From patchwork Tue Feb 21 08:18:27 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Li Qiang X-Patchwork-Id: 730363 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3vSD2K2vHyz9s06 for ; Tue, 21 Feb 2017 19:20:09 +1100 (AEDT) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="IHs7rVgU"; dkim-atps=neutral Received: from localhost ([::1]:42889 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cg5g6-00026d-S1 for incoming@patchwork.ozlabs.org; Tue, 21 Feb 2017 03:20:06 -0500 Received: from eggs.gnu.org ([2001:4830:134:3::10]:42579) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cg5el-0001Gc-4c for qemu-devel@nongnu.org; Tue, 21 Feb 2017 03:18:43 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cg5eh-0000jb-Hx for qemu-devel@nongnu.org; Tue, 21 Feb 2017 03:18:43 -0500 Received: from mail-pg0-x244.google.com ([2607:f8b0:400e:c05::244]:32770) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1cg5eh-0000jX-CD for qemu-devel@nongnu.org; Tue, 21 Feb 2017 03:18:39 -0500 Received: by mail-pg0-x244.google.com with SMTP id 5so17080339pgj.0 for ; Tue, 21 Feb 2017 00:18:39 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=C5N9fZfH5iAFKgDwW++f9BYHJbXKPsPA5QG5fzIQ0RI=; b=IHs7rVgUBqMEB6viq1uLISfnvuJ7Ix6aT6o0GZLL4rPDR1bmsUaFvjzNDLqkFxDjuI EQ8M6ftt5+3Jhn5QkI0Blac5Ifb2MyTWE3Nz2J1dMRf5xv4w+EL1hbvLwgrKv+/QvhaF wjdeRPfdNChkAariJtb9cVeYAV0HFwCUU8zveOi7nrwXEYxFn34yQGKn940n1Xz4gPeE kNA+gDNp4IMGBXHAdhqtVdXmOA+qbGT3CMuisLOAWIe8jZ5cgRPrVO0rB9qW5ltpxLwn 0UkB4Hxl+XuMF+Eyn42FrOYztVREc2/cNzByekGtCyIlkIk+IES0oLoa2NfdICCA444/ 6CJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=C5N9fZfH5iAFKgDwW++f9BYHJbXKPsPA5QG5fzIQ0RI=; b=Em70AuCWDrSMy2GrD9TZMKUvRJcIuH2cEHvCjWFAhF+8pkwhlvbsN6x6tmdbILKL1b y9zNhlGfAxRYV8Lva72l+P0s/41py99Wusz502zZj1ub1ALCYjIUZGjp3P1378057cI7 R6q0ISiT1oeFTNR14W5LxEcqHZDX2q4Q6QngkYspX9RwwZ8Ok6dMZ/N6if0lXfC0Hyvt OfUGIMNUA9w38OwkqlH9N3gTL6plt2eXnkDX+ORRWrK/riwSXr0Zs/w+PmgS+sTDyr7L R2M9GR2aAb6eemFVnZ9oTHt4sX4S0UHs/H9Yp5GHzSU0NkXtIeDq17niOV3ZP23j7ahd Zpfw== X-Gm-Message-State: AMke39k+F+Utlh3CI0zItdkgbbyLb88E12g9b6k5UY/utsoIbGxm6GoThKP0QHPrqCkKtQ== X-Received: by 10.99.105.8 with SMTP id e8mr32508790pgc.217.1487665118471; Tue, 21 Feb 2017 00:18:38 -0800 (PST) Received: from localhost.localdomain.localdomain ([104.192.110.250]) by smtp.gmail.com with ESMTPSA id u24sm39236927pfi.25.2017.02.21.00.18.34 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 21 Feb 2017 00:18:37 -0800 (PST) From: Li Qiang X-Google-Original-From: Li Qiang To: pbonzini@redhat.com, marcandre.lureau@redhat.com, qemu-devel@nongnu.org Date: Tue, 21 Feb 2017 00:18:27 -0800 Message-Id: <1487665107-88004-1-git-send-email-liqiang6-s@360.cn> X-Mailer: git-send-email 1.8.3.1 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 2607:f8b0:400e:c05::244 Subject: [Qemu-devel] [PATCH v2] spice-char: fix segfault in char_spice_finalize X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Li Qiang Errors-To: qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org Sender: "Qemu-devel" In 'qemu_chr_open_spice_vmc' if the 'psubtype' is NULL, it will call 'char_spice_finalize'. But as the SpiceChardev is not inserted in the 'spice_chars' list, the 'QLIST_REMOVE' will cause a segfault. Add a detect to avoid it. Signed-off-by: Li Qiang Reviewed-by: Marc-André Lureau --- spice-qemu-char.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/spice-qemu-char.c b/spice-qemu-char.c index 6f46f46..4d1c76e 100644 --- a/spice-qemu-char.c +++ b/spice-qemu-char.c @@ -215,7 +215,10 @@ static void char_spice_finalize(Object *obj) SpiceChardev *s = SPICE_CHARDEV(obj); vmc_unregister_interface(s); - QLIST_REMOVE(s, next); + + if (s->next.le_prev) { + QLIST_REMOVE(s, next); + } g_free((char *)s->sin.subtype); #if SPICE_SERVER_VERSION >= 0x000c02