From: Matthew Daley Date: Wed, 4 Dec 2013 02:16:18 +0000 (+1300) Subject: xen_disk: fix memory leak X-Git-Tag: xen-4.4.0-rc1^0 X-Git-Url: http://xenbits.xensource.com/gitweb?a=commitdiff_plain;h=96b58a44756a8821c108358439b0f2c06e531159;p=qemu-xen-traditional.git xen_disk: fix memory leak On ioreq_release the full ioreq was memset to 0, losing all the data and memory allocations inside the QEMUIOVector, which leads to a memory leak. Create a new function to specifically reset ioreq. Reported-by: Maik Wessler Signed-off-by: Roger Pau Monné Signed-off-by: Stefano Stabellini Backport to qemu-xen-traditional. Signed-off-by: Matthew Daley Acked-by: Ian Jackson --- diff --git a/hw/xen_disk.c b/hw/xen_disk.c index ee8d36f9..250d806d 100644 --- a/hw/xen_disk.c +++ b/hw/xen_disk.c @@ -116,6 +116,29 @@ struct XenBlkDev { /* ------------------------------------------------------------- */ +static void ioreq_reset(struct ioreq *ioreq) +{ + memset(&ioreq->req, 0, sizeof(ioreq->req)); + ioreq->status = 0; + ioreq->start = 0; + ioreq->presync = 0; + ioreq->postsync = 0; + + memset(ioreq->domids, 0, sizeof(ioreq->domids)); + memset(ioreq->refs, 0, sizeof(ioreq->refs)); + ioreq->prot = 0; + memset(ioreq->page, 0, sizeof(ioreq->page)); + ioreq->pages = NULL; + + ioreq->aio_inflight = 0; + ioreq->aio_errors = 0; + + ioreq->blkdev = NULL; + memset(&ioreq->list, 0, sizeof(ioreq->list)); + + qemu_iovec_reset(&ioreq->v); +} + static struct ioreq *ioreq_start(struct XenBlkDev *blkdev) { struct ioreq *ioreq = NULL; @@ -132,7 +155,6 @@ static struct ioreq *ioreq_start(struct XenBlkDev *blkdev) /* get one from freelist */ ioreq = LIST_FIRST(&blkdev->freelist); LIST_REMOVE(ioreq, list); - qemu_iovec_reset(&ioreq->v); } LIST_INSERT_HEAD(&blkdev->inflight, ioreq, list); blkdev->requests_inflight++; @@ -156,7 +178,7 @@ static void ioreq_release(struct ioreq *ioreq, bool finish) struct XenBlkDev *blkdev = ioreq->blkdev; LIST_REMOVE(ioreq, list); - memset(ioreq, 0, sizeof(*ioreq)); + ioreq_reset(ioreq); ioreq->blkdev = blkdev; LIST_INSERT_HEAD(&blkdev->freelist, ioreq, list); if (finish) {