Go to file
Kevin Wolf 1bffe1ae7a block: Fix AioContext switch for bs->drv == NULL
Even for block nodes with bs->drv == NULL, we can't just ignore a
bdrv_set_aio_context() call. Leaving the node in its old context can
mean that it's still in an iothread context in bdrv_close_all() during
shutdown, resulting in an attempted unlock of the AioContext lock which
we don't hold.

This is an example stack trace of a related crash:

 #0  0x00007ffff59da57f in raise () at /lib64/libc.so.6
 #1  0x00007ffff59c4895 in abort () at /lib64/libc.so.6
 #2  0x0000555555b97b1e in error_exit (err=<optimized out>, msg=msg@entry=0x555555d386d0 <__func__.19059> "qemu_mutex_unlock_impl") at util/qemu-thread-posix.c:36
 #3  0x0000555555b97f7f in qemu_mutex_unlock_impl (mutex=mutex@entry=0x5555568002f0, file=file@entry=0x555555d378df "util/async.c", line=line@entry=507) at util/qemu-thread-posix.c:97
 #4  0x0000555555b92f55 in aio_context_release (ctx=ctx@entry=0x555556800290) at util/async.c:507
 #5  0x0000555555b05cf8 in bdrv_prwv_co (child=child@entry=0x7fffc80012f0, offset=offset@entry=131072, qiov=qiov@entry=0x7fffffffd4f0, is_write=is_write@entry=true, flags=flags@entry=0)
         at block/io.c:833
 #6  0x0000555555b060a9 in bdrv_pwritev (qiov=0x7fffffffd4f0, offset=131072, child=0x7fffc80012f0) at block/io.c:990
 #7  0x0000555555b060a9 in bdrv_pwrite (child=0x7fffc80012f0, offset=131072, buf=<optimized out>, bytes=<optimized out>) at block/io.c:990
 #8  0x0000555555ae172b in qcow2_cache_entry_flush (bs=bs@entry=0x555556810680, c=c@entry=0x5555568cc740, i=i@entry=0) at block/qcow2-cache.c:51
 #9  0x0000555555ae18dd in qcow2_cache_write (bs=bs@entry=0x555556810680, c=0x5555568cc740) at block/qcow2-cache.c:248
 #10 0x0000555555ae15de in qcow2_cache_flush (bs=0x555556810680, c=<optimized out>) at block/qcow2-cache.c:259
 #11 0x0000555555ae16b1 in qcow2_cache_flush_dependency (c=0x5555568a1700, c=0x5555568a1700, bs=0x555556810680) at block/qcow2-cache.c:194
 #12 0x0000555555ae16b1 in qcow2_cache_entry_flush (bs=bs@entry=0x555556810680, c=c@entry=0x5555568a1700, i=i@entry=0) at block/qcow2-cache.c:194
 #13 0x0000555555ae18dd in qcow2_cache_write (bs=bs@entry=0x555556810680, c=0x5555568a1700) at block/qcow2-cache.c:248
 #14 0x0000555555ae15de in qcow2_cache_flush (bs=bs@entry=0x555556810680, c=<optimized out>) at block/qcow2-cache.c:259
 #15 0x0000555555ad242c in qcow2_inactivate (bs=bs@entry=0x555556810680) at block/qcow2.c:2124
 #16 0x0000555555ad2590 in qcow2_close (bs=0x555556810680) at block/qcow2.c:2153
 #17 0x0000555555ab0c62 in bdrv_close (bs=0x555556810680) at block.c:3358
 #18 0x0000555555ab0c62 in bdrv_delete (bs=0x555556810680) at block.c:3542
 #19 0x0000555555ab0c62 in bdrv_unref (bs=0x555556810680) at block.c:4598
 #20 0x0000555555af4d72 in blk_remove_bs (blk=blk@entry=0x5555568103d0) at block/block-backend.c:785
 #21 0x0000555555af4dbb in blk_remove_all_bs () at block/block-backend.c:483
 #22 0x0000555555aae02f in bdrv_close_all () at block.c:3412
 #23 0x00005555557f9796 in main (argc=<optimized out>, argv=<optimized out>, envp=<optimized out>) at vl.c:4776

The reproducer I used is a qcow2 image on gluster volume, where the
virtual disk size (4 GB) is larger than the gluster volume size (64M),
so we can easily trigger an ENOSPC. This backend is assigned to a
virtio-blk device using an iothread, and then from the guest a
'dd if=/dev/zero of=/dev/vda bs=1G count=1' causes the VM to stop
because of an I/O error. qemu_gluster_co_flush_to_disk() sets
bs->drv = NULL on error, so when virtio-blk stops the dataplane, the
block nodes stay in the iothread AioContext. A 'quit' monitor command
issued from this paused state crashes the process.

Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1631227
Cc: qemu-stable@nongnu.org
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
Reviewed-by: Eric Blake <eblake@redhat.com>
Reviewed-by: Max Reitz <mreitz@redhat.com>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
2019-04-30 15:29:00 +02:00
accel cputlb: Fix io_readx() to respect the access_type 2019-04-25 10:40:06 -07:00
audio audio: fix audio timer rate conversion bug 2019-04-02 07:50:49 +02:00
authz filemon: fix watch IDs to avoid potential wraparound issues 2019-04-02 13:52:02 +01:00
backends vhost-user: simplify vhost_user_init/vhost_user_cleanup 2019-03-12 21:22:31 -04:00
block block/qapi: Clean up how we print to monitor or stdout 2019-04-18 22:18:59 +02:00
bsd-user cpu: Rename parse_cpu_model() to parse_cpu_option() 2019-04-25 14:17:35 -03:00
capstone@22ead3e0bf disas: Add capstone as submodule 2017-10-26 11:56:20 +02:00
chardev char-pty: Print "char device redirected" message to stdout 2019-04-18 22:18:59 +02:00
contrib contrib/rdmacm-mux: Fix out-of-bounds risk 2019-03-16 15:45:12 +02:00
crypto trace-events: Shorten file names in comments 2019-03-22 16:18:07 +00:00
default-configs Add generic Nios II board. 2019-04-29 16:09:51 +01:00
disas disas: Rename include/disas/bfd.h back to include/disas/dis-asm.h 2019-04-18 22:18:59 +02:00
docs Machine queue, 2019-04-25 2019-04-26 14:30:18 +01:00
dtc@88f18909db Update dtc/libfdt submodule to v1.4.7 2018-10-02 13:53:26 +10:00
fpu hardfloat: fix float32/64 fused multiply-add 2019-03-25 10:35:32 +00:00
fsdev qemu/queue.h: leave head structs anonymous unless necessary 2019-01-11 15:46:55 +01:00
gdb-xml RISC-V: Add 64-bit gdb xml files. 2019-03-19 05:13:24 -07:00
hw hw/devices: Move SMSC 91C111 declaration into a new header 2019-04-29 17:57:21 +01:00
include hw/devices: Move SMSC 91C111 declaration into a new header 2019-04-29 17:57:21 +01:00
io trace-events: Shorten file names in comments 2019-03-22 16:18:07 +00:00
libdecnumber build: remove CONFIG_LIBDECNUMBER 2017-10-16 18:03:52 +02:00
linux-headers linux-headers: add linux/mman.h. 2019-04-25 14:17:36 -03:00
linux-user cpu: Rename parse_cpu_model() to parse_cpu_option() 2019-04-25 14:17:35 -03:00
migration migration/ram.c: Fix use-after-free in multifd_recv_unfill_packet() 2019-04-09 20:46:34 +01:00
nbd nbd/client: Fix error message for server with unusable sizing 2019-04-08 13:51:25 -05:00
net net: tap: use qemu_set_nonblock 2019-03-29 15:22:18 +08:00
pc-bios Support for booting from a vfio-ccw passthrough dasd device 2019-04-25 14:09:20 +02:00
po po/Makefile: Modern shell scripting (use $() instead of ``) 2018-10-24 07:39:10 +01:00
python/qemu Python queue, 2019-02-22 2019-03-07 16:16:02 +00:00
qapi qapi/migration.json: Rename COLOStatus last_mode to last-mode 2019-04-02 13:32:15 +02:00
qga qga: process_event() simplification 2019-03-18 10:48:06 -05:00
qobject json: Fix off-by-one assert check in next_state() 2019-03-26 08:10:11 +01:00
qom qom/cpu: Simplify how CPUClass:cpu_dump_state() prints 2019-04-18 22:18:59 +02:00
replay replay: Exit on errors reading from replay log 2018-11-08 13:24:35 +00:00
roms roms: build edk2 firmware binaries and variable store templates 2019-04-17 15:38:35 +02:00
scripts scripts/update-linux-headers: add linux/mman.h 2019-04-25 14:17:36 -03:00
scsi log: Make glib logging go through QEMU 2019-04-17 19:08:27 +02:00
slirp slirp: Gcc 9 -O3 fix 2019-04-15 20:01:18 +02:00
stubs qemu-print: New qemu_printf(), qemu_vprintf() etc. 2019-04-18 22:18:59 +02:00
target target/arm: Enable FPU for Cortex-M4 and Cortex-M33 2019-04-29 17:36:03 +01:00
tcg tcg/arm: Restrict constant pool displacement to 12 bits 2019-04-25 10:39:39 -07:00
tests tests/qemu-iotests: Fix output of qemu-io related tests 2019-04-30 15:29:00 +02:00
trace trace: Simplify how st_print_trace_file_status() prints 2019-04-18 22:18:59 +02:00
ui curses: fix wchar_t printf warning 2019-04-12 12:58:00 +01:00
util util/mmap-alloc: support MAP_SYNC in qemu_ram_mmap() 2019-04-25 14:17:36 -03:00
