From nobody Sat Sep 26 20:01:43 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1788610808; cv=none; d=zohomail.com; s=zohoarc; b=m/9Nf22LRkPBKJux8Y1ht2xeCF+dQdajzrMO5k1gcqjmnKsS+cwFoBrPjPkzMdgK4HwbHiJbTUnV71KuEijWTm2JpuG/cdPVYkTV0gzZAkRCXeQotTLWPZ1GBYy7jtyuvWnEFHRlg+Av+jzTvt1WvVhUv2Uynp94F3fV672zTfM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788610808; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=+IUpNcB02wW+cFoYTYG7CNyjL1aH81MjtkfSh/Ay9Rc=; b=Qsc9bbJTxrnZZgLsfs4oJ4zqvVTz93AV4DHw4smP0b4PKHHtUZrQgxK5RKpGU8YUuXkqRgEOf4C/mni0iGKijXKik5FlWkhbyQyW4QS2xmVaRNAmeHdP1DdFjQVXLAbbIZdC+vUAMIfC+Lr3/2/XZZhDsSPIaxKGZXaw5QknisQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788610808262637.9782639007086; Sat, 5 Sep 2026 05:20:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2pLy-0004Ml-S2; Sat, 05 Sep 2026 08:18:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2pLx-0004Le-6x for qemu-devel@nongnu.org; Sat, 05 Sep 2026 08:18:37 -0400 Received: from mail-wr2-x10.google.com ([2a00:1450:4864:30::10]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x2pLv-0001A2-Gv for qemu-devel@nongnu.org; Sat, 05 Sep 2026 08:18:36 -0400 Received: by mail-wr2-x10.google.com with SMTP id ffacd0b85a97d-482e1b55da9so208753f8f.2 for ; Sat, 05 Sep 2026 05:18:35 -0700 (PDT) Received: from AtiePC ([79.116.0.198]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cee5f912esm234546625e9.4.2026.09.05.05.18.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 05:18:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788610714; x=1789215514; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+IUpNcB02wW+cFoYTYG7CNyjL1aH81MjtkfSh/Ay9Rc=; b=PLoRi6rZaVjxvEuzHaO0Ah+FhqyIYL4RmsZqL/6BftHhCdTMPkaT+emag+OnEMPpVo KUCnUptZYh5ZmGc/rcId0snKx3FEn5NqB6xjCPTZC8HHtk57oLwEj29IaSuF57JB43c5 ttMreSggSg3TFcNmZbmXk/aykUoNMC2HSR+TtdtqJCvIZoeSRFIL7/H31Pxo2yJeoQgH cJwLTn66XL6CapzZMhTrqJLGYEee3Y/3flK2i4bqSZdtiXkyjh95ktYAEmu2RG+Y6gq7 5Pti6W14/xz3zfYM4vIe1sjb3ToqU5aedKcv76X1YMduNtqwwsiyzHLdIYIq1Ye6Uzjv 68fw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788610714; x=1789215514; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+IUpNcB02wW+cFoYTYG7CNyjL1aH81MjtkfSh/Ay9Rc=; b=KJ7E9N1hP6FT8yLOH8W15l0wWoDBCxWZd/6FSqWjL0YL2AA+wM8yscBDlXE0UW0Ubr gTUAiFb7jQrPVcZ0JQbF7mZktxnjceifc6IToV0b7kpohFeklUsYKghEQ7hV8uH50vJL 0QOQMvpQo0p4Hm1LVFW8GGQ/oHGJWzzSm9fkjDhVQYl5ASOMekE/NX3gERRYLaLbg61L PJzVclh5+PQ7uT0+FPCjApA6LsgGwlb9ugAgMK2V/NkQWDnP3uc3j3Pv0WMYVhEYBqhw jP4Z/XF0epYhf0jchGr8d0so27nIExscO7ibPY7KQJYyfColPOEZvgn5pmzFR12GvW6U 6pbQ== X-Forwarded-Encrypted: i=1; AKwUvBzmnUizeBuLY8YnICqyuX/8VAVuGBAgH/FiBLQXV52lLhjpumCpnhmVOXsZEKlY0/SN5i21balnDq3d@nongnu.org X-Gm-Message-State: AFuF++ldQc4vQEKr6hGeoJJxEKB5uIPZhJEQSN5+jZKYYAXwAuyGcNIj hml8BI94tdAmN5Zp3Udikme4xDzibvwX4CcQelBAAbnZurKJcn2nma6R X-Gm-Gg: AYBFou3CRkUHHAgreCgF2uaumwS2+Wm52c2CSZY8cHC1uHqyLb9udy6ptEb5ieE9bz2 