Fix a memory leak in jtag_tap_free():  unregister the event
callback too.
 
Also fix the associated conceptual bug in unregistering JTAG
event callbacks:  since the same callback procedure is used
many times with different callback data (a TAP handle), that
data must be considered when unregistering any callback.

This could fix some crashes after TAP registration errors,
by making sure the reset event handler doesn't scribble over
memory that's now used by something else.
---
 src/jtag/core.c |   18 +++++++++++++-----
 src/jtag/jtag.h |    2 +-
 2 files changed, 14 insertions(+), 6 deletions(-)

Fix a memory leak in jtag_tap_free():  unregister the event
callback too.

Also fix the associated conceptual bug in unregistering JTAG
event callbacks:  since the same callback procedure is used
many times with different callback data (a TAP handle), that
data must be considered when unregistering any callback.

This could fix some crashes after TAP registration errors,
by making sure the reset event handler doesn't scribble over
memory that's now used by something else.
---
 src/jtag/core.c |   18 +++++++++++++-----
 src/jtag/jtag.h |    2 +-
 2 files changed, 14 insertions(+), 6 deletions(-)

--- a/src/jtag/core.c
+++ b/src/jtag/core.c
@@ -243,24 +243,30 @@ int jtag_register_event_callback(jtag_ev
 	return ERROR_OK;
 }
 
-int jtag_unregister_event_callback(jtag_event_handler_t callback)
+int jtag_unregister_event_callback(jtag_event_handler_t callback, void *priv)
 {
-	jtag_event_callback_t **callbacks_p = &jtag_event_callbacks;
+	jtag_event_callback_t **callbacks_p;
+	jtag_event_callback_t **next;
 
 	if (callback == NULL)
 	{
 		return ERROR_INVALID_ARGUMENTS;
 	}
 
-	while (*callbacks_p)
+	for (callbacks_p = &jtag_event_callbacks;
+			*callbacks_p != NULL;
+			callbacks_p = next)
 	{
-		jtag_event_callback_t **next = &((*callbacks_p)->next);
+		next = &((*callbacks_p)->next);
+
+		if ((*callbacks_p)->priv != priv)
+			continue;
+
 		if ((*callbacks_p)->callback == callback)
 		{
 			free(*callbacks_p);
 			*callbacks_p = *next;
 		}
-		callbacks_p = next;
 	}
 
 	return ERROR_OK;
@@ -1092,6 +1098,8 @@ void jtag_tap_init(jtag_tap_t *tap)
 
 void jtag_tap_free(jtag_tap_t *tap)
 {
+	jtag_unregister_event_callback(&jtag_reset_callback, tap);
+
 	/// @todo is anything missing? no memory leaks please 
 	free((void *)tap->expected_ids);
 	free((void *)tap->chip);
--- a/src/jtag/jtag.h
+++ b/src/jtag/jtag.h
@@ -230,7 +230,7 @@ struct jtag_tap_event_action_s
 typedef int (*jtag_event_handler_t)(enum jtag_event event, void* priv);
 
 extern int jtag_register_event_callback(jtag_event_handler_t f, void *x);
-extern int jtag_unregister_event_callback(jtag_event_handler_t f);
+extern int jtag_unregister_event_callback(jtag_event_handler_t f, void *x);
 
 extern int jtag_call_event_callbacks(enum jtag_event event);
 
_______________________________________________
Openocd-development mailing list
[email protected]
https://lists.berlios.de/mailman/listinfo/openocd-development

Reply via email to