All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2 0/3] A few leak fixes for QTest
@ 2026-09-09 22:14 Fabiano Rosas
  2026-09-09 22:14 ` [PATCH v2 1/3] ahci: Fix leak of IRQState Fabiano Rosas
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Fabiano Rosas @ 2026-09-09 22:14 UTC (permalink / raw)
  To: qemu-devel


Fabiano Rosas (3):
  ahci: Fix leak of IRQState
  migration: Drop iochannel reference during snapshot setup
  migration: Free the JSON writer during snapshots

 hw/ide/ahci.c         |  1 +
 migration/migration.c |  2 +-
 migration/migration.h |  1 +
 migration/savevm.c    | 10 ++++++++--
 4 files changed, 11 insertions(+), 3 deletions(-)

-- 
2.53.0



^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v2 1/3] ahci: Fix leak of IRQState
  2026-09-09 22:14 [PATCH v2 0/3] A few leak fixes for QTest Fabiano Rosas
@ 2026-09-09 22:14 ` Fabiano Rosas
  2026-09-09 22:14 ` [PATCH v2 2/3] migration: Drop iochannel reference during snapshot setup Fabiano Rosas
  2026-09-09 22:14 ` [PATCH v2 3/3] migration: Free the JSON writer during snapshots Fabiano Rosas
  2 siblings, 0 replies; 5+ messages in thread
From: Fabiano Rosas @ 2026-09-09 22:14 UTC (permalink / raw)
  To: qemu-devel; +Cc: Denis V. Lunev, John Snow

ASAN spotted an indirect leak in ahci-test:

Indirect leak of 576 byte(s) in 6 object(s) allocated from:
    #0 0x556112a08ca0 in malloc
    #1 0x7f21591e595d in g_malloc
    #2 0x7f21591ffe38 in g_slice_alloc
    #3 0x7f21591c988d in g_hash_table_new_full
    #4 0x556114d756f1 in object_initialize_with_type ../qom/object.c:506:23
    #5 0x556114d77590 in object_new_with_type ../qom/object.c:706:5
    #6 0x556114d777e8 in object_new ../qom/object.c:722:12
    #7 0x556114d6d2be in qemu_allocate_irq ../hw/core/irq.c:94:25
    #8 0x556114d6d1bc in qemu_extend_irqs ../hw/core/irq.c:82:16
    #9 0x556114d6d329 in qemu_allocate_irqs ../hw/core/irq.c:89:12
    #10 0x5561135da9bd in ahci_realize ../hw/ide/ahci.c:1644:12
    #11 0x55611360156a in pci_ich9_ahci_realize ../hw/ide/ich.c:132:5

Although ahci_realize() frees the return of qemu_allocate_irqs() right
away, the individual IRQStates are still left around.

Issue qemu_free_irq() at ahci_uninit().

Reviewed-by: Denis V. Lunev <den@openvz.org>
Signed-off-by: Fabiano Rosas <farosas@suse.de>
---
 hw/ide/ahci.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c
index 6b04762c4a..86f6297dc9 100644
--- a/hw/ide/ahci.c
+++ b/hw/ide/ahci.c
@@ -1688,6 +1688,7 @@ void ahci_uninit(AHCIState *s)
             }
             ide_exit(ide_state);
         }
+        qemu_free_irq(ad->port.irq);
         object_unparent(OBJECT(&ad->port));
     }
 
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH v2 2/3] migration: Drop iochannel reference during snapshot setup
  2026-09-09 22:14 [PATCH v2 0/3] A few leak fixes for QTest Fabiano Rosas
  2026-09-09 22:14 ` [PATCH v2 1/3] ahci: Fix leak of IRQState Fabiano Rosas
@ 2026-09-09 22:14 ` Fabiano Rosas
  2026-09-09 22:14 ` [PATCH v2 3/3] migration: Free the JSON writer during snapshots Fabiano Rosas
  2 siblings, 0 replies; 5+ messages in thread
From: Fabiano Rosas @ 2026-09-09 22:14 UTC (permalink / raw)
  To: qemu-devel; +Cc: Marc-André Lureau, Peter Xu

During migration there are usually two references to the iochannel,
one from the channel creation itself and another from the ownership
transfer into QEMUFile.

