From nobody Thu Sep 24 20:23:56 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1787116604; cv=none; d=zohomail.com; s=zohoarc; b=bByZ6CWvlsD8DBkgC/ifYBIZOtFI8kGqM4jSxT+WFWF5LzMhfvqOV8KJBzYUaEDKyKCWjExeTIfixTz2+pjOw03/HpC8RgTrm5BMrbumrrqMxrno3uZyyq/6mA3bVoYR4yBfLY/y/PRfhbilagubSX3dpo3498CpSpkZ1z4UArc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787116604; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=piSppthAjFb2KSi6feItTL2z0Ec385nKO3fFaIX3res=; b=h6bdTOpzkAwMzrq7XH+K8evc5uuLO1OlGzrKXprMHne6+jwOgp6PFq9Jy5v0HHh3zXUdx77xlBkZMtaEvStAstBCwMz1PPQcGzXJn7yIzBiFcou19XYd4aVrYK35BRfbK7+r3+ydObniG3ZxGWvExuxzxbeo2q6DJ0QWSDTQdG0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1787116604417868.4020797733763; Tue, 18 Aug 2026 22:16:44 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1394520.1633252 (Exim 4.92) (envelope-from ) id 1wwYet-0001RP-4U; Wed, 19 Aug 2026 05:16:15 +0000 Received: by outflank-mailman (output) from mailman id 1394520.1633252; Wed, 19 Aug 2026 05:16:15 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwYet-0001RH-14; Wed, 19 Aug 2026 05:16:15 +0000 Received: by outflank-mailman (input) for mailman id 1394520; Wed, 19 Aug 2026 05:16:13 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwYer-0001Qq-NI for xen-devel@lists.xenproject.org; Wed, 19 Aug 2026 05:16:13 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wwYer-00H41C-4A for xen-devel@lists.xenproject.org; Wed, 19 Aug 2026 07:16:13 +0200 Received: from [10.42.69.12] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a853c0f-bab6-0a2a0a5309dd-0a2a450ca3d0-36 for ; Wed, 19 Aug 2026 07:16:13 +0200 Received: from [209.85.221.44] (helo=mail-wr1-f44.google.com) by tlsNG-d25034.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a853c1c-f479-0a2a450c0019-d155dd2cec05-3 for ; Wed, 19 Aug 2026 07:16:12 +0200 Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-476a130c138so606489f8f.0 for ; Tue, 18 Aug 2026 22:16:12 -0700 (PDT) Received: from notebook.. ([78.173.117.23]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482b14b80a5sm2827700f8f.24.2026.08.18.22.16.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 22:16:12 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=20251104 header.d=gmail.com header.i="@gmail.com" header.h="Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-Id:Date:Subject:Cc:To:From" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787116572; x=1787721372; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=piSppthAjFb2KSi6feItTL2z0Ec385nKO3fFaIX3res=; b=DX098R+KTA1cBN5RFfFLCbOUZoM+nV1+01sjfgqtP4rKXmVLigBqY0U5E8zxd4TP1g lwMmVY/FGXhcqrjzR2F9ytZ5Q6zT7xGmJIpS27kXdmBJ6X4X2AizqlSdYbkYyhrBY427 ZVC6Jc4l/dHTKt+MgZsxemEz9uIps05InNrVvTWtECtvq/civjYliJrJzAYrhAvCQVC8 Dd+8A3eTBuKRMmLR4Shgnhk157X1RsHrhp3yCvcPWMzstJdITt9GnYiFYcYBT8a/bdjj BLPvJzPuoIqGUHjDhi4g0I4Z+/5oz47kK72foFaZCOKvtonLHNlHkpRs8qUXDbGvsoG4 