From nobody Thu Aug 27 08:08:38 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1785934608; cv=none; d=zohomail.com; s=zohoarc; b=GI+LR0TsoQ5thiZbRQDi2A2sdE5l3TIrmVaPthD+An0M55rYBC0YA6ZG9VP6hnTsp0QGSE+Tj3U2/fVPEAcV5RCxLOoPcyaQS3J+F54K6LvSRjdOMGMrwqNKIPH/dMtwy1L3QfB3UZYSQiVfiLxaUenO4VCEsSDuAmfO6amrLuY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785934608; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=k4EmmzszfD+1kffTictZyQ8sdVf2+Y0ZJ/alY0rtd6c=; b=T6EJKQEliwTWqufSiw4+NAyXujNtiQUQjaL+qB51th2f2u2sQ0vDmizNVk4vpv9iUQZw+F7YLLg6RqY9Y1ANeiEn1evwGINT/KW16Xnsfip2WwiLm0LJDqt+qM0VLBGUo/bOX9oTfIwcamp3DlyS4xWUTY22SNKfPo5aji5D6SE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785934608296376.143671199355; Wed, 5 Aug 2026 05:56:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrb0p-0007vu-Sp; Wed, 05 Aug 2026 08:46:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrb03-0007mi-KD for qemu-devel@nongnu.org; Wed, 05 Aug 2026 08:45:36 -0400 Received: from mail-wm1-x334.google.com ([2a00:1450:4864:20::334]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wrb00-0006dT-Ml for qemu-devel@nongnu.org; Wed, 05 Aug 2026 08:45:35 -0400 Received: by mail-wm1-x334.google.com with SMTP id 5b1f17b1804b1-490791a3e92so963155e9.0 for ; Wed, 05 Aug 2026 05:45:29 -0700 (PDT) Received: from AtiePC ([79.116.13.250]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4994a100e14sm166453775e9.14.2026.08.05.05.45.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 05:45:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785933929; x=1786538729; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=k4EmmzszfD+1kffTictZyQ8sdVf2+Y0ZJ/alY0rtd6c=; b=S4OuGRmbpWPvxmixJYdF0KJCivypbN2mpNbDwbitttI3085ILzRdtZFW4pKm1OU2Ra 9tKZjCwklsJDvqxkoMv3XTSvw6Lpqbqr/8jSSuceZUyaDLHBJKb82V6dWfZOUId+cwKc HhCiDWI242vspHcAX6xrnNAxyEHXaM4dBJTG9lhpHiNsHPwxOBpkzYjo/322BJuPaIBp FOrfXvwWOrfIl+bP7kZssI8VbNyE8wRjXrO6Av/9mFoCuVCFoZjEHWzntvlcECTfHlmr RPM0LJnsMEGU7e0iQ7iWfBGbOcfeh1OrBBLos3SjvsCanf7wNHp3WFyoHfSBqw+54wvu 10lg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785933929; x=1786538729; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=k4EmmzszfD+1kffTictZyQ8sdVf2+Y0ZJ/alY0rtd6c=; b=D0R8t3fhDFIHoPB0mEFBHUdopZ255sAQlBjdKyFK/k4Znq8HB4vfF3hL0JMSTLfDOB axqoRK1XStj8Cw/ZHGQ2mDneSl4ZfS2uJ+esM21RjPcXTlLxyWnH1Qu/qSZ7+/ZcpR+s XuRcJdz2TZL07AXdtDXRBXOFzD40Izs7kLs7KTlmOMf62j633w45xUG/lsgI/s88frr2 1qSYuEHAzcOTc9COnSEuJucRpg6/GpAKljjSd6OK4fq25O2/zNwfLsdB0eci7z8LOKx1 hIoozZcqTNq1r/yXM7llvGg6aHwQI6gGk9D7ma+luzZoXk26+9Qz+QnF7NeheH/yQm13 kKQA== X-Forwarded-Encrypted: i=1; AHgh+RrfZFTNM+SX75gFV4zP/KN4bmbSHBiYV6JM9jy3oKKUSST/Xu4bC+dLSDgGO5APMaQKruua/tA3vsrz@nongnu.org X-Gm-Message-State: AOJu0Yz/vNFeyqL6+JEYrUjBnZ/vo8TFOkCtyhQbiaA0Z7d3lNxDIZBE D0p/d8my+gopKfeBLnceNNObc9CHUrfEnOBzfYombOh0YHvyrE1SPYLC X-Gm-Gg: AR+sD11StSpjqbG0n1FhrSPvusHmp+ZQwKVV1W/BsFX77Oxi/Py3YWheptaTJgvhD94 qdr9oBvZhrZq1z3is8AFTCmFnm1IQx+en7QOxGuvWKV164HcADnJFUZVwx3v5PlTmSzva1K6l24 1iFdhQY0fmVV47ZK822hkoGxKXCfOwe3gkxwXJMNfu/sAFtl6D/Ho9DPPqTPxHgRSHqmgpAhZxi R3ntv+N209jbPcQ4P0UJl6y+drhfmwwfN8lldLsBI8Mu1Qihz8csi7tfinBx/6gedpuEfD/MQJa oEivMJOV7zrm2dKdgoFi2nladxTDpTPFrSfqvH/8ngiFVcyCgODG5zv5FaQwMSPOqysEhyzGQdg