[PATCH v2] KVM: x86: Cancel PIT timer on failed creation

From: Bruno Produit

Date: Tue Oct 06 2026 - 05:34:37 EST


Cancel the PIT hrtimer if PIT creation fails after registering the PIO
device. This matches normal teardown and ensures the timer no longer
uses the PIT before its memory is freed.

KVM registers the PIT's PIO device before registering the optional dummy
speaker device. If speaker registration fails, a vCPU can have already
programmed channel 0 and armed pit_state.timer through the published PIT
device. When I/O bus registration became fallible, its cleanup did not
cancel the timer before freeing the PIT.

Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: Codex:gpt-5.6-sol
Reported-by: Kyle Zeng <kylebot@xxxxxxxxxx>
Signed-off-by: Kyle Zeng <kylebot@xxxxxxxxxx>
Signed-off-by: Bruno Produit <bruno.produit@xxxxxxxxxxxxxxx>
---
Sean's proposal, feel free to change the FROM upstream
see https://lore.kernel.org/all/ar_PNEIvsQMQPMLg@xxxxxxxxxx/

arch/x86/kvm/i8254.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1982b0077ddd..33d772c7160b 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -790,6 +790,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)

fail_register_speaker:
kvm_io_bus_unregister_dev(kvm, KVM_PIO_BUS, &pit->dev);
+ hrtimer_cancel(&pit->pit_state.timer);
fail_register_pit:
mutex_unlock(&kvm->slots_lock);
kvm_pit_set_reinject(pit, false);
--
2.53.0