char: remove watch callback on chardev detach from frontend

If a frontend device releases the chardev (via unplug), the chr handlers
are set to NULL via qdev's exit callbacks invoking
qemu_chr_add_handlers().  If the chardev had a pending operation, a
callback will be invoked, which will try to access data in the
just-released frontend, causing a segfault.

Ensure the callbacks are disabled when frontends release chardevs.

This was seen when a virtio-serial port was unplugged when heavy
guest->host IO was in progress (causing a callback to be registered).
In the window in which the throttling was active, unplugging ports
caused a qemu segfault.

https://bugzilla.redhat.com/show_bug.cgi?id=985205

CC: <qemu-stable@nongnu.org>
Reported-by: Sibiao Luo <sluo@redhat.com>
Reviewed-by: Gerd Hoffmann <kraxel@redhat.com>
Signed-off-by: Amit Shah <amit.shah@redhat.com>
1 file changed
tree: c65829a5be0be6978005dc0047ffbbc0533f7497
  1. .exrc
  2. .gitignore
  3. .gitmodules
  4. .mailmap
  5. CODING_STYLE
  6. COPYING
  7. COPYING.LIB
  8. Changelog
  9. HACKING
  10. LICENSE
  11. MAINTAINERS
  12. Makefile
  13. Makefile.objs
  14. Makefile.target
  15. QMP/
  16. README
  17. VERSION
  18. aio-posix.c
  19. aio-win32.c
  20. arch_init.c
  21. async.c
  22. audio/
  23. backends/
  24. balloon.c
  25. block-migration.c
  26. block.c
  27. block/
  28. blockdev-nbd.c
  29. blockdev.c
  30. blockjob.c
  31. bsd-user/
  32. bt-host.c
  33. bt-vhci.c
  34. configure
  35. coroutine-gthread.c
  36. coroutine-sigaltstack.c
  37. coroutine-ucontext.c
  38. coroutine-win32.c
  39. cpu-exec.c
  40. cpus.c
  41. cputlb.c
  42. default-configs/
  43. device-hotplug.c
  44. device_tree.c
  45. disas.c
  46. disas/
  47. dma-helpers.c
  48. docs/
  49. dump.c
  50. exec.c
  51. fpu/
  52. fsdev/
  53. gdb-xml/
  54. gdbstub.c
  55. hmp-commands.hx
  56. hmp.c
  57. hmp.h
  58. hw/
  59. include/
  60. iohandler.c
  61. ioport.c
  62. kvm-all.c
  63. kvm-stub.c
  64. libcacard/
  65. linux-headers/
  66. linux-user/
  67. main-loop.c
  68. memory.c
  69. memory_mapping.c
  70. migration-exec.c
  71. migration-fd.c
  72. migration-rdma.c
  73. migration-tcp.c
  74. migration-unix.c
  75. migration.c
  76. monitor.c
  77. nbd.c
  78. net/
  79. os-posix.c
  80. os-win32.c
  81. page_cache.c
  82. pc-bios/
  83. po/
  84. qapi-schema.json
  85. qapi/
  86. qdev-monitor.c
  87. qdict-test-data.txt
  88. qemu-bridge-helper.c
  89. qemu-char.c
  90. qemu-coroutine-io.c
  91. qemu-coroutine-lock.c
  92. qemu-coroutine-sleep.c
  93. qemu-coroutine.c
  94. qemu-doc.texi
  95. qemu-img-cmds.hx
  96. qemu-img.c
  97. qemu-img.texi
  98. qemu-io-cmds.c
  99. qemu-io.c
  100. qemu-log.c
  101. qemu-nbd.c
  102. qemu-nbd.texi
  103. qemu-options-wrapper.h
  104. qemu-options.h
  105. qemu-options.hx
  106. qemu-seccomp.c
  107. qemu-tech.texi
  108. qemu-timer.c
  109. qemu.nsi
  110. qemu.sasl
  111. qga/
  112. qmp-commands.hx
  113. qmp.c
  114. qobject/
  115. qom/
  116. qtest.c
  117. readline.c
  118. roms/
  119. rules.mak
  120. savevm.c
  121. scripts/
  122. slirp/
  123. spice-qemu-char.c
  124. stubs/
  125. sysconfigs/
  126. target-alpha/
  127. target-arm/
  128. target-cris/
  129. target-i386/
  130. target-lm32/
  131. target-m68k/
  132. target-microblaze/
  133. target-mips/
  134. target-moxie/
  135. target-openrisc/
  136. target-ppc/
  137. target-s390x/
  138. target-sh4/
  139. target-sparc/
  140. target-unicore32/
  141. target-xtensa/
  142. tcg-runtime.c
  143. tcg/
  144. tci.c
  145. tests/
  146. thread-pool.c
  147. thunk.c
  148. tpm.c
  149. trace-events
  150. trace/
  151. translate-all.c
  152. translate-all.h
  153. ui/
  154. user-exec.c
  155. util/
  156. version.rc
  157. vl.c
  158. xbzrle.c
  159. xen-all.c
  160. xen-mapcache.c
  161. xen-stub.c