Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
10e74b75cb | ||
|
|
67283bdf89 | ||
|
|
e092293a63 | ||
|
|
41a6b3c03f | ||
|
|
31256f3d0d | ||
|
|
abac39a1b8 | ||
|
|
39e9be886f | ||
|
|
3db4281bc0 | ||
|
|
249ba7e495 | ||
|
|
33a8555d08 | ||
|
|
dfb6f9eee6 | ||
|
|
f5c4597c0a | ||
|
|
766bb232e8 | ||
|
|
266d5e2fcb | ||
|
|
c6cfdf3963 | ||
|
|
e3da3b01fc | ||
|
|
b340367499 | ||
|
|
ca7cc971b8 | ||
|
|
774125b7ed | ||
|
|
afd39d2091 | ||
|
|
cc16b7cd3a | ||
|
|
be942ea860 | ||
|
|
938b89f090 | ||
|
|
f7283923a3 | ||
|
|
1ad100593a | ||
|
|
21608be3b1 | ||
|
|
6347aef63f | ||
|
|
1c5d25ffeb | ||
|
|
8386ba3e9d | ||
|
|
03d3983515 | ||
|
|
1b0f3aaf64 | ||
|
|
647354eaf9 | ||
|
|
1392d7120d | ||
|
|
f80d27e126 | ||
|
|
63cd2ced20 | ||
|
|
cad1b6966f | ||
|
|
a27f478451 | ||
|
|
b94faf01a5 | ||
|
|
60a70c925a | ||
|
|
e184d967ac | ||
|
|
985ee7390d | ||
|
|
156ce5b5c7 | ||
|
|
77b02695ab | ||
|
|
50057212b3 | ||
|
|
c61c2c83ef | ||
|
|
e3e721c529 | ||
|
|
7bf08eb7cb | ||
|
|
0862e2b778 | ||
|
|
9ae002fc72 | ||
|
|
7749fc4a26 | ||
|
|
5b0f05f970 | ||
|
|
36079ddefa | ||
|
|
9abc69f078 | ||
|
|
f4d251ad6e | ||
|
|
b0d2e09842 | ||
|
|
b0dd011728 | ||
|
|
2513c9ff81 | ||
|
|
9ef5501a94 | ||
|
|
659f2f0b36 | ||
|
|
f3cac3532b | ||
|
|
6eb56c2e71 | ||
|
|
93a549eb1a | ||
|
|
f2a998ce76 | ||
|
|
8556d44e84 | ||
|
|
f8539fae13 | ||
|
|
80a3188a20 | ||
|
|
56d89b1d61 | ||
|
|
2a7828bae8 | ||
|
|
c879325741 | ||
|
|
edf6aa6cd7 | ||
|
|
163b87484b | ||
|
|
5828ec5da6 | ||
|
|
adaeee1c2c | ||
|
|
200f2942a9 | ||
|
|
cbf07f0551 | ||
|
|
eb9ceebe38 | ||
|
|
507eb37491 | ||
|
|
3e211fa0f6 | ||
|
|
d4bb64489a | ||
|
|
6d908194bf | ||
|
|
2333a80c1a | ||
|
|
f4fd6d7df6 | ||
|
|
c1a3411c3b |
@@ -1,40 +0,0 @@
|
|||||||
From 6f3ee0c553bafec957e69df7fc42f83985d55c0f Mon Sep 17 00:00:00 2001
|
|
||||||
From: Martin Kletzander <mkletzan@redhat.com>
|
|
||||||
Date: Tue, 27 Feb 2024 16:20:12 +0100
|
|
||||||
Subject: [PATCH] Fix off-by-one error in udevListInterfacesByStatus
|
|
||||||
MIME-Version: 1.0
|
|
||||||
Content-Type: text/plain; charset=UTF-8
|
|
||||||
Content-Transfer-Encoding: 8bit
|
|
||||||
|
|
||||||
Ever since this function was introduced in 2012 it could've tried
|
|
||||||
filling in an extra interface name. That was made worse in 2019 when
|
|
||||||
the caller functions started accepting NULL arrays of size 0.
