From: Stefan Hajnoczi <stefanha@redhat.com>
To: elena.ufimtseva@oracle.com
Cc: fam@euphon.net, john.g.johnson@oracle.com,
swapnil.ingle@nutanix.com, mst@redhat.com, qemu-devel@nongnu.org,
kraxel@redhat.com, jag.raman@oracle.com, quintela@redhat.com,
armbru@redhat.com, kanth.ghatraju@oracle.com, felipe@nutanix.com,
thuth@redhat.com, ehabkost@redhat.com, konrad.wilk@oracle.com,
dgilbert@redhat.com, liran.alon@oracle.com,
thanos.makatos@nutanix.com, rth@twiddle.net, kwolf@redhat.com,
berrange@redhat.com, mreitz@redhat.com,
ross.lagerwall@citrix.com, marcandre.lureau@gmail.com,
pbonzini@redhat.com
Subject: Re: [PATCH RESEND v6 20/36] multi-process: Forward PCI config space acceses to the remote process
Date: Tue, 12 May 2020 14:50:55 +0100 [thread overview]
Message-ID: <20200512135055.GJ300009@stefanha-x1.localdomain> (raw)
In-Reply-To: <901295bf44c731d232bb60579ffb48dce5b05cc4.1587614626.git.elena.ufimtseva@oracle.com>
[-- Attachment #1: Type: text/plain, Size: 3713 bytes --]
On Wed, Apr 22, 2020 at 09:13:55PM -0700, elena.ufimtseva@oracle.com wrote:
> +static int config_op_send(PCIProxyDev *dev, uint32_t addr, uint32_t *val, int l,
> + unsigned int op)
> +{
> + MPQemuMsg msg;
> + struct conf_data_msg conf_data;
> + int wait;
> +
> + memset(&msg, 0, sizeof(MPQemuMsg));
> + conf_data.addr = addr;
> + conf_data.val = (op == PCI_CONFIG_WRITE) ? *val : 0;
> + conf_data.l = l;
> +
> + msg.data2 = (uint8_t *)&conf_data;
> + if (!msg.data2) {
> + return -ENOMEM;
This can never happen since conf_data is on the stack.
> + }
> +
> + msg.size = sizeof(conf_data);
> + msg.cmd = op;
> + msg.bytestream = 1;
> +
> + if (op == PCI_CONFIG_WRITE) {
> + msg.num_fds = 0;
> + } else {
> + /* TODO: Dont create fd each time for send. */
> + wait = GET_REMOTE_WAIT;
> + msg.num_fds = 1;
> + msg.fds[0] = wait;
> + }
> +
> + mpqemu_msg_send(&msg, dev->mpqemu_link->dev);
> +
> + if (op == PCI_CONFIG_READ) {
Are you sure it's correct for writes to be posted instead of waiting for
completion?
> + *val = (uint32_t)wait_for_remote(wait);
> + PUT_REMOTE_WAIT(wait);
> + }
> +
> + return 0;
> +}
> +
> +static uint32_t pci_proxy_read_config(PCIDevice *d, uint32_t addr, int len)
> +{
> + uint32_t val;
> +
> + (void)pci_default_read_config(d, addr, len);
Please add a comment explaining why this local read is necessary.
> +
> + config_op_send(PCI_PROXY_DEV(d), addr, &val, len, PCI_CONFIG_READ);
> +
> + return val;
> +}
> +
> +static void pci_proxy_write_config(PCIDevice *d, uint32_t addr, uint32_t val,
> + int l)
> +{
> + pci_default_write_config(d, addr, val, l);
Please add a comment explaining why this local write is necessary.
> +
> + config_op_send(PCI_PROXY_DEV(d), addr, &val, l, PCI_CONFIG_WRITE);
> +}
...
> diff --git a/io/mpqemu-link.c b/io/mpqemu-link.c
> index f780b65181..ef4a07b81a 100644
> --- a/io/mpqemu-link.c
> +++ b/io/mpqemu-link.c
> @@ -381,6 +381,12 @@ bool mpqemu_msg_valid(MPQemuMsg *msg)
> return false;
> }
> break;
> + case PCI_CONFIG_WRITE:
> + case PCI_CONFIG_READ:
> + if (msg->size != sizeof(struct conf_data_msg)) {
> + return false;
> + }
conf_data_msg.l is not validated.
