* [PATCH v2 0/2] KVM: selftests: Fix two VMs leaked on early returns
@ 2026-08-11 5:00 Gokul K
2026-08-11 5:00 ` [PATCH v2 1/2] KVM: selftests: Free the VM when the SEV smoke test's guest completes Gokul K
2026-08-11 5:00 ` [PATCH v2 2/2] KVM: selftests: Free the VM when NX hugepage disabling is denied Gokul K
0 siblings, 2 replies; 3+ messages in thread
From: Gokul K @ 2026-08-11 5:00 UTC (permalink / raw)
To: Sean Christopherson, Paolo Bonzini
Cc: Shuah Khan, kvm, linux-kselftest, linux-kernel
Two x86 selftests create a VM and then take an early return that skips the
kvm_vm_free() at the end of the function. Both now jump to that existing
cleanup instead.
Patch 1 is the plain-SEV path of sev_smoke_test(), which returns straight
out of the UCALL_DONE case instead of leaving the loop. The SEV-ES path
next to it breaks out and frees correctly.
Patch 2 is nx_huge_pages_test, which returns as soon as it has confirmed
that disabling NX huge pages is denied without CAP_SYS_BOOT.
The two patches are independent and either can be applied on its own.
Found by auditing every function under tools/testing/selftests/kvm/ that
creates a VM and later calls kvm_vm_free(), looking for returns in
between. Seven other hits were false positives, mostly returns after
REPORT_GUEST_ASSERT() or TEST_FAIL(), which abort the process and make the
return unreachable. Two more that do look real, in get-reg-list.c and
arm64/external_aborts.c, are left out because they belong to different
maintainers.
Compile-tested only. This host has neither SEV (kvm_amd sev=N) nor hugetlb
configured, so both tests SKIP rather than run.
Note patch 1 touches sev_smoke_test.c, which an unrelated patch I sent
earlier also touches [1]. They modify different functions and do not
conflict in either order.
v2:
- nx_huge_pages_test: goto the existing cleanup instead of open-coding
kvm_vm_free() before the return, matching patch 1 (Sean)
- Drop the claims that these paths never exercise VM teardown, and that
the nx_huge_pages path is not obscure. Neither justification holds
up: teardown still happens, just at process exit, and how often a
leaking path runs does not change whether it should be fixed (Sean)
- Rebase onto current kvm-x86/next
[1] https://lore.kernel.org/all/20260807071026.195503-1-gokul02k@gmail.com/
v1: https://lore.kernel.org/all/20260808081050.408657-1-gokul02k@gmail.com/
Gokul K (2):
KVM: selftests: Free the VM when the SEV smoke test's guest completes
KVM: selftests: Free the VM when NX hugepage disabling is denied
tools/testing/selftests/kvm/x86/nx_huge_pages_test.c | 3 ++-
tools/testing/selftests/kvm/x86/sev_smoke_test.c | 3 ++-
2 files changed, 4 insertions(+), 2 deletions(-)
--
2.54.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH v2 1/2] KVM: selftests: Free the VM when the SEV smoke test's guest completes
2026-08-11 5:00 [PATCH v2 0/2] KVM: selftests: Fix two VMs leaked on early returns Gokul K
@ 2026-08-11 5:00 ` Gokul K
2026-08-11 5:00 ` [PATCH v2 2/2] KVM: selftests: Free the VM when NX hugepage disabling is denied Gokul K
1 sibling, 0 replies; 3+ messages in thread
From: Gokul K @ 2026-08-11 5:00 UTC (permalink / raw)
To: Sean Christopherson, Paolo Bonzini
Cc: Shuah Khan, kvm, linux-kselftest, linux-kernel
test_sev() returns directly out of the UCALL_DONE case rather than
leaving the loop, so the plain-SEV path skips the kvm_vm_free() at the
end of the function. The SEV-ES path is unaffected; it breaks out of
the loop and frees the VM correctly.
main() invokes test_sev() once per supported SEV VM type, so a full run
leaks a VM and its file descriptors. Nothing fails today because the
process exits shortly afterwards, which is presumably why this was not
noticed, but the leak also means the plain-SEV path never exercises VM
teardown.
