[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] Stub domain crash on Xen v4.6.1


It works now!

Many, many thanks for your invaluable time.

By the way, Do you know when the patch will be included in the stable-4.6 branch? Maybe will be on time for the 4.6.2 version?

IMHO is an important patch because of the added security shielding it provides (allowing the use of stub domains on some cases).

Best regards,


2016-04-12 10:36 GMT+02:00 Wei Liu <wei.liu2@xxxxxxxxxx>:
On Tue, Apr 05, 2016 at 05:17:00PM +0200, Fanny Dwargee wrote:

(d21) read error -1 on /local/domain/21/device/vbd/768 at offset 0, num bytes 512
(XEN) grant_table.c:525:d0v0 Bad flags (0) or dom (0). (expected dom 0)
(d21) read error -1 on /local/domain/21/device/vbd/768 at offset 0, num bytes 512
(XEN) grant_table.c:525:d0v0 Bad flags (0) or dom (0). (expected dom 0)

This reminds me of a bug that would cause error in disk:


Are you able to apply the patch in that thread and test?

For your convenience I've attached the patch. It needs to be applied to

>From c519e3dfcdbc1edeac994dfa3918c175aae44983 Mon Sep 17 00:00:00 2001
From: Samuel Thibault <samuel.thibault@xxxxxxxxxxxx>
Date: Fri, 1 Apr 2016 20:17:01 +0200
Subject: [PATCH] Mini-OS: netfront: fix off-by-one error introduced in

7c8f3483 introduced a break within a loop in netfront.c such that
cons and nr_consumed were no longer always being incremented. The
offset at cons will be processed multiple times with the break in

This commit reverts to using the "some" variable in the loop condition,
but avoids ifdefs for the non-libc case. It also renames it to dobreak
to make its usage clearer.

Signed-off-by: Samuel Thibault <samuel.thibault@xxxxxxxxxxxx>
Tested-by: Sarah Newman <srn@xxxxxxxxx>
 netfront.c | 20 ++++++--------------
 1 file changed, 6 insertions(+), 14 deletions(-)

diff --git a/netfront.c b/netfront.c
index 0eca5b5..b8fac62 100644
--- a/netfront.c
+++ b/netfront.c
@@ -97,19 +97,15 @@ void network_rx(struct netfront_dev *dev)
     RING_IDX rp,cons,req_prod;
     int nr_consumed, more, i, notify;
-#ifdef HAVE_LIBC
-    int some;
+    int dobreak;

     nr_consumed = 0;
     rp = dev->rx.sring->rsp_prod;
     rmb(); /* Ensure we see queued responses up to 'rp'. */

-#ifdef HAVE_LIBC
-    some = 0;
-    for (cons = dev->rx.rsp_cons; cons != rp; nr_consumed++, cons++)
+    dobreak = 0;
+    for (cons = dev->rx.rsp_cons; cons != rp && !dobreak; nr_consumed++, cons++)
         struct net_buffer* buf;
         unsigned char* page;
@@ -134,8 +130,8 @@ moretodo:
                    len = dev->len;
                memcpy(dev->data, page+rx->offset, len);
                dev->rlen = len;
-               some = 1;
-                break;
+               /* No need to receive the rest for now */
+               dobreak = 1;
            } else
@@ -144,11 +140,7 @@ moretodo:

-#ifdef HAVE_LIBC
-    if(more && !some) goto moretodo;
-    if(more) goto moretodo;
+    if(more && !dobreak) goto moretodo;

     req_prod = dev->rx.req_prod_pvt;


Xen-devel mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.