From: Eduardo Habkost <ehabkost@redhat.com>
To: Thomas Huth <thuth@redhat.com>
Cc: "Peter Maydell" <peter.maydell@linaro.org>,
"Markus Armbruster" <armbru@redhat.com>,
"Alistair Francis" <alistair@alistair23.me>,
qemu-devel@nongnu.org,
"Subbaraya Sundeep" <sundeep.lkml@gmail.com>,
"Beniamino Galvani" <b.galvani@gmail.com>,
qemu-arm@nongnu.org, "Paolo Bonzini" <pbonzini@redhat.com>,
"Andreas Färber" <afaerber@suse.de>
Subject: Re: [Qemu-arm] [Qemu-devel] [PATCH v2 01/16] qom/object: Add a new function object_initialize_child()
Date: Thu, 16 Aug 2018 22:40:29 -0300 [thread overview]
Message-ID: <20180817014029.GV15372@localhost.localdomain> (raw)
In-Reply-To: <4551aa70-343e-1362-cfd3-d567c476d6fe@redhat.com>
On Thu, Aug 16, 2018 at 01:59:49PM +0200, Thomas Huth wrote:
> On 07/14/2018 12:57 AM, Eduardo Habkost wrote:
> > On Fri, Jul 13, 2018 at 10:27:29AM +0200, Thomas Huth wrote:
> >> A lot of code is using the object_initialize() function followed by a call
> >> to object_property_add_child() to add the newly initialized object as a child
> >> of the current object. Both functions increase the reference counter of the
> >> new object, but many spots that call these two functions then forget to drop
> >> one of the superfluous references. So the newly created object is often not
> >> cleaned up correctly when the parent is destroyed. In the worst case, this
> >> can cause crashes, e.g. because device objects are not correctly removed from
> >> their parent_bus.
> >>
> >> Since this is a common pattern between many code spots, let's introdcue a
> >> new function that takes care of calling all three required initialization
> >> functions, first object_initialize(), then object_property_add_child() and
> >> finally object_unref().
> >>
> >> And while we're at object.h, also fix some copy-n-paste errors in the
> >> comments there ("to store the area" --> "to store the error").
> >>
> >> Signed-off-by: Thomas Huth <thuth@redhat.com>
> >
> > Potential candidates for using the new function, found using the
> > following Coccinelle patch:
> >
> > @@
> > expression child, size, type, parent, errp, propname;
> > @@
> > -object_initialize(child, size, type);
> > -object_property_add_child(
> > +object_initialize_child(
> > parent, propname,
> > - OBJECT(child),
> > + child, size, type,
> > errp);
> >
> > Some of them (very few) already call object_unref() and need to
> > be fixed manually.
> >
> > Most of the remaining ~50 object_initialize() callers are also
> > candidates, even if they don't call object_property_add_child()
> > today.
> >
> > Signed-off-by: Eduardo Habkost <ehabkost@redhat.com>
>
> Care to turn this into a proper patch, now that we left the freeze period?
It's possible, but we need a volunteer to review each hunk
because the existing code might be (correctly) calling
object_unref() (either immediately or when parent is finalized).
I will keep this in my TODO list, but it's not my top priority
right now.
