From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:40325) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1biTe1-0004BA-SS for qemu-devel@nongnu.org; Fri, 09 Sep 2016 17:47:37 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1biTe0-0004PA-Ox for qemu-devel@nongnu.org; Fri, 09 Sep 2016 17:47:33 -0400 Received: from mx1.redhat.com ([209.132.183.28]:59440) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1biTe0-0004P1-Je for qemu-devel@nongnu.org; Fri, 09 Sep 2016 17:47:32 -0400 Date: Sat, 10 Sep 2016 00:47:30 +0300 From: "Michael S. Tsirkin" Message-ID: <1473456998-14863-8-git-send-email-mst@redhat.com> References: <1473456998-14863-1-git-send-email-mst@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1473456998-14863-1-git-send-email-mst@redhat.com> Subject: [Qemu-devel] [PULL v2 07/14] virtio-balloon: discard virtqueue element on reset List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Peter Maydell , Ladi Prosek , Roman Kagan , Stefan Hajnoczi From: Ladi Prosek The one pending element is being freed but not discarded on device reset, which causes svq->inuse to creep up, eventually hitting the "Virtqueue size exceeded" error. Properly discarding the element on device reset makes sure that its buffers are unmapped and the inuse counter stays balanced. Cc: Michael S. Tsirkin Cc: Roman Kagan Cc: Stefan Hajnoczi Signed-off-by: Ladi Prosek Reviewed-by: Stefan Hajnoczi Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin --- hw/virtio/virtio-balloon.c | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/virtio/virtio-balloon.c b/hw/virtio/virtio-balloon.c index 5af429a..ad4189a 100644 --- a/hw/virtio/virtio-balloon.c +++ b/hw/virtio/virtio-balloon.c @@ -463,6 +463,7 @@ static void virtio_balloon_device_reset(VirtIODevice *vdev) VirtIOBalloon *s = VIRTIO_BALLOON(vdev); if (s->stats_vq_elem != NULL) { + virtqueue_discard(s->svq, s->stats_vq_elem, 0); g_free(s->stats_vq_elem); s->stats_vq_elem = NULL; } -- MST