qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 0/3] net: socket: do not close file descriptor if it's not a socket
@ 2023-06-09  7:27 Laurent Vivier
  2023-06-09  7:27 ` [PATCH 1/3] net: socket: prepare to cleanup net_init_socket() Laurent Vivier
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Laurent Vivier @ 2023-06-09  7:27 UTC (permalink / raw)
  To: qemu-devel; +Cc: David Gibson, Jason Wang, Laurent Vivier

The socket netdev with a file descriptor (fd) cannot be removed
and then added again because the fd is closed when the backend is
removed and thus is not available anymore when we want to add the
backend again.

But this can bring to a core dump:
1- boot a VM with an fd socket netdev
2- remove the netdev
3- reboot
4- add the netdev again, it fails because the fd is not a
   socket, and then closed
5- stop QEMU -> core dump

On reboot (step 3) the fd is allocated to another use in QEMU, and when
we try to use it with a socket netdev, it fails. But the netdev backend
closes the file descriptor that is in use by another part of QEMU.
We can see the core dump on QEMU exit because it tries to close
an invalid file descriptor.

It happens for instance when we have a PCI device and the fd is allocated
to a VirtIOIRQFD on reboot.

Moreover, using "netdev socket,fd=X" allows an user to close any QEMU
internal file descriptor from an HMP or QMP interface.

Laurent Vivier (3):
  net: socket: prepare to cleanup net_init_socket()
  net: socket: move fd type checking to its own function
  net: socket: remove net_init_socket()

 net/socket.c | 53 +++++++++++++++++++++++++++-------------------------
 1 file changed, 28 insertions(+), 25 deletions(-)

-- 
2.39.2



^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2023-06-30  6:02 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-06-09  7:27 [PATCH 0/3] net: socket: do not close file descriptor if it's not a socket Laurent Vivier
2023-06-09  7:27 ` [PATCH 1/3] net: socket: prepare to cleanup net_init_socket() Laurent Vivier
2023-06-15  5:06   ` David Gibson
2023-06-09  7:27 ` [PATCH 2/3] net: socket: move fd type checking to its own function Laurent Vivier
2023-06-15  5:09   ` David Gibson
2023-06-09  7:27 ` [PATCH 3/3] net: socket: remove net_init_socket() Laurent Vivier
2023-06-15  5:10   ` David Gibson
2023-06-30  6:02 ` [PATCH 0/3] net: socket: do not close file descriptor if it's not a socket Jason Wang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).