Re: [PATCH] KVM: x86: Cancel PIT timer on failed creation

From: Bruno Produit

Date: Mon Oct 05 2026 - 11:28:11 EST


Yes, agreed, thanks for pointing that out. I’ll send a new patch with
that change

On Fri, Oct 2, 2026 at 5:35 PM Sean Christopherson <seanjc@xxxxxxxxxx> wrote:
>
> On Fri, Oct 02, 2026, Bruno Produit wrote:
> > From: Kyle Zeng <kylebot@xxxxxxxxxx>
> >
> > Cancel the PIT hrtimer if PIT creation fails after registering the PIO
> > device. This matches normal teardown and ensures the timer no longer
> > uses the PIT before its memory is freed.
> >
> > KVM registers the PIT's PIO device before registering the optional dummy
> > speaker device. If speaker registration fails, a vCPU can have already
> > programmed channel 0 and armed pit_state.timer through the published PIT
> > device. When I/O bus registration became fallible, its cleanup did not
> > cancel the timer before freeing the PIT.
> >
> > Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
> > Cc: stable@xxxxxxxxxxxxxxx
> > Assisted-by: Codex:gpt-5.6-sol
> > Signed-off-by: Kyle Zeng <kylebot@xxxxxxxxxx>
> > Signed-off-by: Bruno Produit <bruno.produit@xxxxxxxxxxxxxxx>
> > ---
> > arch/x86/kvm/i8254.c | 1 +
> > 1 file changed, 1 insertion(+)
> >
> > diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
> > index 1982b0077..b7875345f 100644
> > --- a/arch/x86/kvm/i8254.c
> > +++ b/arch/x86/kvm/i8254.c
> > @@ -793,6 +793,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
> > fail_register_pit:
> > mutex_unlock(&kvm->slots_lock);
> > kvm_pit_set_reinject(pit, false);
> > + hrtimer_cancel(&pit->pit_state.timer);
>
> Given that the timer can be armed if and only if the PIT was successfully registered,
> wouldn't this suffice?
>
> diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
> index 1982b0077ddd..33d772c7160b 100644
> --- a/arch/x86/kvm/i8254.c
> +++ b/arch/x86/kvm/i8254.c
> @@ -790,6 +790,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
>
> fail_register_speaker:
> kvm_io_bus_unregister_dev(kvm, KVM_PIO_BUS, &pit->dev);
> + hrtimer_cancel(&pit->pit_state.timer);
> fail_register_pit:
> mutex_unlock(&kvm->slots_lock);
> kvm_pit_set_reinject(pit, false);
>
>
> > kthread_destroy_worker(pit->worker);
> > fail_kthread:
> > kfree(pit);
> > --
> > 2.53.0
> >