gVAA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787116572; x=1787721372; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=piSppthAjFb2KSi6feItTL2z0Ec385nKO3fFaIX3res=; b=DbQA9m9mCLckTRiomBKcZzWwaV8QNO6kRcJ3LTGWW+xNNBjYTyv3Wc4U64Ll3xOt2k G5XIDAimiMeId8DEdoGLUuMaWHEUrcSFD1sRFtS1IlCLn3pm8ePSlUOAQWhztcZhtAzP RrDh45bASme/ZX9KLC9CdVpHPy5TCj9HRxwXbaPl25+VBkUKflaCxVjrfGpy0ZmUppJ4 atkBo6l1lXIr9vHcjM6yp3PyWxNnrdjnZ0IRP9LpxG0kZBiZGluzkV/nh6p8Jm73/KUb nKSqFZnuDSkhHa0qlYfxOQQ0Knnih/ikK4rEAhovsGCzdw6nCKe42h0FBfa/a0NpPMia AUng== X-Gm-Message-State: AOJu0YwN+9WZgkPfqfqEYlrc45NXqdOMYYP/PRAV9ytUaOVGu4hlKKtJ X6C6YRrybMXlNzMUdAodhXO9GjZTSCF681rMr0l4ba7ftv53PGIswZIMXsml8Q== X-Gm-Gg: AR+sD13YDzbttV8aEff0g0tuIBb+WPI5qk3ZNinC8rkUhUVxR1zRdPF+3CoZ8Cj+U2p vrwziPhu04e6g22ZQO8iWqRyU/kkMnlVLoceXzdEDCGqNGQ3v3unNGclIj5/Pk+KRMCJogZUMnQ 8Yjp0nMNnKyN/35zHHfmrtViox8rD3AIwP3wS7k+he7rwMAb0McGBNlTrmRi8vcTTTuRCMc2G0C 6IDLZ8htWXB2i6g7AuKfRLv7Lxu9VGlNZPGIMAMUsNaaX2rgIrKcRJUCloqv/t4if0Y7SkZL/ot k6uy4QxJSQU7d0acSGxPWy2/YsAXVjW6iCK0EyrspjQLZu2+8JGMFnDkbZ3tV2ddo74VZtoRI4c TZJhSsNu6uacK4sLZr6PwA3hveHANnJMFL0U+yrcz+0YYpKocUp/82UWjIfRbNj0qE4KMor/Xut BrTyb1kHyLgVm6fvgX0rml+91uUNcLEd9yN0hfKyg/f/6RS/hYlfdPJv2bsl+o X-Received: by 2002:a05:6000:60c:b0:47f:71a6:970e with SMTP id ffacd0b85a97d-482b1e84686mr2710317f8f.2.1787116572430; Tue, 18 Aug 2026 22:16:12 -0700 (PDT) From: Furkan Caliskan To: xen-devel@lists.xenproject.org Cc: jgross@suse.com, jbeulich@suse.com, andrew.cooper3@citrix.com, dfaggioli@suse.com, gwd@xenproject.org, Furkan Caliskan Subject: [PATCH v2 1/2] xen/sched: core: skip missing vcpu slots in sched_move_domain() Date: Wed, 19 Aug 2026 08:15:31 +0300 Message-Id: <20260819051532.9197-2-frn1furkan10@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260819051532.9197-1-frn1furkan10@gmail.com> References: <20260819051532.9197-1-frn1furkan10@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-d25034/1787116572-02CDBA5B-B8771B32/0/0 X-purgate-type: clean X-purgate-size: 3009 X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1787116606432158500 Content-Type: text/plain; charset="utf-8" sched_move_domain() derives the number of units to rebuild from d->max_vcpus, which is fixed at domain creation and never rolled back if vcpu_create() fails partway through building a domain. So d->vcpu[i] can be NULL for some i even though max_vcpus still counts it - this happens if sched_alloc_udata() returns NULL. The per-unit loop doesn't check for this: it sets unit->vcpu_list =3D d->vcpu[unit_id] (NULL) and hands that broken unit straight to the destination scheduler's alloc_udata(), which assumes vcpu_list is always valid and crashes Xen when it is not. Reproduced by building a domain in a non-default cpupool where vcpu creation fails partway through, then destroying it. domain_kill() moves the domain back to the default cpupool via sched_move_domain() before actually destroying