mirror of
				https://gitlab.com/qemu-project/qemu.git
				synced 2025-10-30 07:57:14 +08:00 
			
		
		
		
	 300a87c502
			
		
	
	300a87c502
	
	
	
		
			
			When we unrealize a CPU object (which happens on vCPU hot-unplug), we
should destroy all the AddressSpace objects we created via calls to
cpu_address_space_init() when the CPU was realized.
Commit 24bec42f3d added a function to do this for a specific
AddressSpace, but did not add any places where the function was
called.
Since we always want to destroy all the AddressSpaces on unrealize,
regardless of the target architecture, we don't need to try to keep
track of how many are still undestroyed, or make the target
architecture code manually call a destroy function for each AS it
created.  Instead we can adjust the function to always completely
destroy the whole cpu->ases array, and arrange for it to be called
during CPU unrealize as part of the common code.
Without this fix, AddressSanitizer will report a leak like this
from a run where we hot-plugged and then hot-unplugged an x86 KVM
vCPU:
Direct leak of 416 byte(s) in 1 object(s) allocated from:
    #0 0x5b638565053d in calloc (/data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/qemu-system-x86_64+0x1ee153d) (BuildId: c1cd6022b195142106e1bffeca23498c2b752bca)
    #1 0x7c28083f77b1 in g_malloc0 (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x637b1) (BuildId: 1eb6131419edb83b2178b682829a6913cf682d75)
    #2 0x5b6386999c7c in cpu_address_space_init /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../system/physmem.c:797:25
    #3 0x5b638727f049 in kvm_cpu_realizefn /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../target/i386/kvm/kvm-cpu.c:102:5
    #4 0x5b6385745f40 in accel_cpu_common_realize /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../accel/accel-common.c:101:13
    #5 0x5b638568fe3c in cpu_exec_realizefn /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../hw/core/cpu-common.c:232:10
    #6 0x5b63874a2cd5 in x86_cpu_realizefn /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../target/i386/cpu.c:9321:5
    #7 0x5b6387a0469a in device_set_realized /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../hw/core/qdev.c:494:13
    #8 0x5b6387a27d9e in property_set_bool /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../qom/object.c:2375:5
    #9 0x5b6387a2090b in object_property_set /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../qom/object.c:1450:5
    #10 0x5b6387a35b05 in object_property_set_qobject /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../qom/qom-qobject.c:28:10
    #11 0x5b6387a21739 in object_property_set_bool /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../qom/object.c:1520:15
    #12 0x5b63879fe510 in qdev_realize /data_nvme1n1/linaro/qemu-from-laptop/qemu/build/x86-tgts-asan/../../hw/core/qdev.c:276:12
Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2517
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: David Hildenbrand <david@redhat.com>
Link: https://lore.kernel.org/r/20250929144228.1994037-4-peter.maydell@linaro.org
Signed-off-by: Peter Xu <peterx@redhat.com>
		
	
		
			
				
	
	
		
			101 lines
		
	
	
		
			3.2 KiB
		
	
	
	
		
			Meson
		
	
	
	
	
	
			
		
		
	
	
			101 lines
		
	
	
		
			3.2 KiB
		
	
	
	
		
			Meson
		
	
	
	
	