.cirrus.yml cirrus.yml: Add macOS continuous integration task 2019-03-08 09:54:29 +01:00
.dir-locals.el Add .dir-locals.el file to configure emacs coding style 2015-10-08 19:46:01 +03:00
.editorconfig editorconfig: set emacs mode 2018-11-01 12:13:12 +04:00
.exrc qemu: add .exrc 2012-09-07 09:02:44 +03:00
.gdbinit .gdbinit: load QEMU sub-commands when gdb starts 2017-06-07 14:38:45 +01:00
.gitignore Makefile: install the edk2 firmware images and their descriptors 2019-04-17 15:38:35 +02:00
.gitlab-ci.yml Add a gitlab-ci file for Continuous Integration testing on Gitlab 2019-02-22 09:32:32 +00:00
.gitmodules roms: add the edk2 project as a git submodule 2019-02-21 12:28:41 -05:00
.gitpublish Add a git-publish configuration file 2018-03-05 09:03:17 +00:00
.mailmap maint: Grammar fix to mailmap 2018-12-11 18:35:54 +01:00
.shippable.yml .shippable.yml: disable the win cross tests 2018-12-17 13:02:12 +00:00
.travis.yml .travis.yml: reduce number of targets built while disabling things 2019-03-25 10:34:46 +00:00
arch_init.c arch_init: sort architectures 2018-06-01 19:20:38 +03:00
balloon.c balloon: Allow multiple inhibit users 2018-08-17 09:27:15 -06:00
block.c block: Fix AioContext switch for bs->drv == NULL 2019-04-30 15:29:00 +02:00
blockdev-nbd.c nbd: allow authorization with nbd-server-start QMP command 2019-03-06 11:05:27 -06:00
blockdev.c blockdev: Make -drive format=help print to stdout 2019-04-18 22:18:59 +02:00
blockjob.c blockjob: fix user pause in block_job_error_action 2019-03-19 15:49:29 +01:00
bootdevice.c fw_cfg: ignore suffixes in the bootdevice list dependent on machine class 2018-08-16 22:27:43 -03:00
bt-host.c all: Clean up includes 2016-02-04 17:41:30 +00:00
bt-vhci.c all: Clean up includes 2016-02-04 17:41:30 +00:00
Changelog Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
CODING_STYLE CODING_STYLE: Define our preferred form for multiline comments 2018-06-15 15:23:34 +01:00
configure configure: Remove --source-path option 2019-04-29 17:35:57 +01:00
COPYING COPYING: update from FSF 2008-10-12 17:54:42 +00:00
COPYING.LIB COPYING.LIB: Synchronize the LGPL 2.1 with the version from gnu.org 2019-01-30 11:01:22 +01:00
cpus-common.c qemu/queue.h: simplify reverse access to QTAILQ 2019-01-11 15:46:55 +01:00
cpus.c qom/cpu: Simplify how CPUClass:cpu_dump_state() prints 2019-04-18 22:18:59 +02:00
device_tree.c device_tree: Fix integer overflowing in load_device_tree() 2019-04-09 16:35:40 -07:00
device-hotplug.c hmp: Fix drive_add ... format=help crash 2019-04-08 17:42:06 +02:00
disas.c disas: Rename include/disas/bfd.h back to include/disas/dis-asm.h 2019-04-18 22:18:59 +02:00
dma-helpers.c block: explicitly acquire aiocontext in bottom halves that need it 2017-02-21 11:39:39 +00:00
dump.c dump: Set correct vaddr for ELF dump 2019-02-06 15:51:12 +01:00
exec.c Machine queue, 2019-04-25 2019-04-26 14:30:18 +01:00
gdbstub.c gdbstub: fix vCont packet handling when no thread is specified 2019-03-26 12:53:26 +00:00
gitdm.config contrib: gitdm: add a mapping for Janus Technologies 2019-03-12 19:31:29 +00:00
HACKING HACKING: document preference for g_new instead of g_malloc 2018-05-20 08:32:09 +03:00
hmp-commands-info.hx {hmp, hw/pvrdma}: Expose device internals via monitor interface 2019-03-16 15:52:44 +02:00
hmp-commands.hx hmp: Add hmp_announce_self 2019-03-05 11:27:41 +08:00
hmp.c block/qapi: Clean up how we print to monitor or stdout 2019-04-18 22:18:59 +02:00
hmp.h {hmp, hw/pvrdma}: Expose device internals via monitor interface 2019-03-16 15:52:44 +02:00
ioport.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
iothread.c iothread: document about why we need explicit aio_poll() 2019-03-08 10:20:57 +00:00
job-qmp.c jobs: canonize Error object 2018-08-31 16:28:33 +02:00
job.c job: Fix off-by-one assert checks for JobSTT and JobVerbTable 2018-11-12 17:49:21 +01:00
Kconfig.host kconfig: add dependencies on CONFIG_MSI_NONBROKEN 2019-03-18 09:39:57 +01:00
LICENSE vfio: move hw/misc/vfio.c to hw/vfio/pci.c Move vfio.h into include/hw/vfio 2014-12-19 15:24:06 -07:00
