Go to file
Michael Qiu 076d467aac blockjob: Fix crash with IOthread when block commit after snapshot
Currently, if guest has workloads, IO thread will acquire aio_context
lock before do io_submit, it leads to segmentfault when do block commit
after snapshot. Just like below:

Program received signal SIGSEGV, Segmentation fault.

[Switching to Thread 0x7f7c7d91f700 (LWP 99907)]
0x00005576d0f65aab in bdrv_mirror_top_pwritev at ../block/mirror.c:1437
1437    ../block/mirror.c: No such file or directory.
(gdb) p s->job
$17 = (MirrorBlockJob *) 0x0
(gdb) p s->stop
$18 = false

Call trace of IO thread:
0  0x00005576d0f65aab in bdrv_mirror_top_pwritev at ../block/mirror.c:1437
1  0x00005576d0f7f3ab in bdrv_driver_pwritev at ../block/io.c:1174
2  0x00005576d0f8139d in bdrv_aligned_pwritev at ../block/io.c:1988
3  0x00005576d0f81b65 in bdrv_co_pwritev_part at ../block/io.c:2156
4  0x00005576d0f8e6b7 in blk_do_pwritev_part at ../block/block-backend.c:1260
5  0x00005576d0f8e84d in blk_aio_write_entry at ../block/block-backend.c:1476
...

Switch to qemu main thread:
0  0x00007f903be704ed in __lll_lock_wait at
/lib/../lib64/libpthread.so.0
1  0x00007f903be6bde6 in _L_lock_941 at /lib/../lib64/libpthread.so.0
2  0x00007f903be6bcdf in pthread_mutex_lock at
/lib/../lib64/libpthread.so.0
3  0x0000564b21456889 in qemu_mutex_lock_impl at
../util/qemu-thread-posix.c:79
4  0x0000564b213af8a5 in block_job_add_bdrv at ../blockjob.c:224
5  0x0000564b213b00ad in block_job_create at ../blockjob.c:440
6  0x0000564b21357c0a in mirror_start_job at ../block/mirror.c:1622
7  0x0000564b2135a9af in commit_active_start at ../block/mirror.c:1867
8  0x0000564b2133d132 in qmp_block_commit at ../blockdev.c:2768
9  0x0000564b2141fef3 in qmp_marshal_block_commit at
qapi/qapi-commands-block-core.c:346
10 0x0000564b214503c9 in do_qmp_dispatch_bh at
../qapi/qmp-dispatch.c:110
11 0x0000564b21451996 in aio_bh_poll at ../util/async.c:164
12 0x0000564b2146018e in aio_dispatch at ../util/aio-posix.c:381
13 0x0000564b2145187e in aio_ctx_dispatch at ../util/async.c:306
14 0x00007f9040239049 in g_main_context_dispatch at
/lib/../lib64/libglib-2.0.so.0
15 0x0000564b21447368 in main_loop_wait at ../util/main-loop.c:232
16 0x0000564b21447368 in main_loop_wait at ../util/main-loop.c:255
17 0x0000564b21447368 in main_loop_wait at ../util/main-loop.c:531
18 0x0000564b212304e1 in qemu_main_loop at ../softmmu/runstate.c:721
19 0x0000564b20f7975e in main at ../softmmu/main.c:50

In IO thread when do bdrv_mirror_top_pwritev, the job is NULL, and stop field
is false, this means the MirrorBDSOpaque "s" object has not been initialized
yet, and this object is initialized by block_job_create(), but the initialize
process is stuck in acquiring the lock.

In this situation, IO thread come to bdrv_mirror_top_pwritev(),which means that
mirror-top node is already inserted into block graph, but its bs->opaque->job
is not initialized.

The root cause is that qemu main thread do release/acquire when hold the lock,
at the same time, IO thread get the lock after release stage, and the crash
occured.

Actually, in this situation, job->job.aio_context will not equal to
qemu_get_aio_context(), and will be the same as bs->aio_context,
thus, no need to release the lock, becasue bdrv_root_attach_child()
will not change the context.

This patch fix this issue.

Fixes: 132ada80 "block: Adjust AioContexts when attaching nodes"

