From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:39255) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1QJSh6-0004eK-NU for qemu-devel@nongnu.org; Mon, 09 May 2011 11:48:26 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1QJSh4-0003Mp-M9 for qemu-devel@nongnu.org; Mon, 09 May 2011 11:48:24 -0400 Received: from david.siemens.de ([192.35.17.14]:33335) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1QJSh4-0003KU-DX for qemu-devel@nongnu.org; Mon, 09 May 2011 11:48:22 -0400 Message-ID: <4DC80CC3.2030807@siemens.com> Date: Mon, 09 May 2011 17:48:19 +0200 From: Jan Kiszka MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 7bit Subject: [Qemu-devel] [PATCH] ahci: Fix crashes on duplicate BH registration List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Alexander Graf , Kevin Wolf Cc: qemu-devel If ahci_dma_set_inactive is called a while there is still a pending BH from a previous run, we will crash on the second run of ahci_check_cmd_bh as it overwrites AHCIDevice::check_bh. Avoid this broken and redundant duplicate registration. Signed-off-by: Jan Kiszka --- hw/ide/ahci.c | 8 +++++--- 1 files changed, 5 insertions(+), 3 deletions(-) diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c index c6e0c77..744d19d 100644 --- a/hw/ide/ahci.c +++ b/hw/ide/ahci.c @@ -1066,9 +1066,11 @@ static int ahci_dma_set_inactive(IDEDMA *dma) ad->dma_cb = NULL; - /* maybe we still have something to process, check later */ - ad->check_bh = qemu_bh_new(ahci_check_cmd_bh, ad); - qemu_bh_schedule(ad->check_bh); + if (!ad->check_bh) { + /* maybe we still have something to process, check later */ + ad->check_bh = qemu_bh_new(ahci_check_cmd_bh, ad); + qemu_bh_schedule(ad->check_bh); + } return 0; } -- 1.7.1