MAINTAINERS hw/devices: Move TI touchscreen declarations into a new header 2019-04-29 17:57:21 +01:00
Makefile Makefile: install the edk2 firmware images and their descriptors 2019-04-17 15:38:35 +02:00
Makefile.objs RISC-V: Convert trap debugging to trace events 2019-03-19 05:14:40 -07:00
Makefile.target tests/tcg: enable tcg tests for softmmu 2019-03-12 17:05:21 +00:00
memory_ldst.inc.c exec: Fix MAP_RAM for cached access 2018-06-28 19:05:30 +02:00
memory_mapping.c qemu/queue.h: simplify reverse access to QTAILQ 2019-01-11 15:46:55 +01:00
memory.c memory: Clean up how mtree_info() prints 2019-04-18 22:18:59 +02:00
module-common.c all: Clean up includes 2016-02-04 17:41:30 +00:00
monitor.c monitor: Clean up how monitor_disas() funnels output to monitor 2019-04-18 22:18:59 +02:00
numa.c numa: Fixed the memory leak of numa error message 2019-01-28 15:52:05 -02:00
os-posix.c util: add qemu_write_pidfile() 2018-10-02 18:47:55 +02:00
os-win32.c util: add qemu_write_pidfile() 2018-10-02 18:47:55 +02:00
qdev-monitor.c monitor: Simplify how -device/device_add print help 2019-04-18 22:18:59 +02:00
qemu-bridge-helper.c all: Remove unnecessary glib.h includes 2016-06-07 18:19:24 +03:00
qemu-deprecated.texi socket: allow wait=false for client socket 2019-04-16 10:40:43 +01:00
qemu-doc.texi qemu-doc: Add section on MIPS' Boston board 2019-02-27 14:26:14 +01:00
qemu-edid.c display/edid: add edid generator to qemu. 2018-09-27 08:07:51 +02:00
qemu-ga.texi qemu-ga: Remove stray 'q' in documentation 2016-10-28 18:17:23 +03:00
qemu-img-cmds.hx qemu-img: fix .hx and .texi disparity 2019-04-12 14:17:10 +01:00
qemu-img.c block/qapi: Clean up how we print to monitor or stdout 2019-04-18 22:18:59 +02:00
qemu-img.texi qemu-img: fix .hx and .texi disparity 2019-04-12 14:17:10 +01:00
qemu-io-cmds.c block/qapi: Clean up how we print to monitor or stdout 2019-04-18 22:18:59 +02:00
qemu-io.c log: Make glib logging go through QEMU 2019-04-17 19:08:27 +02:00
qemu-keymap.c ui: use enum to string helpers 2018-08-24 08:40:10 +02:00
qemu-nbd.c log: Make glib logging go through QEMU 2019-04-17 19:08:27 +02:00
qemu-nbd.texi qemu-nbd: add support for authorization of TLS clients 2019-03-06 11:05:27 -06:00
qemu-option-trace.texi qemu-option-trace: -trace enable= is a pattern, not a file 2018-05-20 08:29:01 +03:00
qemu-options-wrapper.h qemu-img: remove references to GEN_DOCS 2018-05-20 08:35:54 +03:00
qemu-options.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
qemu-options.hx Add Nios II semihosting support. 2019-04-29 16:09:51 +01:00
qemu-seccomp.c seccomp: report more useful errors from seccomp 2019-03-27 13:11:38 +01:00
qemu-tech.texi cli qmp: Mark --preconfig, exit-preconfig experimental 2018-07-16 15:38:19 +02:00
qemu.nsi Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
qemu.sasl Default to GSSAPI (Kerberos) instead of DIGEST-MD5 for SASL 2017-05-09 14:41:47 +01:00
qmp.c qapi: make query-cpu-definitions depend on specific targets 2019-02-18 14:44:05 +01:00
qtest.c char: allow specifying a GMainContext at opening time 2019-02-13 14:23:39 +01:00
README README: use 'https://' instead of 'git://' 2018-11-12 11:26:02 +00:00
replication.c replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
replication.h block/replication: Remove protocol_name field 2018-03-26 12:16:00 +02:00
rules.mak build: switch to Kconfig 2019-03-07 21:45:53 +01:00
thunk.c thunk: improve readability of allocation loop 2019-03-11 18:48:20 +01:00
tpm.c tpm: Clean up error reporting in tpm_init_tpmdev() 2018-10-19 14:51:34 +02:00
trace-events trace-events: Fix attribution of trace points to source 2019-03-22 16:18:07 +00:00
VERSION Open 4.1 development tree 2019-04-24 10:12:22 +01:00
version.rc Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
vl.c trace: fix runstate tracing 2019-04-29 11:57:19 -04:00
win_dump.c dump: fix Windows dump memory run mapping 2018-10-02 18:47:55 +02:00
win_dump.h dump: move Windows dump structures definitions 2018-10-02 19:09:12 +02:00

