Bug 1510809

Summary: qemu-kvm core dumped when booting up guest using both virtio-vga and VGA
Product: Red Hat Enterprise Linux 7 Reporter: yilzhang
Component: qemu-kvm-rhevAssignee: Gerd Hoffmann <kraxel>
Status: CLOSED ERRATA QA Contact: Guo, Zhiyi <zhguo>
Severity: high Docs Contact:
Priority: medium    
Version: 7.5CC: chayang, coli, jinzhao, juzhang, knoel, lmiksik, michen, qzhang, virt-maint, yilzhang, zhguo
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: qemu-kvm-rhev-2.10.0-17.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-04-11 00:46:47 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description yilzhang 2017-11-08 09:48:47 UTC
Description of problem:
qemu-kvm aborts abnormally with core dumped when booting up guest using both virtio-vga and VGA

Version-Release number of selected component (if applicable):
Host kernel:   3.10.0-771.el7.ppc64le
Guest kernel:  3.10.0-771.el7.ppc64le
qemu-kvm-rhev: qemu-kvm-rhev-2.10.0-4.el7
SLOF:          SLOF-20170724-2.git89f519f.el7.noarch

How reproducible: 100%


Steps to Reproduce:
1. Boot up a guest with two VGA cards (virtio-vga and VGA)
/usr/libexec/qemu-kvm \
 -name yilzhang_vm \
 -smp 8,sockets=2,cores=2,threads=2 \
 -m 8192 \
 -nodefaults \
 -serial unix:/tmp/vga-path,server,nowait \
 -rtc base=localtime,clock=host \
 -boot menu=on \
 -monitor stdio \
 -qmp tcp:0:999,server,nowait \
 -device nec-usb-xhci,id=xhci0 \
 -device usb-kbd,id=usb-kbd0 \
 -device usb-mouse,id=usb-mouse0 \
 -device usb-tablet,id=usb-table0 \
\
 -netdev tap,id=net0,script=/etc/qemu-ifup,downscript=/etc/qemu-ifdown,vhost=on \
 -device virtio-net-pci,netdev=net0,id=nic0,mac=52:54:00:c3:e7:84 \
\
 -device virtio-scsi-pci,id=scsi0 \
 -drive file=/home/rhel75-kernel-3.10.0-771.qcow2,format=qcow2,id=drive_sysdisk,if=none,cache=none,aio=native,werror=stop,rerror=stop \
 -device scsi-hd,drive=drive_sysdisk,bus=scsi0.0,id=sysdisk,bootindex=0 \
 -device virtio-vga,id=vga1 -vnc :10,display=vga1 \
 -device VGA,id=vga2 -vnc :11,display=vga2


Actual results:
[root@ibm-p8-rhevm-18 vga]# sh  two-vga-1.sh
QEMU 2.10.0 monitor - type 'help' for more information
(qemu) qemu-kvm: ui/console.c:1437: register_displaychangelistener: Assertion `!dcl->ds' failed.
two-vga-1.sh: line 23: 67596 Aborted                 (core dumped) /usr/libexec/qemu-kvm -name yilzhang_vm -smp 8,sockets=2,cores=2,threads=2 -m 8192 -nodefaults -serial unix:/tmp/vga-path,server,nowait -rtc base=localtime,clock=host -boot menu=on -monitor stdio -qmp tcp:0:999,server,nowait -device nec-usb-xhci,id=xhci0 -device usb-kbd,id=usb-kbd0 -device usb-mouse,id=usb-mouse0 -device usb-tablet,id=usb-table0 -netdev tap,id=net0,script=/etc/qemu-ifup,downscript=/etc/qemu-ifdown,vhost=on -device virtio-net-pci,netdev=net0,id=nic0,mac=52:54:00:c3:e7:84 -device virtio-scsi-pci,id=scsi0 -drive file=/home/rhel75-kernel-3.10.0-771.qcow2,format=qcow2,id=drive_sysdisk,if=none,cache=none,aio=native,werror=stop,rerror=stop -device scsi-hd,drive=drive_sysdisk,bus=scsi0.0,id=sysdisk,bootindex=0 -device virtio-vga,id=vga1 -vnc :10,display=vga1 -device VGA,id=vga2 -vnc :11,display=vga2