o+Y5/EYpyOnn0YsYaR6TR6lsuZfyf64hW3rKQRqrvEDYZbHP4BCJtp130oa18hpWDDzPqkwgYUV Vf3cd6A3uVmanvxjomiZ8kAUj83IEYeAjg4bxCNMJRxj1i8otuPRoa1D/+1APQMwVnFUAzNQjCK P367c4BERnn+3nNv4ntNwl0Dbr0eJ9QVDo3vgf8VKWrmqskpf2l3wgAMl7Rm9KLYOIFM3IXRv9S lePEbJzkuF4C0KehqxN8DQKVeswWq8cUBCZuZjrXy6BR9Ijyy/bDwz17wgp6lCAKfTpCafyZcpB yFwPi2xU2ycPBglJ28OA1sD/K5um9pUoItl8TYD/E1IPpDVh070F7SRhCoB5mYlDMMrnabO1lyh FR6vNxlTdF9f3JQoP6g2Avqw006sughy8Uup8a7WSxrJs8BQYXUMF7MuJx7A== X-Received: by 2002:a05:600c:a305:b0:49c:ff81:e062 with SMTP id 5b1f17b1804b1-49cff81e076mr53512705e9.2.1788610713850; Sat, 05 Sep 2026 05:18:33 -0700 (PDT) From: Daniel Paziyski To: Keith Busch , Klaus Jensen Cc: Daniel Paziyski , qemu-stable@nongnu.org, Jesper Devantier , qemu-block@nongnu.org (open list:nvme), qemu-devel@nongnu.org (open list:All patches CC here) Subject: [PATCH 1/2] hw/nvme: fix assertion failure on sr-iov capable nvme controller removal Date: Sat, 5 Sep 2026 14:18:11 +0200 Message-ID: <20260905121812.47816-2-danielpaziyski@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260905121812.47816-1-danielpaziyski@gmail.com> References: <20260905121812.47816-1-danielpaziyski@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:30::10; envelope-from=danielpaziyski@gmail.com; helo=mail-wr2-x10.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1788610810964158500 Content-Type: text/plain; charset="utf-8" In a nvme subsystem, the ctrls array maps controller IDs to nvme controller= s. The value of the array elements can either be NULL (no controller present f= or this ID), SUBSYS_SLOT_RSVD, or any other value, representing a pointer to t= he nvme controller structure. The SUBSYS_SLOT_RSVD value is special: when a nvme controller physical func= tion is being created and is reserving the controller IDs for its virtual functi= ons, it indicates that the slot is soon going to be filled by its corresponding virtual function when it is realized, and on virtual function removal, it m= eans that its controller has been removed. When the physical function is being removed, it goes through its list of secondary controllers (virtual functions), ensures that their slots have the SUBSYS_SLOT_RSVD values, and then frees up the controller IDs by setting the NULL value. This traversal occurs before the virtual functions are destroye= d, causing an assertion failure because the slots contain as values the pointe= rs to the secondary controllers. Destroy the virtual functions (and therefore, the secondary controllers) af= ter they are offlined in the nvme_ctrl_reset call of the physical function, but before releasing the controller IDs of the secondary controllers in nvme_subsys_unregister_ctrl. QEMU command line (boot with a hotunplug-aware OS, such as Linux): qemu-system-x86_64 -M q35 -device pcie-root-port,id=3Drp -monitor stdio= \ -device