Signed-off-by: Michael Qiu <qiudayu@huayun.com>
Message-Id: <20210203024059.52683-1-08005325@163.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2021-02-15 15:10:14 +01:00
.github .github: point Repo Lockdown bot to GitLab repo 2021-02-09 20:53:56 +00:00
.gitlab-ci.d gitlab-ci: Add alpine to pipeline 2021-01-20 10:46:54 +01:00
accel accel/tcg: Add URL of clang bug to comment about our workaround 2021-02-11 11:50:14 +00:00
audio audio: space prohibited between function name and parenthesis'(' 2021-01-15 11:49:26 +01:00
authz authz-simple: Check that 'identity' property is set 2020-11-18 10:51:35 +00:00
backends memory: alloc RAM from file at offset 2021-02-09 20:53:56 +00:00
block bitmaps patches for 2021-02-12 2021-02-13 21:26:00 +00:00
bsd-user accel: replace struct CpusAccel with AccelOpsClass 2021-02-05 10:24:15 -10:00
capstone@f8b1b83301 capstone: Update to upstream "next" branch 2020-10-03 04:23:14 -05:00
chardev chardev: check if the chardev is registered for yanking 2021-02-04 15:58:54 +01:00
contrib vhost-user-gpu: handle display-info in a callback 2021-02-04 15:58:54 +01:00
crypto crypto: Add spaces around operator 2021-01-29 17:07:53 +00:00
default-configs Testing, gdbstub and semihosting patches: 2021-01-18 12:10:20 +00:00
disas build-system: clean up TCG/TCI configury 2021-01-21 13:00:41 +01:00
docs bswap.h: Remove unused float-access functions 2021-02-15 09:38:50 +00:00
dtc@85e5d83984 Makefile: dtc: update, build the libfdt target 2020-06-16 14:49:05 +01:00
dump qapi: More complex uses of QAPI_LIST_APPEND 2021-01-28 08:08:45 +01:00
fpu softfloat: Define misc operations for bfloat16 2020-08-28 10:48:07 -07:00
fsdev meson: Declare have_virtfs_proxy_helper in main meson.build 2021-01-23 15:55:04 -05:00
gdb-xml target/riscv: Remove built-in GDB XML files for CSRs 2021-01-16 10:57:21 -08:00
hw Pull request m68k-20210212 2021-02-13 18:16:43 +00:00
include bswap.h: Remove unused float-access functions 2021-02-15 09:38:50 +00:00
io io: error_prepend() in qio_channel_readv_full_all() causes segfault 2021-02-12 07:50:59 -06:00
libdecnumber qemu/: fix some comment spelling errors 2020-09-17 20:35:43 +02:00
linux-headers Update linux headers to 5.11-rc2 2021-01-21 11:19:45 +01:00
linux-user accel: replace struct CpusAccel with AccelOpsClass 2021-02-05 10:24:15 -10:00
meson@776acd2a80 submodules: bump meson to 0.55.3 2020-10-17 10:45:42 -04:00
migration migration: dirty-bitmap: Allow control of bitmap persistence 2021-02-12 15:24:36 -06:00
monitor migration: introduce a delete_snapshot wrapper 2021-02-08 11:19:51 +00:00
nbd nbd/server: Quiesce coroutines on context switch 2021-01-20 14:48:54 -06:00
net Trivial patches 20210129 2021-01-29 10:10:43 +00:00
pc-bios pc-bios: update mirror URLs to GitLab 2021-02-09 20:53:56 +00:00
plugins cfi: Initial support for cfi-icall in QEMU 2021-01-02 21:03:35 +01:00
po configure: move gettext detection to meson.build 2021-01-02 21:03:09 +01:00
python python: add __repr__ to ConsoleSocket to aid debugging 2021-01-02 21:03:09 +01:00
qapi migration: dirty-bitmap: Allow control of bitmap persistence 2021-02-12 15:24:36 -06:00
qga qapi: More complex uses of QAPI_LIST_APPEND 2021-01-28 08:08:45 +01:00
qobject qobject: braces {} are necessary for all arms of this statement 2021-02-04 13:20:29 +01:00
qom qom: Allow optional sugar props 2021-02-08 16:57:37 +11:00
replay migration: wire up support for snapshot device selection 2021-02-08 11:19:51 +00:00
roms qboot: update to latest upstream 2020-11-20 10:48:53 -05:00
scripts travis.yml: Move gprof/gcov test across to gitlab 2021-02-15 09:38:19 +00:00
scsi qapi: Use QAPI_LIST_APPEND in trivial cases 2021-01-28 08:08:45 +01:00
slirp@8f43a99191 slirp: update to fix CVE-2020-29129 CVE-2020-29130 2020-11-27 20:57:11 +04:00
softmmu memory: alloc RAM from file at offset 2021-02-09 20:53:56 +00:00
storage-daemon qemu-storage-daemon: Enable object-add 2021-02-15 15:10:14 +01:00
stubs qapi/meson: Restrict qdev code to system-mode emulation 2021-02-08 14:43:55 +01:00
subprojects/libvhost-user build-sys: add libvhost-user missing dependencies 2021-01-23 09:26:41 -05:00
target target/ppc: Drop use of gdb_get_float64() and ldfq_p() 2021-02-15 09:38:44 +00:00
tcg tcg/tci: Remove TCG_CONST 2021-02-05 10:24:14 -10:00
tests iotests: Consistent $IMGOPTS boundary matching 2021-02-15 15:10:14 +01:00
tools virtiofsd: Add restart_syscall to the seccomp whitelist 2021-02-04 17:50:08 +00:00
trace trace: add meson custom_target() depend_files for tracetool 2021-02-01 10:50:55 +00:00
ui display/ui: add a callback to indicate GL state is flushed 2021-02-04 15:58:54 +01:00
util memory: alloc RAM from file at offset 2021-02-09 20:53:56 +00:00
.cirrus.yml cirrus/msys2: Cache msys2 mingw in a better way. 2021-01-12 12:38:03 +01:00
.dir-locals.el
.editorconfig meson: rename included C source files to .c.inc 2020-08-21 06:18:30 -04:00
.exrc
.gdbinit .gdbinit: load QEMU sub-commands when gdb starts 2017-06-07 14:38:45 +01:00
.gitattributes buildsys: Help git-diff adding .gitattributes config file 2020-11-18 09:33:16 +01:00
