From nobody Mon Sep 14 04:49:24 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1788939963; cv=none; d=zohomail.com; s=zohoarc; b=ibnhRcvEwUZWMU3SvVJUuaqIeH/fkmidrdX+4uHdlV9RfFLCE5RPZRaTEkil9yUv9jS/j3xcU6wAku6/KNwGu4AJEfm0T30m4/F+Pi/3J1C9IKoGgWb+9kNGMQhBle7R3A1e8I0buZeduE59m7Z0ciUCElLFmc4gEX9hi4oPzcM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788939963; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Subject:Subject:To:To:Message-Id; bh=jm4361clOJRbA3GaNQPbFHyPsSd8vUL3WiGs4vHZcXc=; b=cf6u/zSpAAbeTCenGLnNKq13p7JOD9A0JvPLlrFTqF/lNALcKf0BY4GDIdP3d0sATVCuDiDe0zpPBkRZQ8nlH+oJPKWiVgtgnymcpmYHCG4g4Uw/Y6R7MQBhkN7xVGdPaveHX7Lum1vxkHMkry54FoCuMG2QdttozxWZpJDq6h0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 1788939963476582.5122165040292; Wed, 9 Sep 2026 00:46:03 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id D35123F835; Wed, 9 Sep 2026 03:46:01 -0400 (EDT) Received: from [172.19.199.13] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id 02853417FA for ; Wed, 9 Sep 2026 03:44:55 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 5EB9F3F30F; Wed, 9 Sep 2026 03:44:46 -0400 (EDT) Received: from mx0a-0064b401.pphosted.com (mx0a-0064b401.pphosted.com [205.220.166.238]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id 4B1393F2E6 for ; Wed, 9 Sep 2026 03:44:43 -0400 (EDT) Received: from pps.filterd (m0250810.ppops.net [127.0.0.1]) by mx0a-0064b401.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6896r99p107535 for ; Wed, 9 Sep 2026 00:15:39 -0700 Received: from ala-exchng02.corp.ad.wrs.com (ala-exchng02.wrs.com [128.224.246.37]) by mx0a-0064b401.pphosted.com (PPS) with ESMTPS id 4ggec0wg4h-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT) for ; Wed, 09 Sep 2026 00:15:38 -0700 (PDT) Received: from ala-p2exch01.corp.ad.wrs.com (10.11.226.101) by ALA-EXCHNG02.corp.ad.wrs.com (10.11.224.122) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.61; Wed, 9 Sep 2026 00:15:37 -0700 Received: from ala-exchng01.corp.ad.wrs.com (10.11.224.121) by ala-p2exch01.corp.ad.wrs.com (10.11.226.101) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.2.2562.46; Wed, 9 Sep 2026 00:15:37 -0700 Received: from oak-lpgbuild11.wrs.com (10.11.232.110) by ala-exchng01.corp.ad.wrs.com (10.11.224.121) with Microsoft SMTP Server id 15.1.2507.61 via Frontend Transport; Wed, 9 Sep 2026 00:15:37 -0700 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=-3.4 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_LOW,RCVD_IN_MSPIKE_H2, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 X-Greylist: delayed 1743 seconds by postgrey-1.37 at lists.libvirt.org; Wed, 09 Sep 2026 03:44:43 EDT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=windriver.com; h=cc:content-transfer-encoding:content-type:date:from :message-id:mime-version:subject:to; s=PPS06212021; bh=jm4361clO JRbA3GaNQPbFHyPsSd8vUL3WiGs4vHZcXc=; b=VdZ+9XacHLN1kNuDzSmnzd7Yq czmscwbr5WAoaVNJFL/r+YUFEzRwNUcTex6aKNDFtaocb8JQRUM0DBhzgDmgaAWc 0yokpKlbEWhadW9QsR8Pzu/m0v0rEcsCkiE0wJmm+Rmr6JfV1F5XV/yvvtB/W6B0 Fg8ZAgRglEGNDhHRZ1sqRtYp3GLEuf0CS1afPpJgbFygmeEegwcFQhR5m7c2fUV8 6MzyDSh+iSN0WlcjBELiEKt15JS4OpOy943ef7/B1cto5ivJpq5tpxysjdRMfJ2M P4D+hmbp4O+/xDYwQpn59y2+cvjmkiRsh5fk4c1F4U9fSDL8o4hnSDwq31EaQ== To: Subject: [PATCH v2] qemu: Fix crash in qemuProcessStop due to NULL eventThread Date: Wed, 9 Sep 2026 07:15:37 +0000 Message-ID: <20260909071537.758416-1-PritamSrichandan.Sahoo@windriver.com> X-Mailer: git-send-email 2.53.0 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=E+v9Y6dl c=1 sm=1 tr=0 ts=6aa1079b cx=c_pps a=Lg6ja3A245NiLSnFpY5YKQ==:117 a=Lg6ja3A245NiLSnFpY5YKQ==:17 a=VdqzKS8jKosA:10 a=VkNPw1HP01LnGYTKEx00:22 a=bi6dqmuHe4P4UrxVR6um:22 a=HK-ge7EqtdluswH-FwHe:22 a=t7CeM3EgAAAA:8 a=9aAowi-9eXi5CmZZo7kA:9 a=FdTzh2GWekK77mhwV6Dw:22 