|
|
||||||
|
|
||||||
This is assigned CVE-2024-1441.
|
|
||||||
|
|
||||||
Signed-off-by: Martin Kletzander <mkletzan@redhat.com>
|
|
||||||
Reported-by: Alexander Kuznetsov <kuznetsovam@altlinux.org>
|
|
||||||
Fixes: 5a33366f5c0b18c93d161bd144f9f079de4ac8ca
|
|
||||||
Fixes: d6064e2759a24e0802f363e3a810dc5a7d7ebb15
|
|
||||||
Reviewed-by: Ján Tomko <jtomko@redhat.com>
|
|
||||||
(cherry picked from commit c664015fe3a7bf59db26686e9ed69af011c6ebb8)
|
|
||||||
---
|
|
||||||
src/interface/interface_backend_udev.c | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/src/interface/interface_backend_udev.c b/src/interface/interface_backend_udev.c
|
|
||||||
index ef334f175b..abeb766294 100644
|
|
||||||
--- a/src/interface/interface_backend_udev.c
|
|
||||||
+++ b/src/interface/interface_backend_udev.c
|
|
||||||
@@ -222,7 +222,7 @@ udevListInterfacesByStatus(virConnectPtr conn,
|
|
||||||
g_autoptr(virInterfaceDef) def = NULL;
|
|
||||||
|
|
||||||
/* Ensure we won't exceed the size of our array */
|
|
||||||
- if (count > names_len)
|
|
||||||
+ if (count >= names_len)
|
|
||||||
break;
|
|
||||||
|
|
||||||
path = udev_list_entry_get_name(dev_entry);
|
|
||||||
--
|
|
||||||
2.43.0
|
|
||||||
|
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
From 845210011a9ffd9d17e30c51cbc81ba67c5d3166 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Michal Privoznik <mprivozn@redhat.com>
|
||||||
|
Date: Tue, 20 Jan 2026 10:08:29 +0100
|
||||||
|
Subject: [PATCH] esx: Allow connecting to IPv6 server
|
||||||
|
MIME-Version: 1.0
|
||||||
|
Content-Type: text/plain; charset=UTF-8
|
||||||
|
Content-Transfer-Encoding: 8bit
|
||||||
|
|
||||||
|
When connecting to a VMWare server, the hostname from URI is
|
||||||
|
resolved using esxUtil_ResolveHostname() which in turn calls
|
||||||
|
getaddrinfo(). But in the hints argument, we restrict the return
|
||||||
|
address to be IPv4 (AF_INET) which obviously fails if the address
|
||||||
|
to resolve is an IPv6 address. Set the hint to AF_UNSPEC which
|
||||||
|
allows both IPv4 and IPv6. While at it, also allow IPv4 addresses
|
||||||
|
mapped in IPv6 by setting AI_V4MAPPED flag.
|
||||||
|
|
||||||
|
Resolves: https://issues.redhat.com/browse/RHEL-138300
|
||||||
|
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
|
||||||
|
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
|
||||||
|
---
|
||||||
|
src/esx/esx_util.c | 4 ++--
|
||||||
|
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/src/esx/esx_util.c b/src/esx/esx_util.c
|
||||||
|
index 88b3dc893f..a6275babd5 100644
|
||||||
|
--- a/src/esx/esx_util.c
|
||||||
|
+++ b/src/esx/esx_util.c
|
||||||
|
@@ -275,8 +275,8 @@ esxUtil_ResolveHostname(const char *hostname, char **ipAddress)
|
||||||
|
int errcode;
|
||||||
|
g_autofree char *address = NULL;
|
||||||
|
|
||||||
|
- hints.ai_flags = AI_ADDRCONFIG;
|
||||||
|
- hints.ai_family = AF_INET;
|
||||||
|
+ hints.ai_flags = AI_ADDRCONFIG | AI_V4MAPPED;
|
||||||
|
+ hints.ai_family = AF_UNSPEC;
|
||||||
|
hints.ai_socktype = SOCK_STREAM;
|
||||||
|
hints.ai_protocol = 0;
|
||||||
|
|
||||||
|
--
|
||||||
|
2.52.0
|
||||||
|
|
||||||
@@ -1,90 +0,0 @@
|
|||||||
From 13ea81b22cde0a429aa1de8b58655296084ce8d7 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Dmitry Frolov <frolov@swemel.ru>
|
|
||||||
Date: Tue, 12 Sep 2023 15:56:47 +0300
|
|
||||||
Subject: [PATCH] interface: fix udev_device_get_sysattr_value return value
|
|
||||||
check
|
|
||||||
|
|
||||||
Reviewing the code I found that return value of function
|
|
||||||
udev_device_get_sysattr_value() is dereferenced without a check.
