* [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues
@ 2017-04-26 6:45 Yunjian Wang
2017-04-26 9:17 ` Jason Wang
0 siblings, 1 reply; 4+ messages in thread
From: Yunjian Wang @ 2017-04-26 6:45 UTC (permalink / raw)
To: jasowang, mst, qemu-devel; +Cc: caihe, Yunjian Wang
The tx_bh or tx_timer will free in virtio_net_del_queue() function, when
removing virtio-net queues if the guest doesn't support multiqueue. But
it might be still referenced by virtio_net_set_status(), which needs to
be set NULL. And also the tx_waiting needs to be set zero to prevent
virtio_net_set_status() accessing tx_bh or tx_timer.
Signed-off-by: Yunjian Wang <wangyunjian@huawei.com>
---
hw/net/virtio-net.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c
index 7d091c9..98bd683 100644
--- a/hw/net/virtio-net.c
+++ b/hw/net/virtio-net.c
@@ -1522,9 +1522,12 @@ static void virtio_net_del_queue(VirtIONet *n, int index)
if (q->tx_timer) {
timer_del(q->tx_timer);
timer_free(q->tx_timer);
+ q->tx_timer = NULL;
} else {
qemu_bh_delete(q->tx_bh);
+ q->tx_bh = NULL;
}
+ q->tx_waiting = 0;
virtio_del_queue(vdev, index * 2 + 1);
}
--
1.8.3.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues
2017-04-26 6:45 [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues Yunjian Wang
@ 2017-04-26 9:17 ` Jason Wang
2017-04-26 10:45 ` wangyunjian
0 siblings, 1 reply; 4+ messages in thread
From: Jason Wang @ 2017-04-26 9:17 UTC (permalink / raw)
To: Yunjian Wang, mst, qemu-devel; +Cc: caihe
On 2017年04月26日 14:45, Yunjian Wang wrote:
> The tx_bh or tx_timer will free in virtio_net_del_queue() function, when
> removing virtio-net queues if the guest doesn't support multiqueue. But
> it might be still referenced by virtio_net_set_status(), which needs to
> be set NULL. And also the tx_waiting needs to be set zero to prevent
> virtio_net_set_status() accessing tx_bh or tx_timer.
>
> Signed-off-by: Yunjian Wang <wangyunjian@huawei.com>
> ---
> hw/net/virtio-net.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c
> index 7d091c9..98bd683 100644
> --- a/hw/net/virtio-net.c
> +++ b/hw/net/virtio-net.c
> @@ -1522,9 +1522,12 @@ static void virtio_net_del_queue(VirtIONet *n, int index)
> if (q->tx_timer) {
> timer_del(q->tx_timer);
> timer_free(q->tx_timer);
> + q->tx_timer = NULL;
> } else {
> qemu_bh_delete(q->tx_bh);
> + q->tx_bh = NULL;
> }
> + q->tx_waiting = 0;
> virtio_del_queue(vdev, index * 2 + 1);
> }
>
Thanks for the patch.
It looks to me that clearing tx_waiting is sufficient or is there any
other reason that you need set tx_timer/tx_bh to NULL?
Thanks
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues
2017-04-26 9:17 ` Jason Wang
@ 2017-04-26 10:45 ` wangyunjian
2017-05-02 6:02 ` Jason Wang
0 siblings, 1 reply; 4+ messages in thread
From: wangyunjian @ 2017-04-26 10:45 UTC (permalink / raw)
To: Jason Wang, mst, qemu-devel; +Cc: caihe
> -----Original Message-----
> From: Jason Wang [mailto:jasowang@redhat.com]
> Sent: Wednesday, April 26, 2017 5:18 PM
> To: wangyunjian <wangyunjian@huawei.com>; mst@redhat.com; qemu-devel@nongnu.org
> Cc: caihe <caihe@huawei.com>
> Subject: Re: [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues
>
>
>
> On 2017年04月26日 14:45, Yunjian Wang wrote:
> > The tx_bh or tx_timer will free in virtio_net_del_queue() function,
> > when removing virtio-net queues if the guest doesn't support
> > multiqueue. But it might be still referenced by
> > virtio_net_set_status(), which needs to be set NULL. And also the
> > tx_waiting needs to be set zero to prevent
> > virtio_net_set_status() accessing tx_bh or tx_timer.