SFnKUaanhzfYE+1zlcGiHC1K7syMsz5ts0OkVBlQaf25yb+DosIEhc0gAIaW0WsIFtoY8eM6bNn 64MfW+1yCK4+aQyMKrx/+3eLELJtx0TJFPcF7ildWHtSdDNR+KDUYMPO/50wdDA31Zo7GPOIQ= X-Received: by 2002:a05:600c:c4a5:b0:499:521e:86c1 with SMTP id 5b1f17b1804b1-499521e86cemr1123385e9.1.1785933928593; Wed, 05 Aug 2026 05:45:28 -0700 (PDT) From: Daniel Paziyski To: Keith Busch , Klaus Jensen , "Michael S. Tsirkin" Cc: Daniel Paziyski , qemu-stable@nongnu.org, Jesper Devantier , qemu-block@nongnu.org (open list:nvme), qemu-devel@nongnu.org (open list:All patches CC here) Subject: [PATCH 1/3] hw/nvme: fix assertion failure on sr-iov capable nvme controller removal Date: Wed, 5 Aug 2026 14:45:16 +0200 Message-ID: <20260805124519.30054-2-danielpaziyski@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805124519.30054-1-danielpaziyski@gmail.com> References: <20260805124519.30054-1-danielpaziyski@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::334; envelope-from=danielpaziyski@gmail.com; helo=mail-wm1-x334.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1785934610534158500 Content-Type: text/plain; charset="utf-8" In a nvme subsystem, the ctrls array maps controller IDs to nvme controller= s. The value of the array elements can either be NULL (no controller present f= or this ID), SUBSYS_SLOT_RSVD, or any other value, representing a pointer to t= he nvme controller structure. The SUBSYS_SLOT_RSVD value is special: when a nvme controller physical func= tion is being created and is reserving the controller IDs for its virtual functi= ons, it indicates that the slot is soon going to be filled by its corresponding virtual function when it is realized, and on virtual function removal, it m= eans that its controller has been removed. When the physical function is being removed, it goes through its list of secondary controllers (virtual functions), ensures that their slots have the SUBSYS_SLOT_RSVD values, and then frees up the controller IDs by setting the NULL value. This traversal occurs before the virtual functions are destroye= d, causing an assertion failure because the slots contain as values the pointe= rs to the secondary controllers. Destroy the virtual functions (and therefore, the secondary controllers) af= ter they are offlined in the nvme_ctrl_reset call of the physical function, but before releasing the controller IDs of the secondary controllers in nvme_subsys_unregister_ctrl. QEMU command line (boot with a hotunplug-aware OS, such as Linux): qemu-system-x86_64 -M q35 -device pcie-root-port,id=3Drp -monitor stdio= \ -device nvme-subsys,id=3Dsubsys0 \ -device nvme,subsys=3Dsubsys0,serial=3Dctrl0,sriov_max_vfs=3D1,\ sriov_vq_flexible=3D2,sriov_vi_flexible=3D1,max_ioqpairs=3D4,msix_qsize=3D2= ,bus=3Drp,id=3Dctrl0 In the QEMU monitor: device_del ctrl0 Message in stderr: qemu-system-x86_64: ../hw/nvme/subsys.c:49: nvme_subsys_unreserve_cntlids: = Assertion `subsys->ctrls[cntlid] =3D=3D SUBSYS_SLOT_RSVD' failed. Cc: qemu-stable@nongnu.org Fixes: 44c2c09488db ("hw/nvme: Add support for SR-IOV") Signed-off-by: Daniel Paziyski --- hw/nvme/ctrl.