From: Alexander Graf Date: Wed, 6 May 2009 00:58:48 +0000 (+0200) Subject: AIO deletion race fix X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=79d5ca5617cfc9be13a4f314ed800fca1267d903;p=qemu.git AIO deletion race fix When deleting an fd event there is a chance the object doesn't get deleted, but only ->deleted set positive and deleted somewhere later. Now, if we create a handler for the fd again before the actual deletion occurs, we end up writing data into an object that has ->deleted set, which is obviously wrong. I see two ways to fix this: 1. Don't return ->deleted objects in the search 2. Unset ->deleted in the search This patch implements 1. which feels safer to do. It fixes AIO issues I've seen with curl, as libcurl unsets fd event listeners pretty frequently. Signed-off-by: Alexander Graf Signed-off-by: Anthony Liguori --- diff --git a/aio.c b/aio.c index 200320c979..11fbb6c0c5 100644 --- a/aio.c +++ b/aio.c @@ -44,7 +44,8 @@ static AioHandler *find_aio_handler(int fd) LIST_FOREACH(node, &aio_handlers, node) { if (node->fd == fd) - return node; + if (!node->deleted) + return node; } return NULL;