From mboxrd@z Thu Jan 1 00:00:00 1970 From: Chris Webb Subject: Re: qemu-kvm segfaults in qemu_del_timer (0.10.5 and 0.10.6) Date: Thu, 13 Aug 2009 13:41:20 +0100 Message-ID: <20090813124120.GM2539@arachsys.com> References: <20090812150159.GW5348@arachsys.com> <4A82E200.3040107@redhat.com> <20090812162401.GB8115@arachsys.com> <20090813122333.GA2863@arachsys.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: kvm@vger.kernel.org, qemu-devel@nongnu.org To: Avi Kivity Return-path: Received: from alpha.arachsys.com ([91.203.57.7]:36241 "EHLO alpha.arachsys.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751594AbZHMMlV (ORCPT ); Thu, 13 Aug 2009 08:41:21 -0400 Content-Disposition: inline In-Reply-To: <20090813122333.GA2863@arachsys.com> Sender: kvm-owner@vger.kernel.org List-ID: Chris Webb writes: > The segfault appears to be a null pointer dereference. ts->clock is NULL > and line 1161 uses ts->clock->type: > > (gdb) p ts > $4 = (QEMUTimer *) 0x30d1f30 > (gdb) p ts->clock > $5 = (QEMUClock *) 0x0 Sorry, meant to paste this too: (gdb) p *ts $1 = {clock = 0x0, expire_time = 49, cb = 0x2b63630, opaque = 0x30fe000, next = 0x495b40} Cheers, Chris.