it, crashing inside the destination scheduler's alloc_udata() (seen in Credit2's csched2_alloc_udata() -> is_idle_unit() -> NULL deref). Before building a unit in sched_move_domain(), check whether all vpcu slots belonging to that unit are populated. If any of its vpcus is missing: - For a dying domain, skip the unit allocation. - For an active domain, abort the move and return -EINVAL to prevent running with dropped vCPUs. Fixes: 70fadc41635b ("xen/cpupool: support moving domain between cpupools w= ith different granularity") Signed-off-by: Furkan Caliskan Reviewed-by: Juergen Gross --- v2: - Fail with -EINVAL if vcpu slots are missing in an active domain. - Added Fixes: tag. --- xen/common/sched/core.c | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/xen/common/sched/core.c b/xen/common/sched/core.c index d3a0a97e1d..a9daa42339 100644 --- a/xen/common/sched/core.c +++ b/xen/common/sched/core.c @@ -745,6 +745,38 @@ int sched_move_domain(struct domain *d, struct cpupool= *c) =20 for ( unit_idx =3D 0; unit_idx < n_units; unit_idx++ ) { + /* + * A vcpu slot can be missing if creation failed partway + * through. A dying domain is being torn down regardless, so + * skip the unit -- but a domain that isn't dying still needs + * every vcpu it has schedulable, so fail instead of silently + * dropping some of them. + */ + bool vcpu_failed =3D false; + + for ( unsigned int i =3D 0; + i < gran && unit_idx * gran + i < d->max_vcpus; i++ ) + { + if ( !d->vcpu[unit_idx * gran + i] ) + { + vcpu_failed =3D true; + break; + } + } + + if ( vcpu_failed ) + { + if ( !d->is_dying ) + { + sched_move_domain_cleanup(c->sched, new_units, domdata); + rcu_read_unlock(&sched_res_rculock); + + return -EINVAL; + } + + continue; + } + unit =3D sched_alloc_unit_mem(); if ( unit ) { --=20 2.34.1 From nobody Thu Sep 24 20:23:56 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1787116620; cv=none; d=zohomail.com; s=zohoarc; b=CLlmYbw8t5/w7WGz22i9XTWJYApHbxTmHyX3J1kTwL6SQoAqbjZn8yUBGcKXpqWO27JDd6+5V9TZtcKYkEabqS+OiFZKzp9BZbj9XaDRwS0HjIETdFboeZF45XPqNAAh3+rpWE7EaxkUOiM3aanJZ0n/VFCnnbAS4Mm8uZ+dA40= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787116620; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tvsq1Oa/wr/4Q3UAsjMQRqR3JBXbuIwTjFhPnZ06ijg=; b=IKg0l2EUE/vn/p7avUbaSskChonE6hqMcdbJqKH+YA3Z54+JJhR9yIbbNlce9u/WfjJhqu1CU/ii2OEIs/wNoiWFuTfW14qh3oR5cO2+KFgnz/wlwKODwPaBMlXWTEmnvC7LdeaLDCG1hqmLUUTBT0MoHe8GdI6iXaK5tRyoP7I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1787116620160706.5019819292932; Tue, 18 Aug 2026 22:17:00 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1394532.1633262 (Exim 4.92) (envelope-from ) id 1wwYfP-000241-CM; Wed, 19 Aug 2026 05:16:47 +0000 Received: by outflank-mailman (output) from mailman id 1394532.1633262; Wed, 19 Aug 2026 05:16:47 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwYfP-00023u-8t; Wed, 19 Aug 2026 