.gitignore Makefile: add GNU global tags support 2021-01-18 10:04:31 +00:00
.gitlab-ci.yml travis.yml: Move the -fsanitize=thread testing to the gitlab-CI 2021-02-15 09:38:26 +00:00
.gitmodules gitmodules: use GitLab repos instead of qemu.org 2021-02-09 20:53:56 +00:00
.gitpublish Add a git-publish configuration file 2018-03-05 09:03:17 +00:00
.mailmap MAINTAINERS: chenhc@lemote.com -> chenhuacai@kernel.org 2020-12-13 16:00:58 +01:00
.patchew.yml ci: store Patchew configuration in the tree 2019-06-03 14:03:02 +02:00
.readthedocs.yml readthedocs: build with Python 3.6 2020-10-05 16:30:45 +01:00
.travis.yml travis-ci: Disable C++ optional objects on AArch64 container 2021-02-15 09:38:33 +00:00
block.c block: use return status of bdrv_append() 2021-02-12 15:39:44 -06:00
blockdev-nbd.c qemu-nbd: Use SOMAXCONN for socket listen() backlog 2021-02-12 07:42:08 -06:00
blockdev.c block: use return status of bdrv_append() 2021-02-12 15:39:44 -06:00
blockjob.c blockjob: Fix crash with IOthread when block commit after snapshot 2021-02-15 15:10:14 +01:00
CODING_STYLE.rst CODING_STYLE.rst: Be less strict about 80 character limit 2020-12-13 17:51:33 +01:00
configure multi-process: Add config option for multi-process QEMU 2021-02-09 20:53:56 +00:00
COPYING
COPYING.LIB COPYING.LIB: Synchronize the LGPL 2.1 with the version from gnu.org 2019-01-30 11:01:22 +01:00
cpu.c accel/tcg: split TCG-only code from cpu_exec_realizefn 2021-02-05 10:24:14 -10:00
cpus-common.c overall/alpha tcg cpus|hppa: Fix Lesser GPL version number 2020-11-15 16:43:54 +01:00
disas.c disas: Push const down through host disassembly 2021-01-07 05:09:42 -10:00
exec-vary.c nomaintainer: Fix Lesser GPL version number 2020-11-15 17:04:40 +01:00
gdbstub.c gdbstub: Fix handle_query_xfer_auxv 2021-02-08 10:55:15 +00:00
gitdm.config contrib: gitdm: add a mapping for Janus Technologies 2019-03-12 19:31:29 +00:00
hmp-commands-info.hx replay: introduce info hmp/qmp command 2020-10-06 08:34:49 +02:00
hmp-commands.hx hmp: remove "change vnc TARGET" command 2021-01-23 15:55:07 -05:00
iothread.c multi-process: define MPQemuMsg format and transmission functions 2021-02-10 09:23:28 +00:00
job-qmp.c qapi: Use QAPI_LIST_APPEND in trivial cases 2021-01-28 08:08:45 +01:00
job.c job: add .cancel handler for the driver 2021-02-12 11:23:19 -06:00
Kconfig Makefile: simplify MINIKCONF rules 2020-07-10 18:02:21 -04:00
Kconfig.host multi-process: Add config option for multi-process QEMU 2021-02-09 20:53:56 +00:00
LICENSE tcg/LICENSE: Remove out of date claim about TCG subdirectory licensing 2019-11-11 15:11:21 +01:00
MAINTAINERS MAINTAINERS: Add gdbstub.h to the "GDB stub" section 2021-02-15 09:38:33 +00:00
Makefile tests/docker: alias docker-help target for consistency 2021-02-08 09:41:00 +00:00
memory_ldst.c.inc fuzz: ignore address_space_map is_write flag 2021-02-08 14:43:54 +01:00
meson_options.txt configure: Improve TCI feature description 2021-02-08 14:43:55 +01:00
meson.build multi-process: define MPQemuMsg format and transmission functions 2021-02-10 09:23:28 +00:00
module-common.c
os-posix.c os: deprecate the -enable-fips option and QEMU's FIPS enforcement 2021-01-29 17:07:53 +00:00
os-win32.c vl: relocate paths to data directories 2020-09-30 19:11:36 +02:00
qemu-bridge-helper.c qemu-bridge-helper: relocate path to default ACL 2020-09-30 19:11:36 +02:00
qemu-edid.c qemu-edid: drop cast 2020-10-14 06:05:56 +02:00
qemu-img-cmds.hx qemu-img: add support for rate limit in qemu-img convert 2020-10-27 15:26:20 +01:00
qemu-img.c qapi: Use QAPI_LIST_APPEND in trivial cases 2021-01-28 08:08:45 +01:00
qemu-io-cmds.c qemu-io: add preallocate mode parameter for truncate command 2020-12-18 12:35:55 +01:00
qemu-io.c trace: remove argument from trace_init_file 2020-11-11 13:08:09 +00:00
qemu-keymap.c Include qemu-common.h exactly where needed 2019-06-12 13:20:20 +02:00
qemu-nbd.c qemu-nbd: Permit --shared=0 for unlimited clients 2021-02-12 07:42:08 -06:00
qemu-options-wrapper.h qemu-img: remove references to GEN_DOCS 2018-05-20 08:35:54 +03:00
qemu-options.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
qemu-options.hx machine: add missing doc for memory-backend option 2021-02-08 14:43:54 +01:00
qemu.nsi nsis: adjust for new MinGW paths 2021-01-23 15:55:05 -05:00
qemu.sasl Default to GSSAPI (Kerberos) instead of DIGEST-MD5 for SASL 2017-05-09 14:41:47 +01:00
README.rst docs: update README to use GitLab repo URLs 2021-02-09 20:53:56 +00:00
replication.c replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
replication.h Include qemu/module.h where needed, drop it from qemu-common.h 2019-06-12 13:18:33 +02:00
thunk.c overall usermode...: Fix Lesser GPL version number 2020-11-15 16:43:40 +01:00
trace-events trace-events: Fix attribution of trace points to source 2020-09-09 17:17:58 +01:00
VERSION Open 6.0 development tree 2020-12-08 21:04:57 +00:00
version.rc configure: remove CONFIG_FILEVERSION and CONFIG_PRODUCTVERSION 2021-01-02 21:03:37 +01:00

