From: "Jürgen Groß" <jgross@suse.com>
To: Furkan Caliskan <frn1furkan10@gmail.com>, xen-devel@lists.xenproject.org
Cc: jbeulich@suse.com, andrew.cooper3@citrix.com, dfaggioli@suse.com,
gwd@xenproject.org, roger@xenproject.org,
anthony.perard@vates.tech, julien@xen.org,
bertrand.marquis@arm.com, michal.orzel@amd.com,
Volodymyr_Babchuk@epam.com, teddy.astie@vates.tech
Subject: Re: [PATCH v3 2/2] xen/sched: core: kill unarmed timers on sched_init_vcpu() failure
Date: Mon, 31 Aug 2026 10:15:02 +0200 [thread overview]
Message-ID: <dc4dbc44-db87-4de3-9246-e91f50a50c9c@suse.com> (raw)
In-Reply-To: <20260831051637.5029-3-frn1furkan10@gmail.com>
[-- Attachment #1.1.1: Type: text/plain, Size: 1631 bytes --]
On 31.08.26 07:16, Furkan Caliskan wrote:
> sched_init_vcpu() calls init_timer() for a vcpu's periodic_timer,
> singleshot_timer and poll_timer before it can fail -- these
> become live, linked into their target pCPU's per-cpu timer list
> regardless of what happens next. If the sched_alloc_udata() call
> further down then fails, the function frees the sched_unit via
> sched_free_unit() and returns 1, but never unlinks these three
> timers.
>
> The caller, vcpu_create(), makes this worse: on sched_init_vcpu()
> returning nonzero it jumps to fail_wq, skipping fail_sched and
> thus sched_destroy_vcpu() -- the only function on this path that
> calls kill_timer() on them. vcpu_destroy() then frees the vcpu,
> and the three timers embedded in it, while they are still linked
> into that shared list.
>
> This silently corrupts that list. It only shows up later, when
> something else touches a neighboring timer: sched_move_domain()
> crashed with "Assertion 'entry->prev->next == entry' failed" on a
> completely unrelated, valid vcpu's timer.
>
> Call sched_destroy_vcpu() in sched_init_vcpu()'s own failure
> branch instead of sched_free_unit(), so it doesn't depend
> on the caller reaching sched_destroy_vcpu() to undo what it set
> up itself. sched_destroy_vcpu() assumes unit->priv is set, which
> is not the case here, so make it only free the udata and remove
> the unit if unit->priv in non-NULL.
>
> Fixes: d884b1077817 ("Domain creation/destruction cleanups.")
> Signed-off-by: Furkan Caliskan <frn1furkan10@gmail.com>
Reviewed-by: Juergen Gross <jgross@suse.com>
Juergen
[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3743 bytes --]
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]
prev parent reply other threads:[~2026-08-31 8:15 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 5:16 [PATCH v3 0/2] xen/sched: fix crashes when vcpu creation fails Furkan Caliskan
2026-08-31 5:16 ` [PATCH v3 1/2] xen/common: add vcpus_create() and keep max_vcpus in sync Furkan Caliskan
2026-08-31 8:13 ` Jürgen Groß
2026-08-31 9:13 ` Furkan Çalışkan
2026-08-31 9:32 ` [PATCH v4] " Furkan Caliskan
2026-08-31 9:45 ` [PATCH v3 1/2] " Andrew Cooper
2026-08-31 12:59 ` Jürgen Groß
2026-09-01 7:22 ` Jan Beulich
2026-09-01 8:07 ` Jürgen Groß
2026-09-01 8:15 ` Jan Beulich
2026-09-01 8:24 ` Jürgen Groß
2026-09-01 8:36 ` Jan Beulich
2026-09-01 9:03 ` Jürgen Groß
2026-08-31 5:16 ` [PATCH v3 2/2] xen/sched: core: kill unarmed timers on sched_init_vcpu() failure Furkan Caliskan
2026-08-31 8:15 ` Jürgen Groß [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dc4dbc44-db87-4de3-9246-e91f50a50c9c@suse.com \
--to=jgross@suse.com \
--cc=Volodymyr_Babchuk@epam.com \
--cc=andrew.cooper3@citrix.com \
--cc=anthony.perard@vates.tech \
--cc=bertrand.marquis@arm.com \
--cc=dfaggioli@suse.com \
--cc=frn1furkan10@gmail.com \
--cc=gwd@xenproject.org \
--cc=jbeulich@suse.com \
--cc=julien@xen.org \
--cc=michal.orzel@amd.com \
--cc=roger@xenproject.org \
--cc=teddy.astie@vates.tech \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.