From patchwork Wed Mar 6 03:05:59 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: David Gibson X-Patchwork-Id: 10840335 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id B27EE17E0 for ; Wed, 6 Mar 2019 03:09:46 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 9EB372C517 for ; Wed, 6 Mar 2019 03:09:46 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 935452C575; Wed, 6 Mar 2019 03:09:46 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.7 required=2.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI autolearn=ham version=3.3.1 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 438852C517 for ; Wed, 6 Mar 2019 03:09:36 +0000 (UTC) Received: from localhost ([127.0.0.1]:53365 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1h1Mw3-0007mE-Kl for patchwork-qemu-devel@patchwork.kernel.org; Tue, 05 Mar 2019 22:09:35 -0500 Received: from eggs.gnu.org ([209.51.188.92]:51051) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1h1Msm-0005Kv-LY for qemu-devel@nongnu.org; Tue, 05 Mar 2019 22:06:13 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1h1Msl-0003sM-QT for qemu-devel@nongnu.org; Tue, 05 Mar 2019 22:06:12 -0500 Received: from ozlabs.org ([203.11.71.1]:59311) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1h1Msk-0003r1-Rn; Tue, 05 Mar 2019 22:06:11 -0500 Received: by ozlabs.org (Postfix, from userid 1007) id 44Ddv1264Qz9sBF; Wed, 6 Mar 2019 14:06:05 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gibson.dropbear.id.au; s=201602; t=1551841565; bh=R+nwR6O5bjcrVQQkkhgKbN1a7JpgYUD7QXFwM9sVs1k=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=AoLLxTs3YjRFv7n/OCcjmtbvPa7b36PC1NAXUpFR7e7e4ztPVsAZo7OFKNCZfv3Bu kkE8DCLVscb8C0QOjL7H6c9iq9l1oapKnQkNecPHfbAmlzye1wY9PC8ox8jQ4AQzkN sTy/iFgtBLxb0lCqYRkvpQq36YyABkcAtrFbPORA= From: David Gibson To: Michael Tsirkin , David Hildenbrand , Peter Maydell Date: Wed, 6 Mar 2019 14:05:59 +1100 Message-Id: <20190306030601.21986-2-david@gibson.dropbear.id.au> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20190306030601.21986-1-david@gibson.dropbear.id.au> References: <20190306030601.21986-1-david@gibson.dropbear.id.au> MIME-Version: 1.0 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 203.11.71.1 Subject: [Qemu-devel] [PATCH 1/3] virtio-balloon: Don't mismatch g_malloc()/free (CID 1399146) X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: qemu-ppc@nongnu.org, qemu-devel@nongnu.org, David Gibson Errors-To: qemu-devel-bounces+patchwork-qemu-devel=patchwork.kernel.org@nongnu.org Sender: "Qemu-devel" X-Virus-Scanned: ClamAV using ClamSMTP ed48c59875b6 "virtio-balloon: Safely handle BALLOON_PAGE_SIZE < host page size" introduced a new temporary data structure which tracks 4kiB chunks which have been inserted into the balloon by the guest but don't yet form a full host page which we can discard. Unfortunately, I had a thinko and allocated that structure with g_malloc0() but freed it with a plain free() rather than g_free(). This corrects the problem. Fixes: ed48c59875b6 Reported-by: Peter Maydell Signed-off-by: David Gibson Reviewed-by: David Hildenbrand --- hw/virtio/virtio-balloon.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/virtio/virtio-balloon.c b/hw/virtio/virtio-balloon.c index d3f2913a85..127289ae0e 100644 --- a/hw/virtio/virtio-balloon.c +++ b/hw/virtio/virtio-balloon.c @@ -81,7 +81,7 @@ static void balloon_inflate_page(VirtIOBalloon *balloon, /* We've partially ballooned part of a host page, but now * we're trying to balloon part of a different one. Too hard, * give up on the old partial page */ - free(balloon->pbp); + g_free(balloon->pbp); balloon->pbp = NULL; } @@ -106,7 +106,7 @@ static void balloon_inflate_page(VirtIOBalloon *balloon, * has already reported them, and failing to discard a balloon * page is not fatal */ - free(balloon->pbp); + g_free(balloon->pbp); balloon->pbp = NULL; } }