]> git.ipfire.org Git - thirdparty/libvirt.git/commit
mdev: Fix daemon crash on domain shutdown after reconnect
authorErik Skultety <eskultet@redhat.com>
Fri, 28 Apr 2017 07:24:31 +0000 (09:24 +0200)
committerErik Skultety <eskultet@redhat.com>
Thu, 4 May 2017 06:30:47 +0000 (08:30 +0200)
commit950f1a395649a95a5f03ce353099b15a42b2f303
treebc0e0873d1946e0a59abfd05157d09017f35e9a6
parent5d4ecee94fdcf128be95a06a62844fe87cf9c613
mdev: Fix daemon crash on domain shutdown after reconnect

The problem resides in virHostdevUpdateActiveMediatedDevices which gets
called during qemuProcessReconnect. The issue here is that
virMediatedDeviceListAdd takes a pointer to the item to be added to the
list to which VIR_APPEND_ELEMENT is used, which also clears the pointer.
However, in this case only the local copy of the pointer got cleared,
leaving the original pointing to valid memory. To sum it up, during
cleanup phase, the original pointer is freed and the daemon crashes
basically any time it would access it.

Backtrace:
0x00007ffff3ccdeba in __strcmp_sse2_unaligned
0x00007ffff72a444a in virMediatedDeviceListFindIndex
0x00007ffff7241446 in virHostdevReAttachMediatedDevices
0x00007fffc60215d9 in qemuHostdevReAttachMediatedDevices
0x00007fffc60216dc in qemuHostdevReAttachDomainDevices
0x00007fffc6046e6f in qemuProcessStop
0x00007fffc6091596 in processMonitorEOFEvent
0x00007fffc6091793 in qemuProcessEventHandler
0x00007ffff7294bf5 in virThreadPoolWorker
0x00007ffff7294184 in virThreadHelper
0x00007ffff3fdc3c4 in start_thread () from /lib64/libpthread.so.0
0x00007ffff3d269cf in clone () from /lib64/libc.so.6

Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1446455

(cherry picked from commit 92e30a4dace54d06433f763e1acba0a81bb5c82e)
Signed-off-by: Erik Skultety <eskultet@redhat.com>
src/util/virhostdev.c
src/util/virmdev.c
src/util/virmdev.h