[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL 14/15] cpus: fix deadlock and segfault in qemu_mutex_
From: |
Paolo Bonzini |
Subject: |
[Qemu-devel] [PULL 14/15] cpus: fix deadlock and segfault in qemu_mutex_lock_iothread |
Date: |
Mon, 2 Mar 2015 11:08:53 +0100 |
When two threads (other than the low-priority TCG VCPU thread)
are competing for the iothread lock, a deadlock can happen. This
is because iothread_requesting_mutex is set to false by the first
thread that gets the mutex, and then the VCPU thread might never
yield from the execution loop. If iothread_requesting_mutex is
changed from a bool to a counter, the deadlock is fixed.
However, there is another bug in qemu_mutex_lock_iothread that
can be triggered by the new call_rcu thread. The bug happens
if qemu_mutex_lock_iothread is called before the CPUs are
created. In that case, first_cpu is NULL and the caller
segfaults in qemu_mutex_lock_iothread. To fix this, just
do not do the kick if first_cpu is NULL.
Reported-by: Leon Alrae <address@hidden>
Reported-by: Andreas Gustafsson <address@hidden>
Tested-by: Leon Alrae <address@hidden>
Signed-off-by: Paolo Bonzini <address@hidden>
---
cpus.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/cpus.c b/cpus.c
index 1cd9867..83c078e 100644
--- a/cpus.c
+++ b/cpus.c
@@ -778,7 +778,7 @@ static void qemu_tcg_init_cpu_signals(void)
static QemuMutex qemu_global_mutex;
static QemuCond qemu_io_proceeded_cond;
-static bool iothread_requesting_mutex;
+static unsigned iothread_requesting_mutex;
static QemuThread io_thread;
@@ -1115,15 +1115,15 @@ bool qemu_in_vcpu_thread(void)
void qemu_mutex_lock_iothread(void)
{
- if (!tcg_enabled()) {
+ if (!tcg_enabled() || !first_cpu) {
qemu_mutex_lock(&qemu_global_mutex);
} else {
- iothread_requesting_mutex = true;
+ atomic_inc(&iothread_requesting_mutex);
if (qemu_mutex_trylock(&qemu_global_mutex)) {
qemu_cpu_kick_thread(first_cpu);
qemu_mutex_lock(&qemu_global_mutex);
}
- iothread_requesting_mutex = false;
+ atomic_dec(&iothread_requesting_mutex);
qemu_cond_broadcast(&qemu_io_proceeded_cond);
}
}
--
2.3.0
- [Qemu-devel] [PULL 04/15] timer: replace time() with QEMU_CLOCK_HOST, (continued)
- [Qemu-devel] [PULL 04/15] timer: replace time() with QEMU_CLOCK_HOST, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 05/15] bootdevice: fix segment fault when booting guest with '-kernel' and '-initrd', Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 06/15] Add specific config options for PCI-E bridges, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 07/15] Create specific config option for "platform-bus", Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 08/15] Give ivshmem its own config option, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 01/15] scsi: give device a parent before setting properties, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 09/15] iscsi: Handle write protected case in reopen, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 13/15] virtio-scsi: Allocate op blocker reason before blocking, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 10/15] Makefile: fix up parallel building under MSYS+MinGW, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 11/15] Makefile: don't silence mak file test with V=1, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 14/15] cpus: fix deadlock and segfault in qemu_mutex_lock_iothread,
Paolo Bonzini <=
- [Qemu-devel] [PULL 15/15] cpus: be more paranoid in avoiding deadlocks, Paolo Bonzini, 2015/03/02
- [Qemu-devel] [PULL 12/15] Makefile.target: binary depends on config-devices, Paolo Bonzini, 2015/03/02
- Re: [Qemu-devel] [PULL 00/15] Misc changes for 2015-03-02, Eric Blake, 2015/03/02
- Re: [Qemu-devel] [PULL 00/15] Misc changes for 2015-03-02, Peter Maydell, 2015/03/03