	
| # If possible, add new files to other directories, by using "if_false".
 | |
| # If you need them here, try to add them under one of the if statements
 | |
| # below, so that it is clear who needs the stubbed functionality.
 | |
| 
 | |
| stub_ss.add(files('cpu-get-clock.c'))
 | |
| stub_ss.add(files('error-printf.c'))
 | |
| stub_ss.add(files('fdset.c'))
 | |
| stub_ss.add(files('iothread-lock.c'))
 | |
| stub_ss.add(files('is-daemonized.c'))
 | |
| stub_ss.add(files('monitor-core.c'))
 | |
| stub_ss.add(files('replay-mode.c'))
 | |
| stub_ss.add(files('trace-control.c'))
 | |
| 
 | |
| if have_block
 | |
|   stub_ss.add(files('bdrv-next-monitor-owned.c'))
 | |
|   stub_ss.add(files('blk-commit-all.c'))
 | |
|   stub_ss.add(files('blk-exp-close-all.c'))
 | |
|   stub_ss.add(files('blockdev-close-all-bdrv-states.c'))
 | |
|   stub_ss.add(files('change-state-handler.c'))
 | |
|   stub_ss.add(files('get-vm-name.c'))
 | |
|   stub_ss.add(files('iothread-lock-block.c'))
 | |
|   stub_ss.add(files('migr-blocker.c'))
 | |
|   stub_ss.add(files('physmem.c'))
 | |
|   stub_ss.add(files('ram-block.c'))
 | |
|   stub_ss.add(files('runstate-check.c'))
 | |
|   stub_ss.add(files('uuid.c'))
 | |
| endif
 | |
| 
 | |
| if have_block or have_ga
 | |
|   stub_ss.add(files('replay-tools.c'))
 | |
|   # stubs for hooks in util/main-loop.c, util/async.c etc.
 | |
|   stub_ss.add(files('cpus-virtual-clock.c'))
 | |
|   stub_ss.add(files('icount.c'))
 | |
|   stub_ss.add(files('graph-lock.c'))
 | |
|   if linux_io_uring.found()
 | |
|     stub_ss.add(files('io_uring.c'))
 | |
|   endif
 | |
|   if libaio.found()
 | |
|     stub_ss.add(files('linux-aio.c'))
 | |
|   endif
 | |
|   stub_ss.add(files('qemu-timer-notify-cb.c'))
 | |
| 
 | |
|   # stubs for monitor
 | |
|   stub_ss.add(files('monitor-internal.c'))
 | |
|   stub_ss.add(files('qmp-command-available.c'))
 | |
|   stub_ss.add(files('qmp-quit.c'))
 | |
| endif
 | |
| 
 | |
| if have_block or have_user
 | |
|   stub_ss.add(files('qtest.c'))
 | |
|   stub_ss.add(files('vm-stop.c'))
 | |
|   stub_ss.add(files('vmstate.c'))
 | |
| endif
 | |
| 
 | |
| if have_user
 | |
|   # Symbols that are used by hw/core.
 | |
|   stub_ss.add(files('cpu-synchronize-state.c'))
 | |
|   stub_ss.add(files('cpu-destroy-address-spaces.c'))
 | |
| 
 | |
|   # Stubs for QAPI events.  Those can always be included in the build, but
 | |
|   # they are not built at all for --disable-system builds.
 | |
|   if not have_system
 | |
|     stub_ss.add(files('qdev.c'))
 | |
|   endif
 | |
| 
 | |
|   stub_ss.add(files('monitor-internal.c'))
 | |
| endif
 | |
| 
 | |
| if have_system
 | |
|   # Symbols that are only needed in some configurations.  Try not
 | |
|   # adding more of these.  If the symbol is used in specific_ss,
 | |
|   # in particular, consider defining a preprocessor macro via
 | |
|   # Kconfig or configs/targets/.
 | |
|   stub_ss.add(files('dump.c'))
 | |
|   stub_ss.add(files('cmos.c'))
 | |
|   stub_ss.add(files('fw_cfg.c'))
 | |
|   stub_ss.add(files('target-get-monitor-def.c'))
 | |
|   stub_ss.add(files('target-monitor-defs.c'))
 | |
|   stub_ss.add(files('win32-kbd-hook.c'))
 | |
|   stub_ss.add(files('xen-hw-stub.c'))
 | |
|   stub_ss.add(files('monitor-arm-gic.c'))
 | |
|   stub_ss.add(files('monitor-i386-rtc.c'))
 | |
|   stub_ss.add(files('monitor-i386-sev.c'))
 | |
|   stub_ss.add(files('monitor-i386-sgx.c'))
 | |
|   stub_ss.add(files('monitor-i386-xen.c'))
 | |
|   stub_ss.add(files('monitor-cpu.c'))
 | |
|   stub_ss.add(files('monitor-cpu-s390x.c'))
 | |
|   stub_ss.add(files('monitor-cpu-s390x-kvm.c'))
 | |
| endif
 | |
| 
 | |
| if have_system or have_user
 | |
|   stub_ss.add(files('gdbstub.c'))
 | |
| 
 | |
|   # Also included in have_system for --disable-tcg builds
 | |
|   stub_ss.add(files('replay.c'))
 | |
| 
 | |
|   # Also included in have_system for tests/unit/test-qdev-global-props
 | |
|   stub_ss.add(files('hotplug-stubs.c'))
 | |
|   stub_ss.add(files('sysbus.c'))
 | |
| endif
 |