
> > chdir("/"), change_root(), or change_process_uid().
> this one really no go.
> I see 2 options here,
>
> * move init code that opens files to early stage (before preconfig monitor)
> or split it to open files early.
> (I've spotted several obvious places fwcfg/vnc/replay_start/migration)
> but there might be code somewhere in callbacks that would do it too,
> so it rather risky to go this route.
> (I'd do this anyways one place at the time using sanitizing
> initialization sequence pretext.)
We might have QMP commands that take file paths as input, so is
this really an option?
>
> * split out signaling part that tells parent process to exit into
> separate helper that's called once before/from main_loop().
> This option seems low risk and additionally error output to
> stderr will work as it does currently (until os_setup_post())
My assumption is that separating the chdir()/stdout/stderr logic
from the fork/daemonize/exit steps wouldn't be possible without
breaking expectations about -daemonize.
--
Eduardo
next prev parent reply other threads:[~2018-06-11 19:06 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-06-05 14:00 [Qemu-devel] [PATCH v3 0/2] fix -nodefaults and -daemonize regressions caused by --preconfig introduction Igor Mammedov
2018-06-05 14:00 ` [Qemu-devel] [PATCH v3 1/2] cli: Don't run early event loop if no --preconfig was specified Igor Mammedov
2018-06-05 18:12 ` Eduardo Habkost
2018-06-06 7:22 ` Igor Mammedov
2018-06-11 17:34 ` Eduardo Habkost
2018-06-05 14:00 ` [Qemu-devel] [PATCH v3 2/2] vl: fix use of --daemonize with --preconfig Igor Mammedov
2018-06-05 15:13 ` Eric Blake
2018-06-05 15:28 ` [Qemu-devel] [PATCH v4 " Igor Mammedov
2018-06-05 18:30 ` [Qemu-devel] [PATCH v3 " Eduardo Habkost
2018-06-06 8:34 ` Igor Mammedov
2018-06-06 8:37 ` [Qemu-devel] [PATCH v5 " Igor Mammedov
2018-06-06 13:50 ` Eduardo Habkost
2018-06-07 12:00 ` [Qemu-devel] [PATCH v6 " Igor Mammedov
2018-06-08 13:21 ` Eduardo Habkost
2018-06-11 13:16 ` Igor Mammedov
2018-06-11 19:06 ` Eduardo Habkost [this message]
2018-06-11 21:29 ` Igor Mammedov
2018-06-11 22:36 ` Eduardo Habkost
2018-06-12 9:17 ` [Qemu-devel] [libvirt] " Michal Privoznik
2018-06-12 12:42 ` Igor Mammedov
2018-06-12 12:50 ` Daniel P. Berrangé
2018-06-13 14:17 ` Eduardo Habkost
2018-06-13 14:23 ` Daniel P. Berrangé
2018-06-13 17:09 ` Eduardo Habkost
2018-06-14 12:32 ` Igor Mammedov
2018-06-12 13:04 ` Michal Privoznik
2018-06-12 13:10 ` Peter Krempa
2018-06-12 13:17 ` Daniel P. Berrangé
2018-06-06 8:55 ` [Qemu-devel] [PATCH v3 0/2] fix -nodefaults and -daemonize regressions caused by --preconfig introduction no-reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180611190607.GU7451@localhost.localdomain \
--to=ehabkost@redhat.com \
--cc=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=eblake@redhat.com \
--cc=imammedo@redhat.com \
--cc=ldoktor@redhat.com \
--cc=mreitz@redhat.com \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).