Bug 846933 - [virtio-win][scsi] core dump when hotunplug in-used virtio scsi disks
[virtio-win][scsi] core dump when hotunplug in-used virtio scsi disks
Status: CLOSED DUPLICATE of bug 805501
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: qemu-kvm (Show other bugs)
Unspecified Unspecified
high Severity high
: rc
: ---
Assigned To: Vadim Rozenfeld
Virtualization Bugs
Depends On:
  Show dependency treegraph
Reported: 2012-08-09 03:26 EDT by Mike Cao
Modified: 2012-08-19 09:24 EDT (History)
13 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2012-08-19 09:24:09 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Mike Cao 2012-08-09 03:26:10 EDT
Description of problem:

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1.Start VM w/ virtio-scsi-pci
/usr/libexec/qemu-kvm -boot dc -m 4G -smp 2 -cpu Westmere -usb -device usb-tablet -netdev tap,sndbuf=0,id=hostnet2,script=/etc/qemu-ifup,downscript=no -device e1000,netdev=hostnet2,mac=00:52:13:20:F5:22,bus=pci.0,addr=0x6 -uuid 7976cd92-6557-493d-86a3-7e2055a2d4cd -no-kvm-pit-reinjection -monitor stdio -rtc base=localtime,clock=host,driftfix=slew -device virtio-scsi-pci,id=bus1 -drive file=/home/win2k8-64.qcow2,if=none,media=disk,format=qcow2,rerror=stop,werror=stop,cache=none,aio=native,id=scsi-disk0 -device scsi-disk,drive=scsi-disk0,id=disk,bus=bus1.0,serial=miketest -spice port=5910,disable-ticketing -vga qxl  -fda /home/virtio-win.vfd -bios /usr/share/seabios/bios-pm.bin  -drive file=/home/hotadd2.qcow2,format=qcow2,if=none,id=drive-test,serial=test,werror=stop,rerror=stop,cache=none -device virtio-scsi-pci,id=hotaddscsi -device scsi-hd,drive=drive-test,id=test,bus=hotaddscsi.0
2.run crystal benchmark on the data image 
3.during step hotplug data image 
(qemu)device_del test
Actual results:
Core dumped occurs

Expected results:

Additional info:
(gdb) bt
#0  0x00007f6ea3f24e89 in scsi_req_cancel (req=0x7f6e8c011010) at /usr/src/debug/qemu-kvm-
#1  0x00007f6ea3f24ed5 in scsi_device_purge_requests (sdev=0x7f6ea6736d20, sense=...) at /usr/src/debug/qemu-kvm-
#2  0x00007f6ea3f28b93 in scsi_destroy (dev=<value optimized out>) at /usr/src/debug/qemu-kvm-
#3  0x00007f6ea3f26417 in scsi_qdev_exit (qdev=0x7f6ea6736d20) at /usr/src/debug/qemu-kvm-
#4  0x00007f6ea3f3538c in qdev_free (dev=0x7f6ea6736d20) at /usr/src/debug/qemu-kvm-
#5  0x00007f6ea3f35439 in qdev_simple_unplug_cb (dev=<value optimized out>) at /usr/src/debug/qemu-kvm-
#6  0x00007f6ea3ebabb0 in monitor_call_handler (mon=0x7f6ea673b470, cmd=0x7f6ea43861a0, params=<value optimized out>)
    at /usr/src/debug/qemu-kvm-
#7  0x00007f6ea3ebfecf in handle_user_command (mon=0x7f6ea673b470, cmdline=<value optimized out>) at /usr/src/debug/qemu-kvm-
#8  0x00007f6ea3ec000a in monitor_command_cb (mon=0x7f6ea673b470, cmdline=<value optimized out>, opaque=<value optimized out>)
    at /usr/src/debug/qemu-kvm-
#9  0x00007f6ea3f1801d in readline_handle_byte (rs=0x7f6ea7b6ec50, ch=<value optimized out>) at readline.c:369
#10 0x00007f6ea3ec0230 in monitor_read (opaque=<value optimized out>, buf=0x7fff402272b0 "\r", size=1) at /usr/src/debug/qemu-kvm-
#11 0x00007f6ea3f2d64b in qemu_chr_read (opaque=0x7f6ea63d8e50) at qemu-char.c:180
#12 fd_chr_read (opaque=0x7f6ea63d8e50) at qemu-char.c:688
#13 0x00007f6ea3eb34af in main_loop_wait (timeout=1000) at /usr/src/debug/qemu-kvm-
#14 0x00007f6ea3ed4d5a in kvm_main_loop () at /usr/src/debug/qemu-kvm-
#15 0x00007f6ea3eb5ffc in main_loop (argc=20, argv=<value optimized out>, envp=<value optimized out>) at /usr/src/debug/qemu-kvm-
#16 main (argc=20, argv=<value optimized out>, envp=<value optimized out>) at /usr/src/debug/qemu-kvm-
Comment 2 Ademar Reis 2012-08-10 14:18:14 EDT
Relatively similar: Bug 846920
Comment 3 Paolo Bonzini 2012-08-19 09:24:09 EDT
Yes, the root cause is the same.

*** This bug has been marked as a duplicate of bug 805501 ***

Note You need to log in before you can comment on or make changes to this bug.