From nobody Sun Sep 28 15:27:18 2025 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1759049856; cv=none; d=zohomail.com; s=zohoarc; b=kY7DCg/MLfslxbBFFKLztA/NQKnJT7EAXpslHtzPYwoJOs+eGlSzZmlA4OAgbINiEpUTYUAtpYzky+7dFSFE2Li+/U65L0y2TK03yeJ6TXJiPIldh4VbHMQ9v5DoMoWx02zNXWv8ozY2baIiAQfjmtviVtpa42armhsO9PD1rTI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1759049856; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=95L43Biap+ZMJ1mQGIMpfUZB5tlHi8COoJYlDkGuwwE=; b=XF6mBr6fvUXOpghFRLl2f3eXa1ksWJTpFbio3nchyHJnkkfatKKw57ujbQeJe6UjlNN0li2J1qyYb6xVEDxX8YmlAo1/4fVLflsJc++cQwsI6EY921u969Di1ifiBUGF3JJTI6d9wvlCtFacwqAqH81neIKSB5la6VGSJxzNGmo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1759049856221557.2659358998407; Sun, 28 Sep 2025 01:57:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1v2nCH-0006VF-WC; Sun, 28 Sep 2025 04:55:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1v2nCF-0006UO-4C for qemu-devel@nongnu.org; Sun, 28 Sep 2025 04:55:55 -0400 Received: from mgamail.intel.com ([192.198.163.12]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1v2nC8-00044H-Lw for qemu-devel@nongnu.org; Sun, 28 Sep 2025 04:55:54 -0400 Received: from orviesa007.jf.intel.com ([10.64.159.147]) by fmvoesa106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 28 Sep 2025 01:55:28 -0700 Received: from unknown (HELO gnr-sp-2s-612.sh.intel.com) ([10.112.230.229]) by orviesa007-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 28 Sep 2025 01:55:26 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1759049749; x=1790585749; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=kPLupQPAUBUcNZDsIGDQVNkPtYijna1nTxTrWEhgc4I=; b=mX4TshKd3GFuU01vdwwvGRDTy+NyqBXvfKLeg6F3P20kNYplQDKs2D7e pflVGcnMNMR/daHwOL/KwG9kUAqVz9BnpVq7Yq7GSy3TLB3qe8J6n1709 c0pUvxIREgQgepEsFGdenlQM+KVDpH4y+M9E7aBNfTu/Meums8pHt9fba RNM4GupWJgrunw0zGw6dkB2jpF35YLzcpmAW+8VWfb6/6JSZ0SBBvHdbx L/iv1FoCsXOzmXfF54m7x90CQWQcQhqUJDTbv1rpbF5jwI6tkUm+v9lp/ Dw0BdGfSqld9TjlhOqYjkCjzVZzWV2Ew1t641MvFBmiVVC3DEAzqwvxp1 g==; X-CSE-ConnectionGUID: 5IXCqz8JRJChPZHJbjrgaQ== X-CSE-MsgGUID: uNC98ggHQeapacoNgGd3VQ== X-IronPort-AV: E=McAfee;i="6800,10657,11566"; a="65167447" X-IronPort-AV: E=Sophos;i="6.18,299,1751266800"; d="scan'208";a="65167447" X-CSE-ConnectionGUID: Pw3ed5hcTn+pDadMFJaZNg== X-CSE-MsgGUID: bXU8akrsSMKkdwdkaEJEGA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.18,299,1751266800"; d="scan'208";a="177810823" From: Zhenzhong Duan To: qemu-devel@nongnu.org Cc: alex.williamson@redhat.com, clg@redhat.com, eric.auger@redhat.com, steven.sistare@oracle.com, Zhenzhong Duan , Markus Armbruster Subject: [PATCH v2 6/6] accel/kvm: Fix SIGSEGV when execute "query-balloon" after CPR transfer Date: Sun, 28 Sep 2025 04:54:32 -0400 Message-ID: <20250928085432.40107-7-zhenzhong.duan@intel.com> X-Mailer: git-send-email 2.47.1 In-Reply-To: <20250928085432.40107-1-zhenzhong.duan@intel.com> References: <20250928085432.40107-1-zhenzhong.duan@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=192.198.163.12; envelope-from=zhenzhong.duan@intel.com; helo=mgamail.intel.com X-Spam_score_int: -47 X-Spam_score: -4.8 X-Spam_bar: ---- X-Spam_report: (-4.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.442, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1759049856539116600 Content-Type: text/plain; charset="utf-8" After CPR transfer, source QEMU closes kvm fd and sets kvm_state to NULL, "query-balloon" will check kvm_state->sync_mmu and trigger NULL pointer reference. We don't need to NULL kvm_state as all states in kvm_state aren't released actually. Just closing kvm fd is enough so we could still query states through "query_*" qmp command. Opportunistically drop an unnecessary check in kvm_close(). Fixes: 7ed0919119b0 ("migration: close kvm after cpr") Suggested-by: Markus Armbruster Signed-off-by: Zhenzhong Duan --- accel/kvm/kvm-all.c | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c index 23fd491441..b4c717290d 100644 --- a/accel/kvm/kvm-all.c +++ b/accel/kvm/kvm-all.c @@ -639,13 +639,10 @@ void kvm_close(void) cpu->kvm_vcpu_stats_fd =3D -1; } =20 - if (kvm_state && kvm_state->fd !=3D -1) { - close(kvm_state->vmfd); - kvm_state->vmfd =3D -1; - close(kvm_state->fd); - kvm_state->fd =3D -1; - } - kvm_state =3D NULL; + close(kvm_state->vmfd); + kvm_state->vmfd =3D -1; + close(kvm_state->fd); + kvm_state->fd =3D -1; } =20 /* --=20 2.47.1