From nobody Thu Sep 24 20:23:56 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1787034848; cv=none; d=zohomail.com; s=zohoarc; b=ZrvTzUKSMslURBNh00SGxwrYiSYHXpKuf+y4D6udTqA/9LTZ4U3NWj+s/dliFwoJZH1//m5El4zYqzeI5ZKYTgnMTFh6XLAyRVzsxLmY49Z0NNjdR3indgTkIny8F8FxzfpzrMuQrwGOdSTefObS+d34+rm/M+vs/53FcYX41Ig= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787034848; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Kd6Uf/jaILnHhDnAFQz92ldpUytfMBZNj1lRHYK8kiA=; b=TdqpVmeNPeaW8yS9fM9jiK8AoetY/V62IHddJytQq+sMXpFXG7rvK189mWQGpmDPYYZtDxLiZHwNCN2PXGlXdiNLpakwPwT2EnQdd1NUNy3fyq6dq/Md/KDxnquj2+KMWNqvO+jDYpIGNiYV1g8o8H7brjdRZ5Z1CmVAN5c47L4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1787034848304535.6103324802071; Mon, 17 Aug 2026 23:34:08 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1393454.1632270 (Exim 4.92) (envelope-from ) id 1wwDON-0000vf-E7; Tue, 18 Aug 2026 06:33:47 +0000 Received: by outflank-mailman (output) from mailman id 1393454.1632270; Tue, 18 Aug 2026 06:33:47 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwDON-0000vY-AI; Tue, 18 Aug 2026 06:33:47 +0000 Received: by outflank-mailman (input) for mailman id 1393454; Tue, 18 Aug 2026 06:33:46 +0000 Received: from mx.expurgate.net ([194.145.224.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwDOM-0000v7-Pg for xen-devel@lists.xenproject.org; Tue, 18 Aug 2026 06:33:46 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wwDOM-0053YC-6i for xen-devel@lists.xenproject.org; Tue, 18 Aug 2026 08:33:46 +0200 Received: from [10.42.69.12] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a83fcca-bab6-0a2a0a5309dd-0a2a450c9ec2-0 for ; Tue, 18 Aug 2026 08:33:46 +0200 Received: from [209.85.128.53] (helo=mail-wm1-f53.google.com) by tlsNG-d25034.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a83fcca-f479-0a2a450c0019-d1558035e8be-3 for ; Tue, 18 Aug 2026 08:33:46 +0200 Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4954f5e8020so22039905e9.2 for ; Mon, 17 Aug 2026 23:33:46 -0700 (PDT) Received: from notebook.. ([88.230.46.229]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49996188217sm490215315e9.13.2026.08.17.23.33.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Aug 2026 23:33:45 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=20251104 header.d=gmail.com header.i="@gmail.com" header.h="Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-Id:Date:Subject:Cc:To:From" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787034826; x=1787639626; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Kd6Uf/jaILnHhDnAFQz92ldpUytfMBZNj1lRHYK8kiA=; b=PZ71Li1x7JJH9i9peXHTk2FT8wZ6QzaF5aEp/XNz4rocXIlHfhn+KM3WjUZ6Tc7rY4 9pj1CSOYvLjTD3YIN3tdFdN0NJRnBYzKeoMTdSlTh8+Y5F4sQPEz2mC4swV9sTMM4Mg/ aaQNIafP3C7jYfK5TJ2ACbeqXhRLG9iCLeX/OjciUH62eZ6mpJ1JAhN+A5q4rYnzpgza 9QFZW1d4qJBAkWdrJYVFu80WmmSnCd1P3XRyCRYMZ3vImj84mV4TDbedX/GrAJhV9Rnb gRD4NFwLQtrEfqKlOESOQ/t7feaxswP1ag/iiOt5kUe0tIkkRrpPqJxb47h+mtZI69aY 08IQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787034826; x=1787639626; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Kd6Uf/jaILnHhDnAFQz92ldpUytfMBZNj1lRHYK8kiA=; b=m4uPYQhLT4m0OT8k87hiBYsikegjOHlox8fMBAvVcmjNAAC2LggkV+kaZZdoN0uzyG uEtxoolJMi/UbkZQlZb8mrBJb5776HJzE6maztsdL3XmXJ4q3ZlBxC35V56tF7FsNSTg 3nqzrBvlT/Peayr+Bttr43GbH1HmTtgROlKP796/tyKxYCbIoWeNC+Gj1+pSU1Rk1EOB J653tq0FvgfUlQg9qeo+dAdapshGIhYVe0bMPmnUusw4LWDYw4Ec/rJEU4mWYDIBP/si DU3zbF7kzjBUyBQez+rXFwRIyQNQ1NL2LQPZvtExJi18qoOsGk9l73eX7dB3nOsu3U5F