|
|
||||||
udev_device_get_sysattr_value() may return NULL by number of reasons.
|
|
||||||
|
|
||||||
v2: VIR_DEBUG added, replaced STREQ(NULLSTR()) with STREQ_NULLABLE()
|
|
||||||
v3: More checks added, to skip earlier. More verbose VIR_DEBUG.
|
|
||||||
|
|
||||||
Signed-off-by: Dmitry Frolov <frolov@swemel.ru>
|
|
||||||
Reviewed-by: Martin Kletzander <mkletzan@redhat.com>
|
|
||||||
(cherry picked from commit 2ca94317ac642a70921947150ced8acc674ccdc8)
|
|
||||||
---
|
|
||||||
src/interface/interface_backend_udev.c | 26 +++++++++++++++++++-------
|
|
||||||
1 file changed, 19 insertions(+), 7 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/src/interface/interface_backend_udev.c b/src/interface/interface_backend_udev.c
|
|
||||||
index 54b43fb999..ef334f175b 100644
|
|
||||||
--- a/src/interface/interface_backend_udev.c
|
|
||||||
+++ b/src/interface/interface_backend_udev.c
|
|
||||||
@@ -23,6 +23,7 @@
|
|
||||||
#include <dirent.h>
|
|
||||||
#include <libudev.h>
|
|
||||||
|
|
||||||
+#include "virlog.h"
|
|
||||||
#include "virerror.h"
|
|
||||||
#include "virfile.h"
|
|
||||||
#include "datatypes.h"
|
|
||||||
@@ -40,6 +41,8 @@
|
|
||||||
|
|
||||||
#define VIR_FROM_THIS VIR_FROM_INTERFACE
|
|
||||||
|
|
||||||
+VIR_LOG_INIT("interface.interface_backend_udev");
|
|
||||||
+
|
|
||||||
struct udev_iface_driver {
|
|
||||||
struct udev *udev;
|
|
||||||
/* pid file FD, ensures two copies of the driver can't use the same root */
|
|
||||||
@@ -354,11 +357,20 @@ udevConnectListAllInterfaces(virConnectPtr conn,
|
|
||||||
const char *macaddr;
|
|
||||||
g_autoptr(virInterfaceDef) def = NULL;
|
|
||||||
|
|
||||||
- path = udev_list_entry_get_name(dev_entry);
|
|
||||||
- dev = udev_device_new_from_syspath(udev, path);
|
|
||||||
- name = udev_device_get_sysname(dev);
|
|
||||||
+ if (!(path = udev_list_entry_get_name(dev_entry))) {
|
|
||||||
+ VIR_DEBUG("Skipping interface, path == NULL");
|
|
||||||
+ continue;
|
|
||||||
+ }
|
|
||||||
+ if (!(dev = udev_device_new_from_syspath(udev, path))) {
|
|
||||||
+ VIR_DEBUG("Skipping interface '%s', dev == NULL", path);
|
|
||||||
+ continue;
|
|
||||||
+ }
|
|
||||||
+ if (!(name = udev_device_get_sysname(dev))) {
|
|
||||||
+ VIR_DEBUG("Skipping interface '%s', name == NULL", path);
