Re: [PATCH] KVM: x86: Cancel PIT timer on failed creation
From: Sean Christopherson
Date: Fri Oct 02 2026 - 11:36:32 EST
On Fri, Oct 02, 2026, Bruno Produit wrote:
> From: Kyle Zeng <kylebot@xxxxxxxxxx>
>
> Cancel the PIT hrtimer if PIT creation fails after registering the PIO
> device. This matches normal teardown and ensures the timer no longer
> uses the PIT before its memory is freed.
>
> KVM registers the PIT's PIO device before registering the optional dummy
> speaker device. If speaker registration fails, a vCPU can have already
> programmed channel 0 and armed pit_state.timer through the published PIT
> device. When I/O bus registration became fallible, its cleanup did not
> cancel the timer before freeing the PIT.
>
> Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Kyle Zeng <kylebot@xxxxxxxxxx>
> Signed-off-by: Bruno Produit <bruno.produit@xxxxxxxxxxxxxxx>
> ---
> arch/x86/kvm/i8254.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
> index 1982b0077..b7875345f 100644
> --- a/arch/x86/kvm/i8254.c
> +++ b/arch/x86/kvm/i8254.c
> @@ -793,6 +793,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
> fail_register_pit:
> mutex_unlock(&kvm->slots_lock);
> kvm_pit_set_reinject(pit, false);
> + hrtimer_cancel(&pit->pit_state.timer);
Given that the timer can be armed if and only if the PIT was successfully registered,
wouldn't this suffice?
diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1982b0077ddd..33d772c7160b 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -790,6 +790,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
fail_register_speaker:
kvm_io_bus_unregister_dev(kvm, KVM_PIO_BUS, &pit->dev);
+ hrtimer_cancel(&pit->pit_state.timer);
fail_register_pit:
mutex_unlock(&kvm->slots_lock);
kvm_pit_set_reinject(pit, false);
> kthread_destroy_worker(pit->worker);
> fail_kthread:
> kfree(pit);
> --
> 2.53.0
>