mirror of
https://github.com/yuzu-emu/unicorn.git
synced 2025-08-29 16:01:02 +00:00
exec: Stop using memory after free
memory_region_unref(mr) can free memory. For example I got: Program received signal SIGSEGV, Segmentation fault. [Switching to Thread 0x7f43280d4700 (LWP 4462)] 0x00007f43323283c0 in phys_section_destroy (mr=0x7f43259468b0) at /home/don/xen/tools/qemu-xen-dir/exec.c:1023 1023 if (mr->subpage) { (gdb) bt at /home/don/xen/tools/qemu-xen-dir/exec.c:1023 at /home/don/xen/tools/qemu-xen-dir/exec.c:1034 at /home/don/xen/tools/qemu-xen-dir/exec.c:2205 (gdb) p mr $1 = (MemoryRegion *) 0x7f43259468b0 And this change prevents this. Backports commit 55b4e80b047300e1512df02887b7448ba3786b62 from qemu
This commit is contained in:
parent
5218799171
commit
86436964b5
|
@ -821,9 +821,11 @@ static uint16_t phys_section_add(PhysPageMap *map,
|
||||||
|
|
||||||
static void phys_section_destroy(MemoryRegion *mr)
|
static void phys_section_destroy(MemoryRegion *mr)
|
||||||
{
|
{
|
||||||
|
bool have_sub_page = mr->subpage;
|
||||||
|
|
||||||
memory_region_unref(mr);
|
memory_region_unref(mr);
|
||||||
|
|
||||||
if (mr->subpage) {
|
if (have_sub_page) {
|
||||||
subpage_t *subpage = container_of(mr, subpage_t, iomem);
|
subpage_t *subpage = container_of(mr, subpage_t, iomem);
|
||||||
object_unref(mr->uc, OBJECT(&subpage->iomem));
|
object_unref(mr->uc, OBJECT(&subpage->iomem));
|
||||||
g_free(subpage);
|
g_free(subpage);
|
||||||
|
|
Loading…
Reference in a new issue