X-Proofpoint-ORIG-GUID: 7wN-bKPO5UKPLH9XTQnveQ1fsMYnG4-L X-Proofpoint-Spam-Info: AW1haW4tMjYwOTA5MDA4MCBTYWx0ZWRfX1BqO9Vi9N54B W2WJ5OUb+o/mjKLxopLejrSX5McSI1/X+Oux6sJzo8pNuMNalpjbZv3iEeBkE9GDP+LsACnNa4B tZ6rAAQu4UpInr5Z2dtMkQvdbHc2IYzAnNOboUNxnlpM44ZW1Xv7 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTA5MDA4MCBTYWx0ZWRfX2AtGdPA4nxZC cG6IB49M7BFjA7kFigp3Qt/HgFRBIJshwP7jxoZCrLFwjF6eVS3yU59AT/alVett5/TuCKj1dP8 uSp6euxv0hqAc/xXsYv/dVIj70A3QN+3k/8xHu+LPeF9AAJDgjGv47Zjhlx/nqiBQTJ2JvItSyI BVE/ebigzlu9SLJCt1SiTj+TxMf7J036hGEKIcs/jl8ZsvkCOlpM+DpBaUSdEnK0a0oq6lXPC6n VnUHV9rF0Pfo3EH9Z+kE2ma/+a4qBs6RvRn7tqzp5DjI34tOE0UtQxD8lMKmNgs6zh/3Cl8i0CR XKQCnI0hGc1vSTsVlZilJQtZ4PqlQTfkiC6bBbnHPDmUJAPvROHu9xNfcnzD/fsiFm3ULoOZx7C TRB/3GzSFwhXobVWKwW/Dc1fJEkR3xAVSweADxVPpAA+DROEQU8ueiaKemw6QBfKT56aKI8+6Gt teOfLZXWxKY1mFOhprA== X-Proofpoint-GUID: 7wN-bKPO5UKPLH9XTQnveQ1fsMYnG4-L X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-08_03,2026-09-08_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 impostorscore=0 clxscore=1015 adultscore=0 bulkscore=0 spamscore=0 malwarescore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2609090080 Message-ID-Hash: ETUQEGOD2SOKZLPAJQ2T7DJAVYPOOPZX X-Message-ID-Hash: ETUQEGOD2SOKZLPAJQ2T7DJAVYPOOPZX X-MailFrom: prvs=371242890c=pritamsrichandan.sahoo@windriver.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: PritamSrichandan.Sahoo@windriver.com, Prashant.Chikhalkar@windriver.com X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Pritam Srichandan Sahoo via Devel Reply-To: Pritam Srichandan Sahoo X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1788939966348158500 Content-Type: text/plain; charset="utf-8" When a VM shuts down, the monitor EOF event is queued to the worker thread pool. If another thread enters qemuProcessStop() first and frees priv->eventThread via g_steal_pointer(), the second call from the EOF event worker thread hits a NULL dereference when calling virEventThreadStop(priv->eventThread). The existing 'if (priv->eventThread)' guard is insufficient because the VM object is unlocked between the check and the call to virEventThreadStop(), allowing a concurrent thread to clear the pointer in the meantime. Fix this by taking a GObject reference to eventThread before unlocking the VM. This ensures the pointer remains valid for virEventThreadStop() even if another thread clears priv->eventThread concurrently. Crash backtrace: #0 virEventThreadStop (evt=3D0x0) #1 qemuProcessStop (reason=3DVIR_DOMAIN_SHUTOFF_SHUTDOWN, asyncJob=3DVI= R_ASYNC_JOB_NONE) #2 processMonitorEOFEvent (driver=3D..., vm=3D...) #3 qemuProcessEventHandler (data=3D..., opaque=3D...) #4 virThreadPoolWorker (opaque=3D...) Signed-off-by: Pritam Srichandan Sahoo --- v2: Resend as an inline plain-text patch. The v1 posting was delivered as an email attachment which is harder to review; no code changes from v1. src/qemu/qemu_process.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/qemu/qemu_process.c b/src/qemu/qemu_process.c index 0d9b8bcb93..642e18eeb1 100644 --- a/src/qemu/qemu_process.c +++ b/src/qemu/qemu_process.c @@ -8850,13 +8850,15 @@ void qemuProcessStop(virQEMUDriver *driver, * the global domain object list code depends on it (and it can't actu= ally * check 'priv->beingDestroyed as that's private). */ if (priv->eventThread) { + virEventThread *eventThread =3D g_object_ref(priv->eventThread); /* Explicitly set priv->beingDestroyed. While it's done in * qemuProcessBeginStopJob(), qemuProcessStop() is called from pla= ces * where stop job is not acquired. */ priv->beingDestroyed =3D true; virObjectUnlock(vm); - virEventThreadStop(priv->eventThread); + virEventThreadStop(eventThread); virObjectLock(vm); + g_object_unref(eventThread); } =20 if (priv->agent) { --=20 2.53.0