--
Eduardo
WARNING: multiple messages have this Message-ID (diff)
From: Eduardo Habkost <ehabkost@redhat.com>
To: Thomas Huth <thuth@redhat.com>
Cc: qemu-devel@nongnu.org, "Peter Maydell" <peter.maydell@linaro.org>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Alistair Francis" <alistair@alistair23.me>,
"Markus Armbruster" <armbru@redhat.com>,
"Subbaraya Sundeep" <sundeep.lkml@gmail.com>,
"Beniamino Galvani" <b.galvani@gmail.com>,
qemu-arm@nongnu.org,
"Edgar E. Iglesias" <edgar.iglesias@gmail.com>,
"Andreas Färber" <afaerber@suse.de>
Subject: Re: [Qemu-devel] [PATCH v2 01/16] qom/object: Add a new function object_initialize_child()
Date: Thu, 16 Aug 2018 22:40:29 -0300 [thread overview]
Message-ID: <20180817014029.GV15372@localhost.localdomain> (raw)
In-Reply-To: <4551aa70-343e-1362-cfd3-d567c476d6fe@redhat.com>
On Thu, Aug 16, 2018 at 01:59:49PM +0200, Thomas Huth wrote:
> On 07/14/2018 12:57 AM, Eduardo Habkost wrote:
> > On Fri, Jul 13, 2018 at 10:27:29AM +0200, Thomas Huth wrote:
> >> A lot of code is using the object_initialize() function followed by a call
> >> to object_property_add_child() to add the newly initialized object as a child
> >> of the current object. Both functions increase the reference counter of the
> >> new object, but many spots that call these two functions then forget to drop
> >> one of the superfluous references. So the newly created object is often not
> >> cleaned up correctly when the parent is destroyed. In the worst case, this
> >> can cause crashes, e.g. because device objects are not correctly removed from
> >> their parent_bus.
> >>
> >> Since this is a common pattern between many code spots, let's introdcue a
> >> new function that takes care of calling all three required initialization
> >> functions, first object_initialize(), then object_property_add_child() and
> >> finally object_unref().
> >>
> >> And while we're at object.h, also fix some copy-n-paste errors in the
> >> comments there ("to store the area" --> "to store the error").
> >>
> >> Signed-off-by: Thomas Huth <thuth@redhat.com>
> >
> > Potential candidates for using the new function, found using the
> > following Coccinelle patch:
> >
> > @@
> > expression child, size, type, parent, errp, propname;
> > @@
> > -object_initialize(child, size, type);
> > -object_property_add_child(
> > +object_initialize_child(
> > parent, propname,
> > - OBJECT(child),
> > + child, size, type,
> > errp);
> >
> > Some of them (very few) already call object_unref() and need to
> > be fixed manually.
> >
> > Most of the remaining ~50 object_initialize() callers are also
> > candidates, even if they don't call object_property_add_child()
> > today.
> >
> > Signed-off-by: Eduardo Habkost <ehabkost@redhat.com>
>
> Care to turn this into a proper patch, now that we left the freeze period?
It's possible, but we need a volunteer to review each hunk
because the existing code might be (correctly) calling
object_unref() (either immediately or when parent is finalized).
I will keep this in my TODO list, but it's not my top priority
right now.
--
Eduardo
next prev parent reply other threads:[~2018-08-17 1:40 UTC|newest]
Thread overview: 82+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-07-13 8:27 [Qemu-arm] [PATCH v2 00/16] Fix crashes with introspection of ARM devices Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 01/16] qom/object: Add a new function object_initialize_child() Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 11:14 ` Paolo Bonzini
2018-07-13 11:14 ` Paolo Bonzini
2018-07-13 21:16 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:16 ` [Qemu-devel] " Eduardo Habkost
2018-07-13 21:29 ` [Qemu-arm] " Andreas Färber
2018-07-13 21:29 ` [Qemu-devel] " Andreas Färber
2018-07-13 21:46 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:46 ` [Qemu-devel] " Eduardo Habkost
2018-07-16 7:05 ` [Qemu-arm] " Thomas Huth
2018-07-16 7:05 ` [Qemu-devel] " Thomas Huth
2018-07-13 22:57 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 22:57 ` Eduardo Habkost
2018-07-16 7:16 ` [Qemu-arm] " Thomas Huth
2018-07-16 7:16 ` Thomas Huth
2018-08-16 11:59 ` [Qemu-arm] " Thomas Huth
2018-08-16 11:59 ` Thomas Huth
2018-08-17 1:40 ` Eduardo Habkost [this message]
2018-08-17 1:40 ` Eduardo Habkost
