From ed963d3967fd8e5ca551c1cc6fcbabaef010d72e Mon Sep 17 00:00:00 2001 From: GuoHan Zhao Date: Mon, 29 Jun 2026 17:26:18 +0800 Subject: [PATCH] vhost-user-base: free virtqueue array during cleanup vhost-user-base stores the VirtQueue pointers in a GPtrArray, but its cleanup helper only deletes the VirtQueues and leaves the array itself allocated. Free the GPtrArray after deleting the queues and clear the pointer so cleanup remains safe if the error path reaches it with no queues to release. Fixes: 6275989647ef (virtio: split into vhost-user-base and vhost-user-device) Signed-off-by: GuoHan Zhao Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-ID: <20260629092619.2607275-1-zhaoguohan@kylinos.cn> --- hw/virtio/vhost-user-base.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/hw/virtio/vhost-user-base.c b/hw/virtio/vhost-user-base.c index 39b5e637fc..6ac523f9eb 100644 --- a/hw/virtio/vhost-user-base.c +++ b/hw/virtio/vhost-user-base.c @@ -193,9 +193,13 @@ static void do_vhost_user_cleanup(VirtIODevice *vdev, VHostUserBase *vub) { vhost_user_cleanup(&vub->vhost_user); - for (int i = 0; i < vub->num_vqs; i++) { - VirtQueue *vq = g_ptr_array_index(vub->vqs, i); - virtio_delete_queue(vq); + if (vub->vqs) { + for (int i = 0; i < vub->num_vqs; i++) { + VirtQueue *vq = g_ptr_array_index(vub->vqs, i); + virtio_delete_queue(vq); + } + g_ptr_array_free(vub->vqs, true); + vub->vqs = NULL; } virtio_cleanup(vdev);