From: sashiko-bot@kernel.org
To: "Chaithanya Lagisetty" <nagachaithanya9911@gmail.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v2 2/2] LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path
Date: Wed, 02 Sep 2026 07:20:59 +0000 [thread overview]
Message-ID: <20260902072059.90ADC1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260902070724.3459457-3-nagachaithanya9911@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Resources allocated by kvm_loongarch_env_init() are leaked and lead to a Use-After-Free if kvm_init() fails in kvm_loongarch_init().
--
commit 694694d624a3a8bfec5f756c533d743cd130b9fa
Author: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path
This commit fixes a resource leak in the error path of kvm_loongarch_env_init().
It ensures that previously acquired resources and device registrations are
unwound in reverse order if any subsequent registration fails.
Fixes: c532de5a67a7 ("LoongArch: KVM: Add IPI device support")
> diff --git a/arch/loongarch/kvm/main.c b/arch/loongarch/kvm/main.c
> index 3e1005526f4bd..c9cb3fc2e5605 100644
> --- a/arch/loongarch/kvm/main.c
> +++ b/arch/loongarch/kvm/main.c
[ ... ]
> @@ -385,27 +385,51 @@ static int kvm_loongarch_env_init(void)
> /* Register LoongArch IPI interrupt controller interface. */
> ret = kvm_loongarch_register_ipi_device();
> if (ret)
> - return ret;
> + goto err_env;
>
> /* Register LoongArch EIOINTC interrupt controller interface. */
> ret = kvm_loongarch_register_eiointc_device();
> if (ret)
> - return ret;
> + goto err_ipi;
>
> /* Register LoongArch PCH-PIC interrupt controller interface. */
> ret = kvm_loongarch_register_pch_pic_device();
> if (ret)
> - return ret;
> + goto err_eiointc;
>
> /* Register LoongArch DMSINTC interrupt contrroller interface */
> - if (cpu_has_msgint)
> + if (cpu_has_msgint) {
> ret = kvm_loongarch_register_dmsintc_device();
> + if (ret)
> + goto err_pch_pic;
> + }
> +
> + return 0;
> +
> +err_pch_pic:
> + kvm_loongarch_unregister_pch_pic_device();
> +err_eiointc:
> + kvm_loongarch_unregister_eiointc_device();
> +err_ipi:
> + kvm_loongarch_unregister_ipi_device();
> +err_env:
> + kvm_unregister_perf_callbacks();
> + kfree(kvm_loongarch_ops);
> + kvm_loongarch_ops = NULL;
> + free_percpu(vmcs);
> + vmcs = NULL;
>
> return ret;
> }
[Severity: High]
This is a pre-existing issue, but does this leak the vmcs, kvm_loongarch_ops,
and device registrations when kvm_init() fails in kvm_loongarch_init()?
arch/loongarch/kvm/main.c:kvm_loongarch_init() {
...
r = kvm_loongarch_env_init();
if (r)
return r;
return kvm_init(sizeof(struct kvm_vcpu), 0, THIS_MODULE);
}
If kvm_init() fails, kvm_loongarch_init() returns the error directly without
calling kvm_loongarch_env_exit() to clean up the successful
kvm_loongarch_env_init() setup.
Could this leave dangling function pointers in the perf core that lead to a
kernel panic upon the next performance counter event?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260902070724.3459457-1-nagachaithanya9911@gmail.com?part=2
next prev parent reply other threads:[~2026-09-02 7:20 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 11:58 [PATCH] LoongArch: KVM: Fix memory leak in kvm_loongarch_env_init() error path Chaithanya Lagisetty
2026-08-17 12:09 ` sashiko-bot
2026-08-31 14:05 ` Huacai Chen
2026-09-01 1:29 ` Bibo Mao
2026-09-02 7:07 ` [PATCH v2 0/2] LoongArch: KVM: Fix " Chaithanya Lagisetty
2026-09-02 7:07 ` [PATCH v2 1/2] LoongArch: KVM: Add unregister helpers for the KVM interrupt devices Chaithanya Lagisetty
2026-09-02 7:07 ` [PATCH v2 2/2] LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path Chaithanya Lagisetty
2026-09-02 7:20 ` sashiko-bot [this message]
2026-09-02 8:04 ` [PATCH v2 0/2] LoongArch: KVM: Fix " Bibo Mao
2026-09-05 15:06 ` Huacai Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902072059.90ADC1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=nagachaithanya9911@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.