From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:51746) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1QM0d4-0000iv-Bk for qemu-devel@nongnu.org; Mon, 16 May 2011 12:26:47 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1QM0d3-0005Xs-5t for qemu-devel@nongnu.org; Mon, 16 May 2011 12:26:46 -0400 Received: from mail-wy0-f173.google.com ([74.125.82.173]:49247) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1QM0d3-0005Xm-0p for qemu-devel@nongnu.org; Mon, 16 May 2011 12:26:45 -0400 Received: by wyb42 with SMTP id 42so4095971wyb.4 for ; Mon, 16 May 2011 09:26:44 -0700 (PDT) Sender: Paolo Bonzini Message-ID: <4DD15040.7030809@redhat.com> Date: Mon, 16 May 2011 18:26:40 +0200 From: Paolo Bonzini MIME-Version: 1.0 References: <1288876539-8300-1-git-send-email-kwolf@redhat.com> <1288876539-8300-4-git-send-email-kwolf@redhat.com> <20110516111926.GA7928@elie> <4DD13EFF.80000@redhat.com> <20110516154301.GA25150@elie> <4DD149A2.6020801@redhat.com> In-Reply-To: <4DD149A2.6020801@redhat.com> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [regression] qemu-system-arm: segfault in lsi_do_command List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Kevin Wolf Cc: Jonathan Nieder , Stefan Hajnoczi , qemu-devel@nongnu.org On 05/16/2011 05:58 PM, Kevin Wolf wrote: > Thanks. Still doesn't make much sense to me, the patch shouldn't change > anything with respect to a malloc, but I can reproduce a segfault now. I > think I'll have a closer look tomorrow. This fixes it on top of my SCSI refactoring series. Should I send v3 with this one squashed in appropriately? Or should this be sent later? Paolo diff --git a/hw/scsi-bus.c b/hw/scsi-bus.c index 2f0ffda..57cfc87 100644 --- a/hw/scsi-bus.c +++ b/hw/scsi-bus.c @@ -167,11 +167,17 @@ int scsi_req_get_sense(SCSIRequest *req, uint8_t *buf, int len) int32_t scsi_req_enqueue(SCSIRequest *req, uint8_t *buf) { + int32_t rc; assert(!req->enqueued); scsi_req_ref(req); req->enqueued = true; QTAILQ_INSERT_TAIL(&req->dev->requests, req, next); - return req->dev->info->send_command(req, buf); + + /* Make sure the request doesn't disappear under send_command's feet. */ + scsi_req_ref(req); + rc = req->dev->info->send_command(req, buf); + scsi_req_unref(req); + return rc; } static void scsi_req_dequeue(SCSIRequest *req)