sF+g== X-Gm-Message-State: AOJu0YwgtnOJjFpDhpM1MIHuBP5gP6Rlg7ubVlgXLEBHKng81i2WQoiP O9BdG7k3ItWYxAW4tRCdaE3Dd12RA9jD+qpOhSFAOb8eQxcVB5+VNoVJaBCw+g== X-Gm-Gg: AR+sD12htkfojvIScPAJ1gGo5Kcd8hqCkKyoGk68Hz2ASFNDFH9AGBnpq5Mfe34BkFo Xg6Iv/5ZBPZGTvucha1dLxY7aoazIJ6Wk14Ru6XAWaR2yd1QI087WG0Y0xPDus3XtAxnOupZ2Lh Dzaf09yUalJz1vrTeUhs04QwCQAOcf+Z1t55gRrhhzTVHIQPpr6nWgqsKrGjdBAiBjZEYG6oQZH IwI1v+d4YdIUByYXritVsyN5DhQT56spgZolN1qaaZwvW8QiB5XshuSHopjtLXqUMSXtNWAstVu 5l8lihhUYWOL9gGwfxOTKzfKrwZ4ZvE4jBrHJgyvyF5+bGxLxVg1PSVvieN/6h2mjJHA2baE+0g 6hwN7ndR1/8ByEM0nTvSXhVRoTtaaGQUAbnA6E1/v5i89bXpVsiZtjNMeUUNe7ursN8gBoY1OFz VD5SOlh2eBLswbs73uoqjts0+q8foygvUwFL/c9AihtrKtrhXcdcygSfy6GtmB X-Received: by 2002:a05:600c:6287:b0:495:5fdf:2075 with SMTP id 5b1f17b1804b1-499878ccf00mr444504555e9.0.1787034825529; Mon, 17 Aug 2026 23:33:45 -0700 (PDT) From: Furkan Caliskan To: xen-devel@lists.xenproject.org Cc: jgross@suse.com, jbeulich@suse.com, andrew.cooper3@citrix.com, dfaggioli@suse.com, gwd@xenproject.org, Furkan Caliskan Subject: [PATCH 1/2] xen/sched: core: skip missing vcpu slots in sched_move_domain() Date: Tue, 18 Aug 2026 09:32:58 +0300 Message-Id: <20260818063259.18733-2-frn1furkan10@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260818063259.18733-1-frn1furkan10@gmail.com> References: <20260818063259.18733-1-frn1furkan10@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-d25034/1787034826-012C8A5B-680D25A9/0/0 X-purgate-type: clean X-purgate-size: 2307 X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1787034849662158500 Content-Type: text/plain; charset="utf-8" sched_move_domain() derives the number of units to rebuild from d->max_vcpus, which is fixed at domain creation and never rolled back if vcpu_create() fails partway through building a domain. So d->vcpu[i] can be NULL for some i even though max_vcpus still counts it - this happens if sched_alloc_udata() returns NULL. The per-unit loop doesn't check for this: it sets unit->vcpu_list =3D d->vcpu[unit_id] (NULL) and hands that broken unit straight to the destination scheduler's alloc_udata(), which assumes vcpu_list is always valid and crashes Xen when it is not. Reproduced by building a domain in a non-default cpupool where vcpu creation fails partway through, then destroying it. domain_kill() moves the domain back to the default cpupool via sched_move_domain() before actually destroying it, crashing inside the destination scheduler's alloc_udata() (seen in Credit2's csched2_alloc_udata() -> is_idle_unit() -> NULL deref). Before building a unit in sched_move_domain(), check that all of its vcpu slots are populated, and skip it if any are missing. The rest of the function walks the vcpus that actually exist, via for_each_vcpu() rather than n_units, so skipping a unit here does not leave anything else out of sync. Signed-off-by: Furkan Caliskan --- xen/common/sched/core.c | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/xen/common/sched/core.c b/xen/common/sched/core.c index d3a0a97e1d..d542c76543 100644 --- a/xen/common/sched/core.c +++ b/xen/common/sched/core.c @@ -745,6 +745,25 @@ int sched_move_domain(struct domain *d, struct cpupool= *c) =20 for ( unit_idx =3D 0; unit_idx < n_units; unit_idx++ ) { + /* + * Skip this unit if any of its vcpus is missing. Bounded by + * max_vcpus. + */ + bool vcpu_failed =3D false; + + for ( unsigned int i =3D 0; + i < gran && unit_idx * gran + i < d->max_vcpus; i++ ) + { + if ( !d->vcpu[unit_idx * gran + i] ) + { + vcpu_failed =3D true; + break; + } + } + + if ( vcpu_failed ) + continue; + unit =3D sched_alloc_unit_mem(); if ( unit ) { --=20 2.34.1 From nobody Thu Sep 24 20:23:56 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1787034842; cv=none; d=zohomail.com; s=zohoarc; b=D966TcQkKqosuPdtXsXPBfvYA5uAK2c9JQmb1pvTC9gNM+86xAN+xh1JIBM7SLNoFA52fGCPVS5P6jhz1knvE/bvqatnrBnCvzRvSM7E1l99vddK5IQEzQUrf+U89TkSsnLkKXnZpPtOgnALdQ2remOrgtWPvalp9edfUk/MtEc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787034842; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=WoJZAAWBUAZrL1iWvSjl3oV3lSy2PEyJsi9Rwklp8Qc=; b=Opt52tfmVLpNvABl9orV8KgFz/ZU5BTD6YNm+XHhAEG4Gh8Zf7gV4pmg4Pqt+nRhl0BzHXcgsa90qEamCzXtHp9UDfke7cyzM5/mclSE+qVe8xyU71Nt2+gLJlaUZIpY3JFrrlUk+wxq9kgWiO373rCCcmrKpnixZeMt5SaEtQk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 178703484248695.11829997123209; Mon, 17 Aug 2026 23:34:02 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1393455.1632280 (Exim 4.92) (envelope-from ) id 1wwDOS-0001Cr-M8; Tue, 18 Aug 2026 06:33:52 +0000 Received: by outflank-mailman (output) from mailman id 1393455.1632280; Tue, 18 Aug 2026 06:33:52 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwDOS-0001Ci-I6; Tue, 18 Aug 2026 06:33:52 +0000 Received: by outflank-mailman (input) for mailman id 1393455; Tue, 18 Aug 2026 06:33:51 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwDOR-0001Bf-Pp for xen-devel@lists.xenproject.org; Tue, 18 Aug 2026 06:33:51 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wwDOR-005gEc-2r for xen-devel@lists.xenproject.org; Tue, 18 Aug 2026 08:33:51 +0200 Received: from [10.42.69.11] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a83fcc9-2eae-0a2a0a5409dd-0a2a450bebb6-32 for ; Tue, 18 Aug 2026 08:33:51 +0200 Received: from [209.85.221.50] (helo=mail-wr1-f50.google.com) by tlsNG-42698a.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a83fcce-b7e8-0a2a450b0019-d155dd32b908-3 for ; Tue, 18 Aug 2026 08:33:51 +0200 Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-47f84023916so4024716f8f.3 for ; Mon, 17 Aug 2026 23:33:51 -0700 (PDT) Received: from notebook.. ([88.230.46.229]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49996188217sm490215315e9.13.2026.08.17.23.33.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Aug 2026 23:33:50 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=20251104 header.d=gmail.com header.i="@gmail.com" header.h="Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-Id:Date:Subject:Cc:To:From" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787034830; x=1787639630; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WoJZAAWBUAZrL1iWvSjl3oV3lSy2PEyJsi9Rwklp8Qc=; b=oVjjYwB0MJ4FSRTqIf5CIWzsm5ldYx3FiM6MHXThOaxGR/dQN+H9yUZrXZnHnd+qQI ce4AfrwGbb/LVDqVrwkk9A4VGnsRb+QH2zL4b4nKPr3ubpMbPP9hMNEpoWNS2IG1MsE8 1l7mTzUExR/Vzp7JdJiXV1bHKDxunjiIaBzUejk/zGzOLQvBH8cFcrUjNBCosCBlHIw8 DFiatUN05tbb4dFNLjDFz/mXxENAKY+C3DsWQDWRx1YmVTyeH6uqCf3X2Op0j2kKVVBR A/yHQHPw+jONK4tqvIZgwqqOpDXUCr6OOK8EuZJGkJasRJ73T7o/v21pptvaPw3dHlwa mbbA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787034830; x=1787639630; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=WoJZAAWBUAZrL1iWvSjl3oV3lSy2PEyJsi9Rwklp8Qc=; b=I/sVInWJ1dXJNxwYe7Mjg9RpSdpu/MijPcBQDzWVS+wnowF3KwPp+5MqFDfMK4zL1v MriIyUGO/o5Z6uFo/5nPhwEoJuvf1seOq4u0hSv8XxtKlgqhOfEKEvCCKkM+oN/iZnbw u7j+pUcJpZ2vbj1NJjF+R3uy8Gh9vl/gedYBkHMf3ay6yeRyBpcn3IOKJCPDbQqn6eqy