[GIT PULL 8/9] hw/display/virtio-gpu: Unmap DMA regions on reset
Marc-André Lureau <[email protected]> Tue, 04 Aug 2026 11:18:57 +0400
| Newsgroups | gmane.comp.emulators.qemu |
|---|---|
| Message-ID | <[email protected]> |
From: Bin Guo <[email protected]> virtio_gpu_reset() freed in-flight commands without unmapping the DMA regions acquired by virtqueue_pop(). Call virtqueue_detach_element() before g_free() in both drain loops. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3467 Cc: [email protected] Signed-off-by: Bin Guo <[email protected]> Reviewed-by: Akihiko Odaki <[email protected]> Reviewed-by: Marc-André Lureau <[email protected]> Message-ID: <[email protected]> --- hw/display/virtio-gpu.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index c15d4b527d0e..fbb6fec7a0ad 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -1725,12 +1725,14 @@ void virtio_gpu_reset(VirtIODevice *vdev) while (!QTAILQ_EMPTY(&g->cmdq)) { cmd = QTAILQ_FIRST(&g->cmdq); QTAILQ_REMOVE(&g->cmdq, cmd, next); + virtqueue_detach_element(cmd->vq, &cmd->elem, 0); g_free(cmd); } while (!QTAILQ_EMPTY(&g->fenceq)) { cmd = QTAILQ_FIRST(&g->fenceq); QTAILQ_REMOVE(&g->fenceq, cmd, next); + virtqueue_detach_element(cmd->vq, &cmd->elem, 0); g->inflight--; g_free(cmd); } -- 2.55.0