[PATCH-for-5.1] hw/isa/isa-superio: Fix IDE controller realization

Philippe Mathieu-Daudé posted 1 patch 5 years, 3 months ago
Test docker-quick@centos7 failed
Test docker-mingw@fedora failed
Test checkpatch failed
Test FreeBSD passed
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20200720172348.23465-1-f4bug@amsat.org
There is a newer version of this series
hw/isa/isa-superio.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH-for-5.1] hw/isa/isa-superio: Fix IDE controller realization
Posted by Philippe Mathieu-Daudé 5 years, 3 months ago
When realizing a Super I/O with IDE controller [*], we get:

  qom/object.c:1684: object_property_try_add_child: Assertion `!child->parent' failed.
  Aborted (core dumped)

This is because the device is already realized when we try to
add the QOM property to the parent. Fix by realizing *after*
adding the QOM relationship.

[*] Set ISASuperIOClass::ide.count = N with N not zero

Fixes: e508430619 ("hw/isa/superio: Make the components QOM children")
Signed-off-by: Philippe Mathieu-Daudé <f4bug@amsat.org>
---
 hw/isa/isa-superio.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/isa/isa-superio.c b/hw/isa/isa-superio.c
index e2e47d8fd9..179c185695 100644
--- a/hw/isa/isa-superio.c
+++ b/hw/isa/isa-superio.c
@@ -158,8 +158,8 @@ static void isa_superio_realize(DeviceState *dev, Error **errp)
         if (k->ide.get_irq) {
             qdev_prop_set_uint32(d, "irq", k->ide.get_irq(sio, 0));
         }
-        isa_realize_and_unref(isa, bus, &error_fatal);
         object_property_add_child(OBJECT(sio), "isa-ide", OBJECT(isa));
+        isa_realize_and_unref(isa, bus, &error_fatal);
         sio->ide = isa;
         trace_superio_create_ide(0,
                                  k->ide.get_iobase ?
-- 
2.21.3


Re: [PATCH-for-5.1] hw/isa/isa-superio: Fix IDE controller realization
Posted by Richard Henderson 5 years, 3 months ago
On 7/20/20 10:23 AM, Philippe Mathieu-Daudé wrote:
> When realizing a Super I/O with IDE controller [*], we get:
> 
>   qom/object.c:1684: object_property_try_add_child: Assertion `!child->parent' failed.
>   Aborted (core dumped)
> 
> This is because the device is already realized when we try to
> add the QOM property to the parent. Fix by realizing *after*
> adding the QOM relationship.
> 
> [*] Set ISASuperIOClass::ide.count = N with N not zero
> 
> Fixes: e508430619 ("hw/isa/superio: Make the components QOM children")
> Signed-off-by: Philippe Mathieu-Daudé <f4bug@amsat.org>
> ---
>  hw/isa/isa-superio.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

Reviewed-by: Richard Henderson <richard.henderson@linaro.org>

r~

Re: [PATCH-for-5.1] hw/isa/isa-superio: Fix IDE controller realization
Posted by Markus Armbruster 5 years, 3 months ago
Philippe Mathieu-Daudé <f4bug@amsat.org> writes:

> When realizing a Super I/O with IDE controller [*], we get:
>
>   qom/object.c:1684: object_property_try_add_child: Assertion `!child->parent' failed.
>   Aborted (core dumped)
>
> This is because the device is already realized when we try to
> add the QOM property to the parent. Fix by realizing *after*
> adding the QOM relationship.
>
> [*] Set ISASuperIOClass::ide.count = N with N not zero

Is this a latent bug, or can it bite in master?  If the latter, can you
show how to reproduce?

> Fixes: e508430619 ("hw/isa/superio: Make the components QOM children")
> Signed-off-by: Philippe Mathieu-Daudé <f4bug@amsat.org>
> ---
>  hw/isa/isa-superio.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/hw/isa/isa-superio.c b/hw/isa/isa-superio.c
> index e2e47d8fd9..179c185695 100644
> --- a/hw/isa/isa-superio.c
> +++ b/hw/isa/isa-superio.c
> @@ -158,8 +158,8 @@ static void isa_superio_realize(DeviceState *dev, Error **errp)
>          if (k->ide.get_irq) {
>              qdev_prop_set_uint32(d, "irq", k->ide.get_irq(sio, 0));
>          }
> -        isa_realize_and_unref(isa, bus, &error_fatal);
>          object_property_add_child(OBJECT(sio), "isa-ide", OBJECT(isa));
> +        isa_realize_and_unref(isa, bus, &error_fatal);
>          sio->ide = isa;
>          trace_superio_create_ide(0,
>                                   k->ide.get_iobase ?


Re: [PATCH-for-5.1] hw/isa/isa-superio: Fix IDE controller realization
Posted by Philippe Mathieu-Daudé 5 years, 3 months ago
On 7/21/20 10:15 AM, Markus Armbruster wrote:
> Philippe Mathieu-Daudé <f4bug@amsat.org> writes:
> 
>> When realizing a Super I/O with IDE controller [*], we get:
>>
>>   qom/object.c:1684: object_property_try_add_child: Assertion `!child->parent' failed.
>>   Aborted (core dumped)
>>
>> This is because the device is already realized when we try to
>> add the QOM property to the parent. Fix by realizing *after*
>> adding the QOM relationship.
>>
>> [*] Set ISASuperIOClass::ide.count = N with N not zero
> 
> Is this a latent bug, or can it bite in master?  If the latter, can you
> show how to reproduce?