|
|
||||||
+ continue;
|
|
||||||
+ }
|
|
||||||
macaddr = udev_device_get_sysattr_value(dev, "address");
|
|
||||||
- status = STREQ(udev_device_get_sysattr_value(dev, "operstate"), "up");
|
|
||||||
+ status = STREQ_NULLABLE(udev_device_get_sysattr_value(dev, "operstate"), "up");
|
|
||||||
|
|
||||||
def = udevGetMinimalDefForDevice(dev);
|
|
||||||
if (!virConnectListAllInterfacesCheckACL(conn, def)) {
|
|
||||||
@@ -962,9 +974,9 @@ udevGetIfaceDef(struct udev *udev, const char *name)
|
|
||||||
|
|
||||||
/* MTU */
|
|
||||||
mtu_str = udev_device_get_sysattr_value(dev, "mtu");
|
|
||||||
- if (virStrToLong_ui(mtu_str, NULL, 10, &mtu) < 0) {
|
|
||||||
+ if (!mtu_str || virStrToLong_ui(mtu_str, NULL, 10, &mtu) < 0) {
|
|
||||||
virReportError(VIR_ERR_INTERNAL_ERROR,
|
|
||||||
- _("Could not parse MTU value '%s'"), mtu_str);
|
|
||||||
+ _("Could not parse MTU value '%s'"), NULLSTR(mtu_str));
|
|
||||||
goto error;
|
|
||||||
}
|
|
||||||
ifacedef->mtu = mtu;
|
|
||||||
@@ -1087,7 +1099,7 @@ udevInterfaceIsActive(virInterfacePtr ifinfo)
|
|
||||||
goto cleanup;
|
|
||||||
|
|
||||||
/* Check if it's active or not */
|
|
||||||
- status = STREQ(udev_device_get_sysattr_value(dev, "operstate"), "up");
|
|
||||||
+ status = STREQ_NULLABLE(udev_device_get_sysattr_value(dev, "operstate"), "up");
|
|
||||||
|
|
||||||
udev_device_unref(dev);
|
|
||||||
|
|
||||||
--
|
|
||||||
2.43.0
|
|
||||||
|
|
||||||
@@ -1,58 +0,0 @@
|
|||||||
From: Peter Krempa <pkrempa@redhat.com>
|
|
||||||
Date: Thu, 9 Feb 2023 09:40:32 +0100
|
|
||||||
Subject: [PATCH] qemuProcessRefreshDisks: Don't skip filling of disk
|
|
||||||
information if tray state didn't change
|
|
||||||
Content-type: text/plain
|
|
||||||
|
|
||||||
Commit 5ef2582646eb98 added emitting of even when refreshign disk state,
|
|
||||||
where it wanted to avoid sending the event if disk state didn't change.
|
|
||||||
This was achieved by using 'continue' in the loop filling the
|
|
||||||
information. Unfortunately this skips extraction of whether the device
|
|
||||||
has a tray which is propagated into internal structures, which in turn
|
|
||||||
broke cdrom media change as the code thought there's no tray for the
|
|
||||||
device.