05:16:47 +0000 Received: by outflank-mailman (input) for mailman id 1394532; Wed, 19 Aug 2026 05:16:45 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wwYfN-00021z-Kg for xen-devel@lists.xenproject.org; Wed, 19 Aug 2026 05:16:45 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wwYfN-008kHn-1n for xen-devel@lists.xenproject.org; Wed, 19 Aug 2026 07:16:45 +0200 Received: from [10.42.69.7] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a853bff-e002-0a2a0a5209dd-0a2a45079188-32 for ; Wed, 19 Aug 2026 07:16:45 +0200 Received: from [209.85.221.44] (helo=mail-wr1-f44.google.com) by tlsNG-ef75cf.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a853c3c-b4ea-0a2a45070019-d155dd2cdc0a-3 for ; Wed, 19 Aug 2026 07:16:45 +0200 Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-47f92e3c14bso454593f8f.0 for ; Tue, 18 Aug 2026 22:16:44 -0700 (PDT) Received: from notebook.. ([78.173.117.23]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482b14b80a5sm2827700f8f.24.2026.08.18.22.16.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 22:16:44 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=20251104 header.d=gmail.com header.i="@gmail.com" header.h="Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-Id:Date:Subject:Cc:To:From" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787116604; x=1787721404; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tvsq1Oa/wr/4Q3UAsjMQRqR3JBXbuIwTjFhPnZ06ijg=; b=Yy8E6bYQ66ihRmuo8dBoIvVYXlnbzu1vjWZ4tUQ5f9n44zbazWzuw/f6iHY4REgv9j MsyCObsXJisl0alXJ0eqWCAHAp56s/7Ga7SXuO1HOeWeehn9S5VL3e7bnof/9KkqjznK kM00QTHVyw9oMRJUoQ5qReVF9/KUXkGSjUkjRoaGdLtE7FTYUtiIuDOHTqcV0YYG29cY 20FPhz9IOndF+q9aGXf2iGBiBsBse5rZQrs3VmpSpV++XwxkW3kt9a5yuXStDG22lRcA cQd0K1EDdNmdPziBSG6uHzf4tvv1PRRY6kkbjS37KT0ttn/A3Zu7oGgJrb/cdm0A5Xbk c8yg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787116604; x=1787721404; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=tvsq1Oa/wr/4Q3UAsjMQRqR3JBXbuIwTjFhPnZ06ijg=; b=X6PyhaYLlDGJiOBWpSVXB9CWwBFbRz7VxofGFOu4xvzmv0mvxqEowbTG49oJsLSttJ HUGNLGDXNkBe05tpmopU4P19squ/y63dmi9WGCrWIF6mDdquxjIVhOQt8AR3RcCssZOQ cqrgsGuBzFI8woewL8UlAi2QXpdfG57o0lkZqabw4pO5N+awKF5/bo88CWezD53RxJ81 2ogtRaYfSalt78pAkF3pSvEv2wkOLQ+rTnZ3uZ+ROUs82WeFEcadhlbzUeGy5qaSdzgh IFShWOVbRuOzoDPHUwjgwk/wvZ5YE1Fp/D6uxFc8gHOMFsMgNlK2gGc9ICcU2ziLwn9a uk1g== X-Gm-Message-State: AOJu0YzPa/VUMShDg5XyptPRYjLzkbHN/5kdo/4TdN4pdWE08wq2SlRm dWBmL3V5h6JqIcOOHfJ2FrlSNn8mw7D2bTy9SuStf1kqkCG8H030FOKBU9kMtA== X-Gm-Gg: AR+sD12udQj3kqiun457qXDN5pgp+axwGSDHGTKmLBjfydXP1rx3O7+DdPMvcuxfSJA GeRZhd3wAn2QezuKG40uueaEHwjAjoPtwnd9htyaQm7ILfDoS5fzwR2n8Y3IN2fWL5jN2d0EKLj mb9HvOjziF6vAgRKWaCZwBA9hCSBUyH4dQcZx+8IVhypeG2Q427HtLs2PmZGXcMwFz3rVuTNfEg MuwaQp/v6AE+g43WMnOf+xFhWLWvxnQHZgG0KSb/ru0aa02T0UF2AMHmVc19cNH4KSqziGg1BuX nwyX1K71OXM6j2OmOcIQ7GH9T09G1bXX1Bprifvw91a2ThgYs7gR5LTwmaB3FhuUmBiXbH4NJCL DyBfZ/ETtEDQuLDowyFFRdLzlpC9VWU/AqUeauC7HZXNSYg50mxhH5uU6nbzgUn2i2jhqzpCAIf