Commit fff77cfb84 for qemu.org

commit fff77cfb8413190c6362b95203ef0973c83b50d2
Author: Dorinda Bassey <dbassey@redhat.com>
Date:   Thu Dec 4 17:20:13 2025 +0100

    virtio-dmabuf: Ensure UUID persistence for hash table insertion

    In `virtio_add_resource` function, the UUID used as a key for
    `g_hash_table_insert` was temporary, which could lead to
    invalid lookups when accessed later. This patch ensures that
    the UUID remains valid by duplicating it into a newly allocated
    memory space. The value is then inserted into the hash table
    with this persistent UUID key to ensure that the key stored in
    the hash table remains valid as long as the hash table entry
    exists.

    Fixes: faefdba847 ("hw/display: introduce virtio-dmabuf")
    Signed-off-by: Dorinda Bassey <dbassey@redhat.com>
    Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
    Reviewed-by: Albert Esteve <aesteve@redhat.com>
    Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
    Reviewed-by: Jim MacArthur <jim.macarthur@linaro.org>
    Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
    Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
    Message-Id: <20251204162129.262745-1-dbassey@redhat.com>

diff --git a/hw/display/virtio-dmabuf.c b/hw/display/virtio-dmabuf.c
index 3dba4577ca..5e0395be77 100644
--- a/hw/display/virtio-dmabuf.c
+++ b/hw/display/virtio-dmabuf.c
@@ -35,11 +35,13 @@ static bool virtio_add_resource(QemuUUID *uuid, VirtioSharedObject *value)
     if (resource_uuids == NULL) {
         resource_uuids = g_hash_table_new_full(qemu_uuid_hash,
                                                uuid_equal_func,
-                                               NULL,
+                                               g_free,
                                                g_free);
     }
     if (g_hash_table_lookup(resource_uuids, uuid) == NULL) {
-        g_hash_table_insert(resource_uuids, uuid, value);
+        g_hash_table_insert(resource_uuids,
+                            g_memdup2(uuid, sizeof(*uuid)),
+                            value);
     } else {
         result = false;
     }