Re: [PATCH] serial: clear transmit retry callback on unrealize

Marc-André Lureau <[email protected]>
Newsgroups gmane.comp.emulators.qemu
Message-ID <CAJ+F1CKuBR9TWnCzTjyFC=6Xn8q9ZDiXRXSoD+6if=cJRDkPMw@mail.gmail.com>
Hi

On Tue, Aug 18, 2026 at 6:29 PM Paolo Bonzini <[email protected]> wrote:
>
> The GSource is removed when resetting but remains active (and can
> cause use-after-free) on hot-unplug.  Remove it before the character
> device is disconnected.
>
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4125
> Signed-off-by: Paolo Bonzini <[email protected]>

it fixes a use-after-free, so
Reviewed-by: Marc-André Lureau <[email protected]>

But should we care about flushing pending data?

> ---
>  hw/char/serial.c | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/hw/char/serial.c b/hw/char/serial.c
> index 0729cd2ce9d..4339562ab00 100644
> --- a/hw/char/serial.c
> +++ b/hw/char/serial.c
> @@ -936,6 +936,7 @@ static void serial_unrealize(DeviceState *dev)
>  {
>      SerialState *s = SERIAL(dev);
>
> +    g_clear_handle_id(&s->watch_tag, g_source_remove);
>      qemu_chr_fe_deinit(&s->chr, false);
>
>      timer_free(s->modem_status_poll);
> --
> 2.55.0
>
>


-- 
Marc-André Lureau
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.