mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] KVM: x86: Cancel PIT timer on failed creation
@ 2026-10-02 15:19 Bruno Produit
  2026-10-02 15:35 ` Sean Christopherson
  0 siblings, 1 reply; 2+ messages in thread
From: Bruno Produit @ 2026-10-02 15:19 UTC (permalink / raw)
  To: Sean Christopherson, Paolo Bonzini, Thomas Gleixner, Ingo Molnar,
	Borislav Petkov, Dave Hansen, H. Peter Anvin, x86
  Cc: kvm, Kyle Zeng, linux-kernel, Dominik Czarnota, stable, Bruno Produit

From: Kyle Zeng <kylebot@openai.com>

Cancel the PIT hrtimer if PIT creation fails after registering the PIO
device. This matches normal teardown and ensures the timer no longer
uses the PIT before its memory is freed.

KVM registers the PIT's PIO device before registering the optional dummy
speaker device.  If speaker registration fails, a vCPU can have already
programmed channel 0 and armed pit_state.timer through the published PIT
device. When I/O bus registration became fallible, its cleanup did not
cancel the timer before freeing the PIT.

Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Signed-off-by: Bruno Produit <bruno.produit@trailofbits.com>
---
 arch/x86/kvm/i8254.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1982b0077..b7875345f 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -793,6 +793,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
 fail_register_pit:
 	mutex_unlock(&kvm->slots_lock);
 	kvm_pit_set_reinject(pit, false);
+	hrtimer_cancel(&pit->pit_state.timer);
 	kthread_destroy_worker(pit->worker);
 fail_kthread:
 	kfree(pit);
-- 
2.53.0

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] KVM: x86: Cancel PIT timer on failed creation
  2026-10-02 15:19 [PATCH] KVM: x86: Cancel PIT timer on failed creation Bruno Produit
@ 2026-10-02 15:35 ` Sean Christopherson
  0 siblings, 0 replies; 2+ messages in thread
From: Sean Christopherson @ 2026-10-02 15:35 UTC (permalink / raw)
  To: Bruno Produit
  Cc: Paolo Bonzini, Thomas Gleixner, Ingo Molnar, Borislav Petkov,
	Dave Hansen, H. Peter Anvin, x86, kvm, Kyle Zeng, linux-kernel,
	Dominik Czarnota, stable

On Fri, Oct 02, 2026, Bruno Produit wrote:
> From: Kyle Zeng <kylebot@openai.com>
> 
> Cancel the PIT hrtimer if PIT creation fails after registering the PIO
> device. This matches normal teardown and ensures the timer no longer
> uses the PIT before its memory is freed.
> 
> KVM registers the PIT's PIO device before registering the optional dummy
> speaker device.  If speaker registration fails, a vCPU can have already
> programmed channel 0 and armed pit_state.timer through the published PIT
> device. When I/O bus registration became fallible, its cleanup did not
> cancel the timer before freeing the PIT.
> 
> Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Kyle Zeng <kylebot@openai.com>
> Signed-off-by: Bruno Produit <bruno.produit@trailofbits.com>
> ---
>  arch/x86/kvm/i8254.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
> index 1982b0077..b7875345f 100644
> --- a/arch/x86/kvm/i8254.c
> +++ b/arch/x86/kvm/i8254.c
> @@ -793,6 +793,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
>  fail_register_pit:
>  	mutex_unlock(&kvm->slots_lock);
>  	kvm_pit_set_reinject(pit, false);
> +	hrtimer_cancel(&pit->pit_state.timer);

Given that the timer can be armed if and only if the PIT was successfully registered,
wouldn't this suffice?

diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1982b0077ddd..33d772c7160b 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -790,6 +790,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
 
 fail_register_speaker:
 	kvm_io_bus_unregister_dev(kvm, KVM_PIO_BUS, &pit->dev);
+	hrtimer_cancel(&pit->pit_state.timer);
 fail_register_pit:
 	mutex_unlock(&kvm->slots_lock);
 	kvm_pit_set_reinject(pit, false);


>  	kthread_destroy_worker(pit->worker);
>  fail_kthread:
>  	kfree(pit);
> -- 
> 2.53.0
> 

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-02 15:35 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 15:19 [PATCH] KVM: x86: Cancel PIT timer on failed creation Bruno Produit
2026-10-02 15:35 ` Sean Christopherson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®