- The reference from the QEMUFile is decremented at qemu_fclose.

- The original reference is decremented at migration_connect_outgoing()
for regular migration and not at all for snapshots.

The ide-test has recently added migration support and ASAN has
flagged:

Indirect leak of 32 byte(s) in 1 object(s) allocated from:
    #0 0x55ca12aac0b9 in realloc
    #1 0x7fd97d7e5a05 in g_realloc
    #3 0x7fd97d7c98c6 in g_hash_table_new_full
    #4 0x55ca14e186f1 in object_initialize_with_type ../qom/object.c:506:23
    #5 0x55ca14e1a590 in object_new_with_type ../qom/object.c:706:5
    #6 0x55ca14e1a7e8 in object_new ../qom/object.c:722:12
    #7 0x55ca12de896f in qio_channel_block_new ../migration/channel-block.c:32:29
    #8 0x55ca12ec8f2d in qemu_fopen_bdrv ../migration/savevm.c:172:49
    #9 0x55ca12ec8b42 in save_snapshot ../migration/savevm.c:3375:9
    #10 0x55ca12ee18e3 in hmp_savevm ../migration/migration-hmp-cmds.c:497:5

Change qemu_fopen_bdrv() to drop the original reference once the
QEMUFile has taken over the object. The xen code already does the
same.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Fabiano Rosas <farosas@suse.de>
---
 migration/savevm.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/migration/savevm.c b/migration/savevm.c
index 5b0e89ca7c..8d4bdc28ab 100644
--- a/migration/savevm.c
+++ b/migration/savevm.c
@@ -168,11 +168,16 @@ static bool qemu_loadvm_thread_pool_wait(MigrationState *s,
 
 static QEMUFile *qemu_fopen_bdrv(BlockDriverState *bs, int is_writable)
 {
+    QIOChannel *ioc = QIO_CHANNEL(qio_channel_block_new(bs));
+    QEMUFile *f;
+
     if (is_writable) {
-        return qemu_file_new_output(QIO_CHANNEL(qio_channel_block_new(bs)));
+        f = qemu_file_new_output(ioc);
     } else {
-        return qemu_file_new_input(QIO_CHANNEL(qio_channel_block_new(bs)));
+        f = qemu_file_new_input(ioc);
     }
+    object_unref(ioc);
+    return f;
 }
 
 
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH v2 3/3] migration: Free the JSON writer during snapshots
  2026-09-09 22:14 [PATCH v2 0/3] A few leak fixes for QTest Fabiano Rosas
  2026-09-09 22:14 ` [PATCH v2 1/3] ahci: Fix leak of IRQState Fabiano Rosas
  2026-09-09 22:14 ` [PATCH v2 2/3] migration: Drop iochannel reference during snapshot setup Fabiano Rosas
@ 2026-09-09 22:14 ` Fabiano Rosas
  2026-09-10 12:24   ` Peter Xu
  2 siblings, 1 reply; 5+ messages in thread
From: Fabiano Rosas @ 2026-09-09 22:14 UTC (permalink / raw)
  To: qemu-devel; +Cc: Peter Xu

The JSON writer is created at migrate_init() and freed at
migration_cleanup(). The latter is not called for snapshots. Add a
call to migration_cleanup_json_writer() to make sure it doesn't leak:

Indirect leak of 24 byte(s) in 1 object(s) allocated from:
    #0 0x55ca12aabca0 in malloc
    #1 0x7fd97d7e595d in g_malloc
    #2 0x7fd97d7ffe38 in g_slice_alloc
    #3 0x7fd97d8042e2 in g_string_sized_new
    #4 0x55ca1571dd6b in json_writer_new ../qobject/json-writer.c:36:24
    #5 0x55ca12e0de56 in migrate_init ../migration/migration.c:1718:21
    #6 0x55ca12ec8fe6 in qemu_savevm_state ../migration/savevm.c:1921:11
    #7 0x55ca12ec8b93 in save_snapshot ../migration/savevm.c:3380:11

