From nobody Tue Apr 23 13:29:48 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zoho.com; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1496227800513901.0747687602704; Wed, 31 May 2017 03:50:00 -0700 (PDT) Received: from localhost ([::1]:58448 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dG1CR-00086h-3Z for importer@patchew.org; Wed, 31 May 2017 06:49:59 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:56810) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dG18r-0005jp-Hy for qemu-devel@nongnu.org; Wed, 31 May 2017 06:46:18 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dG18n-0006Cs-L4 for qemu-devel@nongnu.org; Wed, 31 May 2017 06:46:17 -0400 Received: from szxga01-in.huawei.com ([45.249.212.187]:4004) by eggs.gnu.org with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16) (Exim 4.71) (envelope-from ) id 1dG18n-0006Bj-0O for qemu-devel@nongnu.org; Wed, 31 May 2017 06:46:13 -0400 Received: from 172.30.72.55 (EHLO DGGEML403-HUB.china.huawei.com) ([172.30.72.55]) by dggrg01-dlp.huawei.com (MOS 4.4.6-GA FastPath queued) with ESMTP id APM93740; Wed, 31 May 2017 18:46:01 +0800 (CST) Received: from localhost (10.177.24.66) by DGGEML403-HUB.china.huawei.com (10.3.17.33) with Microsoft SMTP Server id 14.3.301.0; Wed, 31 May 2017 18:45:52 +0800 From: Yunjian Wang To: Date: Wed, 31 May 2017 18:45:32 +0800 Message-ID: <1496227532-15192-1-git-send-email-wangyunjian@huawei.com> X-Mailer: git-send-email 1.9.5.msysgit.1 MIME-Version: 1.0 X-Originating-IP: [10.177.24.66] X-CFilter-Loop: Reflected X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A010205.592E9EEA.0032, ss=1, re=0.000, recu=0.000, reip=0.000, cl=1, cld=1, fgs=0, ip=0.0.0.0, so=2014-11-16 11:51:01, dmn=2013-03-21 17:37:32 X-Mirapoint-Loop-Id: 01057e5b0e72812956ef6a93886aa46a X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.4.x-2.6.x [generic] [fuzzy] X-Received-From: 45.249.212.187 Subject: [Qemu-devel] [PATCH v2] vhost-user: fix watcher need be removed when vhost-user hotplug X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: jasowang@redhat.com, w00273186 , caihe@huawei.com, mst@redhat.com Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail: RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: w00273186 "nc" is freed after hotplug vhost-user, but the watcher don't be removed. The QEMU crash when the watcher access the "nc" on socket disconnect. Call Trace: #0 object_get_class (obj=3Dobj@entry=3D0x2) at qom/object.c:751 #1 0x00007fc031c79f41 in qemu_chr_fe_disconnect (be=3D)= at chardev/char.c:1048 #2 0x00007fc031bd62e0 in net_vhost_user_watch (chan=3D,= cond=3D, opaque=3D) at net/vhost-user.c:191 #3 0x00007fc02c23e99a in g_main_context_dispatch () from /lib64/libgli= b-2.0.so.0 #4 0x00007fc031ccfc0c in glib_pollfds_poll () at util/main-loop.c:213 #5 os_host_main_loop_wait (timeout=3D) at util/main-loo= p.c:261 #6 main_loop_wait (nonblocking=3Dnonblocking@entry=3D0) at util/main-l= oop.c:517 #7 0x00007fc03193bc87 in main_loop () at vl.c:1899 #8 main (argc=3D, argv=3D, envp=3D) at vl.c:4719 Signed-off-by: Yunjian Wang Reviewed-by: Marc-Andr=C3=A9 Lureau --- net/vhost-user.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/net/vhost-user.c b/net/vhost-user.c index 00a0c1c..8da314d 100644 --- a/net/vhost-user.c +++ b/net/vhost-user.c @@ -153,6 +153,10 @@ static void vhost_user_cleanup(NetClientState *nc) if (nc->queue_index =3D=3D 0) { Chardev *chr =3D qemu_chr_fe_get_driver(&s->chr); =20 + if (s->watch) { + g_source_remove(s->watch); + s->watch =3D 0; + } qemu_chr_fe_deinit(&s->chr); object_unparent(OBJECT(chr)); } --=20 1.8.3.1