Yajun Wu <yaj...@nvidia.com> writes:
> In fetch_or_create_notifier, idx begins with 0. So the GPtrArray size > should be idx + 1 and g_ptr_array_set_size should be called with idx + 1. > > This wrong GPtrArray size causes fetch_or_create_notifier return an invalid > address. Passing this invalid pointer to vhost_user_host_notifier_remove > causes assert fail: > > qemu/include/qemu/int128.h:27: int128_get64: Assertion `r == a' failed. > shutting down, reason=crashed > > Backends like dpdk-vdpa which sends out vhost notifier requests almost always > hit qemu crash. My bad. I was looking for ways to exercise this code but the internal tests didn't do it. I guess I should look at getting a test setup for dpdk. Anyway: Reviewed-by: Alex Bennée <alex.ben...@linaro.org> > > Fixes: 503e355465 ("virtio/vhost-user: dynamically assign > VhostUserHostNotifiers") > Signed-off-by: Yajun Wu <yaj...@nvidia.com> > Acked-by: Parav Pandit <pa...@nvidia.com> > Change-Id: I87e0f7591ca9a59d210879b260704a2d9e9d6bcd > --- > hw/virtio/vhost-user.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/hw/virtio/vhost-user.c b/hw/virtio/vhost-user.c > index b040c1ad2b..dbc690d16c 100644 > --- a/hw/virtio/vhost-user.c > +++ b/hw/virtio/vhost-user.c > @@ -1525,7 +1525,7 @@ static VhostUserHostNotifier > *fetch_or_create_notifier(VhostUserState *u, > { > VhostUserHostNotifier *n = NULL; > if (idx >= u->notifiers->len) { > - g_ptr_array_set_size(u->notifiers, idx); > + g_ptr_array_set_size(u->notifiers, idx + 1); > } > > n = g_ptr_array_index(u->notifiers, idx); -- Alex Bennée