From nobody Mon Apr 29 12:46:57 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zoho.com; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1494338727096575.4553427799937; Tue, 9 May 2017 07:05:27 -0700 (PDT) Received: from localhost ([::1]:37429 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d85lP-0001s2-Kk for importer@patchew.org; Tue, 09 May 2017 10:05:19 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:39602) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d85kO-0001M6-SC for qemu-devel@nongnu.org; Tue, 09 May 2017 10:04:17 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1d85kL-0007C2-OB for qemu-devel@nongnu.org; Tue, 09 May 2017 10:04:16 -0400 Received: from szxga01-in.huawei.com ([45.249.212.187]:3985) by eggs.gnu.org with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16) (Exim 4.71) (envelope-from ) id 1d85kL-0006w4-4b for qemu-devel@nongnu.org; Tue, 09 May 2017 10:04:13 -0400 Received: from 172.30.72.54 (EHLO dggeml406-hub.china.huawei.com) ([172.30.72.54]) by dggrg01-dlp.huawei.com (MOS 4.4.6-GA FastPath queued) with ESMTP id AOF36986; Tue, 09 May 2017 22:03:41 +0800 (CST) Received: from localhost (10.177.24.66) by dggeml406-hub.china.huawei.com (10.3.17.50) with Microsoft SMTP Server id 14.3.301.0; Tue, 9 May 2017 22:03:34 +0800 From: Yunjian Wang To: Date: Tue, 9 May 2017 22:03:06 +0800 Message-ID: <1494338586-13416-1-git-send-email-wangyunjian@huawei.com> X-Mailer: git-send-email 1.9.5.msysgit.1 MIME-Version: 1.0 X-Originating-IP: [10.177.24.66] X-CFilter-Loop: Reflected X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A020206.5911CC3E.00A9, ss=1, re=0.000, recu=0.000, reip=0.000, cl=1, cld=1, fgs=0, ip=0.0.0.0, so=2014-11-16 11:51:01, dmn=2013-03-21 17:37:32 X-Mirapoint-Loop-Id: 757099a203f89c299a26cac69e6a5ac5 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.4.x-2.6.x [generic] [fuzzy] X-Received-From: 45.249.212.187 Subject: [Qemu-devel] [PATCH] vhost-user: fix watcher need be removed when vhost-user hotplug X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: jasowang@redhat.com, w00273186 , caihe@huawei.com, mst@redhat.com Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail: RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: w00273186 "nc" is freed after hotplug vhost-user, but the watcher don't be removed. The QEMU crash when the watcher access the "nc" on socket disconnect. Call Trace: #0 object_get_class (obj=3Dobj@entry=3D0x2) at qom/object.c:751 #1 0x00007fc031c79f41 in qemu_chr_fe_disconnect (be=3D)= at chardev/char.c:1048 #2 0x00007fc031bd62e0 in net_vhost_user_watch (chan=3D,= cond=3D, opaque=3D) at net/vhost-user.c:191 #3 0x00007fc02c23e99a in g_main_context_dispatch () from /lib64/libgli= b-2.0.so.0 #4 0x00007fc031ccfc0c in glib_pollfds_poll () at util/main-loop.c:213 #5 os_host_main_loop_wait (timeout=3D) at util/main-loo= p.c:261 #6 main_loop_wait (nonblocking=3Dnonblocking@entry=3D0) at util/main-l= oop.c:517 #7 0x00007fc03193bc87 in main_loop () at vl.c:1899 #8 main (argc=3D, argv=3D, envp=3D) at vl.c:4719 Signed-off-by: Yunjian Wang --- net/vhost-user.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/net/vhost-user.c b/net/vhost-user.c index 00a0c1c..5cc2178 100644 --- a/net/vhost-user.c +++ b/net/vhost-user.c @@ -155,6 +155,10 @@ static void vhost_user_cleanup(NetClientState *nc) =20 qemu_chr_fe_deinit(&s->chr); object_unparent(OBJECT(chr)); + if (s->watch) { + g_source_remove(s->watch); + s->watch =3D 0; + } } =20 qemu_purge_queued_packets(nc); --=20 1.8.3.1