* [PATCH] KVM: x86: Cancel PIT timer on failed creation
@ 2026-10-02 15:19 Bruno Produit
2026-10-02 15:35 ` Sean Christopherson
0 siblings, 1 reply; 2+ messages in thread
From: Bruno Produit @ 2026-10-02 15:19 UTC (permalink / raw)
To: Sean Christopherson, Paolo Bonzini, Thomas Gleixner, Ingo Molnar,
Borislav Petkov, Dave Hansen, H. Peter Anvin, x86
Cc: kvm, Kyle Zeng, linux-kernel, Dominik Czarnota, stable, Bruno Produit
From: Kyle Zeng <kylebot@openai.com>
Cancel the PIT hrtimer if PIT creation fails after registering the PIO
device. This matches normal teardown and ensures the timer no longer
uses the PIT before its memory is freed.
KVM registers the PIT's PIO device before registering the optional dummy
speaker device. If speaker registration fails, a vCPU can have already
programmed channel 0 and armed pit_state.timer through the published PIT
device. When I/O bus registration became fallible, its cleanup did not
cancel the timer before freeing the PIT.
Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Signed-off-by: Bruno Produit <bruno.produit@trailofbits.com>
---
arch/x86/kvm/i8254.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1982b0077..b7875345f 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -793,6 +793,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
fail_register_pit:
mutex_unlock(&kvm->slots_lock);
kvm_pit_set_reinject(pit, false);
+ hrtimer_cancel(&pit->pit_state.timer);
kthread_destroy_worker(pit->worker);
fail_kthread:
kfree(pit);
--
2.53.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] KVM: x86: Cancel PIT timer on failed creation
2026-10-02 15:19 [PATCH] KVM: x86: Cancel PIT timer on failed creation Bruno Produit
@ 2026-10-02 15:35 ` Sean Christopherson
0 siblings, 0 replies; 2+ messages in thread
From: Sean Christopherson @ 2026-10-02 15:35 UTC (permalink / raw)
To: Bruno Produit
Cc: Paolo Bonzini, Thomas Gleixner, Ingo Molnar, Borislav Petkov,
Dave Hansen, H. Peter Anvin, x86, kvm, Kyle Zeng, linux-kernel,
Dominik Czarnota, stable
On Fri, Oct 02, 2026, Bruno Produit wrote:
> From: Kyle Zeng <kylebot@openai.com>
>
> Cancel the PIT hrtimer if PIT creation fails after registering the PIO
> device. This matches normal teardown and ensures the timer no longer
> uses the PIT before its memory is freed.
>
> KVM registers the PIT's PIO device before registering the optional dummy
> speaker device. If speaker registration fails, a vCPU can have already
> programmed channel 0 and armed pit_state.timer through the published PIT
> device. When I/O bus registration became fallible, its cleanup did not
> cancel the timer before freeing the PIT.
>
> Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Kyle Zeng <kylebot@openai.com>
> Signed-off-by: Bruno Produit <bruno.produit@trailofbits.com>
> ---
> arch/x86/kvm/i8254.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
> index 1982b0077..b7875345f 100644
> --- a/arch/x86/kvm/i8254.c
> +++ b/arch/x86/kvm/i8254.c
> @@ -793,6 +793,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
> fail_register_pit:
> mutex_unlock(&kvm->slots_lock);
> kvm_pit_set_reinject(pit, false);
> + hrtimer_cancel(&pit->pit_state.timer);
Given that the timer can be armed if and only if the PIT was successfully registered,
wouldn't this suffice?
diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1982b0077ddd..33d772c7160b 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -790,6 +790,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
fail_register_speaker:
kvm_io_bus_unregister_dev(kvm, KVM_PIO_BUS, &pit->dev);
+ hrtimer_cancel(&pit->pit_state.timer);
fail_register_pit:
mutex_unlock(&kvm->slots_lock);
kvm_pit_set_reinject(pit, false);
> kthread_destroy_worker(pit->worker);
> fail_kthread:
> kfree(pit);
> --
> 2.53.0
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-02 15:35 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 15:19 [PATCH] KVM: x86: Cancel PIT timer on failed creation Bruno Produit
2026-10-02 15:35 ` Sean Christopherson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®