@samitouri / QOSamiQemu / commits / 8a16a38f3d

hw/i3c/dw-i3c: Fix memory leaks in error logging paths

object_get_canonical_path() returns an allocated string that must be freed by the caller. Use g_autofree variables to ensure that memory is not leaked. Resolves: Coverity CID 1645550 Resolves: Coverity CID 1645553 Signed-off-by: Cédric Le Goater <clg@redhat.com> Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org> Message-ID: <20260309093838.364126-1-clg@redhat.com> Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>

Cédric Le Goater committed Mar 9, 2026 at 10:38 UTC 8a16a38f3d1d4c023e27704fe76efd63ac175035
1 file changed +4 -2
hw/i3c/dw-i3c.c
+4 -2
@@ -490,8 +490,9 @@ static int dw_i3c_recv_data(DWI3C *s, bool is_i2c, uint8_t *data,
490 /* I3C devices can NACK if the controller sends an unsupported CCC. */
491 ret = i3c_recv(s->bus, data, num_to_read, num_read);
492 if (ret) {
493 + g_autofree char *path = object_get_canonical_path(OBJECT(s));
494 qemu_log_mask(LOG_GUEST_ERROR, "%s: NACKed receiving byte\n",
494 - object_get_canonical_path(OBJECT(s)));
495 + path);
496 ARRAY_FIELD_DP32(s->regs, PRESENT_STATE, CM_TFR_ST_STATUS,
497 DW_I3C_TRANSFER_STATE_HALT);
498 ARRAY_FIELD_DP32(s->regs, PRESENT_STATE, CM_TFR_STATUS,
@@ -1107,8 +1108,9 @@ static void dw_i3c_resp_queue_push(DWI3C *s, uint8_t err, uint8_t tid,
1108 static void dw_i3c_push_tx(DWI3C *s, uint32_t val)
1109 {
1110 if (fifo32_is_full(&s->tx_queue)) {
1111 + g_autofree char *path = object_get_canonical_path(OBJECT(s));
1112 qemu_log_mask(LOG_GUEST_ERROR, "%s: Tried to push to TX FIFO when "
1111 - "full\n", object_get_canonical_path(OBJECT(s)));
1113 + "full\n", path);
1114 return;
1115 }
1116