From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:47692) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZduIV-0002Qr-2x for qemu-devel@nongnu.org; Mon, 21 Sep 2015 02:09:55 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ZduIR-0006El-PR for qemu-devel@nongnu.org; Mon, 21 Sep 2015 02:09:54 -0400 From: Markus Armbruster References: <1442577640-11612-1-git-send-email-armbru@redhat.com> <1442577640-11612-6-git-send-email-armbru@redhat.com> <20150918163624.GA4221@thinpad.lan.raisama.net> Date: Mon, 21 Sep 2015 08:09:48 +0200 In-Reply-To: <20150918163624.GA4221@thinpad.lan.raisama.net> (Eduardo Habkost's message of "Fri, 18 Sep 2015 13:36:24 -0300") Message-ID: <87pp1cfglv.fsf@blackfin.pond.sub.org> MIME-Version: 1.0 Content-Type: text/plain Subject: Re: [Qemu-devel] [PATCH 5/7] qdev: Protect device-list-properties against broken devices List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Eduardo Habkost Cc: Peter Maydell , Peter Crosthwaite , qemu-devel@nongnu.org, qemu-stable@nongnu.org, Alistair Francis , Christian Borntraeger , Alexander Graf , qemu-ppc@nongnu.org, Antony Pavlov , stefanha@redhat.com, Cornelia Huck , Paolo Bonzini , afaerber@suse.de, Li Guang , Richard Henderson Eduardo Habkost writes: > On Fri, Sep 18, 2015 at 02:00:38PM +0200, Markus Armbruster wrote: >> Several devices don't survive object_unref(object_new(T)): they crash >> or hang during cleanup, or they leave dangling pointers behind. >> >> This breaks at least device-list-properties, because >> qmp_device_list_properties() needs to create a device to find its >> properties. Broken in commit f4eb32b "qmp: show QOM properties in >> device-list-properties", v2.1. Example reproducer: >> >> $ qemu-system-aarch64 -nodefaults -display none -machine none -S -qmp stdio >> {"QMP": {"version": {"qemu": {"micro": 50, "minor": 4, "major": 2}, "package": ""}, "capabilities": []}} >> { "execute": "qmp_capabilities" } >> {"return": {}} >> { "execute": "device-list-properties", "arguments": { "typename": "pxa2xx-pcmcia" } } >> qemu-system-aarch64: /home/armbru/work/qemu/memory.c:1307: memory_region_finalize: Assertion `((&mr->subregions)->tqh_first == ((void *)0))' failed. >> Aborted (core dumped) >> [Exit 134 (SIGABRT)] >> >> Unfortunately, I can't fix the problems in these devices right now. >> Instead, add DeviceClass member cannot_even_create_with_object_new_yet >> to mark them: >> >> * Crash or hang during cleanup (didn't debug them, so I can't say >> why): "pxa2xx-pcmcia", "realview_pci", "versatile_pci", >> "s390-sclp-event-facility", "sclp" >> >> * Dangling pointers: all CPUs, plus "allwinner-a10", "digic", >> "fsl,imx25", "fsl,imx31", "xlnx,zynqmp", because they create CPUs > > That's isn't true for all CPU classes, only the ones that (incorrectly) > call cpu_exec_init() on instance_init instead of realize. I believe at > least TYPE_POWERPC_CPU is safe already. Okay, I'll try to mark only the ones that actually screw up. Thanks!