Use a goto so UCALL_DONE joins the existing exit path. A plain break
would only leave the switch statement and spin the loop again.
Fixes: be250ff437fa ("KVM: selftests: Add a basic SEV smoke test")
Signed-off-by: Gokul K <gokul02k@gmail.com>
---
tools/testing/selftests/kvm/x86/sev_smoke_test.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/kvm/x86/sev_smoke_test.c b/tools/testing/selftests/kvm/x86/sev_smoke_test.c
index 6b2cbe2a90b7..646ae93e3c46 100644
--- a/tools/testing/selftests/kvm/x86/sev_smoke_test.c
+++ b/tools/testing/selftests/kvm/x86/sev_smoke_test.c
@@ -178,7 +178,7 @@ static void test_sev(void *guest_code, u32 type, u64 policy)
case UCALL_SYNC:
continue;
case UCALL_DONE:
- return;
+ goto done;
case UCALL_ABORT:
REPORT_GUEST_ASSERT(uc);
default:
@@ -187,6 +187,7 @@ static void test_sev(void *guest_code, u32 type, u64 policy)
}
}
+done:
kvm_vm_free(vm);
}
--
2.54.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* [PATCH v2 2/2] KVM: selftests: Free the VM when NX hugepage disabling is denied
2026-08-11 5:00 [PATCH v2 0/2] KVM: selftests: Fix two VMs leaked on early returns Gokul K
2026-08-11 5:00 ` [PATCH v2 1/2] KVM: selftests: Free the VM when the SEV smoke test's guest completes Gokul K
@ 2026-08-11 5:00 ` Gokul K
1 sibling, 0 replies; 3+ messages in thread
From: Gokul K @ 2026-08-11 5:00 UTC (permalink / raw)
To: Sean Christopherson, Paolo Bonzini
Cc: Shuah Khan, kvm, linux-kselftest, linux-kernel
run_test() returns as soon as it has confirmed that disabling NX huge
pages fails with -EPERM, without freeing the VM created a few lines
earlier.
Jump to the kvm_vm_free() at the end of the function instead, matching
the pattern used for the SEV smoke test in the previous patch.
Fixes: b774da3f2e57 ("KVM: selftests: Test disabling NX hugepages on a VM")
Signed-off-by: Gokul K <gokul02k@gmail.com>
---
tools/testing/selftests/kvm/x86/nx_huge_pages_test.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/kvm/x86/nx_huge_pages_test.c b/tools/testing/selftests/kvm/x86/nx_huge_pages_test.c
index 70950067b989..e3b20033a884 100644
--- a/tools/testing/selftests/kvm/x86/nx_huge_pages_test.c
+++ b/tools/testing/selftests/kvm/x86/nx_huge_pages_test.c
@@ -120,7 +120,7 @@ void run_test(int reclaim_period_ms, bool disable_nx_huge_pages,
} else {
TEST_ASSERT(r == -1 && errno == EPERM,
"This process should not have permission to disable NX huge pages");
- return;
+ goto done;
}
}
@@ -213,6 +213,7 @@ void run_test(int reclaim_period_ms, bool disable_nx_huge_pages,
check_2m_page_count(vm, disable_nx_huge_pages ? 3 : 2);
check_split_count(vm, 0);
+done:
kvm_vm_free(vm);
}
--
2.54.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-11 5:00 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-11 5:00 [PATCH v2 0/2] KVM: selftests: Fix two VMs leaked on early returns Gokul K
2026-08-11 5:00 ` [PATCH v2 1/2] KVM: selftests: Free the VM when the SEV smoke test's guest completes Gokul K
2026-08-11 5:00 ` [PATCH v2 2/2] KVM: selftests: Free the VM when NX hugepage disabling is denied Gokul K
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.