Signed-off-by: Fabiano Rosas <farosas@suse.de>
---
 migration/migration.c | 2 +-
 migration/migration.h | 1 +
 migration/savevm.c    | 1 +
 3 files changed, 3 insertions(+), 1 deletion(-)

diff --git a/migration/migration.c b/migration/migration.c
index b413d28622..d0b864a760 100644
--- a/migration/migration.c
+++ b/migration/migration.c
@@ -1330,7 +1330,7 @@ void migrate_set_state(MigrationStatus *state, MigrationStatus old_state,
     }
 }
 
-static void migration_cleanup_json_writer(MigrationState *s)
+void migration_cleanup_json_writer(MigrationState *s)
 {
     g_clear_pointer(&s->vmdesc, json_writer_free);
 }
diff --git a/migration/migration.h b/migration/migration.h
index e47ff4e3d1..683bc7bdd5 100644
--- a/migration/migration.h
+++ b/migration/migration.h
@@ -633,4 +633,5 @@ void migration_bitmap_sync_precopy(bool last_stage);
 void dirty_bitmap_mig_init(void);
 bool should_send_vmdesc(void);
 
+void migration_cleanup_json_writer(MigrationState *s);
 #endif
diff --git a/migration/savevm.c b/migration/savevm.c
index 8d4bdc28ab..4b590ea672 100644
--- a/migration/savevm.c
+++ b/migration/savevm.c
@@ -1952,6 +1952,7 @@ static int qemu_savevm_state(QEMUFile *f, Error **errp)
     }
 cleanup:
     qemu_savevm_state_cleanup();
+    migration_cleanup_json_writer(ms);
 
     if (ret != 0) {
         status = MIGRATION_STATUS_FAILED;
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [PATCH v2 3/3] migration: Free the JSON writer during snapshots
  2026-09-09 22:14 ` [PATCH v2 3/3] migration: Free the JSON writer during snapshots Fabiano Rosas
@ 2026-09-10 12:24   ` Peter Xu
  0 siblings, 0 replies; 5+ messages in thread
From: Peter Xu @ 2026-09-10 12:24 UTC (permalink / raw)
  To: Fabiano Rosas; +Cc: qemu-devel

On Wed, Sep 09, 2026 at 07:14:09PM -0300, Fabiano Rosas wrote:
> The JSON writer is created at migrate_init() and freed at
> migration_cleanup(). The latter is not called for snapshots. Add a
> call to migration_cleanup_json_writer() to make sure it doesn't leak:
> 
> Indirect leak of 24 byte(s) in 1 object(s) allocated from:
>     #0 0x55ca12aabca0 in malloc
>     #1 0x7fd97d7e595d in g_malloc
>     #2 0x7fd97d7ffe38 in g_slice_alloc
>     #3 0x7fd97d8042e2 in g_string_sized_new
>     #4 0x55ca1571dd6b in json_writer_new ../qobject/json-writer.c:36:24
>     #5 0x55ca12e0de56 in migrate_init ../migration/migration.c:1718:21
>     #6 0x55ca12ec8fe6 in qemu_savevm_state ../migration/savevm.c:1921:11
>     #7 0x55ca12ec8b93 in save_snapshot ../migration/savevm.c:3380:11
> 
> Signed-off-by: Fabiano Rosas <farosas@suse.de>

Reviewed-by: Peter Xu <peterx@redhat.com>

-- 
Peter Xu



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-10 12:25 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 22:14 [PATCH v2 0/3] A few leak fixes for QTest Fabiano Rosas
2026-09-09 22:14 ` [PATCH v2 1/3] ahci: Fix leak of IRQState Fabiano Rosas
2026-09-09 22:14 ` [PATCH v2 2/3] migration: Drop iochannel reference during snapshot setup Fabiano Rosas
2026-09-09 22:14 ` [PATCH v2 3/3] migration: Free the JSON writer during snapshots Fabiano Rosas
2026-09-10 12:24   ` Peter Xu

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.