From: Alexey Simakov <bigalex934@gmail.com>
To: Hans de Goede <hansg@kernel.org>
Cc: Alexey Simakov <bigalex934@gmail.com>,
Arnd Bergmann <arnd@arndb.de>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Larry Finger <Larry.Finger@lwfinger.net>,
linux-kernel@vger.kernel.org, lvc-project@linuxtesting.org
Subject: [PATCH] virt: vbox: fix possible circular timer scheduling
Date: Sat, 22 Nov 2025 21:21:43 +0300 [thread overview]
Message-ID: <20251122182142.5179-1-bigalex934@gmail.com> (raw)
According to timer.c documentation, callers of this function should ensure
the timer is not rearmed. Meanwhile, the heartbeat callback may itself
reschedule the heartbeat timer which could lead to theoretically
indefinite loop iterations inside __timer_delete_sync(), due to a race
when the heartbeat callback is always running when it's attempted to be
detached.
Use timer_shutdown_sync() instead to avoid this issue.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 0ba002bc4393 ("virt: Add vboxguest driver for Virtual Box Guest integration"):
Signed-off-by: Alexey Simakov <bigalex934@gmail.com>
---
drivers/virt/vboxguest/vboxguest_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/virt/vboxguest/vboxguest_core.c b/drivers/virt/vboxguest/vboxguest_core.c
index b177a534b6a4..508ba711669d 100644
--- a/drivers/virt/vboxguest/vboxguest_core.c
+++ b/drivers/virt/vboxguest/vboxguest_core.c
@@ -495,7 +495,7 @@ static int vbg_heartbeat_init(struct vbg_dev *gdev)
*/
static void vbg_heartbeat_exit(struct vbg_dev *gdev)
{
- timer_delete_sync(&gdev->heartbeat_timer);
+ timer_shutdown_sync(&gdev->heartbeat_timer);
vbg_heartbeat_host_config(gdev, false);
vbg_req_free(gdev->guest_heartbeat_req,
sizeof(*gdev->guest_heartbeat_req));
--
2.34.1
reply other threads:[~2025-11-22 18:22 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251122182142.5179-1-bigalex934@gmail.com \
--to=bigalex934@gmail.com \
--cc=Larry.Finger@lwfinger.net \
--cc=arnd@arndb.de \
--cc=gregkh@linuxfoundation.org \
--cc=hansg@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lvc-project@linuxtesting.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®