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 02/16] hw/core/sysbus: Add a function for creating and attaching an object Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 21:17 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:17 ` [Qemu-devel] " Eduardo Habkost
2018-07-13 8:27 ` [Qemu-devel] [PATCH v2 03/16] hw/arm/bcm2836: Fix crash with device_add bcm2837 on unsupported machines Thomas Huth
2018-07-13 8:27 ` Thomas Huth
2018-07-13 21:26 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:26 ` [Qemu-devel] " Eduardo Habkost
2018-07-16 7:09 ` [Qemu-arm] " Thomas Huth
2018-07-16 7:09 ` [Qemu-devel] " Thomas Huth
2018-07-16 19:48 ` [Qemu-arm] " Eduardo Habkost
2018-07-16 19:48 ` [Qemu-devel] " Eduardo Habkost
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 04/16] hw/arm/armv7: Fix crash when introspecting the "iotkit" device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 21:31 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:31 ` [Qemu-devel] " Eduardo Habkost
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 05/16] hw/cpu/a15mpcore: Fix introspection problem with the a15mpcore_priv device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 21:48 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:48 ` [Qemu-devel] " Eduardo Habkost
2018-07-13 8:27 ` [Qemu-devel] [PATCH v2 06/16] hw/display/xlnx_dp: Move problematic code from instance_init to realize Thomas Huth
2018-07-13 8:27 ` Thomas Huth
2018-07-13 11:13 ` [Qemu-arm] " Paolo Bonzini
2018-07-13 11:13 ` [Qemu-devel] " Paolo Bonzini
2018-07-13 15:59 ` [Qemu-arm] " Thomas Huth
2018-07-13 15:59 ` [Qemu-devel] " Thomas Huth
2018-07-13 17:13 ` [Qemu-arm] " Paolo Bonzini
2018-07-13 17:13 ` [Qemu-devel] " Paolo Bonzini
2018-07-16 11:34 ` [Qemu-arm] " Thomas Huth
2018-07-16 11:34 ` Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 07/16] hw/arm/xlnx-zynqmp: Fix crash when introspecting the "xlnx, zynqmp" device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 21:49 ` Eduardo Habkost
2018-07-13 21:49 ` Eduardo Habkost
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 08/16] hw/arm/msf2-soc: Fix introspection problem with the "msf2-soc" device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 21:53 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:53 ` [Qemu-devel] " Eduardo Habkost
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 09/16] hw/cpu/a9mpcore: Fix introspection problems with the "a9mpcore_priv" device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 21:53 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 21:53 ` [Qemu-devel] " Eduardo Habkost
2018-07-13 8:27 ` [Qemu-devel] [PATCH v2 10/16] hw/arm/fsl-imx6: Fix introspection problems with the "fsl, imx6" device Thomas Huth
2018-07-13 8:27 ` Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 11/16] hw/arm/fsl-imx7: Fix introspection problems with the "fsl, imx7" device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 12/16] hw/arm/fsl-imx25: Fix introspection problem with the "fsl, imx25" device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 13/16] hw/arm/fsl-imx31: Fix introspection problem with the "fsl, imx31" device Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 14/16] hw/cpu/arm11mpcore: Fix introspection problem with 'arm11mpcore_priv' Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 15/16] hw/*/realview: Fix introspection problem with 'realview_mpcore' & 'realview_gic' Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 8:27 ` [Qemu-arm] [PATCH v2 16/16] hw/arm/allwinner-a10: Fix introspection problem with 'allwinner-a10' Thomas Huth
2018-07-13 8:27 ` [Qemu-devel] " Thomas Huth
2018-07-13 10:56 ` [Qemu-arm] [Qemu-devel] [PATCH v2 00/16] Fix crashes with introspection of ARM devices Richard Henderson
2018-07-13 10:56 ` Richard Henderson
2018-07-13 22:00 ` [Qemu-arm] " Eduardo Habkost
2018-07-13 22:00 ` [Qemu-devel] " Eduardo Habkost
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180817014029.GV15372@localhost.localdomain \
--to=ehabkost@redhat.com \
--cc=afaerber@suse.de \
--cc=alistair@alistair23.me \
--cc=armbru@redhat.com \
--cc=b.galvani@gmail.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=sundeep.lkml@gmail.com \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.