]> git.ipfire.org Git - thirdparty/libvirt.git/commit
Don't crash if a connection closes early
authorJiri Denemark <jdenemar@redhat.com>
Thu, 9 Jan 2014 21:26:40 +0000 (22:26 +0100)
committerEric Blake <eblake@redhat.com>
Wed, 15 Jan 2014 04:31:23 +0000 (21:31 -0700)
commitb06acd14cae3e2322e3bdc299447d8bebf7348e0
tree8a78df52ac9819f94b152f7e6c0100bcb3a93d4f
parentc6fbbe85aa496d178d5e4188bee166a5abb97029
Don't crash if a connection closes early

https://bugzilla.redhat.com/show_bug.cgi?id=1047577

When a client closes its connection to libvirtd early during
virConnectOpen, more specifically just after making
REMOTE_PROC_CONNECT_SUPPORTS_FEATURE call to check if
VIR_DRV_FEATURE_PROGRAM_KEEPALIVE is supported without even waiting for
the result, libvirtd may crash due to a race in keep-alive
initialization. Once receiving the REMOTE_PROC_CONNECT_SUPPORTS_FEATURE
call, the daemon's event loop delegates it to a worker thread. In case
the event loop detects EOF on the connection and calls
virNetServerClientClose before the worker thread starts to handle
REMOTE_PROC_CONNECT_SUPPORTS_FEATURE call, client->keepalive will be
disposed by the time virNetServerClientStartKeepAlive gets called from
remoteDispatchConnectSupportsFeature. Because the flow is common for
both authenticated and read-only connections, even unprivileged clients
may cause the daemon to crash.

To avoid the crash, virNetServerClientStartKeepAlive needs to check if
the connection is still open before starting keep-alive protocol.

Every libvirt release since 0.9.8 is affected by this bug.

(cherry picked from commit 173c2914734eb5c32df6d35a82bf503e12261bcf)
src/rpc/virnetserverclient.c