GixV/7r/iugFTh9HjZVdsAMj6Fa382pf0pM8Hni8rAZ5Rz4amp/Qtk8LOtG+tn5qUCrp EcS91TPXh/CyanVJ6y6tnliswt0aF62vegtYVcZDFQpVdSd0IXOcbJaOjSi+/TwEd4G7 zv6w== X-Gm-Message-State: AOJu0YyQ/ygkZJzBHODv3MfvH3DKm5ZAvCN59HBO8Sz3DZV0x1x1RcQN CILibewmFxF2V1u2v5wgl0STINhIHqdd4Pt1b8sCdc2CokwbWwhh+K0G2xKWvw== X-Gm-Gg: AR+sD11cdzCkLbSwzALlDOz0sM0Zlql8m0bEa6lVbgcoZX4NxEV230wpstX8VkrPbI3 XLV7cyrceL4aDUV4mpvoSY19Qqt6Uo1jzklFD7vSE53H7XxAjz8Kif4KMQJRyihE60xHTM2hN6l SRcxSeiHXn1n3/p4QXCYOCT1XlkLXekN+QNGfnNvfzdukgGLVi0Wpp4YSZR9kRNScokLre6ev8F 3kEae126BGTe/YvYa8B+qblKMMBGFACM9schdt6NStZZarh1yIuTOvKSBe3Wlha/4LAcvSJHcXQ esKqEm8TdUoWJoZkRrheDkmxaXpBJsnrs3hAuifmRLcr2w6TCTDPlzeXby59HO1CFcytyn4wg1b 08QTL7SrL5fSASUS2EUghF0rmSPDbNhHgOcCFy/O4VbHkW7Eg2yli+YImVPNubnZQihSoJYJcPn SvW6pTm3JIubgCPCYij/n3uWwOpwjkBLUs7bzvqpjSYZpASQ6h5vfIURnMvX7E X-Received: by 2002:a05:600c:4745:b0:499:9eb7:4558 with SMTP id 5b1f17b1804b1-4999fb6d4e4mr87879565e9.10.1787034830534; Mon, 17 Aug 2026 23:33:50 -0700 (PDT) From: Furkan Caliskan To: xen-devel@lists.xenproject.org Cc: jgross@suse.com, jbeulich@suse.com, andrew.cooper3@citrix.com, dfaggioli@suse.com, gwd@xenproject.org, Furkan Caliskan Subject: [PATCH 2/2] xen/sched: core: kill unarmed timers on sched_init_vcpu() failure Date: Tue, 18 Aug 2026 09:32:59 +0300 Message-Id: <20260818063259.18733-3-frn1furkan10@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260818063259.18733-1-frn1furkan10@gmail.com> References: <20260818063259.18733-1-frn1furkan10@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-42698a/1787034831-1B4D39EA-C63C98B3/0/0 X-purgate-type: clean X-purgate-size: 1865 X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1787034843752158500 Content-Type: text/plain; charset="utf-8" sched_init_vcpu() calls init_timer() for a vcpu's periodic_timer, singleshot_timer and poll_timer before it can fail -- these become live, linked into their target pCPU's per-cpu timer list regardless of what happens next. If the sched_alloc_udata() call further down then fails, the function frees the sched_unit via sched_free_unit() and returns 1, but never unlinks these three timers. The caller, vcpu_create(), does worse: on sched_init_vcpu() returning nonzero it jumps to fail_wq, skipping fail_sched and thus sched_destroy_vcpu() -- the only function on this path that calls kill_timer() on them. vcpu_destroy() then frees the vcpu, and the three timers embedded in it, while they are still linked into that shared list. This silently corrupts that list. It only shows up later, when something else touches a neighboring timer: sched_move_domain() crashed with "Assertion 'entry->prev->next =3D=3D entry' failed" on a completely unrelated, valid vcpus's timer. Kill all three timers in sched_init_vcpu()'s own failure branch, so it doesn't depend on the caller reaching sched_destroy_vcpu() to undo what it set up itself. Signed-off-by: Furkan Caliskan Reviewed-by: Juergen Gross --- xen/common/sched/core.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/xen/common/sched/core.c b/xen/common/sched/core.c index d542c76543..f3ae9998ef 100644 --- a/xen/common/sched/core.c +++ b/xen/common/sched/core.c @@ -589,6 +589,9 @@ int sched_init_vcpu(struct vcpu *v) unit->priv =3D sched_alloc_udata(dom_scheduler(d), unit, d->sched_priv= ); if ( unit->priv =3D=3D NULL ) { + kill_timer(&v->periodic_timer); + kill_timer(&v->singleshot_timer); + kill_timer(&v->poll_timer); sched_free_unit(unit, v); rcu_read_unlock(&sched_res_rculock); return 1; --=20 2.34.1