From nobody Sat Sep 26 20:51:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1788463678; cv=none; d=zohomail.com; s=zohoarc; b=S0764Scuy+qdyzUaICUsrC7zbRNk/xmFQJeo2e7aqUg8WfD8Fpk6WlDhPkXXGDx3KIh06Ryn/cf6TsdyXo/1EaKdmAINB64AtPHU61INYMXS1sSz38NSWFPvHJD1F9q5oudubAyLADxEe+9/zAcMQmmLVyr3iZMYNCniYnglWbQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788463678; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/paBWoTU/+U3EiPt0qTWWxiaUQi+TbCN+6Q+i9Aj4sU=; b=IqlHgVFEE+zMa5j7FVCGB1TgemnWQeNwSLMMreJ7xmhY5F+I7QNi8ZchRH0pNojuf7uW2zfvGm4jM9yjsnwLkr2ZtGWPtc09QG6K/0tqs5cfOsCSPnqWLEIuQmt8MjpXlrqdSZxSxdqK+pKVd1+3x3q03wTuDk0FTtB9dAUDQiA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788463678715307.60821269529265; Thu, 3 Sep 2026 12:27:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2D5L-0005Dt-Tq; Thu, 03 Sep 2026 15:26:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2D5J-0005D6-TQ for qemu-devel@nongnu.org; Thu, 03 Sep 2026 15:26:53 -0400 Received: from mail-wr1-x42e.google.com ([2a00:1450:4864:20::42e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x2D5I-0001Y0-9t for qemu-devel@nongnu.org; Thu, 03 Sep 2026 15:26:53 -0400 Received: by mail-wr1-x42e.google.com with SMTP id ffacd0b85a97d-4858303de5dso302323f8f.2 for ; Thu, 03 Sep 2026 12:26:51 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:83cc:ab98:cda9:7dc]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885c5bbdsm663164f8f.36.2026.09.03.12.26.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 12:26:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1788463611; x=1789068411; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=/paBWoTU/+U3EiPt0qTWWxiaUQi+TbCN+6Q+i9Aj4sU=; b=TLv6s9ka4NvI4z4kaGBotyTojdqyz1tY80il11MFecY4B2XRc91Tns33fl8NQaNtky 1P2Nz3xcv491UWCGKI5iAKT4JbscFfI/Dsfl4QRvJzKyvTU4VTmslQKfer5dvay1QgnN dUkMK/TAUDsG1o+c47/3pryNvsaUW+derqWZfLQe+fA/1XlcYs4xO0T/qXPUwxN6uFsB X8shmOCurNpmCquGG8nMk1DOjegbiGSZMIW/Ipu/xRTakXm12pPx8H94m8EdwBOZ2/6J GEba7GZKh4Hr5Ldpsdx4XOP4M6Bjk5/VChjrQ8LEqVk/KO+bcwcjbLp46jM/1zhDnOSy vraQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788463611; x=1789068411; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=/paBWoTU/+U3EiPt0qTWWxiaUQi+TbCN+6Q+i9Aj4sU=; b=RDeC5UBWwHLP+anQFx8nfWZc6waWXiLdcr/3h/XE/YXlfnk5wrZVqmArVtpPoMs890 91+keIA/wZGh7rAU1bFaNyDH6MngWKLii724oyYSnf0xUtZBjpAkcl400Aa5+yFAzX05 AvDCWqFZYXGdOJbtPEoCjL2dthl4Gnn+RXj4k27jKn5ZWUJYhWRpuAJ9jKnyYEMUJQ1a geE1+HSI8FhsMWHPiT+R9b0pme4bsTFYIPsWsYDq/fXxooKcvGje2cPvqoE8pNHwE6mA PjiBpQau/eOpBQXf8vxQeKPbVOBcVIxEYQxSzsnYyP3+9WngID7D8dkHAM+TOlBOJw/a sAiQ== X-Gm-Message-State: AFuF++mc68+6kikRwJplCNqz2y9RRASsnmlQ2d6s21YgePsXBct9i6tg b5lbTQWmuPPl4CCRJVJ4pJQR/x5N0QzGJmkkMgRKVk9xjQTlO4bBfOPF6YBHND6CCDeNtEX0iAQ H8Ikk X-Gm-Gg: AYBFou1DjiVdgyOdry+m1M44M+sxTLZb9PjNqf6eNMdlMuSjPSMKHckoH7W32CwbPTk zfpSr9rQJ6EzYvemUnMwpX9QM9+s+UHWeU2TnMvxsV7m1LYSYsWjTNnu8i+DFRRvSoY42H5syJy 45am37yQJeN1cVK0JP590ICKqPPRPHNhslQfCdDRzeZxnwoaBJk98ToIC/akNAiPiGUGD5sM1V+ vUSopDINRfcutnqwrKOUkH1CtH6jdTCCr869kfwz/Cp7Es38ekuRAONvqjwnb1SpZKkZlrcDdZx cJmMXGcxPnsIMEms2HU/WI27Q7jQ+6d5AbdcI1KXh1joYN0TQuK9flUN6Je+Uk6KFqiJTx1k/Yd 5qx2AMpHhx1lzSAMI5kmpDtOtjHIPhnz7ZMb7KD3S82jfXjruvPvCvdOhKuSWTI212E1gqZ1LhI 8DjHpg6B6RsNu+Hj1y5/zAx1L/0cS176JHx6fIsq95TtzI+lfclrZboygm X-Received: by 2002:a05:6000:4694:b0:47f:9266:9bde