[PATCH v2 04/10] KVM: Disallow setting memslots when the VM is being destroyed

From: Sean Christopherson

Date: Thu Oct 01 2026 - 16:26:16 EST


Now that KVM doesn't delete KVM-internal memslots as an unnecessary side
effect during VM destruction, WARN and reject any attempt to set memslots
after the VM's refcount has hit 0. There's obviously no need to CREATE,
MOVE, or do a FLAGS_ONLY update when a VM is being destroyed, and there
should be no reason for arch code to manually DELETE a memslot: once KVM
KVM unregisters its mmu_notifier and does the final kvm_flush_shadow_all(),
there absolutely must not be any outstanding references to memslots. I.e.
if arch code "needs" to manually DELETE a memslot, then it's already buggy.

Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
---
virt/kvm/kvm_main.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c
index 9a24c3064896..f368240aa1cd 100644
--- a/virt/kvm/kvm_main.c
+++ b/virt/kvm/kvm_main.c
@@ -2015,6 +2015,9 @@ static int kvm_set_memory_region(struct kvm *kvm,

lockdep_assert_held(&kvm->slots_lock);

+ if (WARN_ON_ONCE(!refcount_read(&kvm->users_count)))
+ return -EIO;
+
r = check_memory_region_flags(kvm, mem);
if (r)
return r;
--
2.56.0.rc1.315.gc6ed9934b7-goog