All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eduardo Habkost <ehabkost@redhat.com>
To: Thomas Huth <thuth@redhat.com>
Cc: qemu-devel@nongnu.org, "Peter Maydell" <peter.maydell@linaro.org>,
	"Paolo Bonzini" <pbonzini@redhat.com>,
	qemu-arm@nongnu.org, "Markus Armbruster" <armbru@redhat.com>,
	"Beniamino Galvani" <b.galvani@gmail.com>,
	"Subbaraya Sundeep" <sundeep.lkml@gmail.com>,
	"Alistair Francis" <alistair@alistair23.me>,
	"Edgar E. Iglesias" <edgar.iglesias@gmail.com>,
	"Andreas Färber" <afaerber@suse.de>
Subject: Re: [Qemu-devel] [PATCH v2 03/16] hw/arm/bcm2836: Fix crash with device_add bcm2837 on unsupported machines
Date: Fri, 13 Jul 2018 18:26:13 -0300	[thread overview]
Message-ID: <20180713212613.GU31657@localhost.localdomain> (raw)
In-Reply-To: <1531470464-21522-4-git-send-email-thuth@redhat.com>

On Fri, Jul 13, 2018 at 10:27:31AM +0200, Thomas Huth wrote:
> When trying to "device_add bcm2837" on a machine that is not suitable for
> this device, you can quickly crash QEMU afterwards, e.g. with "info qtree":
> 
> echo "{'execute':'qmp_capabilities'} {'execute':'device_add', " \
>  "'arguments':{'driver':'bcm2837'}} {'execute': 'human-monitor-command', " \
>  "'arguments': {'command-line': 'info qtree'}}" | \
>  aarch64-softmmu/qemu-system-aarch64 -M integratorcp,accel=qtest -S -qmp stdio
> 
> {"QMP": {"version": {"qemu": {"micro": 50, "minor": 12, "major": 2},
>  "package": "build-all"}, "capabilities": []}}
> {"return": {}}
> {"error": {"class": "GenericError", "desc": "Device 'bcm2837' can not be
>  hotplugged on this machine"}}
> Segmentation fault (core dumped)
> 
> The qdev_set_parent_bus() from instance_init adds a link to the child devices
> which is not valid anymore after the bcm2837 instance has been destroyed.
> Unfortunately, the child devices do not get destroyed / unlinked correctly
> because both object_initialize() and object_property_add_child() increase
> the reference count of the child objects by one, but only one reference
> is dropped when the parent gets removed. So let's use the new functions
> object_initialize_child() and sysbus_init_child_obj() instead to create
> the objects, which will take care of creating the child objects with the
> correct reference count of one.
> 
> Signed-off-by: Thomas Huth <thuth@redhat.com>

Reviewed-by: Eduardo Habkost <ehabkost@redhat.com>

The usage of &error_abort in code that can be triggered from
device-list-properties still makes me nervous, but that's a
separate issue.


> ---
>  hw/arm/bcm2836.c | 18 ++++++------------
>  1 file changed, 6 insertions(+), 12 deletions(-)
> 
> diff --git a/hw/arm/bcm2836.c b/hw/arm/bcm2836.c
> index 6805a7d..af97b2f 100644
> --- a/hw/arm/bcm2836.c
> +++ b/hw/arm/bcm2836.c
> @@ -51,25 +51,19 @@ static void bcm2836_init(Object *obj)
>      int n;
>  
>      for (n = 0; n < BCM283X_NCPUS; n++) {
> -        object_initialize(&s->cpus[n], sizeof(s->cpus[n]),
> -                          info->cpu_type);
> -        object_property_add_child(obj, "cpu[*]", OBJECT(&s->cpus[n]),
> -                                  &error_abort);
> +        object_initialize_child(obj, "cpu[*]", &s->cpus[n], sizeof(s->cpus[n]),
> +                                info->cpu_type, &error_abort);
>      }
>  
> -    object_initialize(&s->control, sizeof(s->control), TYPE_BCM2836_CONTROL);
> -    object_property_add_child(obj, "control", OBJECT(&s->control), NULL);
> -    qdev_set_parent_bus(DEVICE(&s->control), sysbus_get_default());
> +    sysbus_init_child_obj(obj, "control", &s->control, sizeof(s->control),
> +                          TYPE_BCM2836_CONTROL);
>  
> -    object_initialize(&s->peripherals, sizeof(s->peripherals),
> -                      TYPE_BCM2835_PERIPHERALS);
> -    object_property_add_child(obj, "peripherals", OBJECT(&s->peripherals),
> -                              &error_abort);
> +    sysbus_init_child_obj(obj, "peripherals", &s->peripherals,
> +                          sizeof(s->peripherals), TYPE_BCM2835_PERIPHERALS);
>      object_property_add_alias(obj, "board-rev", OBJECT(&s->peripherals),
>                                "board-rev", &error_abort);
>      object_property_add_alias(obj, "vcram-size", OBJECT(&s->peripherals),
>                                "vcram-size", &error_abort);
> -    qdev_set_parent_bus(DEVICE(&s->peripherals), sysbus_get_default());
>  }
>  
>  static void bcm2836_realize(DeviceState *dev, Error **errp)
> -- 
> 1.8.3.1
> 

