* [Qemu-devel] [PATCH v2] nbd: release exp->blk after all clients are closed
@ 2015-09-16 8:35 Wen Congyang
2015-09-16 8:41 ` Paolo Bonzini
0 siblings, 1 reply; 2+ messages in thread
From: Wen Congyang @ 2015-09-16 8:35 UTC (permalink / raw)
To: qemu-devl, Paolo Bonzini; +Cc: Li Zhijian
If the socket fd is shutdown, there may be some data which is received before
shutdown. We will read the data and do read/write in nbd_trip(). But the exp's
blk is NULL, and it will cause qemu crashed.
Reported-by: Li Zhijian <lizhijian@cn.fujitsu.com>
Signed-off-by: Wen Congyang <wency@cn.fujitsu.com>
---
nbd.c | 21 +++++++++++++++------
1 file changed, 15 insertions(+), 6 deletions(-)
diff --git a/nbd.c b/nbd.c
index 06b501b..07240bd 100644
--- a/nbd.c
+++ b/nbd.c
@@ -1131,12 +1131,6 @@ void nbd_export_close(NBDExport *exp)
}
nbd_export_set_name(exp, NULL);
nbd_export_put(exp);
- if (exp->blk) {
- blk_remove_aio_context_notifier(exp->blk, blk_aio_attached,
- blk_aio_detach, exp);
- blk_unref(exp->blk);
- exp->blk = NULL;
- }
}
void nbd_export_get(NBDExport *exp)
@@ -1159,6 +1153,13 @@ void nbd_export_put(NBDExport *exp)
exp->close(exp);
}
+ if (exp->blk) {
+ blk_remove_aio_context_notifier(exp->blk, blk_aio_attached,
+ blk_aio_detach, exp);
+ blk_unref(exp->blk);
+ exp->blk = NULL;
+ }
+
g_free(exp);
}
}
@@ -1305,6 +1306,14 @@ static void nbd_trip(void *opaque)
goto invalid_request;
}
+ if (client->closing) {
+ /*
+ * The client may be closed when we are blocked in
+ * nbd_co_receive_request()
+ */
+ goto done;
+ }
+
switch (command) {
case NBD_CMD_READ:
TRACE("Request type is READ");
--
2.4.3
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [Qemu-devel] [PATCH v2] nbd: release exp->blk after all clients are closed
2015-09-16 8:35 [Qemu-devel] [PATCH v2] nbd: release exp->blk after all clients are closed Wen Congyang
@ 2015-09-16 8:41 ` Paolo Bonzini
0 siblings, 0 replies; 2+ messages in thread
From: Paolo Bonzini @ 2015-09-16 8:41 UTC (permalink / raw)
To: Wen Congyang, qemu-devl; +Cc: qemu-stable, Li Zhijian
On 16/09/2015 10:35, Wen Congyang wrote:
> If the socket fd is shutdown, there may be some data which is received before
> shutdown. We will read the data and do read/write in nbd_trip(). But the exp's
> blk is NULL, and it will cause qemu crashed.
>
> Reported-by: Li Zhijian <lizhijian@cn.fujitsu.com>
> Signed-off-by: Wen Congyang <wency@cn.fujitsu.com>
Thanks, this looks good. I have added
Cc: qemu-stable@nongnu.org
and will send a pull request soon.
Paolo
> ---
> nbd.c | 21 +++++++++++++++------
> 1 file changed, 15 insertions(+), 6 deletions(-)
>
> diff --git a/nbd.c b/nbd.c
> index 06b501b..07240bd 100644
> --- a/nbd.c
> +++ b/nbd.c
> @@ -1131,12 +1131,6 @@ void nbd_export_close(NBDExport *exp)
> }
> nbd_export_set_name(exp, NULL);
> nbd_export_put(exp);
> - if (exp->blk) {
> - blk_remove_aio_context_notifier(exp->blk, blk_aio_attached,
> - blk_aio_detach, exp);
> - blk_unref(exp->blk);
> - exp->blk = NULL;
> - }
> }
>
> void nbd_export_get(NBDExport *exp)
> @@ -1159,6 +1153,13 @@ void nbd_export_put(NBDExport *exp)
> exp->close(exp);
> }
>
> + if (exp->blk) {
> + blk_remove_aio_context_notifier(exp->blk, blk_aio_attached,
> + blk_aio_detach, exp);
> + blk_unref(exp->blk);
> + exp->blk = NULL;
> + }
> +
> g_free(exp);
> }
> }
> @@ -1305,6 +1306,14 @@ static void nbd_trip(void *opaque)
> goto invalid_request;
> }
>
> + if (client->closing) {
> + /*
> + * The client may be closed when we are blocked in
> + * nbd_co_receive_request()
> + */
> + goto done;
> + }
> +
> switch (command) {
> case NBD_CMD_READ:
> TRACE("Request type is READ");
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2015-09-16 8:41 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-09-16 8:35 [Qemu-devel] [PATCH v2] nbd: release exp->blk after all clients are closed Wen Congyang
2015-09-16 8:41 ` Paolo Bonzini
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).