nvme-subsys,id=3Dsubsys0 \ -device nvme,subsys=3Dsubsys0,serial=3Dctrl0,sriov_max_vfs=3D1,\ sriov_vq_flexible=3D2,sriov_vi_flexible=3D1,max_ioqpairs=3D4,msix_qsize=3D2= ,bus=3Drp,id=3Dctrl0 In the QEMU monitor: device_del ctrl0 Message in stderr: qemu-system-x86_64: ../hw/nvme/subsys.c:49: nvme_subsys_unreserve_cntlids: = Assertion `subsys->ctrls[cntlid] =3D=3D SUBSYS_SLOT_RSVD' failed. Cc: qemu-stable@nongnu.org Fixes: 44c2c09488db ("hw/nvme: Add support for SR-IOV") Signed-off-by: Daniel Paziyski Reviewed-by: Klaus Jensen --- hw/nvme/ctrl.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c index 4893cf7e74..3040cb1760 100644 --- a/hw/nvme/ctrl.c +++ b/hw/nvme/ctrl.c @@ -9702,6 +9702,10 @@ static void nvme_exit(PCIDevice *pci_dev) } } =20 + if (!pci_is_vf(pci_dev) && n->params.sriov_max_vfs) { + pcie_sriov_pf_exit(pci_dev); + } + nvme_subsys_unregister_ctrl(n->subsys, n); =20 g_free(n->cq); @@ -9726,10 +9730,6 @@ static void nvme_exit(PCIDevice *pci_dev) host_memory_backend_set_mapped(n->pmr.dev, false); } =20 - if (!pci_is_vf(pci_dev) && n->params.sriov_max_vfs) { - pcie_sriov_pf_exit(pci_dev); - } - if (n->params.msix_exclusive_bar && !pci_is_vf(pci_dev)) { msix_uninit_exclusive_bar(pci_dev); } else { --=20 2.55.0 From nobody Sat Sep 26 20:01:43 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1788610809; cv=none; d=zohomail.com; s=zohoarc; b=KwAeH7r5qsvTesl2FgAErY2L6a1Q0cdbcW4+dTg08sLExa0wk0auYE11wjLAX+oeU0LaO0ivli37Uibz54NIc9ZyTHVrymYsMnfCuadY6pAJEimIRB3jPqb8s/XswZrzbLSeMbMXHOJbxF6NlNaw+KBOCW7H5RwPqZfjSN9bNio= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788610809; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=otgHVEO2QmH4s2/UdC4CuyIgpLvObEOab+8xyU8rtzk=; b=bj/yy/0DHwfBYW8LTO2R4zphmNUjdC9WPMxIv+rrEkH8ZrtqA/LpYiz36J2DFCXaDa0ZD+JCZMYTkj4Refge4MynAdbCme2UiIm6+5SCJtelognZkSgCBPzplH1WkW3DJ8zBXW+a1Km/Qer2NUKRHwsCZ5yReCQaH51xsxsWx+U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788610809718791.6501941114053; Sat, 5 Sep 2026 05:20:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2pM5-0004Ok-0Z; Sat, 05 Sep 2026 08:18:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2pM0-0004Nx-Cf for qemu-devel@nongnu.org; Sat, 05 Sep 2026 08:18:40 -0400 Received: from mail-wm2-x10.google.com ([2a00:1450:4864:31::10]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x2pLx-0001Ah-VO for qemu-devel@nongnu.org; Sat, 05 Sep 2026 08:18:40 -0400 Received: by mail-wm2-x10.google.com with SMTP id 5b1f17b1804b1-49d0726cdbcso43295e9.0 for ; Sat, 05 Sep 2026 05:18:37 -0700 (PDT) Received: from AtiePC ([79.116.0.198]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cee5f912esm234546625e9.4.2026.09.05.05.18.