|
|
||||||
|
|
||||||
Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2166411
|
|
||||||
Fixes: 5ef2582646eb98af208ce37355f82bdef39931fa
|
|
||||||
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
|
|
||||||
Reviewed-by: Kristina Hanicova <khanicov@redhat.com>
|
|
||||||
(cherry picked from commit 86cfe93ef7fdc2d665a2fc88b79af89e7978ba78)
|
|
||||||
---
|
|
||||||
src/qemu/qemu_process.c | 11 +++++------
|
|
||||||
1 file changed, 5 insertions(+), 6 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/src/qemu/qemu_process.c b/src/qemu/qemu_process.c
|
|
||||||
index ee9f0784d3..0c408ee547 100644
|
|
||||||
--- a/src/qemu/qemu_process.c
|
|
||||||
+++ b/src/qemu/qemu_process.c
|
|
||||||
@@ -8724,16 +8724,13 @@ qemuProcessRefreshDisks(virDomainObj *vm,
|
|
||||||
continue;
|
|
||||||
|
|
||||||
if (info->removable) {
|
|
||||||
- virObjectEvent *event = NULL;
|
|
||||||
+ bool emitEvent = info->tray_open != disk->tray_status;
|
|
||||||
int reason;
|
|
||||||
|
|
||||||
if (info->empty)
|
|
||||||
virDomainDiskEmptySource(disk);
|
|
||||||
|
|
||||||
if (info->tray) {
|
|
||||||
- if (info->tray_open == disk->tray_status)
|
|
||||||
- continue;
|
|
||||||
-
|
|
||||||
if (info->tray_open) {
|
|
||||||
reason = VIR_DOMAIN_EVENT_TRAY_CHANGE_OPEN;
|
|
||||||
disk->tray_status = VIR_DOMAIN_DISK_TRAY_OPEN;
|
|
||||||
@@ -8742,8 +8739,10 @@ qemuProcessRefreshDisks(virDomainObj *vm,
|
|
||||||
disk->tray_status = VIR_DOMAIN_DISK_TRAY_CLOSED;
|
|
||||||
}
|
|
||||||
|
|
||||||
- event = virDomainEventTrayChangeNewFromObj(vm, disk->info.alias, reason);
|
|
||||||
- virObjectEventStateQueue(driver->domainEventState, event);
|
|
||||||
+ if (emitEvent) {
|
|
||||||
+ virObjectEvent *event = virDomainEventTrayChangeNewFromObj(vm, disk->info.alias, reason);
|
|
||||||
+ virObjectEventStateQueue(driver->domainEventState, event);
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= <berrange@redhat.com>
|
|
||||||
Date: Wed, 18 Jan 2023 09:45:52 +0000
|
|
||||||
Subject: [PATCH] ch: use CURLOPT_UPLOAD instead of CURLOPT_PUT
|
|
||||||
MIME-Version: 1.0
|
|
||||||
Content-Type: text/plain; charset=UTF-8
|
|
||||||
Content-Transfer-Encoding: 8bit
|
|
||||||
Content-type: text/plain
|
|
||||||
|
|
||||||
The CURLOPT_PUT constant causes a deprecation warning when compiling on
|
|
||||||
Alpine Edge. The docs indicate it is deprecated since 7.2.1
|
|
||||||
|
|
||||||
https://curl.se/libcurl/c/CURLOPT_PUT.html
|
|
||||||
|
|
||||||
Since 7.87 the deprecation is now exposed at build time via a compiler
|
|
||||||
warning.
|
|
||||||
|
|
||||||
We already use CURLOPT_UPLOAD in the ESX driver, so this brings the CH
|
|
||||||
driver into line.
