From nobody Wed Apr 24 13:57:44 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zoho.com; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1487665230428119.26068333012483; Tue, 21 Feb 2017 00:20:30 -0800 (PST) Received: from localhost ([::1]:42889 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cg5gT-00026d-32 for importer@patchew.org; Tue, 21 Feb 2017 03:20:29 -0500 Received: from eggs.gnu.org ([2001:4830:134:3::10]:42579) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cg5el-0001Gc-4c for qemu-devel@nongnu.org; Tue, 21 Feb 2017 03:18:43 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cg5eh-0000jb-Hx for qemu-devel@nongnu.org; Tue, 21 Feb 2017 03:18:43 -0500 Received: from mail-pg0-x244.google.com ([2607:f8b0:400e:c05::244]:32770) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1cg5eh-0000jX-CD for qemu-devel@nongnu.org; Tue, 21 Feb 2017 03:18:39 -0500 Received: by mail-pg0-x244.google.com with SMTP id 5so17080339pgj.0 for ; Tue, 21 Feb 2017 00:18:39 -0800 (PST) Received: from localhost.localdomain.localdomain ([104.192.110.250]) by smtp.gmail.com with ESMTPSA id u24sm39236927pfi.25.2017.02.21.00.18.34 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 21 Feb 2017 00:18:37 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=C5N9fZfH5iAFKgDwW++f9BYHJbXKPsPA5QG5fzIQ0RI=; b=IHs7rVgUBqMEB6viq1uLISfnvuJ7Ix6aT6o0GZLL4rPDR1bmsUaFvjzNDLqkFxDjuI EQ8M6ftt5+3Jhn5QkI0Blac5Ifb2MyTWE3Nz2J1dMRf5xv4w+EL1hbvLwgrKv+/QvhaF wjdeRPfdNChkAariJtb9cVeYAV0HFwCUU8zveOi7nrwXEYxFn34yQGKn940n1Xz4gPeE kNA+gDNp4IMGBXHAdhqtVdXmOA+qbGT3CMuisLOAWIe8jZ5cgRPrVO0rB9qW5ltpxLwn 0UkB4Hxl+XuMF+Eyn42FrOYztVREc2/cNzByekGtCyIlkIk+IES0oLoa2NfdICCA444/ 6CJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=C5N9fZfH5iAFKgDwW++f9BYHJbXKPsPA5QG5fzIQ0RI=; b=Em70AuCWDrSMy2GrD9TZMKUvRJcIuH2cEHvCjWFAhF+8pkwhlvbsN6x6tmdbILKL1b y9zNhlGfAxRYV8Lva72l+P0s/41py99Wusz502zZj1ub1ALCYjIUZGjp3P1378057cI7 R6q0ISiT1oeFTNR14W5LxEcqHZDX2q4Q6QngkYspX9RwwZ8Ok6dMZ/N6if0lXfC0Hyvt OfUGIMNUA9w38OwkqlH9N3gTL6plt2eXnkDX+ORRWrK/riwSXr0Zs/w+PmgS+sTDyr7L R2M9GR2aAb6eemFVnZ9oTHt4sX4S0UHs/H9Yp5GHzSU0NkXtIeDq17niOV3ZP23j7ahd Zpfw== X-Gm-Message-State: AMke39k+F+Utlh3CI0zItdkgbbyLb88E12g9b6k5UY/utsoIbGxm6GoThKP0QHPrqCkKtQ== X-Received: by 10.99.105.8 with SMTP id e8mr32508790pgc.217.1487665118471; Tue, 21 Feb 2017 00:18:38 -0800 (PST) From: Li Qiang X-Google-Original-From: Li Qiang To: pbonzini@redhat.com, marcandre.lureau@redhat.com, qemu-devel@nongnu.org Date: Tue, 21 Feb 2017 00:18:27 -0800 Message-Id: <1487665107-88004-1-git-send-email-liqiang6-s@360.cn> X-Mailer: git-send-email 1.8.3.1 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 2607:f8b0:400e:c05::244 Subject: [Qemu-devel] [PATCH v2] spice-char: fix segfault in char_spice_finalize X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Li Qiang Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail: RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" In 'qemu_chr_open_spice_vmc' if the 'psubtype' is NULL, it will call 'char_spice_finalize'. But as the SpiceChardev is not inserted in the 'spice_chars' list, the 'QLIST_REMOVE' will cause a segfault. Add a detect to avoid it. Signed-off-by: Li Qiang Reviewed-by: Marc-Andr=C3=A9 Lureau --- spice-qemu-char.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/spice-qemu-char.c b/spice-qemu-char.c index 6f46f46..4d1c76e 100644 --- a/spice-qemu-char.c +++ b/spice-qemu-char.c @@ -215,7 +215,10 @@ static void char_spice_finalize(Object *obj) SpiceChardev *s =3D SPICE_CHARDEV(obj); =20 vmc_unregister_interface(s); - QLIST_REMOVE(s, next); + + if (s->next.le_prev) { + QLIST_REMOVE(s, next); + } =20 g_free((char *)s->sin.subtype); #if SPICE_SERVER_VERSION >=3D 0x000c02 --=20 1.8.3.1