Re: [PATCH 3/4] xen-block: Fix BlockBackend leak on unplug of empty CD-ROM

Stefano Stabellini <[email protected]>
Newsgroups org.xenproject.lists.xen-devel,org.nongnu.qemu-devel
Message-ID <alpine.DEB.2.22.394.2607171816240.16921@ubuntu-linux-20-04-desktop>
On Fri, 17 Jul 2026, Mitsuru Kariya wrote:
> When a Xen CD-ROM is created without a backing drive (an empty CD-ROM),
> xen_cdrom_realize() allocates an anonymous BlockBackend for the empty
> drive with blk_new() and attaches it to the device using
> blk_attach_dev().
> 
> blk_new() returns the backend with refcnt == 1 (the creation reference
> owned by the caller) and blk_attach_dev() takes an additional reference
> for the device.  The creation reference was never released, so on
> unplug blk_detach_dev() only drops the device's reference and the
> BlockBackend is leaked.
> 
> Release the creation reference with blk_unref() right after
> blk_attach_dev(), matching the idiom already used in set_drive_helper()
> in hw/core/qdev-properties-system.c ("If we need to keep a reference,
> blk_attach_dev() took it").
> 
> Signed-off-by: Mitsuru Kariya <[email protected]>

Reviewed-by: Stefano Stabellini <[email protected]>


> ---
>  hw/block/xen-block.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/hw/block/xen-block.c b/hw/block/xen-block.c
> index abf9df2eee..e5e14e47ee 100644
> --- a/hw/block/xen-block.c
> +++ b/hw/block/xen-block.c
> @@ -763,6 +763,7 @@ static void xen_cdrom_realize(XenBlockDevice *blockdev, Error **errp)
>  
>          rc = blk_attach_dev(conf->blk, DEVICE(blockdev));
>          assert(rc == 0);
> +        blk_unref(conf->blk);
>      }
>  
>      blockdev->info = VDISK_READONLY | VDISK_CDROM;
> -- 
> 2.43.0
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.