[libvirt] [PATCH] qemu_agent: Remove agent reference only when disposing it

Eric Blake eblake at redhat.com
Thu Jan 10 00:59:41 UTC 2013


On 01/09/2013 06:30 AM, Michal Privoznik wrote:
> https://bugzilla.redhat.com/show_bug.cgi?id=892079
> 
> With current code, if user calls virDomainPMSuspendForDuration()
> followed by virDomainDestroy(), the former API checks for qemu agent
> presence, which will evaluate as true (if agent is configured). While
> talking to qemu agent, the qemu driver is unlocked, so the latter API
> starts executing.  However, if machine dies meanwhile, libvirtd gets
> EOF on the agent socket and qemuProcessHandleAgentEOF() is called. The
> handler clears reference to qemu agent while the destroy API already
> holding a reference to it. This leads to NULL dereferencing later in
> the code. Therefore, the agent pointer should be set to NULL only if
> we are the exclusive owner of it.
> ---
> 
> There's a reproducer in the BZ. It doesn't have to be a windows guest,
> I was able to reproduce with F17 guest as well.
> 
>  src/qemu/qemu_process.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)

ACK.

-- 
Eric Blake   eblake redhat com    +1-919-301-3266
Libvirt virtualization library http://libvirt.org

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 619 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/libvir-list/attachments/20130109/3b69e596/attachment-0001.sig>


More information about the libvir-list mailing list