riscv_iommu_translate() allocates an IOATC entry before passing it to
riscv_iommu_iot_update(). The update helper normally transfers ownership
to the hash table.

When ioatc-limit is zero, however, the helper returns without inserting or
freeing the entry. Every cacheable non-identity translation therefore leaks
one RISCVIOMMUEntry.

Free the entry on the disabled-cache path so that
riscv_iommu_iot_update() consistently consumes the entry passed to it.

Fixes: 9d085a1c3cb2 ("hw/riscv/riscv-iommu: add Address Translation Cache 
(IOATC)")
Cc: [email protected]
Signed-off-by: Tan Chi <[email protected]>
---
 hw/riscv/riscv-iommu.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c
index 323a041b4a..ebf8d7006c 100644
--- a/hw/riscv/riscv-iommu.c
+++ b/hw/riscv/riscv-iommu.c
@@ -1700,6 +1700,7 @@ static void riscv_iommu_iot_update(RISCVIOMMUState *s,
     GHashTable *iot_cache, RISCVIOMMUEntry *iot)
 {
     if (!s->iot_limit) {
+        g_free(iot);
         return;
     }
 
-- 
2.53.0


Reply via email to