with SMTP id ffacd0b85a97d-4858703f92dmr2298462f8f.4.1788463610738; Thu, 03 Sep 2026 12:26:50 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: den@openvz.org, qemu-stable@nongnu.org, =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= Subject: [PATCH 1/2] hw/display/qxl: hold ssd.lock while replacing ssd.cursor Date: Thu, 3 Sep 2026 21:26:46 +0200 Message-ID: <20260903192647.2677279-2-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260903192647.2677279-1-den@openvz.org> References: <20260903192647.2677279-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::42e; envelope-from=den@openvz.org; helo=mail-wr1-x42e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1788463680390158500 From: Denis V. Lunev qxl_spice_reset_cursor() unrefs qxl->ssd.cursor and installs the hidden cursor without holding qxl->ssd.lock. Every other writer of that field takes it: qxl_render_cursor(), display_mouse_define() and qemu_spice_cursor_refresh_bh(). The unlocked path runs on a vCPU thread, reached from ioport_write() on QXL_IO_DESTROY_PRIMARY and QXL_IO_DESTROY_PRIMARY_ASYNC, and holds only the BQL, which the SPICE display worker never takes. Unlike qxl_hard_reset(), it leaves that worker running. spice_qxl_reset_cursor() does round trip through the dispatcher, but the worker is free again as soon as it returns, so it can enter qxl_render_cursor() and unref the same QEMUCursor a few instructions later. Both threads then drop one reference for what is a single reference, freeing a cursor that another user still holds. The store to ssd.cursor races the same way, and a guest that keeps this up also ends up waiting forever in qxl_fence_wait(). A guest reaches this by switching QXL mode while it also updates the pointer shape. Fixes: 958c2bceba06 ("qxl: fix cursor reset") Cc: qemu-stable@nongnu.org Cc: Marc-Andr=C3=A9 Lureau Signed-off-by: Denis V. Lunev Reviewed-by: Marc-Andr=C3=A9 Lureau --- hw/display/qxl.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/display/qxl.c b/hw/display/qxl.c index 384b8767b8..c4f547e88b 100644 --- a/hw/display/qxl.c +++ b/hw/display/qxl.c @@ -294,10 +294,12 @@ void qxl_spice_reset_cursor(PCIQXLDevice *qxl) qemu_mutex_lock(&qxl->track_lock); qxl->guest_cursor =3D 0; qemu_mutex_unlock(&qxl->track_lock); + qemu_mutex_lock(&qxl->ssd.lock); if (qxl->ssd.cursor) { cursor_unref(qxl->ssd.cursor); } qxl->ssd.cursor =3D cursor_builtin_hidden(); + qemu_mutex_unlock(&qxl->ssd.lock); } =20 static uint32_t qxl_crc32(const uint8_t *p, unsigned len) --=20 2.53.0 From nobody Sat Sep 26 20:51:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1788463678; cv=none; d=zohomail.com; s=zohoarc; b=kdCJZBYjrKosnAPNKIsxNOoYnPwuv3V/2JJ9qZtJVcAou693HL9PfjKh81JuDzdxw7eDaDiWB+BCyBzN3F/5SDzJDT64mP/esTOIsRAV9+YTb9UeCIdbUE/DNXI84kpTtotINYDRwvyuQnMut8BSX2f77clSFtrYDBDKVzvutnA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788463678; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=xTYKRztQFUG6AyCovUZ2ESge4XIrHCQrsZ8nsTsCGW8=; b=Ww/p8tXka8IU1Y/vZERT6fCzqZ/v7BJdOEFX3wBa4dA3EU+fsSrCuKKNW4FKtVzj9S/12jJXb+3zswB13hvEWMoNvgTIvQOGb7jEbafdqkGzYmPwCoITclmDFM+xb4uSKI9LURgDK3ClMk5uVnyQYWLuvpZq6Ji2pgk6XUb1T4A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788463678617355.9388948714511; Thu, 3 