[Qemu-devel] [PULL 40/40] Migration+TLS: Fix crash due to double cleanup

From: Juan Quintela
Subject: [Qemu-devel] [PULL 40/40] Migration+TLS: Fix crash due to double cleanup
Date: Wed, 16 May 2018 01:40:17 +0200

From: "Dr. David Alan Gilbert" <address@hidden>

During a TLS connect we see:
  migration_channel_connect calls
  (calls after TLS setup)

My previous error handling fix made migration_channel_connect
call migrate_fd_connect in all cases; unfortunately the above
means it gets called twice and crashes doing double cleanup.

Fixes: 688a3dcba98

Reported-by: Peter Krempa <address@hidden>
Signed-off-by: Dr. David Alan Gilbert <address@hidden>
Reviewed-by: Daniel P. Berrangé <address@hidden>
Message-Id: <address@hidden>
Signed-off-by: Juan Quintela <address@hidden>
 migration/channel.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/migration/channel.c b/migration/channel.c
index 716192bf75..33e0e9b82f 100644
--- a/migration/channel.c
+++ b/migration/channel.c
@@ -71,6 +71,15 @@ void migration_channel_connect(MigrationState *s,
                                  TYPE_QIO_CHANNEL_TLS)) {
             migration_tls_channel_connect(s, ioc, hostname, &error);
+            if (!error) {
+                /* tls_channel_connect will call back to this
+                 * function after the TLS handshake,
+                 * so we mustn't call migrate_fd_connect until then
+                 */
+                return;
+            }
         } else {
             QEMUFile *f = qemu_fopen_channel_output(ioc);