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c index bd6ad64b20..b726c13a56 100644 --- a/hw/nvme/ctrl.c +++ b/hw/nvme/ctrl.c @@ -9676,6 +9676,10 @@ static void nvme_exit(PCIDevice *pci_dev) } } =20 + if (!pci_is_vf(pci_dev) && n->params.sriov_max_vfs) { + pcie_sriov_pf_exit(pci_dev); + } + nvme_subsys_unregister_ctrl(n->subsys, n); =20 g_free(n->cq); @@ -9700,10 +9704,6 @@ static void nvme_exit(PCIDevice *pci_dev) host_memory_backend_set_mapped(n->pmr.dev, false); } =20 - if (!pci_is_vf(pci_dev) && n->params.sriov_max_vfs) { - pcie_sriov_pf_exit(pci_dev); - } - if (n->params.msix_exclusive_bar && !pci_is_vf(pci_dev)) { msix_uninit_exclusive_bar(pci_dev); } else { --=20 2.55.0 From nobody Thu Aug 27 08:08:38 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1785934991; cv=none; d=zohomail.com; s=zohoarc; b=cdi7tAC022d10HoHt54OGTUVjoN8ZP5BlUP04XuwuXkKStb+pF8gocMl0sfCEQ4zJf9BKSMxRxil3VpkTA9r0sHNV2xLJwMOaOPSMpefBcamUeoXJafCOhHCjh5vi4HAK47NrW0ncxMXVhikuFBEVsV289I9mUWppJOXw7u+d9c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785934991; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8QybmKXsQqLSM3yBhrdsFkkm4/OY/6jMO66xFzPollQ=; b=NeQGkJkeuS6yVPIHpLJNa95FIggdOtFd6i+4t/5DGZe41HSCV6RALmQjw0QFk/hD+JLYrq5JebWcIXj4OYcLBMe+vXNyc9OFPOeayvnmptq/akUn5zgffKKfMznoAHgmfV4IMeOQlkXvRaAcMjNjb9m6JrN9vt8KidfaLFfGknQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785934991239702.9302378361228; Wed, 5 Aug 2026 06:03:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrb0Q-0007qQ-Sj; Wed, 05 Aug 2026 08:45:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrb05-0007nl-Kz for qemu-devel@nongnu.org; Wed, 05 Aug 2026 08:45:38 -0400 Received: from mail-wr1-x429.google.com ([2a00:1450:4864:20::429]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wrb00-0006dx-Mj for qemu-devel@nongnu.org; Wed, 05 Aug 2026 08:45:36 -0400 Received: by mail-wr1-x429.google.com with SMTP id ffacd0b85a97d-47f611b3af9so139457f8f.3 for ; Wed, 05 Aug 2026 05:45:31 -0700 (PDT) Received: from AtiePC ([79.116.13.250]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4994a100e14sm166453775e9.14.2026.08.05.05.45.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 05:45:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785933931; x=1786538731; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8QybmKXsQqLSM3yBhrdsFkkm4/OY/6jMO66xFzPollQ=; b=hO6LfnTSiRVp+LZHX3BIyOMt5HP49q4VYjjvBmo3wBtaVQ/KGXEWjOcOq9McZjOPEr 13cInFEpvlxE6uf5zk7MX/EIOW1dlJWQPFItEeqBTXw2rWZ8NIxlMZU72CrNhLQCLtLG aJmDcz9eZFQL3owBIYdmQpIHfAXtAQVMQGzO0gpzZZSA94CmMRyj98VkUaVjJmpJQ9zr D/b9LnaYAp5mewNK1B8aqwoyJJiN15UU+FBuHm0COtFdt+9MvLwmIxSldXPXi6PvGahp 1VZlJImHN9uMAvSwQsPZbG1sJjD8MN1S4egsqc5QK++9jAj2eCQMQhaU1ebVud3Kb+Ub 3xkw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785933931; x=1786538731; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8QybmKXsQqLSM3yBhrdsFkkm4/OY/6jMO66xFzPollQ=; b=Qgx7yDzCCL9bjKPisFZ8MFBsvwjEnEFDrLPTYcGIpSZGmSpGpkRys5cWC3k/5ABTKS 5ZsX9fiqUWchNDh5/3E41Gi/YlerQLdTT14w+WJV6ExQ7+5VKCBHFlUnTjvWPba1BHni Ea0NZbv/lkXr0EOddN3jHFi4Rnl/1THXGgfnbgr6ItbZNrOXPGiI9qaF7qMtoAoKIUB5 Uet2wx//dXzlKjH7dZIUhuJLz93f76IsoDCX7DwOLfHIPRpklhVVjkMo+3DaRbMWwMBL Ex1Bskb9oR8u09ND3Avc8OHGnmryipKMhFwtTFJ1TAtJmRl6/KBouvNDmXXVcivTiiu/ K99w== X-Forwarded-Encrypted: i=1; AHgh+Rr11Bqvkp2SB9Br6RK6V+/p4dmXzbkfKQbEsqHoS5w88GT5j6KdNzMkr2srbAumKWEZOF7MBNQME3NW@nongnu.org X-Gm-Message-State: AOJu0YwyLaIbk4vQSRbfL2GewXyjjTv98H+rIp+VVMnX+g2Gp7/LQ19E WcS/D4mf62OsGqYiuWm87x/LPgKeaEA0pGTH5d8zHM+Qz2X5ttPVBiFQ X-Gm-Gg: AR+sD13OqrQ1z5lfoEWu1M//tFIhDjDMJIGKnFcXNSrGVECtjjpfCNLdlksK0sUTlhR GVyiCxvImSoUCpM6i+2Rr/Tg/xMIuZWWESwkjWBm1Y+sR/R2krB8pF6a1ZP3KRCtDXETk74gfpF L7ODlMjiv/hK1cZTMwvTkhZbPfSp5oz9c0Iyxp2zjB2QPHUPWLooxs8lPoAUfXpDomckUyscQ4z trMMvFeBB+byYdcABC+pfFJ2s3g5O0LNIOjw4YGTceMWB3EYaULQm9+OhKR/UUCeLylRPL4TpFD 2oCvncC3ANA0kDIMkSFp2VOiGItKWmmPEbqTdmh9Mzm4jQB2Iz5TQlOh8C5s0R4GJmrTd1w9Rtx SkeY2iiik5Ez4mIWmamEKoSOX4TWbHswfi21HoMkbwaZv9aBiaSwgkI89avR8OWPrgy2ff5Ys4F Sd7lIFYAi/8osLPoAX4Aoo6+1zzvTBlPa7dBYY8LES6EUOjs7e/V8MiMMfTQw= X-Received: by 2002:a05:600c:1393:b0:495:650b:4c61 with SMTP id 5b1f17b1804b1-4994e7d0166mr45279285e9.3.1785933930865; Wed, 05 Aug 2026 05:45:30 -0700 (PDT) From: Daniel Paziyski To: Keith Busch , Klaus Jensen , "Michael S. Tsirkin" Cc: Daniel Paziyski , qemu-stable@nongnu.org, Jesper Devantier , qemu-block@nongnu.org (open list:nvme), qemu-devel@nongnu.org (open list:All patches CC here) Subject: [PATCH 2/3] hw/nvme: fix memory leak on sr-iov capable nvme controller removal Date: Wed, 5 Aug 2026 14:45:17 +0200 Message-ID: <20260805124519.30054-3-danielpaziyski@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805124519.30054-1-danielpaziyski@gmail.com> References: <20260805124519.30054-1-danielpaziyski@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::429; envelope-from=danielpaziyski@gmail.com; helo=mail-wr1-x429.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1785934992137158500 Content-Type: text/plain; charset="utf-8" If a nvme controller is SR-IOV capable, its list of secondary controllers (virtual functions) is stored in the sec_ctrl_list dynamically allocated array, located in the NvmeCtrl struct. Free the secondary controller list after destroying the virtual functions a= nd freeing their controller IDs. QEMU command line (boot with a hotunplug-aware OS, such as Linux): qemu-system-x86_64 -M q35 -device pcie-root-port,id=3Drp -monitor stdio= \ -device nvme-subsys,id=3Dsubsys0 \ -device nvme,subsys=3Dsubsys0,serial=3Dctrl0,sriov_max_vfs=3D1,\ sriov_vq_flexible=3D2,sriov_vi_flexible=3D1,max_ioqpairs=3D4,msix_qsize=3D2= ,bus=3Drp,id=3Dctrl0 In the QEMU monitor: device_del ctrl0 quit ASAN splat: =3D=3D78982=3D=3DERROR: LeakSanitizer: detected memory leaks Direct leak of 32 byte(s) in 1 object(s) allocated from: #0 0x7fcbab32bea9 in calloc (/usr/lib/libasan.so.8+0x12bea9) (BuildId: = 7f2845989b820f536270e19ec47df085ae89a675) #1 0x7fcbaa2a34b2 in g_malloc0 (/usr/lib/libglib-2.0.so.0+0x694b2) (Bui= ldId: cb17d184459352a7985a010f1cd3acef4a4f90d8) #2 0x559c531fff4b in nvme_subsys_register_ctrl ../hw/nvme/subsys.c:65 #3 0x559c531d715e in nvme_init_subsys ../hw/nvme/ctrl.c:9582 #4 0x559c531d7a7d in nvme_realize ../hw/nvme/ctrl.c:9637 #5 0x559c5323c0da in pci_qdev_realize ../hw/pci/pci.c:2316 #6 0x559c54001e88 in device_set_realized ../hw/core/qdev.c:514 #7 0x559c5402462e in property_set_bool ../qom/object.c:2484 #8 0x559c5401dbd2 in object_property_set ../qom/object.c:1548 #9 0x559c5402b76c