From: Bin Guo <[email protected]>

virtio_gpu_reset() freed in-flight commands without unmapping the
DMA regions acquired by virtqueue_pop().  Call virtqueue_detach_element()
before g_free() in both drain loops.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3467
Cc: [email protected]
Signed-off-by: Bin Guo <[email protected]>
Reviewed-by: Akihiko Odaki <[email protected]>
Reviewed-by: Marc-AndrĂ© Lureau <[email protected]>
Message-ID: <[email protected]>
(cherry picked from commit 5ce01c92389a422389898df481ed441a80ece3c4)
Signed-off-by: Michael Tokarev <[email protected]>

diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
index 4f1c6e64b12..930b069c7ec 100644
--- a/hw/display/virtio-gpu.c
+++ b/hw/display/virtio-gpu.c
@@ -1695,12 +1695,14 @@ void virtio_gpu_reset(VirtIODevice *vdev)
     while (!QTAILQ_EMPTY(&g->cmdq)) {
         cmd = QTAILQ_FIRST(&g->cmdq);
         QTAILQ_REMOVE(&g->cmdq, cmd, next);
+        virtqueue_detach_element(cmd->vq, &cmd->elem, 0);
         g_free(cmd);
     }
 
     while (!QTAILQ_EMPTY(&g->fenceq)) {
         cmd = QTAILQ_FIRST(&g->fenceq);
         QTAILQ_REMOVE(&g->fenceq, cmd, next);
+        virtqueue_detach_element(cmd->vq, &cmd->elem, 0);
         g->inflight--;
         g_free(cmd);
     }
-- 
2.47.3


Reply via email to