From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:48274) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WwSmd-000545-Oa for qemu-devel@nongnu.org; Mon, 16 Jun 2014 05:01:01 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1WwSmX-00054P-G9 for qemu-devel@nongnu.org; Mon, 16 Jun 2014 05:00:55 -0400 Message-ID: <539EB23A.7030608@redhat.com> Date: Mon, 16 Jun 2014 11:00:42 +0200 From: Paolo Bonzini MIME-Version: 1.0 References: <1402507536-15437-1-git-send-email-kroosec@gmail.com> <5398A6C0.3080803@redhat.com> <20140615213742.GB5854@Inspiron-3521> In-Reply-To: <20140615213742.GB5854@Inspiron-3521> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCH] usb: Fix usb-bt-dongle segfault. List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Hani Benhabiles Cc: qemu-stable@nongnu.org, qemu-devel@nongnu.org, kraxel@redhat.com Il 15/06/2014 23:37, Hani Benhabiles ha scritto: >>> diff --git a/hw/usb/dev-bluetooth.c b/hw/usb/dev-bluetooth.c >>> index a9661d2..6d02343 100644 >>> --- a/hw/usb/dev-bluetooth.c >>> +++ b/hw/usb/dev-bluetooth.c >>> @@ -506,6 +506,12 @@ static int usb_bt_initfn(USBDevice *dev) >>> >>> usb_desc_create_serial(dev); >>> usb_desc_init(dev); >>> + s->dev.opaque = s; >>> + s->hci = bt_new_hci(qemu_find_bt_vlan(0)); >>> + s->hci->opaque = s; >>> + s->hci->evt_recv = usb_bt_out_hci_packet_event; >>> + s->hci->acl_recv = usb_bt_out_hci_packet_acl; >>> + usb_bt_handle_reset(&s->dev); >> >> >> All lines but the s->hci assignment should be removed from usb_bt_init too. >> >> As to s->hci, I suggest inlining usb_create_simple into usb_bt_init, and >> initializing s->hci there before doing the qdev_init() call. >> >> Then here you can wrap the assignment under "if (!s->hci)". > > I am afraid I don't quite understand what you want to achieve with this and why. > > Could you please explain how is usb_bt_init() relevant to this case ? usb_bt_init() ends up calling usb_bt_initfn(), via usb_create_simple. So if you add code to usb_bt_initfn() you can remove the corresponding lines in usb_bt_init(). Paolo