]> git.ipfire.org Git - thirdparty/qemu.git/commitdiff
migration: Plug memory leaks after migrate_set_error()
authorMarkus Armbruster <armbru@redhat.com>
Sat, 15 Nov 2025 08:34:58 +0000 (09:34 +0100)
committerPeter Xu <peterx@redhat.com>
Fri, 21 Nov 2025 15:33:21 +0000 (10:33 -0500)
migrate_set_error(s, err) stores a copy of @err in @s.  The original
@err is not freed.  Most callers free it immediately.  Some callers
free it later, or pass it on.  And some leak it.  Fix those.

Perhaps migrate_set_error(s, err) should take ownership of @err.  The
callers that free it immediately would become simpler, and avoid a
copy and a deallocation.  The others would have to pass
error_copy(err).

Signed-off-by: Markus Armbruster <armbru@redhat.com>
Link: https://lore.kernel.org/r/20251115083500.2753895-2-armbru@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
migration/cpr-exec.c
migration/multifd.c

index d284f6e73417be643f73a3a46a880002346be1bd..0b8344a86ff33c2e15e40c9c0dc2dc3666f42573 100644 (file)
@@ -159,11 +159,12 @@ static void cpr_exec_cb(void *opaque)
     error_report_err(error_copy(err));
     migrate_set_state(&s->state, s->state, MIGRATION_STATUS_FAILED);
     migrate_set_error(s, err);
+    error_free(err);
+    err = NULL;
 
     /* Note, we can go from state COMPLETED to FAILED */
     migration_call_notifiers(s, MIG_EVENT_PRECOPY_FAILED, NULL);
 
-    err = NULL;
     if (!migration_block_activate(&err)) {
         /* error was already reported */
         error_free(err);
index 98873cee74f3c7d8d2002c997ea08156ed09dfb6..a529c399e4f66b7ecd5eb38ba67445999344e762 100644 (file)
@@ -964,6 +964,7 @@ bool multifd_send_setup(void)
 
         if (!multifd_new_send_channel_create(p, &local_err)) {
             migrate_set_error(s, local_err);
+            error_free(local_err);
             ret = -1;
         }
     }
@@ -988,6 +989,7 @@ bool multifd_send_setup(void)
         ret = multifd_send_state->ops->send_setup(p, &local_err);
         if (ret) {
             migrate_set_error(s, local_err);
+            error_free(local_err);
             goto err;
         }
         assert(p->iov);