Expected results:
No crash, guest should boot up successfully


Additional info:
(gdb) bt
#0  0x00003fff9076eff0 in raise () from /lib64/libc.so.6
#1  0x00003fff9077136c in abort () from /lib64/libc.so.6
#2  0x00003fff90764c44 in __assert_fail_base () from /lib64/libc.so.6
#3  0x00003fff90764d34 in __assert_fail () from /lib64/libc.so.6
#4  0x000000004f1c3760 in register_displaychangelistener (dcl=0x100186d0060) at ui/console.c:1437
#5  0x000000004f1d4ed8 in vnc_display_open (id=0x10016400698 "default", errp=0x3fffd0e02970) at ui/vnc.c:3978
#6  0x000000004f1d557c in vnc_init_func (opaque=<optimized out>, opts=<optimized out>, errp=<optimized out>) at ui/vnc.c:4064
#7  0x000000004f311574 in qemu_opts_foreach (list=<optimized out>, func=0x4f1d5530 <vnc_init_func>, opaque=0x0, errp=0x0) at util/qemu-option.c:1104
#8  0x000000004eed4da8 in main (argc=<optimized out>, argv=<optimized out>, envp=<optimized out>) at vl.c:4736
(gdb) bt full
#0  0x00003fff9076eff0 in raise () from /lib64/libc.so.6
No symbol table info available.
#1  0x00003fff9077136c in abort () from /lib64/libc.so.6
No symbol table info available.
#2  0x00003fff90764c44 in __assert_fail_base () from /lib64/libc.so.6
No symbol table info available.
#3  0x00003fff90764d34 in __assert_fail () from /lib64/libc.so.6
No symbol table info available.
#4  0x000000004f1c3760 in register_displaychangelistener (dcl=0x100186d0060) at ui/console.c:1437
        nodev = "This VM has no graphic display device."
        dummy = 0x0
        con = <optimized out>
        __PRETTY_FUNCTION__ = "register_displaychangelistener"
#5  0x000000004f1d4ed8 in vnc_display_open (id=0x10016400698 "default", errp=0x3fffd0e02970) at ui/vnc.c:3978
        vd = 0x100186d0000
        opts = 0x10016400698
        saddr = 0x1001640ed00
        wsaddr = 0x0
        nsaddr = 1
        nwsaddr = 0
        share = <optimized out>
        device_id = <optimized out>
        con = 0x100164e1a40
        password = <optimized out>
        reverse = false
        credid = <optimized out>
        sasl = false
        saslErr = <optimized out>
        acl = <optimized out>
        lock_key_sync = <optimized out>
        key_delay_ms = 10
        __func__ = "vnc_display_open"
#6  0x000000004f1d557c in vnc_init_func (opaque=<optimized out>, opts=<optimized out>, errp=<optimized out>) at ui/vnc.c:4064
        local_err = 0x0
        id = 0x10016400698 "default"
        __PRETTY_FUNCTION__ = "vnc_init_func"
#7  0x000000004f311574 in qemu_opts_foreach (list=<optimized out>, func=0x4f1d5530 <vnc_init_func>, opaque=0x0, errp=0x0) at util/qemu-option.c:1104
        loc = {kind = LOC_CMDLINE, num = 2, ptr = 0x3fffd0e03298, prev = 0x4f969300 <std_loc>}
        opts = 0x100164705f0
        rc = 0
        __PRETTY_FUNCTION__ = "qemu_opts_foreach"
#8  0x000000004eed4da8 in main (argc=<optimized out>, argv=<optimized out>, envp=<optimized out>) at vl.c:4736
        i = <optimized out>
        snapshot = <optimized out>
        linux_boot = 0
        initrd_filename = <optimized out>
        kernel_filename = 0x0
        kernel_cmdline = <optimized out>
        boot_order = 0x4f342380 ""
        boot_once = 0x0
        cyls = 0
---Type <return> to continue, or q <return> to quit---
        heads = 0
        secs = 0
        translation = <optimized out>
        opts = <optimized out>
        machine_opts = <optimized out>
        hda_opts = <optimized out>
        icount_opts = <optimized out>
        accel_opts = <optimized out>
        olist = <optimized out>
        optind = 44
        optarg = 0x3fffd0e0f423 ":11,display=vga2"
        loadvm = <optimized out>
        machine_class = 0x4f506888 <qemu_fw_cfg_opts>
        cpu_model = <optimized out>
        vga_model = 0x0
        qtest_chrdev = <optimized out>
        qtest_log = <optimized out>
        pid_file = <optimized out>
        incoming = 0x0
        defconfig = <optimized out>
        userconfig = <optimized out>
        nographic = <optimized out>
        display_type = <optimized out>
        display_remote = <optimized out>
        log_mask = <optimized out>
        log_file = <optimized out>
        trace_file = <optimized out>
        maxram_size = 8589934592
        ram_slots = 0
        vmstate_dump_file = 0x0
        main_loop_err = 0x0
        err = 0x0
        list_data_dirs = <optimized out>
        bdo_queue = {sqh_first = 0x0, sqh_last = 0x3fffd0e02b88}
        __func__ = "main"
        __FUNCTION__ = "main"
(gdb)

Comment 2 yilzhang 2017-11-08 09:54:25 UTC
x86 also has this issue.

Comment 3 Gerd Hoffmann 2017-11-09 07:42:55 UTC
http://patchwork.ozlabs.org/patch/836212/

Comment 4 Gerd Hoffmann 2018-01-12 11:28:04 UTC
upstream commit 777c5f1e436d334a57b650b6951c13d8d2799df0

Comment 6 Miroslav Rezanina 2018-01-16 13:43:51 UTC
Fix included in qemu-kvm-rhev-2.10.0-17.el7

Comment 8 Guo, Zhiyi 2018-01-18 07:21:34 UTC
Test against qemu-kvm-rhev-2.10.0-17.el7.x86_64

Use qemu cli:
/usr/libexec/qemu-kvm -name EPYC -m 8G \
-cpu EPYC,enforce \
-smp 4,cores=2 \
-device VGA \
-device virtio-vga \
-uuid 215e11b2-a869-41b5-91cd-6a32a907be7e \
-device ich9-usb-uhci6 \
-drive file=/home/rhel75.qcow2,if=none,id=drive-scsi-disk0,format=qcow2,cache=none,werror=stop,rerror=sto
p  -device ide-drive,drive=drive-scsi-disk0 \
-qmp unix:/tmp/qmp,server,nowait \
-monitor stdio \
-vnc :0 \
-device usb-tablet \
-netdev tap,id=idinWyYp,vhost=on -device e1000,mac=42:ce:a9:d2:4e:d7,id=idlbq7eA,netdev=idinWyYp \
-serial unix:/tmp/console,server,nowait \

Boot rhel7.5 guest, guest can boot successfully and enter desktop, guest use VGA device as output

Switch display to spice in qemu cli, guest also boot successfully and enter desktop, guest use VGA device as output too.

Comment 9 Guo, Zhiyi 2018-01-18 07:23:18 UTC
Verified per comment 8

Comment 12 errata-xmlrpc 2018-04-11 00:46:47 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:1104