qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-devel] [PATCH] usb: Fix usb-bt-dongle segfault.


From: Paolo Bonzini
Subject: Re: [Qemu-devel] [PATCH] usb: Fix usb-bt-dongle segfault.
Date: Wed, 11 Jun 2014 20:58:08 +0200
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0

Il 11/06/2014 19:25, Hani Benhabiles ha scritto:
Due to an incomplete initialization, adding a usb-bt-dongle device through HMP
or QMP will cause a segmentation fault.

Signed-off-by: Hani Benhabiles <address@hidden>
---

Not sure about the exact policy of qemu-stable. CC'ing it as this bug results in
a segfault.

 hw/usb/dev-bluetooth.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/hw/usb/dev-bluetooth.c b/hw/usb/dev-bluetooth.c
index a9661d2..6d02343 100644
--- a/hw/usb/dev-bluetooth.c
+++ b/hw/usb/dev-bluetooth.c
@@ -506,6 +506,12 @@ static int usb_bt_initfn(USBDevice *dev)

     usb_desc_create_serial(dev);
     usb_desc_init(dev);
+    s->dev.opaque = s;
+    s->hci = bt_new_hci(qemu_find_bt_vlan(0));
+    s->hci->opaque = s;
+    s->hci->evt_recv = usb_bt_out_hci_packet_event;
+    s->hci->acl_recv = usb_bt_out_hci_packet_acl;
+    usb_bt_handle_reset(&s->dev);


All lines but the s->hci assignment should be removed from usb_bt_init too.

As to s->hci, I suggest inlining usb_create_simple into usb_bt_init, and initializing s->hci there before doing the qdev_init() call.

Then here you can wrap the assignment under "if (!s->hci)".

Thanks for TLC of this little-used piece of code.

Paolo

     s->intr = usb_ep_get(dev, USB_TOKEN_IN, USB_EVT_EP);

     return 0;





reply via email to

[Prev in Thread] Current Thread [Next in Thread]