Latent bug for master:

$ git grep ide.count
hw/isa/isa-superio.c:149:    if (k->ide.count && (!k->ide.is_enabled ||
k->ide.is_enabled(sio, 0))) {
hw/isa/isa-superio.c:197:    sc->ide.count = 0;
hw/isa/smc37c669-superio.c:100:    sc->ide.count = 0;
hw/isa/vt82c686.c:529:    sc->ide.count = 0;

I hit it rebasing undergoing series for 5.2 and testing them.

> 
>> Fixes: e508430619 ("hw/isa/superio: Make the components QOM children")
>> Signed-off-by: Philippe Mathieu-Daudé <f4bug@amsat.org>
>> ---
>>  hw/isa/isa-superio.c | 2 +-
>>  1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/hw/isa/isa-superio.c b/hw/isa/isa-superio.c
>> index e2e47d8fd9..179c185695 100644
>> --- a/hw/isa/isa-superio.c
>> +++ b/hw/isa/isa-superio.c
>> @@ -158,8 +158,8 @@ static void isa_superio_realize(DeviceState *dev, Error **errp)
>>          if (k->ide.get_irq) {
>>              qdev_prop_set_uint32(d, "irq", k->ide.get_irq(sio, 0));
>>          }
>> -        isa_realize_and_unref(isa, bus, &error_fatal);
>>          object_property_add_child(OBJECT(sio), "isa-ide", OBJECT(isa));
>> +        isa_realize_and_unref(isa, bus, &error_fatal);
>>          sio->ide = isa;
>>          trace_superio_create_ide(0,
>>                                   k->ide.get_iobase ?
> 
> 

Re: [PATCH-for-5.1] hw/isa/isa-superio: Fix IDE controller realization
Posted by Markus Armbruster 5 years, 3 months ago
Philippe Mathieu-Daudé <f4bug@amsat.org> writes:

> On 7/21/20 10:15 AM, Markus Armbruster wrote:
>> Philippe Mathieu-Daudé <f4bug@amsat.org> writes:
>> 
>>> When realizing a Super I/O with IDE controller [*], we get:
>>>
>>>   qom/object.c:1684: object_property_try_add_child: Assertion `!child->parent' failed.
>>>   Aborted (core dumped)
>>>
>>> This is because the device is already realized when we try to
>>> add the QOM property to the parent. Fix by realizing *after*
>>> adding the QOM relationship.
>>>
>>> [*] Set ISASuperIOClass::ide.count = N with N not zero
>> 
>> Is this a latent bug, or can it bite in master?  If the latter, can you
>> show how to reproduce?
>
> Latent bug for master:
>
> $ git grep ide.count
> hw/isa/isa-superio.c:149:    if (k->ide.count && (!k->ide.is_enabled ||
> k->ide.is_enabled(sio, 0))) {
> hw/isa/isa-superio.c:197:    sc->ide.count = 0;
> hw/isa/smc37c669-superio.c:100:    sc->ide.count = 0;
> hw/isa/vt82c686.c:529:    sc->ide.count = 0;
>
> I hit it rebasing undergoing series for 5.2 and testing them.

Let's tweak the commit message like this

    [*] Set ISASuperIOClass::ide.count = N with N not zero (no such
    thing currently exists; the bug is latent)

Preferably with that or something like it:
Reviewed-by: Markus Armbruster <armbru@redhat.com>


Re: [PATCH-for-5.1] hw/isa/isa-superio: Fix IDE controller realization
Posted by Philippe Mathieu-Daudé 5 years, 3 months ago
On 7/21/20 11:57 AM, Markus Armbruster wrote:
> Philippe Mathieu-Daudé <f4bug@amsat.org> writes:
> 
>> On 7/21/20 10:15 AM, Markus Armbruster wrote:
>>> Philippe Mathieu-Daudé <f4bug@amsat.org> writes:
>>>
>>>> When realizing a Super I/O with IDE controller [*], we get:
>>>>
>>>>   qom/object.c:1684: object_property_try_add_child: Assertion `!child->parent' failed.
>>>>   Aborted (core dumped)
>>>>
>>>> This is because the device is already realized when we try to
>>>> add the QOM property to the parent. Fix by realizing *after*
>>>> adding the QOM relationship.
>>>>
>>>> [*] Set ISASuperIOClass::ide.count = N with N not zero
>>>
>>> Is this a latent bug, or can it bite in master?  If the latter, can you
>>> show how to reproduce?
>>
>> Latent bug for master:
>>
>> $ git grep ide.count
>> hw/isa/isa-superio.c:149:    if (k->ide.count && (!k->ide.is_enabled ||
>> k->ide.is_enabled(sio, 0))) {
>> hw/isa/isa-superio.c:197:    sc->ide.count = 0;
>> hw/isa/smc37c669-superio.c:100:    sc->ide.count = 0;
>> hw/isa/vt82c686.c:529:    sc->ide.count = 0;
>>
>> I hit it rebasing undergoing series for 5.2 and testing them.
> 
> Let's tweak the commit message like this
> 
>     [*] Set ISASuperIOClass::ide.count = N with N not zero (no such
>     thing currently exists; the bug is latent)
> 
> Preferably with that or something like it:
> Reviewed-by: Markus Armbruster <armbru@redhat.com>

OK. I still consider it worthwhile fixing for 5.1, as while it
doesn't bite master, forks might be affected, since the bug is
in master.