All of lore.kernel.org
 help / color / mirror / Atom feed
From: Frederic Konrad <fred.konrad@greensocs.com>
To: Gerd Hoffmann <kraxel@redhat.com>
Cc: qemu-devel <qemu-devel@nongnu.org>
Subject: Re: [Qemu-devel] Bug with mpc8544ds machine.
Date: Mon, 31 Mar 2014 13:43:40 +0200	[thread overview]
Message-ID: <533954EC.1040400@greensocs.com> (raw)
In-Reply-To: <1396265434.3108.11.camel@nilsson.home.kraxel.org>

On 31/03/2014 13:30, Gerd Hoffmann wrote:
> On Fr, 2014-03-28 at 15:37 +0100, Frederic Konrad wrote:
>> Hi everybody,
>>
>> I didn't see anything on the list about that.
>> I get this bug in the current git.
>>
>> I configured qemu with the following command line:
>>
>> ./configure --target-list=ppc-softmmu
>>
>> I ran QEMU with the following command line:
>>
>> ./ppc-softmmu/qemu-system-ppc --M mpc8544ds
> ... then hit any key.  Crashes on first keypress for me, and given the
> stacktrace I think it is the same for you.
Hi,

On my side I don't need to push any key.
>> (gdb) bt
>> #0  0x00007fecf8e2a578 in qemu_input_transform_abs_rotate
>> (evt=<optimized out>) at ui/input.c:79
>> #1  qemu_input_event_send (src=src@entry=0x0,
>> evt=evt@entry=0x7fecfaac3130) at ui/input.c:141
>> #2  0x00007fecf8e2a71a in qemu_input_event_send_key (src=0x0,
>> key=<optimized out>, down=<optimized out>) at ui/input.c:185
>> #3  0x00007fecf8e2a7c2 in qemu_input_event_send_key_number
>> (src=<optimized out>, num=<optimized out>, down=<optimized out>) at
>> ui/input.c:195
> The key press event is created, then sent, and qemu crashes in a code
> path which isn't executed in the first place for keyboard events.
>
> Trying to reproduce locally crashes in a slightly different place, but
> it is a simliar pattern here:
>
> (gdb) bt
> #0  0x00005555557ba7b8 in fprintf (__fmt=<optimized out>,
> __stream=<optimized out>)
>      at /usr/include/bits/stdio2.h:97
> #1  trace_input_event_key_qcode (down=<optimized out>, qcode=<optimized
> out>,
>      conidx=<optimized out>) at ./trace/generated-tracers.h:5664
> #2  qemu_input_event_trace (evt=0x5555564012c0, src=0x0)
>      at /home/kraxel/projects/qemu/ui/input.c:104
> #3  qemu_input_event_send (src=src@entry=0x0,
> evt=evt@entry=0x5555564012c0)
>      at /home/kraxel/projects/qemu/ui/input.c:137
> #4  0x00005555557baab2 in qemu_input_event_send_key (src=0x0,
> key=<optimized out>,
>      down=<optimized out>) at /home/kraxel/projects/qemu/ui/input.c:185
> [ ... ]
>
> (gdb) up
> #1  trace_input_event_key_qcode (down=<optimized out>, qcode=<optimized
> out>,
>      conidx=<optimized out>) at ./trace/generated-tracers.h:5664
> 5664            fprintf(stderr, "input_event_key_qcode " "con %d, key
> qcode %s, down %d" "\n" , conidx, qcode, down);
> (gdb) up
> #2  qemu_input_event_trace (evt=0x5555564012c0, src=0x0)
>      at /home/kraxel/projects/qemu/ui/input.c:104
> 104                 trace_input_event_key_qcode(idx, name,
> evt->key->down);
> (gdb) print *evt
> $1 = {kind = INPUT_EVENT_KIND_KEY, {data = 0x5555564012e0, key =
> 0x5555564012e0,
>      btn = 0x5555564012e0, rel = 0x5555564012e0, abs = 0x5555564012e0}}
> (gdb) print *evt->key->key
> $2 = {kind = KEY_VALUE_KIND_NUMBER, {data = 0x20, number = 32, qcode =
> Q_KEY_CODE_I}}
>
> So, again, qemu crashing in a code path (trace_input_event_key_qcode)
> which it should not have been executed in the first place (we have
> KEY_VALUE_KIND_NUMBER not KEY_VALUE_KIND_QCODE).
>
> Hmm.  Puzzling.  Anyone has an idea what is going on here?
>
> cheers,
>    Gerd
>
>
>
I had a different behaviour with --enable-debug configure flags:

Program received signal SIGSEGV, Segmentation fault.
0x0000555555808193 in qemu_input_event_send (src=0x0, 
evt=0x5555566202f0) at ui/input.c:146
146        s->handler->event(s->dev, src, evt);
2: evt->kind = INPUT_EVENT_KIND_BTN
1: s = (QemuInputHandlerState *) 0x0

Seems qemu_input_find_handler returned NULL for me.

Adding this fixes the issue:

diff --git a/ui/input.c b/ui/input.c
index 2761911..d7670e9 100644
--- a/ui/input.c
+++ b/ui/input.c
@@ -143,8 +143,11 @@ void qemu_input_event_send(QemuConsole *src, 
InputEvent *evt)

      /* send event */
      s = qemu_input_find_handler(1 << evt->kind);
-    s->handler->event(s->dev, src, evt);
-    s->events++;
+
+    if (s != NULL) {
+        s->handler->event(s->dev, src, evt);
+        s->events++;
+    }
  }

  void qemu_input_event_sync(void)

Thanks,
Fred

      reply	other threads:[~2014-03-31 11:44 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-03-28 14:37 [Qemu-devel] Bug with mpc8544ds machine Frederic Konrad
2014-03-31 11:30 ` Gerd Hoffmann
2014-03-31 11:43   ` Frederic Konrad [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=533954EC.1040400@greensocs.com \
    --to=fred.konrad@greensocs.com \
    --cc=kraxel@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.