         QEMU README
         ===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

  https://qemu.org/Hosts/Linux
  https://qemu.org/Hosts/Mac
  https://qemu.org/Hosts/W32


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

   git clone https://git.qemu.org/git/qemu.git

When submitting patches, one common approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the HACKING and CODING_STYLE files.

Additional information on submitting patches can be found online via
the QEMU website

  https://qemu.org/Contribute/SubmitAPatch
  https://qemu.org/Contribute/TrivialPatches

The QEMU website is also maintained under source control.

  git clone https://git.qemu.org/git/qemu-web.git
  https://www.qemu.org/2017/02/04/the-new-qemu-website-is-up/

A 'git-publish' utility was created to make above process less
cumbersome, and is highly recommended for making regular contributions,
or even just for sending consecutive patch series revisions. It also
requires a working 'git send-email' setup, and by default doesn't
automate everything, so you may want to go through the above steps
manually for once.

For installation instructions, please go to

  https://github.com/stefanha/git-publish

The workflow with 'git-publish' is:

  $ git checkout master -b my-feature
  $ # work on new commits, add your 'Signed-off-by' lines to each
  $ git publish

Your patch series will be sent and tagged as my-feature-v1 if you need to refer
back to it in the future.

Sending v2:

  $ git checkout my-feature # same topic branch
  $ # making changes to the commits (using 'git rebase', for example)
  $ git publish

Your patch series will be sent with 'v2' tag in the subject and the git tip
will be tagged as my-feature-v2.

Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

  https://bugs.launchpad.net/qemu/

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

  https://qemu.org/Contribute/ReportABug


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

 - qemu-devel@nongnu.org
   https://lists.nongnu.org/mailman/listinfo/qemu-devel
 - #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

  https://qemu.org/Contribute/StartHere

-- End