in object_property_set_qobject ../qom/qom-qobject.c:28 #10 0x559c5401e24c in object_property_set_bool ../qom/object.c:1618 #11 0x559c53fffd77 in qdev_realize ../hw/core/qdev.c:277 #12 0x559c53934166 in qdev_device_add_from_qdict ../system/qdev-monitor= .c:740 #13 0x559c53934272 in qdev_device_add ../system/qdev-monitor.c:758 #14 0x559c538867c8 in device_init_func ../system/vl.c:1217 #15 0x559c5487236a in qemu_opts_foreach ../util/qemu-option.c:1148 #16 0x559c53891205 in qemu_create_cli_devices ../system/vl.c:2762 #17 0x559c53891968 in qmp_x_exit_preconfig ../system/vl.c:2822 #18 0x559c53898108 in qemu_init ../system/vl.c:3862 #19 0x559c545efabf in main ../system/main.c:71 #20 0x7fcba7627780 (/usr/lib/libc.so.6+0x27780) (BuildId: 1fa174a830ce= f40a5b2388add4318ee2795f573e) #21 0x7fcba76278b8 in __libc_start_main (/usr/lib/libc.so.6+0x278b8) (B= uildId: 1fa174a830cef40a5b2388add4318ee2795f573e) #22 0x559c524df1f4 in _start (BuildId: 35402cb4fc46114b7a4102258726bbde= c82cd9bc) Cc: qemu-stable@nongnu.org Fixes: c6159d0e384f ("hw/nvme: Allocate sec-ctrl-list as a dynamic array") Signed-off-by: Daniel Paziyski --- hw/nvme/ctrl.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c index b726c13a56..284f3964e3 100644 --- a/hw/nvme/ctrl.c +++ b/hw/nvme/ctrl.c @@ -9682,6 +9682,10 @@ static void nvme_exit(PCIDevice *pci_dev) =20 nvme_subsys_unregister_ctrl(n->subsys, n); =20 + if (!pci_is_vf(pci_dev) && n->params.sriov_max_vfs) { + g_free(n->sec_ctrl_list); + } + g_free(n->cq); g_free(n->sq); g_free(n->aer_reqs); --=20 2.55.0 From nobody Thu Aug 27 08:08:38 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1785934785; cv=none; d=zohomail.com; s=zohoarc; b=XmbtYlEMLsISAizcZyl1UT4ghQ/lU8wowaXVcehkxBR2bqBeFLsLErgSwbFebUAIyRHhUz3ZxNu19ogJPb6XY0m76OZfBzljoJe4RO2wFiIIWLo3/mx4LAI+CoSnDnmLWAQA418+6DjjhdhWCzHMhdjs7GGvLfUNpzoSkDMo2sk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785934785; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=emGWraFb85q648++qsD+2jIhcU3Su9wTeLY94uHqiv4=; b=T53kjQUiKPsHL8EAb1SzqY73a2nY7QlNtZcVDziJL4wTKUYS3OBVODFoDa0O9TIc72bUXBuFr/VjnFgwY86LEqj+iuVM+Zbnx6w6WgAhqJCDRFZV7AqLqFEW1kZBpI95+iFMN1k1/n7RFkkMLS+J2rTW7zSRLRg5BYsrf6sK3Hg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785934785372263.3419920447893; Wed, 5 Aug 2026 05:59:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrb0W-0007rO-8n; Wed, 05 Aug 2026 08:46:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrb05-0007nj-Jf for qemu-devel@nongnu.org; Wed, 05 Aug 2026 08:45:38 -0400 Received: from mail-wm1-x32c.google.com ([2a00:1450:4864:20::32c]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wrb03-0006ee-1b for qemu-devel@nongnu.org; Wed, 05 Aug 2026 08:45:36 -0400 Received: by mail-wm1-x32c.google.com with SMTP id 5b1f17b1804b1-4954c08a7c8so1165485e9.3 for ; Wed, 05 Aug 2026 05:45:34 -0700 (PDT) Received: from AtiePC ([79.116.13.250]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4994a100e14sm166453775e9.14.2026.08.05.05.45.