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 05:18:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788610716; x=1789215516; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=otgHVEO2QmH4s2/UdC4CuyIgpLvObEOab+8xyU8rtzk=; b=WHAj9HMNyK/V0JtvgHXYie1nsnolN5SjlC7PKO/w1yzxoH6b3NsKTt+pky6IiHB4H+ n6pH8mfgt7t0FLizpDtGTOLmdyy3RlVsV9owMRKlR+LkhNkrEmv61SiNV5xv/Nef0EmC I/BPnhGE2ThQjBt1GW3VWuX7hwzx8T+TptoNZIFQYHLBjQ9TcueRP5DwtsR4di7LeoFJ 45ahue7FVq0Tlwgrz/xR9Eo2VZ+V6+DfpLhPWKqnESYbLriG5pZty8Y6vtRwOVhWg84C gSZwhQEyD2wQX0Elxy6MqvakP/Dh3nDuXTmcGueIUWt4KIXZ2bOHTa28HoXITmWMAB2N o7MQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788610716; x=1789215516; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=otgHVEO2QmH4s2/UdC4CuyIgpLvObEOab+8xyU8rtzk=; b=IPZd4jZxrC6pHgW2I0huKwq9kUrqGHnLdr7uE/j/qYkJp3i9akXnjxm8pxHUh5Neex to9Keke8DV1fw0sfrEgDgmV5L9a1tpkUzcqOUvq7WwKB7M8hJvoqNLUNz8ShfXTA0/Au /IRb86atVqsiEzCrQiCRRQ1vBiVXpDt4eTyiBWP5Akub7XXX1VsCWMu1MC7RsmvdrYW4 JCxWzYx4/GW7MSz/+pBsk8YAwSU/zz8TNNgNxZQrsFjBMsXLDjJe7f0WA02EM6sp9IB+ kaika/MhZrLq1bJmnVZxlTS5DBAlxwWjOab+FPhIqZUbAFeV2yZkez+aVGGESdJ5dhO/ gJ0g== X-Forwarded-Encrypted: i=1; AKwUvBzITKX87A20XznDqhWY4bvKQuYG44BuplMVOuzIbKaFzrteaFY1DzVOzBvhiyU6Y3bR/2vGeHYfhNwS@nongnu.org X-Gm-Message-State: AFuF++lYLIB+nOYzFAGUUCnIzwJfmGQQPazkj53YLjbXXQHoK1I8REHp ajvwYt7hZli7zmz1kk9ryKVqltx7pqYrAsUQPL+t5ZD1H6D4tr+Rb8qJ X-Gm-Gg: AYBFou0nN9vWlbYp8HDvL+uJOCzr59yqGycN93jBXqx1j1D7hbxQY8PAxTntPb/Xecz I6biqFc8QIAjVUZloz5r8Wf6lPEKe3Ra5pwIMKSSZ9i9rZmwHzMJR2pY0pX1QQE8GWm6jEDFuCZ XCu5JovHsfYKeedl049Ln0PlcscuXB4Q4ZEYaXCD3fEPChzjH39Bd8UTJFUytJc1BqVqkro1fzg zHhkRBJse7JjYGGB9R5F/ayb8DNZVY0fVJ1GXRiIYi6xEbepyvXer2S2UPa/xpzaDt10aWBmtch Iqh9BkBGAhSDOvVEiYvIRLrBDF33VO2pcPSSmBI3R7F9oB/RuyG7tlM59X+F4c5L5fiGENst2tU GDq3ojngTz+OOCxwF2pExAzptZ++BBDduchlVpEsWSYEyj8Efd7O/vbtpAEPszrYnCX7AA0qRs/ KuX9/x510z12PAELjgxRmh7szeT7Vo5GRUhk29M00ac2wWcQ9qX7nlPvszww== X-Received: by 2002:a05:600c:8485:b0:499:5b0f:72b with SMTP id 5b1f17b1804b1-49d01dcc32cmr38381305e9.1.1788610716198; Sat, 05 Sep 2026 05:18:36 -0700 (PDT) From: Daniel Paziyski To: Keith Busch , Klaus Jensen Cc: Daniel Paziyski , qemu-stable@nongnu.org, Jesper Devantier , qemu-block@nongnu.org (open list:nvme), qemu-devel@nongnu.org (open list:All patches CC here) Subject: [PATCH 2/2] hw/nvme: fix memory leak on sr-iov capable nvme controller removal Date: Sat, 5 Sep 2026 14:18:12 +0200 Message-ID: <20260905121812.47816-3-danielpaziyski@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260905121812.47816-1-danielpaziyski@gmail.com> References: <20260905121812.47816-1-danielpaziyski@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:31::10; envelope-from=danielpaziyski@gmail.com; helo=mail-wm2-x10.