qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03
@ 2016-08-03  9:48 Daniel P. Berrange
  2016-08-03  9:48 ` [Qemu-devel] [PULL v1] io: remove mistaken call to object_ref on QTask Daniel P. Berrange
  2016-08-03 13:23 ` [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03 Peter Maydell
  0 siblings, 2 replies; 3+ messages in thread
From: Daniel P. Berrange @ 2016-08-03  9:48 UTC (permalink / raw)
  To: qemu-devel; +Cc: Peter Maydell, Daniel P. Berrange

The following changes since commit 8b54a6a6c63dc84f2744f6b125c1a6c5a16ee10b:

  Merge remote-tracking branch 'remotes/ehabkost/tags/numa-pull-request' into staging (2016-08-02 12:55:12 +0100)

are available in the git repository at:

  git://github.com/berrange/qemu tags/pull-qio-next-2016-08-03-v1

for you to fetch changes up to bc35d51077b33e68a0ab10a057f352747214223f:

  io: remove mistaken call to object_ref on QTask (2016-08-03 10:28:50 +0100)

----------------------------------------------------------------
Merge qio-next 2016-08-03 v1

----------------------------------------------------------------
Daniel P. Berrange (1):
      io: remove mistaken call to object_ref on QTask

 io/channel-websock.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)
-- 
2.7.4

^ permalink raw reply	[flat|nested] 3+ messages in thread

* [Qemu-devel] [PULL v1] io: remove mistaken call to object_ref on QTask
  2016-08-03  9:48 [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03 Daniel P. Berrange
@ 2016-08-03  9:48 ` Daniel P. Berrange
  2016-08-03 13:23 ` [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03 Peter Maydell
  1 sibling, 0 replies; 3+ messages in thread
From: Daniel P. Berrange @ 2016-08-03  9:48 UTC (permalink / raw)
  To: qemu-devel; +Cc: Peter Maydell, Daniel P. Berrange

The QTask struct is just a standalone struct, not a QOM Object,
so calling object_ref() on it is not appropriate. This results
in mangling the 'destroy' field in the QTask struct, causing
the later call to qtask_free() to try to call the function
at address 0x1, with predictably segfault happy results.

There is in fact no need for ref counting with QTask, as the
call to qtask_abort() or qtask_complete() will automatically
free associated memory.

This fixes the crash shown in

  https://bugs.launchpad.net/qemu/+bug/1589923

Reviewed-by: Eric Blake <eblake@redhat.com>
Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
---
 io/channel-websock.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/io/channel-websock.c b/io/channel-websock.c
index 239c75a..533bd4b 100644
--- a/io/channel-websock.c
+++ b/io/channel-websock.c
@@ -317,14 +317,13 @@ static gboolean qio_channel_websock_handshake_io(QIOChannel *ioc,
         return TRUE;
     }
 
-    object_ref(OBJECT(task));
     trace_qio_channel_websock_handshake_reply(ioc);
     qio_channel_add_watch(
         wioc->master,
         G_IO_OUT,
         qio_channel_websock_handshake_send,
         task,
-        (GDestroyNotify)object_unref);
+        NULL);
     return FALSE;
 }
 
-- 
2.7.4

^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03
  2016-08-03  9:48 [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03 Daniel P. Berrange
  2016-08-03  9:48 ` [Qemu-devel] [PULL v1] io: remove mistaken call to object_ref on QTask Daniel P. Berrange
@ 2016-08-03 13:23 ` Peter Maydell
  1 sibling, 0 replies; 3+ messages in thread
From: Peter Maydell @ 2016-08-03 13:23 UTC (permalink / raw)
  To: Daniel P. Berrange; +Cc: QEMU Developers

On 3 August 2016 at 10:48, Daniel P. Berrange <berrange@redhat.com> wrote:
> The following changes since commit 8b54a6a6c63dc84f2744f6b125c1a6c5a16ee10b:
>
>   Merge remote-tracking branch 'remotes/ehabkost/tags/numa-pull-request' into staging (2016-08-02 12:55:12 +0100)
>
> are available in the git repository at:
>
>   git://github.com/berrange/qemu tags/pull-qio-next-2016-08-03-v1
>
> for you to fetch changes up to bc35d51077b33e68a0ab10a057f352747214223f:
>
>   io: remove mistaken call to object_ref on QTask (2016-08-03 10:28:50 +0100)
>
> ----------------------------------------------------------------
> Merge qio-next 2016-08-03 v1
>
> ----------------------------------------------------------------
> Daniel P. Berrange (1):
>       io: remove mistaken call to object_ref on QTask

Applied, thanks.

-- PMM

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2016-08-03 13:24 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-08-03  9:48 [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03 Daniel P. Berrange
2016-08-03  9:48 ` [Qemu-devel] [PULL v1] io: remove mistaken call to object_ref on QTask Daniel P. Berrange
2016-08-03 13:23 ` [Qemu-devel] [PULL v1] Merge qio-next 2016-08-03 Peter Maydell

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).