@samitouri / QOSamiQemu / commits / 4ea7024ff6

hw/display/cg3: Fix crash when introspecting cgthree from the CLI

QEMU currently crashes when introspecting the cgthree device from the command line interface: $ ./qemu-system-sparc -device cgthree,help Segmentation fault (core dumped) This happens because the memory_region_init_rom() function internally calls qemu_ram_alloc_internal() that needs the current_machine pointer to be set up - which is not the case here since the machine has not been created yet. There does not seem to be a compelling reason for initializing the memory regions from the instance_init function, so let's simply move the code into the realize() function instead to fix this issue. Tested-by: Markus Armbruster <armbru@redhat.com> Signed-off-by: Thomas Huth <thuth@redhat.com> Message-ID: <20260317080623.438230-1-thuth@redhat.com>

Thomas Huth committed Mar 17, 2026 at 09:06 UTC 4ea7024ff69e87ae819708e8ba7ce2c907f40514
1 file changed +6 -12
hw/display/cg3.c
+6 -12
@@ -277,10 +277,13 @@ static const GraphicHwOps cg3_ops = {
277 .gfx_update = cg3_update_display,
278 };
279
280 -static void cg3_initfn(Object *obj)
280 +static void cg3_realizefn(DeviceState *dev, Error **errp)
281 {
282 - SysBusDevice *sbd = SYS_BUS_DEVICE(obj);
283 - CG3State *s = CG3(obj);
282 + SysBusDevice *sbd = SYS_BUS_DEVICE(dev);
283 + Object *obj = OBJECT(dev);
284 + CG3State *s = CG3(dev);
285 + int ret;
286 + char *fcode_filename;
287
288 memory_region_init_rom(&s->rom, obj, "cg3.prom", FCODE_MAX_ROM_SIZE,
289 &error_fatal);
@@ -289,14 +292,6 @@ static void cg3_initfn(Object *obj)
292 memory_region_init_io(&s->reg, obj, &cg3_reg_ops, s, "cg3.reg",
293 CG3_REG_SIZE);
294 sysbus_init_mmio(sbd, &s->reg);
292 -}
293 -
294 -static void cg3_realizefn(DeviceState *dev, Error **errp)
295 -{
296 - SysBusDevice *sbd = SYS_BUS_DEVICE(dev);
297 - CG3State *s = CG3(dev);
298 - int ret;
299 - char *fcode_filename;
295
296 /* FCode ROM */
297 fcode_filename = qemu_find_file(QEMU_FILE_TYPE_BIOS, CG3_ROM_FILE);
@@ -381,7 +376,6 @@ static const TypeInfo cg3_info = {
376 .name = TYPE_CG3,
377 .parent = TYPE_SYS_BUS_DEVICE,
378 .instance_size = sizeof(CG3State),
384 - .instance_init = cg3_initfn,
379 .class_init = cg3_class_init,
380 };
381