> >
> > Signed-off-by: Yunjian Wang <wangyunjian@huawei.com>
> > ---
> > hw/net/virtio-net.c | 3 +++
> > 1 file changed, 3 insertions(+)
> >
> > diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c index
> > 7d091c9..98bd683 100644
> > --- a/hw/net/virtio-net.c
> > +++ b/hw/net/virtio-net.c
> > @@ -1522,9 +1522,12 @@ static void virtio_net_del_queue(VirtIONet *n, int index)
> > if (q->tx_timer) {
> > timer_del(q->tx_timer);
> > timer_free(q->tx_timer);
> > + q->tx_timer = NULL;
> > } else {
> > qemu_bh_delete(q->tx_bh);
> > + q->tx_bh = NULL;
> > }
> > + q->tx_waiting = 0;
> > virtio_del_queue(vdev, index * 2 + 1);
> > }
> >
>
> Thanks for the patch.
>
> It looks to me that clearing tx_waiting is sufficient or is there any
> other reason that youneed set tx_timer/tx_bh to NULL?
It's just coding habit to avoid access wild pointer, such as
used-after-free porblem, it hard to locate the code that cause the bug.
Thanks
>
> Thanks
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues
2017-04-26 10:45 ` wangyunjian
@ 2017-05-02 6:02 ` Jason Wang
0 siblings, 0 replies; 4+ messages in thread
From: Jason Wang @ 2017-05-02 6:02 UTC (permalink / raw)
To: wangyunjian, mst, qemu-devel; +Cc: caihe
On 2017年04月26日 18:45, wangyunjian wrote:
>> -----Original Message-----
>> From: Jason Wang [mailto:jasowang@redhat.com]
>> Sent: Wednesday, April 26, 2017 5:18 PM
>> To: wangyunjian <wangyunjian@huawei.com>; mst@redhat.com; qemu-devel@nongnu.org
>> Cc: caihe <caihe@huawei.com>
>> Subject: Re: [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues
>>
>>
>>
>> On 2017年04月26日 14:45, Yunjian Wang wrote:
>>> The tx_bh or tx_timer will free in virtio_net_del_queue() function,
>>> when removing virtio-net queues if the guest doesn't support
>>> multiqueue. But it might be still referenced by
>>> virtio_net_set_status(), which needs to be set NULL. And also the
>>> tx_waiting needs to be set zero to prevent
>>> virtio_net_set_status() accessing tx_bh or tx_timer.
>>>
>>> Signed-off-by: Yunjian Wang <wangyunjian@huawei.com>
>>> ---
>>> hw/net/virtio-net.c | 3 +++
>>> 1 file changed, 3 insertions(+)
>>>
>>> diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c index
>>> 7d091c9..98bd683 100644
>>> --- a/hw/net/virtio-net.c
>>> +++ b/hw/net/virtio-net.c
>>> @@ -1522,9 +1522,12 @@ static void virtio_net_del_queue(VirtIONet *n, int index)
>>> if (q->tx_timer) {
>>> timer_del(q->tx_timer);
>>> timer_free(q->tx_timer);
>>> + q->tx_timer = NULL;
>>> } else {
>>> qemu_bh_delete(q->tx_bh);
>>> + q->tx_bh = NULL;
>>> }
>>> + q->tx_waiting = 0;
>>> virtio_del_queue(vdev, index * 2 + 1);
>>> }
>>>
>> Thanks for the patch.
>>
>> It looks to me that clearing tx_waiting is sufficient or is there any
>> other reason that youneed set tx_timer/tx_bh to NULL?
> It's just coding habit to avoid access wild pointer, such as
> used-after-free porblem, it hard to locate the code that cause the bug.
>
> Thanks
Applied and queued for -stable.
Thanks
>> Thanks
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2017-05-02 6:03 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-04-26 6:45 [Qemu-devel] [PATCH] virtio-net: fix wild pointer when remove virtio-net queues Yunjian Wang
2017-04-26 9:17 ` Jason Wang
2017-04-26 10:45 ` wangyunjian
2017-05-02 6:02 ` Jason Wang
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.