-- 
Eduardo

  reply	other threads:[~2018-07-13 21:26 UTC|newest]

Thread overview: 41+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-07-13  8:27 [Qemu-devel] [PATCH v2 00/16] Fix crashes with introspection of ARM devices Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 01/16] qom/object: Add a new function object_initialize_child() Thomas Huth
2018-07-13 11:14   ` Paolo Bonzini
2018-07-13 21:16   ` Eduardo Habkost
2018-07-13 21:29     ` Andreas Färber
2018-07-13 21:46       ` Eduardo Habkost
2018-07-16  7:05         ` Thomas Huth
2018-07-13 22:57   ` Eduardo Habkost
2018-07-16  7:16     ` Thomas Huth
2018-08-16 11:59     ` Thomas Huth
2018-08-17  1:40       ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 02/16] hw/core/sysbus: Add a function for creating and attaching an object Thomas Huth
2018-07-13 21:17   ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 03/16] hw/arm/bcm2836: Fix crash with device_add bcm2837 on unsupported machines Thomas Huth
2018-07-13 21:26   ` Eduardo Habkost [this message]
2018-07-16  7:09     ` Thomas Huth
2018-07-16 19:48       ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 04/16] hw/arm/armv7: Fix crash when introspecting the "iotkit" device Thomas Huth
2018-07-13 21:31   ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 05/16] hw/cpu/a15mpcore: Fix introspection problem with the a15mpcore_priv device Thomas Huth
2018-07-13 21:48   ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 06/16] hw/display/xlnx_dp: Move problematic code from instance_init to realize Thomas Huth
2018-07-13 11:13   ` Paolo Bonzini
2018-07-13 15:59     ` Thomas Huth
2018-07-13 17:13       ` Paolo Bonzini
2018-07-16 11:34         ` Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 07/16] hw/arm/xlnx-zynqmp: Fix crash when introspecting the "xlnx, zynqmp" device Thomas Huth
2018-07-13 21:49   ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 08/16] hw/arm/msf2-soc: Fix introspection problem with the "msf2-soc" device Thomas Huth
2018-07-13 21:53   ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 09/16] hw/cpu/a9mpcore: Fix introspection problems with the "a9mpcore_priv" device Thomas Huth
2018-07-13 21:53   ` Eduardo Habkost
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 10/16] hw/arm/fsl-imx6: Fix introspection problems with the "fsl, imx6" device Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 11/16] hw/arm/fsl-imx7: Fix introspection problems with the "fsl, imx7" device Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 12/16] hw/arm/fsl-imx25: Fix introspection problem with the "fsl, imx25" device Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 13/16] hw/arm/fsl-imx31: Fix introspection problem with the "fsl, imx31" device Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 14/16] hw/cpu/arm11mpcore: Fix introspection problem with 'arm11mpcore_priv' Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 15/16] hw/*/realview: Fix introspection problem with 'realview_mpcore' & 'realview_gic' Thomas Huth
2018-07-13  8:27 ` [Qemu-devel] [PATCH v2 16/16] hw/arm/allwinner-a10: Fix introspection problem with 'allwinner-a10' Thomas Huth
2018-07-13 10:56 ` [Qemu-devel] [PATCH v2 00/16] Fix crashes with introspection of ARM devices Richard Henderson
2018-07-13 22:00 ` Eduardo Habkost

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180713212613.GU31657@localhost.localdomain \
    --to=ehabkost@redhat.com \
    --cc=afaerber@suse.de \
    --cc=alistair@alistair23.me \
    --cc=armbru@redhat.com \
    --cc=b.galvani@gmail.com \
    --cc=edgar.iglesias@gmail.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=sundeep.lkml@gmail.com \
    --cc=thuth@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.