Sep 2026 12:27:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2D5N-0005F0-Tk; Thu, 03 Sep 2026 15:26:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2D5L-0005Dc-0W for qemu-devel@nongnu.org; Thu, 03 Sep 2026 15:26:55 -0400 Received: from mail-wr1-x430.google.com ([2a00:1450:4864:20::430]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x2D5J-0001YB-5L for qemu-devel@nongnu.org; Thu, 03 Sep 2026 15:26:54 -0400 Received: by mail-wr1-x430.google.com with SMTP id ffacd0b85a97d-48444ec4fe2so177405f8f.0 for ; Thu, 03 Sep 2026 12:26:52 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:83cc:ab98:cda9:7dc]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885c5bbdsm663164f8f.36.2026.09.03.12.26.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 12:26:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1788463612; x=1789068412; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=xTYKRztQFUG6AyCovUZ2ESge4XIrHCQrsZ8nsTsCGW8=; b=hXKnzHGAKTR3sBSZoR9jjRW9vt4QC0E0UR21sbXcPsrZA7KRlLGHDyZS1ciLL/hm9i cYjqpuqyGlVI+JB0FNR5BbR/fF27FK+zgKSoZOd4eiUo48xOgggtYN6usv7armHfT2AV ZKz76WCU8aUhVpOeSz0pe4ORRwcBDS18pxwrlEQtMrmMFVLFXZ6GeXkC4usVeHGkj9tR LfgR9gY3hx1XQHZ6lWBAQTdzemlohSH6bxR8o1h3GVwJEESbLhEr5WLnl93gswpPuxBb +xLPpXdGIQ7bHiaGaEGgwq1d/0cHBGYI+aSqKe6g4kksjoy7EqH27IbaOxE8h8ZV1SDc XsDQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788463612; x=1789068412; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=xTYKRztQFUG6AyCovUZ2ESge4XIrHCQrsZ8nsTsCGW8=; b=i7T4wFsRCknPhQEzQ8sIW/iECXegGt1lzQvCFbgGhtPKlfi++S24yEYHydsmKgx6i7 tD1BY3pf8zM7Y3pR1YrMGVD1swMEmBMUdAf7SZhM25uIY9znFenN+tFoz76LtkxwA4uQ bAmn6qJvVIuOR3gr/mLMn1W045eVqaOME3Gw45okFbjQ2hfrRWF9G1BLKDrb2ZFHnH71 FbCE5bGFD1wDKxqZTvIYHYeAtRiDAqXngecreeAnIEmXx+QwfvYi02JQATWdIOTcOtuA ifyFrU0843QhA2vVFhOF2K5OO3ZnnTlfUe/SzA4XXw7uIjiNUhuRU0gvLoAFB9lAan1W 1WjQ== X-Gm-Message-State: AFuF++lZEz8HQwr9lytkbw/4fc15JUNCt26vGikgfMkGT0o3mq23E9Ko ZKesYbyLnL6r9E+G+EIQrgYvJDV3F8e4+U9RouKhSJhXPTedB6Mvx5GlXhp9H2teMjWYwT4tzHC lJqvX X-Gm-Gg: AYBFou2hLjqSSNlvC8LpBvoiPNvyLRLkfyVE7MNJuijdc04nz9Uhds6HPfs9uFFsyXU 6HeGFb4xvs7E3RgqMZdkhC8DB/EdueF5z9R0GUG7vHW3nF/4xGbEtvKCBfpwVofeHqXr3kRTYxp /Srf57tv3TvhDeo8dh6CFTduW5VeyfNeizt+IArzkfuY3k73Sn0crpXOU+m6qva+kr9lz52rEXW zcGt5H9AqqcSdONbauoPyccrybSAUQmMWCriS58cLx2ptLRI7pZkhAvG9JVY/edMeiIVOYTb1Vj qw/RQe6TjiOcePNtDASkVPtD3rGoJKCQXg9NYn/khz8PQvxJGP2JJmnOY34/Jmsau4oLf3oYJqz dY6YgO7bWZvgvuONtIDU5CSVt4KTe9PyFIU/KPBCrauhsv/47mLO7t/XSSnihltsIUq9yATmKZ4 OXzWZJtOu791vIZcukswuS8sHcGc+4xyDyrvS0DavO1fEJ1xaBGoGH/NUF X-Received: by 2002:a05:6000:2999:10b0:482:ea08:8c97 with SMTP id ffacd0b85a97d-48587046b35mr2012099f8f.2.1788463611709; Thu, 03 Sep 2026 12:26:51 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: den@openvz.org, qemu-stable@nongnu.org, =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= Subject: [PATCH 2/2] ui/cursor: make the cursor refcount atomic Date: Thu, 3 Sep 2026 21:26:47 +0200 Message-ID: <20260903192647.2677279-3-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260903192647.2677279-1-den@openvz.org> References: <20260903192647.2677279-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::430; envelope-from=den@openvz.org; helo=mail-wr1-x430.