===========
QEMU README
===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:


.. code-block:: shell

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

* `<https://qemu.org/Hosts/Linux>`_
* `<https://qemu.org/Hosts/Mac>`_
* `<https://qemu.org/Hosts/W32>`_


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

.. code-block:: shell

   git clone https://gitlab.com/qemu-project/qemu.git

When submitting patches, one common approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the CODING_STYLE.rst file.

Additional information on submitting patches can be found online via
the QEMU website

* `<https://qemu.org/Contribute/SubmitAPatch>`_
* `<https://qemu.org/Contribute/TrivialPatches>`_

The QEMU website is also maintained under source control.

.. code-block:: shell

  git clone https://gitlab.com/qemu-project/qemu-web.git

* `<https://www.qemu.org/2017/02/04/the-new-qemu-website-is-up/>`_

A 'git-publish' utility was created to make above process less
cumbersome, and is highly recommended for making regular contributions,
or even just for sending consecutive patch series revisions. It also
requires a working 'git send-email' setup, and by default doesn't
automate everything, so you may want to go through the above steps
manually for once.

For installation instructions, please go to

*  `<https://github.com/stefanha/git-publish>`_

The workflow with 'git-publish' is:

.. code-block:: shell

  $ git checkout master -b my-feature
  $ # work on new commits, add your 'Signed-off-by' lines to each
  $ git publish

Your patch series will be sent and tagged as my-feature-v1 if you need to refer
back to it in the future.

Sending v2:

.. code-block:: shell

  $ git checkout my-feature # same topic branch
  $ # making changes to the commits (using 'git rebase', for example)
  $ git publish

Your patch series will be sent with 'v2' tag in the subject and the git tip
will be tagged as my-feature-v2.

Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

* `<https://bugs.launchpad.net/qemu/>`_

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

* `<https://qemu.org/Contribute/ReportABug>`_


ChangeLog
=========

For version history and release notes, please visit
`<https://wiki.qemu.org/ChangeLog/>`_ or look at the git history for
more detailed information.


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

* `<mailto:qemu-devel@nongnu.org>`_
* `<https://lists.nongnu.org/mailman/listinfo/qemu-devel>`_
* #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

* `<https://qemu.org/Contribute/StartHere>`_