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 05:45:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785933933; x=1786538733; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=emGWraFb85q648++qsD+2jIhcU3Su9wTeLY94uHqiv4=; b=EiTJaco3rugtpFTBo52DL4TpwD8t6W8YLfMhzSe3kidBeJeelQATrbIW6pVaFg8eHH y/HgWS7tf16RHP8KNB0m7K4sFUHqsnYOEWRu6LjqXF2yui/mIe0mE5Kl9DY/naGnbBim n/jw9AOYwWtjkvCE35OFu597F4Ed0rv8omG1wllG3eahq13OW4UNUzm3lapZ9TEJbVdm bs2RMzjQHkCNG+5eU4X1oIm7WAism9xEuDbs860hpNsm6zQOBWVyG6r6fQ9TzAxcNUA1 8Y4/S6Mv+11UNKUJyNeBEITGepVBVwJYZVGLZ5vkpLMMrsig9lf0GyeLmV4PmuEpDMTY 0TQw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785933933; x=1786538733; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=emGWraFb85q648++qsD+2jIhcU3Su9wTeLY94uHqiv4=; b=DBJu+VaxzVTFCBSiJ9iD0nYqY322GeGeCjqM8DWJSTNbt1jud73niEvRQWm5Yweujz qvs53m6tIri/3N9oyKohiEgLzhdSPgkg6ShgeBW3jdxJIkuSjEhsznl9spkcV6nwNyOf ayxPvj/uXxQYo3zsAmT6QLKUU/7XYWwUrvOfmmrQyhEvfqfKcRlXxRchD1C9nJUwYAWL Yzfki7nMK6FD4JC+fREI3pc0AYq88EVjIhScCkgir4vxZmrRZTJCneMbM1mT8YqXPWmY hXG/9pMpMesrPqnkpxPEpF/gVFoVUxgL+FobORA3wMlXlEhetda7dkW6kHTKN+bZ7zVq bMNA== X-Forwarded-Encrypted: i=1; AHgh+RpSVw7L7ws+9wt0rTNa6k1C/wlAmJ+TZxIQK8EVxiqD50iMRnBxd53ck0E7qyO7heWbX5BuNeg7Gm3s@nongnu.org X-Gm-Message-State: AOJu0YzSXEv37+72kGmSUJMi9AZIr0lhk1ZwB/DarQimugtucsDn3B2g vX0oaS5pgiMngYmUzUrhhL60FlHaIgccfh3m/tZfViVAMXMnT7/miieK X-Gm-Gg: AR+sD12lv7U9CZPKSagVwMjL8aPdKLGKAXbAW+CwOxQs2jOK1RB4hfaxeauxWv3OYPI f+e4xv+OBMy02De495a9mSfmW6wg6IKkjxFzTVpjZ4e84uXClFgi7Mo2h26y4vPXb/ODgZvatDH oyCNw7GD1GxxkE3bxJ3n0TdtL7SGL5br1ljUFnGEVMMfKuidlD6HVHcLAyZif1kneU4JR0RYVMY rT+k08nYiPKQaZLeH5YP2Yeo93oWJKmSi0Jyl6Qot9rj1Lg+9ORdAqldTcUc71wPYfKXU4nIEe+ pYw1TG6xl64fGFeAJWN/kBoXvQgpn9dxRwy1Dm92+iSWO2YQWNlJ4cWXW8PxG64IIZrtLsgDMqh UdaUgZWsgXPijYUWvz9SksoNoTG5awf1revNOw3QwuShfkBYgjPII0dV0AF+YDgkPlkgEOikPJV upuIToh/nyOg0PkiTg4qebQjyzRVDnzwOrIdbK+K9F9du/ucJ1rRmgVJWaIok= X-Received: by 2002:a05:600c:c8c:b0:495:7561:a9cc with SMTP id 5b1f17b1804b1-4994e7d5c76mr38522495e9.4.1785933933280; Wed, 05 Aug 2026 05:45:33 -0700 (PDT) From: Daniel Paziyski To: Keith Busch , Klaus Jensen , "Michael S. Tsirkin" Cc: Daniel Paziyski , qemu-stable@nongnu.org, Jesper Devantier , qemu-block@nongnu.org (open list:nvme), qemu-devel@nongnu.org (open list:All patches CC here) Subject: [PATCH 3/3] pcie_sriov: register user created virtual function before realizing it Date: Wed, 5 Aug 2026 14:45:18 +0200 Message-ID: <20260805124519.30054-4-danielpaziyski@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805124519.30054-1-danielpaziyski@gmail.com> References: <20260805124519.30054-1-danielpaziyski@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::32c; envelope-from=danielpaziyski@gmail.com; helo=mail-wm1-x32c.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1785934787787158500 Content-Type: text/plain; charset="utf-8" There are two ways of creating virtual functions: by using the sriov-pf dev= ice parameter (this way, creating a user created VF and binding it to a PF), or by using a device specific parameter, where the device manually creates a g= iven amount of VFs. When a PCI device is realized, the device specific realize function is call= ed first, and then the pcie_sriov_register_device function is called, which ch= ecks whether the device that has been created is a user created VF, and if it is= the case and the device allows this kind of