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1788610811512158500 Content-Type: text/plain; charset="utf-8" If a nvme controller is SR-IOV capable, its list of secondary controllers (virtual functions) is stored in the sec_ctrl_list dynamically allocated array, located in the NvmeCtrl struct. Free the secondary controller list after destroying the virtual functions a= nd freeing their controller IDs. QEMU command line (boot with a hotunplug-aware OS, such as Linux): qemu-system-x86_64 -M q35 -device pcie-root-port,id=3Drp -monitor stdio= \ -device nvme-subsys,id=3Dsubsys0 \ -device nvme,subsys=3Dsubsys0,serial=3Dctrl0,sriov_max_vfs=3D1,\ sriov_vq_flexible=3D2,sriov_vi_flexible=3D1,max_ioqpairs=3D4,msix_qsize=3D2= ,bus=3Drp,id=3Dctrl0 In the QEMU monitor: device_del ctrl0 quit ASAN splat: =3D=3D78982=3D=3DERROR: LeakSanitizer: detected memory leaks Direct leak of 32 byte(s) in 1 object(s) allocated from: #0 0x7fcbab32bea9 in calloc (/usr/lib/libasan.so.8+0x12bea9) (BuildId: = 7f2845989b820f536270e19ec47df085ae89a675) #1 0x7fcbaa2a34b2 in g_malloc0 (/usr/lib/libglib-2.0.so.0+0x694b2) (Bui= ldId: cb17d184459352a7985a010f1cd3acef4a4f90d8) #2 0x559c531fff4b in nvme_subsys_register_ctrl ../hw/nvme/subsys.c:65 #3 0x559c531d715e in nvme_init_subsys ../hw/nvme/ctrl.c:9582 #4 0x559c531d7a7d in nvme_realize ../hw/nvme/ctrl.c:9637 #5 0x559c5323c0da in pci_qdev_realize ../hw/pci/pci.c:2316 #6 0x559c54001e88 in device_set_realized ../hw/core/qdev.c:514 #7 0x559c5402462e in property_set_bool ../qom/object.c:2484 #8 0x559c5401dbd2 in object_property_set ../qom/object.c:1548 #9 0x559c5402b76c in object_property_set_qobject ../qom/qom-qobject.c:28 #10 0x559c5401e24c in object_property_set_bool ../qom/object.c:1618 #11 0x559c53fffd77 in qdev_realize ../hw/core/qdev.c:277 #12 0x559c53934166 in qdev_device_add_from_qdict ../system/qdev-monitor= .c:740 #13 0x559c53934272 in qdev_device_add ../system/qdev-monitor.c:758 #14 0x559c538867c8 in device_init_func ../system/vl.c:1217 #15 0x559c5487236a in qemu_opts_foreach ../util/qemu-option.c:1148 #16 0x559c53891205 in qemu_create_cli_devices ../system/vl.c:2762 #17 0x559c53891968 in qmp_x_exit_preconfig ../system/vl.c:2822 #18 0x559c53898108 in qemu_init ../system/vl.c:3862 #19 0x559c545efabf in main ../system/main.c:71 #20 0x7fcba7627780 (/usr/lib/libc.so.6+0x27780) (BuildId: 1fa174a830ce= f40a5b2388add4318ee2795f573e) #21 0x7fcba76278b8 in __libc_start_main (/usr/lib/libc.so.6+0x278b8) (B= uildId: 1fa174a830cef40a5b2388add4318ee2795f573e) #22 0x559c524df1f4 in _start (BuildId: 35402cb4fc46114b7a4102258726bbde= c82cd9bc) Cc: qemu-stable@nongnu.org Fixes: c6159d0e384f ("hw/nvme: Allocate sec-ctrl-list as a dynamic array") Signed-off-by: Daniel Paziyski Reviewed-by: Klaus Jensen --- hw/nvme/ctrl.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c index 3040cb1760..76ff92c9eb 100644 --- a/hw/nvme/ctrl.c +++ b/hw/nvme/ctrl.c @@ -9708,6 +9708,10 @@ static void nvme_exit(PCIDevice *pci_dev) =20 nvme_subsys_unregister_ctrl(n->subsys, n); =20 + if (!pci_is_vf(pci_dev) && n->params.sriov_max_vfs) { + g_free(n->sec_ctrl_list); + } + g_free(n->cq); g_free(n->sq); g_free(n->aer_reqs); --=20 2.55.0