L1omeWyLR9QXd+hRQMEfQ5xYmqXCcEHOc0kVHnZLuL3vzqSPLBWultwlUR9P9F X-Received: by 2002:a05:6000:4387:b0:482:aa2a:52f5 with SMTP id ffacd0b85a97d-482b20033dbmr2478043f8f.24.1787116604492; Tue, 18 Aug 2026 22:16:44 -0700 (PDT) From: Furkan Caliskan To: xen-devel@lists.xenproject.org Cc: jgross@suse.com, jbeulich@suse.com, andrew.cooper3@citrix.com, dfaggioli@suse.com, gwd@xenproject.org, Furkan Caliskan Subject: [PATCH v2 2/2] xen/sched: core: kill unarmed timers on sched_init_vcpu() failure Date: Wed, 19 Aug 2026 08:15:32 +0300 Message-Id: <20260819051532.9197-3-frn1furkan10@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260819051532.9197-1-frn1furkan10@gmail.com> References: <20260819051532.9197-1-frn1furkan10@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-ef75cf/1787116605-A68D9AE4-6DC839EA/0/0 X-purgate-type: clean X-purgate-size: 2040 X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1787116622383158500 Content-Type: text/plain; charset="utf-8" sched_init_vcpu() calls init_timer() for a vcpu's periodic_timer, singleshot_timer and poll_timer before it can fail -- these become live, linked into their target pCPU's per-cpu timer list regardless of what happens next. If the sched_alloc_udata() call further down then fails, the function frees the sched_unit via sched_free_unit() and returns 1, but never unlinks these three timers. The caller, vcpu_create(), makes this worse: on sched_init_vcpu() returning nonzero it jumps to fail_wq, skipping fail_sched and thus sched_destroy_vcpu() -- the only function on this path that calls kill_timer() on them. vcpu_destroy() then frees the vcpu, and the three timers embedded in it, while they are still linked into that shared list. This silently corrupts that list. It only shows up later, when something else touches a neighboring timer: sched_move_domain() crashed with "Assertion 'entry->prev->next =3D=3D entry' failed" on a completely unrelated, valid vcpu's timer. Kill all three timers in sched_init_vcpu()'s own failure branch, so it doesn't depend on the caller reaching sched_destroy_vcpu() to undo what it set up itself. Fixes: 1ad5dad74cde ("[XEN] Re-jig VCPU initialisation -- VMX init requires= generic VCPU") Signed-off-by: Furkan Caliskan Reviewed-by: Juergen Gross --- v2: - Added Fixes: tag. --- xen/common/sched/core.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/xen/common/sched/core.c b/xen/common/sched/core.c index a9daa42339..5777096592 100644 --- a/xen/common/sched/core.c +++ b/xen/common/sched/core.c @@ -589,6 +589,9 @@ int sched_init_vcpu(struct vcpu *v) unit->priv =3D sched_alloc_udata(dom_scheduler(d), unit, d->sched_priv= ); if ( unit->priv =3D=3D NULL ) { + kill_timer(&v->periodic_timer); + kill_timer(&v->singleshot_timer); + kill_timer(&v->poll_timer); sched_free_unit(unit, v); rcu_read_unlock(&sched_res_rculock); return 1; --=20 2.34.1