> + break;
> default:
> break;
> }
> diff --git a/remote/remote-main.c b/remote/remote-main.c
> index f541baae6a..834574e172 100644
> --- a/remote/remote-main.c
> +++ b/remote/remote-main.c
> @@ -53,6 +53,32 @@ gchar *print_pid_exec(gchar *str)
>
> #define LINK_TO_DEV(link) ((PCIDevice *)link->opaque)
>
> +static void process_config_write(PCIDevice *dev, MPQemuMsg *msg)
> +{
> + struct conf_data_msg *conf = (struct conf_data_msg *)msg->data2;
> +
> + qemu_mutex_lock_iothread();
The qemu_mutex_lock_iothread() can be dropped once this is integrated in
to QEMU's event loop.
> + pci_default_write_config(dev, conf->addr, conf->val, conf->l);
It is not safe to call this function with arbitrary addr input values.
> + qemu_mutex_unlock_iothread();
> +}
> +
> +static void process_config_read(PCIDevice *dev, MPQemuMsg *msg)
> +{
> + struct conf_data_msg *conf = (struct conf_data_msg *)msg->data2;
> + uint32_t val;
> + int wait;
> +
> + wait = msg->fds[0];
> +
> + qemu_mutex_lock_iothread();
> + val = pci_default_read_config(dev, conf->addr, conf->l);
It is not safe to call this function with arbitrary addr input values.
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
next prev parent reply other threads:[~2020-05-12 13:52 UTC|newest]
Thread overview: 94+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-04-23 4:13 [PATCH RESEND v6 00/36] Initial support for multi-process qemu elena.ufimtseva
2020-04-23 4:13 ` [PATCH RESEND v6 01/36] memory: alloc RAM from file at offset elena.ufimtseva
2020-05-12 8:26 ` Stefan Hajnoczi
2020-05-12 8:48 ` Daniel P. Berrangé
2020-05-12 11:56 ` Jag Raman
2020-05-13 8:40 ` Stefan Hajnoczi
2020-05-13 15:25 ` Igor Mammedov
2020-05-13 20:08 ` Jag Raman
2020-05-14 9:47 ` Igor Mammedov
2020-05-14 9:51 ` Dr. David Alan Gilbert
2020-04-23 4:13 ` [PATCH RESEND v6 02/36] multi-process: Refactor machine_init and exit notifiers elena.ufimtseva
2020-04-23 14:13 ` Philippe Mathieu-Daudé
2020-04-23 4:13 ` [PATCH RESEND v6 03/36] command-line: refractor parser code elena.ufimtseva
2020-04-24 12:55 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 04/36] multi-process: Refactor chardev functions out of vl.c elena.ufimtseva
2020-04-23 4:13 ` [PATCH RESEND v6 05/36] multi-process: Refactor monitor " elena.ufimtseva
2020-04-24 13:02 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 06/36] monitor: destaticize HMP commands elena.ufimtseva
2020-04-23 14:14 ` Philippe Mathieu-Daudé
2020-04-23 15:07 ` Jag Raman
2020-04-23 15:58 ` Philippe Mathieu-Daudé
2020-04-23 4:13 ` [PATCH RESEND v6 07/36] multi-process: add a command line option for debug file elena.ufimtseva
2020-04-23 4:13 ` [PATCH RESEND v6 08/36] multi-process: Add stub functions to facilitate build of multi-process elena.ufimtseva
2020-04-24 13:12 ` Stefan Hajnoczi
2020-04-24 13:47 ` Jag Raman
2020-04-28 16:29 ` Stefan Hajnoczi
2020-04-28 18:58 ` Jag Raman
2020-04-29 9:41 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 09/36] multi-process: Add config option for multi-process QEMU elena.ufimtseva
2020-04-24 13:47 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 10/36] multi-process: build system for remote device process elena.ufimtseva
2020-04-24 15:04 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 11/36] multi-process: define mpqemu-link object elena.ufimtseva
2020-05-12 8:56 ` Stefan Hajnoczi
2020-05-12 12:09 ` Jag Raman
2020-04-23 4:13 ` [PATCH RESEND v6 12/36] multi-process: add functions to synchronize proxy and remote endpoints elena.ufimtseva
2020-05-12 10:21 ` Stefan Hajnoczi
2020-05-12 12:28 ` Jag Raman
2020-05-13 8:43 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 13/36] multi-process: setup PCI host bridge for remote device elena.ufimtseva
2020-05-12 10:31 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 14/36] multi-process: setup a machine object for remote device process elena.ufimtseva
2020-05-12 10:43 ` Stefan Hajnoczi
2020-05-12 12:12 ` Jag Raman
2020-04-23 4:13 ` [PATCH RESEND v6 15/36] multi-process: setup memory manager for remote device elena.ufimtseva
2020-05-12 12:11 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 16/36] multi-process: remote process initialization elena.ufimtseva
