A device which only went through vhost_dev_init_backend() has its VQs not yet initialized, so vq->dev is NULL and vhost_virtqueue_cleanup() would crash dereferencing it. Check vq->dev before use, so that vhost_dev_cleanup() can be called to release a device whose full vhost_dev_init() never ran or failed along the way.
As of now, there's no way for the cleanup path to be reached with vq->dev uninitialized. However after a subsequent patch adding CPR support for vhost-vsock this'll become a possibility, so let's prevent such a crash beforehand. Reviewed-by: Stefano Garzarella <[email protected]> Signed-off-by: Andrey Drobyshev <[email protected]> --- hw/virtio/vhost.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c index 99561ac5868..dfdfd49da3f 100644 --- a/hw/virtio/vhost.c +++ b/hw/virtio/vhost.c @@ -1661,7 +1661,7 @@ fail_call: static void vhost_virtqueue_cleanup(struct vhost_virtqueue *vq) { event_notifier_cleanup(&vq->masked_notifier); - if (vq->dev->vhost_ops->vhost_set_vring_err) { + if (vq->dev && vq->dev->vhost_ops->vhost_set_vring_err) { event_notifier_set_handler(&vq->error_notifier, NULL); event_notifier_cleanup(&vq->error_notifier); } -- 2.47.1
