@samitouri / QOSamiQemu / commits / c9bfe4127d

tests/tcg/plugins/mem: Correct hash iteration code in plugin_exit()

In plugin_exit() we call g_hash_table_get_values() to get a GList which we look at to print some information. This code has multiple issues: * it names the local variable for the GList "count", which shadows the "qemu_plugin_scoreboard *count". This isn't incorrect, but it is unnecessarily confusing * it doesn't free the list, and the leak sanitizer complains: Indirect leak of 2328 byte(s) in 97 object(s) allocated from: #0 0x5589b0b72293 in malloc (/home/pm215/qemu/build/x86-tgt-san/qemu-system-i386+0x1a2f293) (BuildId: 26964cad9e3f81d35fc144d7cc88b53adf6f60c7) #1 0x78fd8cfa1ac9 in g_malloc (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x62ac9) (BuildId: 116e142b9b52c8a4dfd403e759e71ab8f95d8bb3) #2 0x78fd8cf96e4a in g_list_prepend (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x57e4a) (BuildId: 116e142b9b52c8a4dfd403e759e71ab8f95d8bb3) #3 0x78fd8cf8b318 in g_hash_table_get_values (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x4c318) (BuildId: 116e142b9b52c8a4dfd403e759e71ab8f95d8bb3) #4 0x78fd84d1a90c in plugin_exit /home/pm215/qemu/build/x86-tgt-san/../../tests/tcg/plugins/mem.c:87:25 * in iterating through the list it updates "count", so by the time we get to the end of the loop we no longer have a pointer to the head of the list that we could use to free it * it checks for the list being NULL twice (once in an if() and once in the for() loop's "while" condition), which is redundant * it skips the loop if g_list_next(counts) is NULL, which means it will wrongly skip the loop if the list has only one entry Rewrite the iteration code to fix these problems. Signed-off-by: Peter Maydell <peter.maydell@linaro.org> Reviewed-by: Pierrick Bouvier <pierrick.bouvier@linaro.org> Link: https://lore.kernel.org/qemu-devel/20260305161531.1774895-3-peter.maydell@linaro.org Signed-off-by: Pierrick Bouvier <pierrick.bouvier@linaro.org>

Peter Maydell committed Mar 5, 2026 at 16:15 UTC c9bfe4127d60db6b195204dca1caa45f1e638270
1 file changed +12 -14
tests/tcg/plugins/mem.c
+12 -14
@@ -84,24 +84,22 @@ static void plugin_exit(qemu_plugin_id_t id, void *p)
84
85
86 if (do_region_summary) {
87 - GList *counts = g_hash_table_get_values(regions);
87 + g_autoptr(GList) regionlist = g_hash_table_get_values(regions);
88
89 - counts = g_list_sort_with_data(counts, addr_order, NULL);
89 + regionlist = g_list_sort_with_data(regionlist, addr_order, NULL);
90
91 g_string_printf(out, "Region Base, Reads, Writes, Seen all\n");
92
93 - if (counts && g_list_next(counts)) {
94 - for (/* counts */; counts; counts = counts->next) {
95 - RegionInfo *ri = (RegionInfo *) counts->data;
96 -
97 - g_string_append_printf(out,
98 - "0x%016"PRIx64", "
99 - "%"PRId64", %"PRId64", %s\n",
100 - ri->region_address,
101 - ri->reads,
102 - ri->writes,
103 - ri->seen_all ? "true" : "false");
104 - }
93 + for (GList *l = regionlist; l; l = g_list_next(l)) {
94 + RegionInfo *ri = (RegionInfo *) l->data;
95 +
96 + g_string_append_printf(out,
97 + "0x%016"PRIx64", "
98 + "%"PRId64", %"PRId64", %s\n",
99 + ri->region_address,
100 + ri->reads,
101 + ri->writes,
102 + ri->seen_all ? "true" : "false");
103 }
104 qemu_plugin_outs(out->str);
105 }