2020-04-23 4:13 ` [PATCH RESEND v6 17/36] multi-process: introduce proxy object elena.ufimtseva
2020-05-12 12:23 ` Stefan Hajnoczi
2020-05-12 12:35 ` Jag Raman
2020-04-23 4:13 ` [PATCH RESEND v6 18/36] multi-process: Initialize Proxy Object's communication channel elena.ufimtseva
2020-05-12 12:35 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 19/36] multi-process: Connect Proxy Object with device in the remote process elena.ufimtseva
2020-05-12 12:54 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 20/36] multi-process: Forward PCI config space acceses to " elena.ufimtseva
2020-05-12 13:50 ` Stefan Hajnoczi [this message]
2020-04-23 4:13 ` [PATCH RESEND v6 21/36] multi-process: PCI BAR read/write handling for proxy & remote endpoints elena.ufimtseva
2020-05-12 14:19 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 22/36] multi-process: Synchronize remote memory elena.ufimtseva
2020-05-12 15:07 ` Stefan Hajnoczi
2020-05-12 15:49 ` Dr. David Alan Gilbert
2020-04-23 4:13 ` [PATCH RESEND v6 23/36] multi-process: create IOHUB object to handle irq elena.ufimtseva
2020-05-12 15:57 ` Stefan Hajnoczi
2020-05-12 16:12 ` Stefan Hajnoczi
2020-04-23 4:13 ` [PATCH RESEND v6 24/36] multi-process: Retrieve PCI info from remote process elena.ufimtseva
2020-05-12 16:07 ` Stefan Hajnoczi
2020-04-23 4:14 ` [PATCH RESEND v6 25/36] multi-process: Introduce build flags to separate remote process code elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 26/36] multi-process: add parse_cmdline in remote process elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 27/36] multi-process: add support to parse device option elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 28/36] multi-process: send heartbeat messages to remote elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 29/36] multi-process: handle heartbeat messages in remote process elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 30/36] multi-process: perform device reset in the " elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 31/36] multi-process/mon: choose HMP commands based on target elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 32/36] multi-process/mon: stub functions to enable QMP module for remote process elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 33/36] multi-process/mon: enable QMP module support in the " elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 34/36] multi-process/mon: Initialize QMP module for remote processes elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 35/36] multi-process: add the concept description to docs/devel/qemu-multiprocess elena.ufimtseva
2020-04-23 4:14 ` [PATCH RESEND v6 36/36] multi-process: add configure and usage information elena.ufimtseva
2020-04-23 13:54 ` 罗勇刚(Yonggang Luo)
2020-04-23 15:01 ` Jag Raman
2020-04-23 22:56 ` 罗勇刚(Yonggang Luo)
2020-04-24 0:34 ` 罗勇刚(Yonggang Luo)
2020-04-24 12:48 ` [PATCH RESEND v6 00/36] Initial support for multi-process qemu Stefan Hajnoczi
2020-04-24 12:53 ` Daniel P. Berrangé
2020-04-24 12:53 ` Eric Blake
2020-04-24 13:42 ` Max Reitz
2020-04-28 17:29 ` Stefan Hajnoczi
2020-04-28 17:47 ` Michael S. Tsirkin
2020-04-29 9:30 ` Stefan Hajnoczi
2020-04-29 9:59 ` Michael S. Tsirkin
2020-05-11 14:40 ` Stefan Hajnoczi
2020-05-11 19:30 ` Jag Raman
2020-05-12 16:13 ` Stefan Hajnoczi
2020-05-12 16:55 ` Jag Raman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200512135055.GJ300009@stefanha-x1.localdomain \
--to=stefanha@redhat.com \
--cc=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=dgilbert@redhat.com \
--cc=ehabkost@redhat.com \
--cc=elena.ufimtseva@oracle.com \
--cc=fam@euphon.net \
--cc=felipe@nutanix.com \
--cc=jag.raman@oracle.com \
--cc=john.g.johnson@oracle.com \
--cc=kanth.ghatraju@oracle.com \
--cc=konrad.wilk@oracle.com \
--cc=kraxel@redhat.com \
--cc=kwolf@redhat.com \
--cc=liran.alon@oracle.com \
--cc=marcandre.lureau@gmail.com \
--cc=mreitz@redhat.com \
--cc=mst@redhat.com \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=quintela@redhat.com \
--cc=ross.lagerwall@citrix.com \
--cc=rth@twiddle.net \
--cc=swapnil.ingle@nutanix.com \
--cc=thanos.makatos@nutanix.com \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).