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1788463680118158501 From: Denis V. Lunev A QEMUCursor outlives the call that publishes it and is shared between threads, but its refcount was a plain int with no single lock covering every user. qemu_console_set_cursor() takes and drops references from the main loop under the BQL alone, hw/display/qxl-render.c does so from the SPICE display worker thread, and ui/spice-display.c does so under SimpleSpiceDisplay::lock. ui/cocoa.m and ui/dbus-listener.c add two more threads. The pair that collides is qemu_spice_cursor_refresh_bh(), which drops ssd->lock before calling qemu_console_set_cursor(), and the worker refcounting the same cursor under that lock. A lost increment frees the cursor while the console still points at it, so the console's next unref decrements memory the allocator has already handed out again. Locking ssd.cursor is not enough on its own: with that done, this is the race that remains. Assert on the value the decrement observed while here. Dropping a reference that was never taken used to be silent, because the decrement lands in the allocator metadata of the freed chunk: nothing is logged, the object is not freed twice, and the process runs on until some later allocation walks the damaged free list and faults, arbitrarily far from the code that caused it. Fixes: 0b2824e5e48a ("spice: use bottom half instead of refresh timer for c= ursor updates") Cc: qemu-stable@nongnu.org Cc: Marc-Andr=C3=A9 Lureau Signed-off-by: Denis V. Lunev Reviewed-by: Marc-Andr=C3=A9 Lureau --- include/ui/console.h | 9 +++++++++ ui/cursor.c | 17 +++++++++++------ 2 files changed, 20 insertions(+), 6 deletions(-) diff --git a/include/ui/console.h b/include/ui/console.h index 29bf722888..3634956949 100644 --- a/include/ui/console.h +++ b/include/ui/console.h @@ -126,6 +126,15 @@ typedef struct QEMUCursor { } QEMUCursor; =20 QEMUCursor *cursor_alloc(uint16_t width, uint16_t height); + +/* + * A cursor may be shared between the main loop, a vCPU thread and a + * display backend's own thread, so the refcount is atomic and these two + * may be called from any of them. The object itself is not otherwise + * thread-safe: take a reference before publishing the pointer anywhere + * another thread can reach it, and never dereference a cursor you do + * not hold a reference to. + */ QEMUCursor *cursor_ref(QEMUCursor *c); void cursor_unref(QEMUCursor *c); QEMUCursor *cursor_builtin_hidden(void); diff --git a/ui/cursor.c b/ui/cursor.c index 6e23244fbe..69d27d49a1 100644 --- a/ui/cursor.c +++ b/ui/cursor.c @@ -1,4 +1,5 @@ #include "qemu/osdep.h" +#include "qemu/atomic.h" #include "ui/console.h" =20 #include "cursor_hidden.xpm" @@ -103,24 +104,28 @@ QEMUCursor *cursor_alloc(uint16_t width, uint16_t hei= ght) c =3D g_malloc0(sizeof(QEMUCursor) + datasize); c->width =3D width; c->height =3D height; - c->refcount =3D 1; + qatomic_set(&c->refcount, 1); return c; } =20 QEMUCursor *cursor_ref(QEMUCursor *c) { - c->refcount++; + qatomic_inc(&c->refcount); return c; } =20 void cursor_unref(QEMUCursor *c) { + int refcount; + if (c =3D=3D NULL) return; - c->refcount--; - if (c->refcount) - return; - g_free(c); + + refcount =3D qatomic_fetch_dec(&c->refcount); + assert(refcount > 0); + if (refcount =3D=3D 1) { + g_free(c); + } } =20 int cursor_get_mono_bpl(QEMUCursor *c) --=20 2.53.0