Skip to content

Commit

Permalink
jobs: add job lock in find_* functions
Browse files Browse the repository at this point in the history
Both blockdev.c and job-qmp.c have TOC/TOU conditions, because
they first search for the job and then perform an action on it.
Therefore, we need to do the search + action under the same
job mutex critical section.

Note: at this stage, job_{lock/unlock} and job lock guard macros
are *nop*.

Signed-off-by: Emanuele Giuseppe Esposito <[email protected]>
Reviewed-by: Vladimir Sementsov-Ogievskiy <[email protected]>
Reviewed-by: Stefan Hajnoczi <[email protected]>
Reviewed-by: Kevin Wolf <[email protected]>
Message-Id: <[email protected]>
Signed-off-by: Kevin Wolf <[email protected]>
  • Loading branch information
esposem authored and kevmw committed Oct 7, 2022
1 parent f41ab73 commit 9624112
Show file tree
Hide file tree
Showing 2 changed files with 86 additions and 38 deletions.
67 changes: 46 additions & 21 deletions blockdev.c
Original file line number Diff line number Diff line change
Expand Up @@ -3313,17 +3313,21 @@ void qmp_blockdev_mirror(bool has_job_id, const char *job_id,
aio_context_release(aio_context);
}

/* Get a block job using its ID and acquire its AioContext */
static BlockJob *find_block_job(const char *id, AioContext **aio_context,
Error **errp)
/*
* Get a block job using its ID and acquire its AioContext.
* Called with job_mutex held.
*/
static BlockJob *find_block_job_locked(const char *id,
AioContext **aio_context,
Error **errp)
{
BlockJob *job;

assert(id != NULL);

*aio_context = NULL;

job = block_job_get(id);
job = block_job_get_locked(id);

if (!job) {
error_set(errp, ERROR_CLASS_DEVICE_NOT_ACTIVE,
Expand All @@ -3340,21 +3344,27 @@ static BlockJob *find_block_job(const char *id, AioContext **aio_context,
void qmp_block_job_set_speed(const char *device, int64_t speed, Error **errp)
{
AioContext *aio_context;
BlockJob *job = find_block_job(device, &aio_context, errp);
BlockJob *job;

JOB_LOCK_GUARD();
job = find_block_job_locked(device, &aio_context, errp);

if (!job) {
return;
}

block_job_set_speed(job, speed, errp);
block_job_set_speed_locked(job, speed, errp);
aio_context_release(aio_context);
}

void qmp_block_job_cancel(const char *device,
bool has_force, bool force, Error **errp)
{
AioContext *aio_context;
BlockJob *job = find_block_job(device, &aio_context, errp);
BlockJob *job;

JOB_LOCK_GUARD();
job = find_block_job_locked(device, &aio_context, errp);

if (!job) {
return;
Expand All @@ -3364,96 +3374,111 @@ void qmp_block_job_cancel(const char *device,
force = false;
}

if (job_user_paused(&job->job) && !force) {
if (job_user_paused_locked(&job->job) && !force) {
error_setg(errp, "The block job for device '%s' is currently paused",
device);
goto out;
}

trace_qmp_block_job_cancel(job);
job_user_cancel(&job->job, force, errp);
job_user_cancel_locked(&job->job, force, errp);
out:
aio_context_release(aio_context);
}

void qmp_block_job_pause(const char *device, Error **errp)
{
AioContext *aio_context;
BlockJob *job = find_block_job(device, &aio_context, errp);
BlockJob *job;

JOB_LOCK_GUARD();
job = find_block_job_locked(device, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_block_job_pause(job);
job_user_pause(&job->job, errp);
job_user_pause_locked(&job->job, errp);
aio_context_release(aio_context);
}

void qmp_block_job_resume(const char *device, Error **errp)
{
AioContext *aio_context;
BlockJob *job = find_block_job(device, &aio_context, errp);
BlockJob *job;

JOB_LOCK_GUARD();
job = find_block_job_locked(device, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_block_job_resume(job);
job_user_resume(&job->job, errp);
job_user_resume_locked(&job->job, errp);
aio_context_release(aio_context);
}

void qmp_block_job_complete(const char *device, Error **errp)
{
AioContext *aio_context;
BlockJob *job = find_block_job(device, &aio_context, errp);
BlockJob *job;

JOB_LOCK_GUARD();
job = find_block_job_locked(device, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_block_job_complete(job);
job_complete(&job->job, errp);
job_complete_locked(&job->job, errp);
aio_context_release(aio_context);
}

void qmp_block_job_finalize(const char *id, Error **errp)
{
AioContext *aio_context;
BlockJob *job = find_block_job(id, &aio_context, errp);
BlockJob *job;