VFs, it inserts it into a hashmap, = with the key being the ID of the PF, and the items being arrays of VFs. User created VFs are instantiated independently, and later, when the PF cal= ls pcie_sriov_pf_init_from_user_created_vfs, it discovers its VFs from the has= hmap mentioned previously, and sets up in their PCIDevice.ex.sriov_pf structure the pointer to the PF. This means that, during realization, VFs have no acc= ess to the PF. Device created VFs are instantiated during or after PF realization using the pcie_sriov_pf_init function, which sets up for the VFs the pointer to the PF before their realization, so when they're realized, they can access the PF with no issues. The problem here is that pcie_sriov_register_device is called after the realization, and not before. This means that when a user created VF is crea= ted for a device which does not support user created VFs, but supports device created VFs, the realize function will notice that a VF is being created, a= nd may try to access the PF, causing a null pointer dereference fault. Fix this by placing the user created VF check and registering before the realization. This way, incorrectly created user created VFs will be noticed, and device creation will be aborted. Additionally, remove from the pcie_sriov_register_device function the top check. It seems that this check is done to error out if the PF failed for s= ome reason to initialize its list of user created VFs. However, in such situati= ons, the pcie_sriov_pf_init_from_user_created_vfs function will error during realization, and it will be caught before the check is done at all. Moreove= r, since now pcie_sriov_register_device is called before realization, the check will always fail for PFs with user created VFs, because the list will be populated during realization. The rest of the function though, correctly errors out if a user created VF is created for an unsupported device type, if a VF is created for a non-PCIe device, or if the PF is already instantiated, with now the advantage being that the check is done before the VF instantiation. When instantiating a user created VF for a NVME controller: Command line: qemu-system-x86_64 -device nvme-subsys,id=3Dsubsys0 \ -device nvme,id=3Dvctrl0,sriov-pf=3Dctrl0,subsys=3Dsubsys0 \ -device nvme,id=3Dctrl0,subsys=3Dsubsys0,serial=3Ds ASAN splat: ../hw/nvme/ctrl.c:9613:28: runtime error: member access within null pointer= of type 'struct NvmeCtrl' AddressSanitizer:DEADLYSIGNAL =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D91050=3D=3DERROR: AddressSanitizer: SEGV on unknown address 0x0000000= 01cf0 (pc 0x7f79a8573dcd bp 0x7ffd622c1bc0 sp 0x7ffd622c1b68 T0) =3D=3D91050=3D=3DThe signal is caused by a READ memory access. #0 0x7f79a8573dcd (/usr/lib/libc.so.6+0x173dcd) (BuildId: 1fa174a830ce= f40a5b2388add4318ee2795f573e) #1 0x5644c6c0266e in nvme_realize ../hw/nvme/ctrl.c:9613 #2 0x5644c6c67213 in pci_qdev_realize ../hw/pci/pci.c:2316 #3 0x5644c7a2cfc1 in device_set_realized ../hw/core/qdev.c:514 #4 0x5644c7a4f767 in property_set_bool ../qom/object.c:2484 #5 0x5644c7a48d0b in object_property_set ../qom/object.c:1548 #6 0x5644c7a568a5 in object_property_set_qobject ../qom/qom-qobject.c:28 #7 0x5644c7a49385 in object_property_set_bool ../qom/object.c:1618 #8 0x5644c7a2aeb0 in qdev_realize ../hw/core/qdev.c:277 #9 0x5644c735f29f in qdev_device_add_from_qdict ../system/qdev-monitor.