@samitouri / QOSamiQemu / commits / aee404fc7f

hw/pci-host/raven: Fix crash when introspecting raven-pcihost from the CLI

QEMU currently crashes when introspecting raven-pcihost from the command line interface: $ ./qemu-system-ppc -device raven-pcihost,help Segmentation fault (core dumped) This happens because the raven_pcihost_initfn instance init function calls get_system_memory(), but that is not available here yet. There does not seem to be a compelling reason for initializing the memory regions from the instance init function, so let's simply move the code into the realize() function instead to fix this issue. Tested-by: Markus Armbruster <armbru@redhat.com> Signed-off-by: Thomas Huth <thuth@redhat.com> Message-ID: <20260317074049.436460-1-thuth@redhat.com>

Thomas Huth committed Mar 17, 2026 at 08:40 UTC aee404fc7f37521de32d50440f06cba1b3aebf93
1 file changed +31 -37
hw/pci-host/raven.c
+31 -37
@@ -212,8 +212,39 @@ static void raven_pcihost_realizefn(DeviceState *d, Error **errp)
212 PCIHostState *h = PCI_HOST_BRIDGE(dev);
213 PREPPCIState *s = RAVEN_PCI_HOST_BRIDGE(dev);
214 MemoryRegion *address_space_mem = get_system_memory();
215 + Object *obj = OBJECT(d);
216 int i;
217
218 + memory_region_init(&s->pci_io, obj, "pci-io", 0x3f800000);
219 + memory_region_init_io(&s->pci_io_non_contiguous, obj, &raven_io_ops, s,
220 + "pci-io-non-contiguous", 0x00800000);
221 + memory_region_init(&s->pci_memory, obj, "pci-memory", 0x3f000000);
222 + address_space_init(&s->pci_io_as, &s->pci_io, "raven-io");
223 +
224 + /*
225 + * Raven's raven_io_ops use the address-space API to access pci-conf-idx
226 + * (which is also owned by the raven device). As such, mark the
227 + * pci_io_non_contiguous as re-entrancy safe.
228 + */
229 + s->pci_io_non_contiguous.disable_reentrancy_guard = true;
230 +
231 + /* CPU address space */
232 + memory_region_add_subregion(address_space_mem, PCI_IO_BASE_ADDR,
233 + &s->pci_io);
234 + memory_region_add_subregion_overlap(address_space_mem, PCI_IO_BASE_ADDR,
235 + &s->pci_io_non_contiguous, 1);
236 + memory_region_add_subregion(address_space_mem, 0xc0000000, &s->pci_memory);
237 +
238 + /* Bus master address space */
239 + memory_region_init(&s->bm, obj, "bm-raven", 4 * GiB);
240 + memory_region_init_alias(&s->bm_pci_memory_alias, obj, "bm-pci-memory",
241 + &s->pci_memory, 0,
242 + memory_region_size(&s->pci_memory));
243 + memory_region_init_alias(&s->bm_ram_alias, obj, "bm-system",
244 + address_space_mem, 0, 0x80000000);
245 + memory_region_add_subregion(&s->bm, 0 , &s->bm_pci_memory_alias);
246 + memory_region_add_subregion(&s->bm, 0x80000000, &s->bm_ram_alias);
247 +
248 /*
249 * According to PReP specification section 6.1.6 "System Interrupt
250 * Assignments", all PCI interrupts are routed via IRQ 15
@@ -256,42 +287,6 @@ static void raven_pcihost_realizefn(DeviceState *d, Error **errp)
287 pci_setup_iommu(h->bus, &raven_iommu_ops, s);
288 }
289
259 -static void raven_pcihost_initfn(Object *obj)
260 -{
261 - PREPPCIState *s = RAVEN_PCI_HOST_BRIDGE(obj);
262 - MemoryRegion *address_space_mem = get_system_memory();
263 -
264 - memory_region_init(&s->pci_io, obj, "pci-io", 0x3f800000);
265 - memory_region_init_io(&s->pci_io_non_contiguous, obj, &raven_io_ops, s,
266 - "pci-io-non-contiguous", 0x00800000);
267 - memory_region_init(&s->pci_memory, obj, "pci-memory", 0x3f000000);
268 - address_space_init(&s->pci_io_as, &s->pci_io, "raven-io");
269 -
270 - /*
271 - * Raven's raven_io_ops use the address-space API to access pci-conf-idx
272 - * (which is also owned by the raven device). As such, mark the
273 - * pci_io_non_contiguous as re-entrancy safe.
274 - */
275 - s->pci_io_non_contiguous.disable_reentrancy_guard = true;
276 -
277 - /* CPU address space */
278 - memory_region_add_subregion(address_space_mem, PCI_IO_BASE_ADDR,
279 - &s->pci_io);
280 - memory_region_add_subregion_overlap(address_space_mem, PCI_IO_BASE_ADDR,
281 - &s->pci_io_non_contiguous, 1);
282 - memory_region_add_subregion(address_space_mem, 0xc0000000, &s->pci_memory);
283 -
284 - /* Bus master address space */
285 - memory_region_init(&s->bm, obj, "bm-raven", 4 * GiB);
286 - memory_region_init_alias(&s->bm_pci_memory_alias, obj, "bm-pci-memory",
287 - &s->pci_memory, 0,
288 - memory_region_size(&s->pci_memory));
289 - memory_region_init_alias(&s->bm_ram_alias, obj, "bm-system",
290 - get_system_memory(), 0, 0x80000000);
291 - memory_region_add_subregion(&s->bm, 0 , &s->bm_pci_memory_alias);
292 - memory_region_add_subregion(&s->bm, 0x80000000, &s->bm_ram_alias);
293 -}
294 -
290 static void raven_pcihost_class_init(ObjectClass *klass, const void *data)
291 {
292 DeviceClass *dc = DEVICE_CLASS(klass);
@@ -330,7 +325,6 @@ static const TypeInfo raven_types[] = {
325 .name = TYPE_RAVEN_PCI_HOST_BRIDGE,
326 .parent = TYPE_PCI_HOST_BRIDGE,
327 .instance_size = sizeof(PREPPCIState),
333 - .instance_init = raven_pcihost_initfn,
328 .class_init = raven_pcihost_class_init,
329 },
330 {