JOB_LOCK_GUARD();
job = find_block_job_locked(id, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_block_job_finalize(job);
job_ref(&job->job);
job_finalize(&job->job, errp);
job_ref_locked(&job->job);
job_finalize_locked(&job->job, errp);

/*
* Job's context might have changed via job_finalize (and job_txn_apply
* automatically acquires the new one), so make sure we release the correct
* one.
*/
aio_context = block_job_get_aio_context(job);
job_unref(&job->job);
job_unref_locked(&job->job);
aio_context_release(aio_context);
}

void qmp_block_job_dismiss(const char *id, Error **errp)
{
AioContext *aio_context;
BlockJob *bjob = find_block_job(id, &aio_context, errp);
BlockJob *bjob;
Job *job;

JOB_LOCK_GUARD();
bjob = find_block_job_locked(id, &aio_context, errp);

if (!bjob) {
return;
}

trace_qmp_block_job_dismiss(bjob);
job = &bjob->job;
job_dismiss(&job, errp);
job_dismiss_locked(&job, errp);
aio_context_release(aio_context);
}

Expand Down
57 changes: 40 additions & 17 deletions job-qmp.c
Original file line number Diff line number Diff line change
Expand Up @@ -29,14 +29,19 @@
#include "qapi/error.h"
#include "trace/trace-root.h"

/* Get a job using its ID and acquire its AioContext */
static Job *find_job(const char *id, AioContext **aio_context, Error **errp)
/*
* Get a job using its ID and acquire its AioContext.
* Called with job_mutex held.
*/
static Job *find_job_locked(const char *id,
AioContext **aio_context,
Error **errp)
{
Job *job;

*aio_context = NULL;

job = job_get(id);
job = job_get_locked(id);
if (!job) {
error_setg(errp, "Job not found");
return NULL;
Expand All @@ -51,93 +56,111 @@ static Job *find_job(const char *id, AioContext **aio_context, Error **errp)
void qmp_job_cancel(const char *id, Error **errp)
{
AioContext *aio_context;
Job *job = find_job(id, &aio_context, errp);
Job *job;

JOB_LOCK_GUARD();
job = find_job_locked(id, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_job_cancel(job);
job_user_cancel(job, true, errp);
job_user_cancel_locked(job, true, errp);
aio_context_release(aio_context);
}

void qmp_job_pause(const char *id, Error **errp)
{
AioContext *aio_context;
Job *job = find_job(id, &aio_context, errp);
Job *job;

JOB_LOCK_GUARD();
job = find_job_locked(id, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_job_pause(job);
job_user_pause(job, errp);
job_user_pause_locked(job, errp);
aio_context_release(aio_context);
}

void qmp_job_resume(const char *id, Error **errp)
{
AioContext *aio_context;
Job *job = find_job(id, &aio_context, errp);
Job *job;

JOB_LOCK_GUARD();
job = find_job_locked(id, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_job_resume(job);
job_user_resume(job, errp);
job_user_resume_locked(job, errp);
aio_context_release(aio_context);
}

void qmp_job_complete(const char *id, Error **errp)
{
AioContext *aio_context;
Job *job = find_job(id, &aio_context, errp);
Job *job;

JOB_LOCK_GUARD();
job = find_job_locked(id, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_job_complete(job);
job_complete(job, errp);
job_complete_locked(job, errp);
aio_context_release(aio_context);
}

void qmp_job_finalize(const char *id, Error **errp)
{
AioContext *aio_context;
Job *job = find_job(id, &aio_context, errp);
Job *job;

JOB_LOCK_GUARD();
job = find_job_locked(id, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_job_finalize(job);
job_ref(job);
job_finalize(job, errp);
job_ref_locked(job);
job_finalize_locked(job, errp);

/*
* Job's context might have changed via job_finalize (and job_txn_apply
* automatically acquires the new one), so make sure we release the correct
* one.
*/
aio_context = job->aio_context;
job_unref(job);
job_unref_locked(job);
aio_context_release(aio_context);
}

void qmp_job_dismiss(const char *id, Error **errp)
{
AioContext *aio_context;
Job *job = find_job(id, &aio_context, errp);
Job *job;

JOB_LOCK_GUARD();
job = find_job_locked(id, &aio_context, errp);

if (!job) {
return;
}

trace_qmp_job_dismiss(job);
job_dismiss(&job, errp);
job_dismiss_locked(&job, errp);
aio_context_release(aio_context);
}

Expand Down

0 comments on commit 9624112

Please sign in to comment.