From: Paolo Bonzini Date: Mon, 2 Feb 2015 15:36:51 +0000 (+0100) Subject: qemu-thread: fix qemu_event without futexes X-Git-Tag: qemu-xen-4.6.0-rc1~34^2~17 X-Git-Url: http://xenbits.xensource.com/gitweb?a=commitdiff_plain;h=a9eb2b60538e2cb48cc71824d2c6239a8aa85cb8;p=qemu-upstream-unstable.git qemu-thread: fix qemu_event without futexes This had a possible deadlock that was visible with rcutorture. qemu_event_set qemu_event_wait ---------------------------------------------------------------- cmpxchg reads FREE, writes BUSY futex_wait: pthread_mutex_lock futex_wait: value == BUSY xchg reads BUSY, writes SET futex_wake: pthread_cond_broadcast futex_wait: pthread_cond_wait The fix is simply to avoid condvar tricks and do the obvious locking around pthread_cond_broadcast: qemu_event_set qemu_event_wait ---------------------------------------------------------------- cmpxchg reads FREE, writes BUSY futex_wait: pthread_mutex_lock futex_wait: value == BUSY xchg reads BUSY, writes SET futex_wake: pthread_mutex_lock (blocks) futex_wait: pthread_cond_wait (mutex unlocked) futex_wake: pthread_cond_broadcast futex_wake: pthread_mutex_unlock futex_wait: pthread_mutex_unlock Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 158ef8cbb7e0fe8bb430310924b8bebe5f186e6e) Signed-off-by: Michael Roth --- diff --git a/util/qemu-thread-posix.c b/util/qemu-thread-posix.c index d05a6497e..bb14ad4a3 100644 --- a/util/qemu-thread-posix.c +++ b/util/qemu-thread-posix.c @@ -306,11 +306,13 @@ static inline void futex_wait(QemuEvent *ev, unsigned val) #else static inline void futex_wake(QemuEvent *ev, int n) { + pthread_mutex_lock(&ev->lock); if (n == 1) { pthread_cond_signal(&ev->cond); } else { pthread_cond_broadcast(&ev->cond); } + pthread_mutex_unlock(&ev->lock); } static inline void futex_wait(QemuEvent *ev, unsigned val)