= c:740 #10 0x5644c735f3ab in qdev_device_add ../system/qdev-monitor.c:758 #11 0x5644c72b1901 in device_init_func ../system/vl.c:1217 #12 0x5644c829d4a3 in qemu_opts_foreach ../util/qemu-option.c:1148 #13 0x5644c72bc33e in qemu_create_cli_devices ../system/vl.c:2762 #14 0x5644c72bcaa1 in qmp_x_exit_preconfig ../system/vl.c:2822 #15 0x5644c72c3241 in qemu_init ../system/vl.c:3862 #16 0x5644c801abf8 in main ../system/main.c:71 #17 0x7f79a8427780 (/usr/lib/libc.so.6+0x27780) (BuildId: 1fa174a830ce= f40a5b2388add4318ee2795f573e) #18 0x7f79a84278b8 in __libc_start_main (/usr/lib/libc.so.6+0x278b8) (B= uildId: 1fa174a830cef40a5b2388add4318ee2795f573e) #19 0x5644c5f0a1f4 in _start (BuildId: 8483f952216d9e345c3744300d0aefa3= 8feb50d7) =3D=3D91050=3D=3DRegister values: rax =3D 0x00007e49988640f0 rbx =3D 0x00007e49988640f0 rcx =3D 0x00000fc9b= 3104828 rdx =3D 0x0000000000000058 rdi =3D 0x00007e49988640f0 rsi =3D 0x0000000000001cf0 rbp =3D 0x00007ffd6= 22c1bc0 rsp =3D 0x00007ffd622c1b68 r8 =3D 0x00000fc9b3104829 r9 =3D 0x00000fc9b3104828 r10 =3D 0x00000fc9b= 310481e r11 =3D 0x00000fc9b310481e r12 =3D 0x0000000000001cf0 r13 =3D 0x00000f6f32e78578 r14 =3D 0x00000000f= fffffff r15 =3D 0x00007ffd622c1c10 AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV (/usr/lib/libc.so.6+0x173dcd) (BuildId: 1fa= 174a830cef40a5b2388add4318ee2795f573e) =3D=3D91050=3D=3DABORTING Cc: qemu-stable@nongnu.org Fixes: 19e55471d4e8 ("pcie_sriov: Allow user to create SR-IOV device") Signed-off-by: Daniel Paziyski --- hw/pci/pci.c | 11 ++++++----- hw/pci/pcie_sriov.c | 6 ------ 2 files changed, 6 insertions(+), 11 deletions(-) diff --git a/hw/pci/pci.c b/hw/pci/pci.c index d3191609e2..a5b4482bb6 100644 --- a/hw/pci/pci.c +++ b/hw/pci/pci.c @@ -2312,20 +2312,21 @@ static void pci_qdev_realize(DeviceState *qdev, Err= or **errp) if (pci_dev =3D=3D NULL) return; =20 + if (!pcie_sriov_register_device(pci_dev, errp)) { + do_pci_unregister_device(pci_dev); + return; + } + if (pc->realize) { pc->realize(pci_dev, &local_err); if (local_err) { error_propagate(errp, local_err); + pcie_sriov_unregister_device(pci_dev); do_pci_unregister_device(pci_dev); return; } } =20 - if (!pcie_sriov_register_device(pci_dev, errp)) { - pci_qdev_unrealize(DEVICE(pci_dev)); - return; - } - /* * A PCIe Downstream Port that do not have ARI Forwarding enabled must * associate only Device 0 with the device attached to the bus diff --git a/hw/pci/pcie_sriov.c b/hw/pci/pcie_sriov.c index c41ac95bee..69930c7b8c 100644 --- a/hw/pci/pcie_sriov.c +++ b/hw/pci/pcie_sriov.c @@ -357,12 +357,6 @@ int16_t pcie_sriov_pf_init_from_user_created_vfs(PCIDe= vice *dev, =20 bool pcie_sriov_register_device(PCIDevice *dev, Error **errp) { - if (!dev->exp.sriov_pf.vf && dev->qdev.id && - pfs && g_hash_table_contains(pfs, dev->qdev.id)) { - error_setg(errp, "attaching user-created SR-IOV VF unsupported"); - return false; - } - if (dev->sriov_pf) { PCIDevice *pci_pf; GPtrArray *pf; --=20 2.55.0