|
|
||||||
|
|
||||||
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
|
|
||||||
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
|
|
||||||
(cherry picked from commit 9cd70fb25cad171e415fb05a4e01f244304c602e)
|
|
||||||
---
|
|
||||||
src/ch/ch_monitor.c | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/src/ch/ch_monitor.c b/src/ch/ch_monitor.c
|
|
||||||
index 8d8654332f..7b8f0a8077 100644
|
|
||||||
--- a/src/ch/ch_monitor.c
|
|
||||||
+++ b/src/ch/ch_monitor.c
|
|
||||||
@@ -660,7 +660,7 @@ virCHMonitorPutNoContent(virCHMonitor *mon, const char *endpoint)
|
|
||||||
|
|
||||||
curl_easy_setopt(mon->handle, CURLOPT_UNIX_SOCKET_PATH, mon->socketpath);
|
|
||||||
curl_easy_setopt(mon->handle, CURLOPT_URL, url);
|
|
||||||
- curl_easy_setopt(mon->handle, CURLOPT_PUT, true);
|
|
||||||
+ curl_easy_setopt(mon->handle, CURLOPT_UPLOAD, 1L);
|
|
||||||
curl_easy_setopt(mon->handle, CURLOPT_HTTPHEADER, NULL);
|
|
||||||
|
|
||||||
responseCode = virCHMonitorCurlPerform(mon->handle);
|
|
||||||
@@ -1,56 +0,0 @@
|
|||||||
From 9a47442366fcf8a7b6d7422016d7bbb6764a1098 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Peter Krempa <pkrempa@redhat.com>
|
|
||||||
Date: Thu, 13 Jul 2023 16:16:37 +0200
|
|
||||||
Subject: [PATCH] storage: Fix returning of locked objects from
|
|
||||||
'virStoragePoolObjListSearch'
|
|
||||||
MIME-Version: 1.0
|
|
||||||
Content-Type: text/plain; charset=UTF-8
|
|
||||||
Content-Transfer-Encoding: 8bit
|
|
||||||
|
|
||||||
CVE-2023-3750
|
|
||||||
|
|
||||||
'virStoragePoolObjListSearch' explicitly documents that it's returning
|
|
||||||
a pointer to a locked and ref'd pool that maches the lookup function.
|
|
||||||
|
|
||||||
This was not the case as in commit 0c4b391e2a9 (released in
|
|
||||||
libvirt-8.3.0) the code was accidentally converted to use 'VIR_LOCK_GUARD'
|
|
||||||
which auto-unlocked it when leaving the scope, even when the code was
|
|
||||||
originally "leaking" the lock.
|
|
||||||
|
|
||||||
Revert the corresponding conversion and add a comment that this function
|
|
||||||
is intentionally leaking a locked object.
|
|
||||||
|
|
||||||
Fixes: 0c4b391e2a9
|
|
||||||
Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2221851
|
|
||||||
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
|
|
||||||
Reviewed-by: Ján Tomko <jtomko@redhat.com>
|
|
||||||
Signed-off-by: Han Han <hhan@redhat.com>
|
|
||||||
---
|
|
||||||
src/conf/virstorageobj.c | 7 ++++++-
|
|
||||||
1 file changed, 6 insertions(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/src/conf/virstorageobj.c b/src/conf/virstorageobj.c
|
|
||||||
index 7010e97d61..59fa5da372 100644
|
|
||||||
--- a/src/conf/virstorageobj.c
|
|
||||||
+++ b/src/conf/virstorageobj.c
|
|
||||||
@@ -454,11 +454,16 @@ virStoragePoolObjListSearchCb(const void *payload,
|
|
||||||
virStoragePoolObj *obj = (virStoragePoolObj *) payload;
|
|
||||||
struct _virStoragePoolObjListSearchData *data =
|
|
||||||
(struct _virStoragePoolObjListSearchData *)opaque;
|
|
||||||
- VIR_LOCK_GUARD lock = virObjectLockGuard(obj);
|
|
||||||
|
|
||||||
+ virObjectLock(obj);
|
|
||||||
+
|
|
||||||
+ /* If we find the matching pool object we must return while the object is
|
|
||||||
+ * locked as the caller wants to return a locked object. */
|
|
||||||
if (data->searcher(obj, data->opaque))
|
|
||||||
return 1;
|
|
||||||
|
|
||||||
+ virObjectUnlock(obj);
|
|
||||||
+
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
--
|
|
||||||
2.41.0
|
|
||||||
|
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
From 6425a311b8ad19d6f9c0b315bf1d722551ea3585 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Tim Shearer <TShearer@adva.com>
|
|
||||||
Date: Mon, 1 May 2023 13:15:48 +0000
|
|
||||||
Subject: [PATCH] virpci: Resolve leak in virPCIVirtualFunctionList cleanup
|
|
||||||
MIME-Version: 1.0
|
|
||||||
Content-Type: text/plain; charset=UTF-8
|
|
||||||
Content-Transfer-Encoding: 8bit
|
|
||||||
|
|
||||||
Repeatedly querying an SR-IOV PCI device's capabilities exposes a
|
|
||||||
memory leak caused by a failure to free the virPCIVirtualFunction
|
|
||||||
array within the parent struct's g_autoptr cleanup.
