All of lore.kernel.org
 help / color / mirror / Atom feed
From: Furkan Caliskan <frn1furkan10@gmail.com>
To: xen-devel@lists.xenproject.org
Cc: jgross@suse.com, jbeulich@suse.com, andrew.cooper3@citrix.com,
	dfaggioli@suse.com, gwd@xenproject.org,
	Furkan Caliskan <frn1furkan10@gmail.com>
Subject: [PATCH v2 2/2] xen/sched: core: kill unarmed timers on sched_init_vcpu() failure
Date: Wed, 19 Aug 2026 08:15:32 +0300	[thread overview]
Message-ID: <20260819051532.9197-3-frn1furkan10@gmail.com> (raw)
In-Reply-To: <20260819051532.9197-1-frn1furkan10@gmail.com>

sched_init_vcpu() calls init_timer() for a vcpu's periodic_timer,
singleshot_timer and poll_timer before it can fail -- these
become live, linked into their target pCPU's per-cpu timer list
regardless of what happens next. If the sched_alloc_udata() call
further down then fails, the function frees the sched_unit via
sched_free_unit() and returns 1, but never unlinks these three
timers.

The caller, vcpu_create(), makes this worse: on sched_init_vcpu()
returning nonzero it jumps to fail_wq, skipping fail_sched and
thus sched_destroy_vcpu() -- the only function on this path that
calls kill_timer() on them. vcpu_destroy() then frees the vcpu,
and the three timers embedded in it, while they are still linked
into that shared list.

This silently corrupts that list. It only shows up later, when
something else touches a neighboring timer: sched_move_domain()
crashed with "Assertion 'entry->prev->next == entry' failed" on a
completely unrelated, valid vcpu's timer.

Kill all three timers in sched_init_vcpu()'s own failure branch,
so it doesn't depend on the caller reaching sched_destroy_vcpu()
to undo what it set up itself.

Fixes: 1ad5dad74cde ("[XEN] Re-jig VCPU initialisation -- VMX init requires generic VCPU")
Signed-off-by: Furkan Caliskan <frn1furkan10@gmail.com>
Reviewed-by: Juergen Gross <jgross@suse.com>
---
v2:
 - Added Fixes: tag.
---
 xen/common/sched/core.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/xen/common/sched/core.c b/xen/common/sched/core.c
index a9daa42339..5777096592 100644
--- a/xen/common/sched/core.c
+++ b/xen/common/sched/core.c
@@ -589,6 +589,9 @@ int sched_init_vcpu(struct vcpu *v)
     unit->priv = sched_alloc_udata(dom_scheduler(d), unit, d->sched_priv);
     if ( unit->priv == NULL )
     {
+        kill_timer(&v->periodic_timer);
+        kill_timer(&v->singleshot_timer);
+        kill_timer(&v->poll_timer);
         sched_free_unit(unit, v);
         rcu_read_unlock(&sched_res_rculock);
         return 1;
-- 
2.34.1



  parent reply	other threads:[~2026-08-19  5:16 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-19  5:15 [PATCH v2 0/2] xen/sched: fix crashes when vcpu creation fails Furkan Caliskan
2026-08-19  5:15 ` [PATCH v2 1/2] xen/sched: core: skip missing vcpu slots in sched_move_domain() Furkan Caliskan
2026-08-19  6:53   ` Jan Beulich
2026-08-19  7:28     ` Furkan Çalışkan
2026-08-19  7:35       ` Jan Beulich
2026-08-19  5:15 ` Furkan Caliskan [this message]
2026-08-19  7:22   ` [PATCH v2 2/2] xen/sched: core: kill unarmed timers on sched_init_vcpu() failure Jan Beulich
2026-08-19  7:53     ` Furkan Çalışkan
2026-08-19  8:32       ` Jan Beulich
2026-08-19  8:50         ` Furkan Çalışkan
2026-08-19 10:39     ` Furkan Çalışkan
2026-08-19 10:43       ` Jan Beulich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260819051532.9197-3-frn1furkan10@gmail.com \
    --to=frn1furkan10@gmail.com \
    --cc=andrew.cooper3@citrix.com \
    --cc=dfaggioli@suse.com \
    --cc=gwd@xenproject.org \
    --cc=jbeulich@suse.com \
    --cc=jgross@suse.com \
    --cc=xen-devel@lists.xenproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.