Skip to content

Commit f990473

Browse files
Fabiano RosasMichael Tokarev
authored andcommitted
io: Fix TLS bye task leak
Recent fixes to TLS tasks memory handling have left the TLS bye task uncovered. Fix by freeing the task in the same way the handshake task is freed. Direct leak of 704 byte(s) in 4 object(s) allocated from: #1 0x7f5909b1d6a0 in g_malloc0 ../glib/gmem.c:163 #2 0x557650496d61 in qio_task_new ../io/task.c:58:12 #3 0x557650475d7f in qio_channel_tls_bye ../io/channel-tls.c:352:12 #4 0x55764f7a1bb4 in migration_tls_channel_end ../migration/tls.c:159:5 #5 0x55764f709750 in migration_ioc_shutdown_gracefully ../migration/multifd.c:462:9 #6 0x55764f6fcf53 in multifd_send_terminate_threads ../migration/multifd.c:493:13 #7 0x55764f6fcafb in multifd_send_shutdown ../migration/multifd.c:580:5 #8 0x55764f6e1b14 in migration_cleanup ../migration/migration.c:1323:9 #9 0x55764f6f5bac in migration_cleanup_bh ../migration/migration.c:1350:5 Fixes: d39d0f3 ("io: fix cleanup for TLS I/O source data on cancellation") Fixes: 1b63062 ("io: fix cleanup for TLS I/O source data on cancellation") in 10.0.x series Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> Acked-by: Daniel P. Berrangé <berrange@redhat.com> Link: https://lore.kernel.org/qemu-devel/20260311213418.16951-3-farosas@suse.de Signed-off-by: Fabiano Rosas <farosas@suse.de> (cherry picked from commit c20f143) Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
1 parent 7860faa commit f990473

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

io/channel-tls.c

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -347,7 +347,9 @@ void qio_channel_tls_bye(QIOChannelTLS *ioc, Error **errp)
347347
task = qio_task_new(OBJECT(ioc), propagate_error, errp, NULL);
348348

349349
trace_qio_channel_tls_bye_start(ioc);
350-
qio_channel_tls_bye_task(ioc, task, NULL);
350+
if (qio_channel_tls_bye_task(ioc, task, NULL)) {
351+
qio_task_free(task);
352+
}
351353
}
352354

353355
static void qio_channel_tls_init(Object *obj G_GNUC_UNUSED)

0 commit comments

Comments
 (0)