|
|
||||||
|
|
||||||
Valgrind output after getting a single interface's XML description
|
|
||||||
1000 times:
|
|
||||||
|
|
||||||
==325982== 256,000 bytes in 1,000 blocks are definitely lost in loss record 2,634 of 2,635
|
|
||||||
==325982== at 0x4C3C096: realloc (vg_replace_malloc.c:1437)
|
|
||||||
==325982== by 0x59D952D: g_realloc (in /usr/lib64/libglib-2.0.so.0.5600.4)
|
|
||||||
==325982== by 0x4EE1F52: virReallocN (viralloc.c:52)
|
|
||||||
==325982== by 0x4EE1FB7: virExpandN (viralloc.c:78)
|
|
||||||
==325982== by 0x4EE219A: virInsertElementInternal (viralloc.c:183)
|
|
||||||
==325982== by 0x4EE23B2: virAppendElement (viralloc.c:288)
|
|
||||||
==325982== by 0x4F65D85: virPCIGetVirtualFunctionsFull (virpci.c:2389)
|
|
||||||
==325982== by 0x4F65753: virPCIGetVirtualFunctions (virpci.c:2256)
|
|
||||||
==325982== by 0x505CB75: virNodeDeviceGetPCISRIOVCaps (node_device_conf.c:2969)
|
|
||||||
==325982== by 0x505D181: virNodeDeviceGetPCIDynamicCaps (node_device_conf.c:3099)
|
|
||||||
==325982== by 0x505BC4E: virNodeDeviceUpdateCaps (node_device_conf.c:2677)
|
|
||||||
==325982== by 0x260FCBB2: nodeDeviceGetXMLDesc (node_device_driver.c:355)
|
|
||||||
|
|
||||||
Signed-off-by: Tim Shearer <tshearer@adva.com>
|
|
||||||
Reviewed-by: Ján Tomko <jtomko@redhat.com>
|
|
||||||
Signed-off-by: Han Han <hhan@redhat.com>
|
|
||||||
---
|
|
||||||
src/util/virpci.c | 1 +
|
|
||||||
1 file changed, 1 insertion(+)
|
|
||||||
|
|
||||||
diff --git a/src/util/virpci.c b/src/util/virpci.c
|
|
||||||
index 9e564e4a4f..cc2b07bbba 100644
|
|
||||||
--- a/src/util/virpci.c
|
|
||||||
+++ b/src/util/virpci.c
|
|
||||||
@@ -2245,6 +2245,7 @@ virPCIVirtualFunctionListFree(virPCIVirtualFunctionList *list)
|
|
||||||
g_free(list->functions[i].ifname);
|
|
||||||
}
|
|
||||||
|
|
||||||
+ g_free(list->functions);
|
|
||||||
g_free(list);
|
|
||||||
}
|
|
||||||
|
|
||||||
--
|
|
||||||
2.41.0
|
|
||||||
|
|
||||||
+1167
-607
File diff suppressed because it is too large
Load Diff
@@ -1 +1 @@
|
|||||||
SHA512 (libvirt-9.0.0.tar.xz) = 135f690f9fe722161c22579166f10a54d52941a371439165fd0e3d391ca7835049a3bcbff33fc81c50153046230db8a5a318d707383bad3141d489d2faa09ecb
|
SHA512 (libvirt-12.0.0.tar.xz) = 5613e4e59865f688fe4cca2734c6de1cf68d0540c6e3013c9c21e583accd4f4fc21ec98e9c794036c5d6d0c8dd05ad1d22dab61f8c7d2934c8cb507b5bee76ad
|
||||||
|
|||||||
Reference in New Issue
Block a user