[PATCH v1] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure

Fuad Tabba posted 1 patch 2 months ago
arch/arm64/kvm/vgic/vgic-init.c | 1 +
1 file changed, 1 insertion(+)
[PATCH v1] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure
Posted by Fuad Tabba 2 months ago
kvm_vgic_create() sets vgic.in_kernel before allocating the per-vCPU
private IRQs, but the allocation-failure path resets only vgic_model and
leaves in_kernel set. As irqchip_in_kernel() is !!in_kernel, the VM is
left with an in-kernel irqchip but no model, and the -EEXIST guard at the
top of kvm_vgic_create() rejects every retry, so userspace cannot recover
from a transient -ENOMEM.

Reset in_kernel alongside vgic_model on the failure path.

Fixes: 9435c1e1431003 ("KVM: arm64: gic: Set vgic_model before initing private IRQs")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
---
 arch/arm64/kvm/vgic/vgic-init.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/arm64/kvm/vgic/vgic-init.c b/arch/arm64/kvm/vgic/vgic-init.c
index 907057881b26a..fdac6e24762da 100644
--- a/arch/arm64/kvm/vgic/vgic-init.c
+++ b/arch/arm64/kvm/vgic/vgic-init.c
@@ -176,6 +176,7 @@ int kvm_vgic_create(struct kvm *kvm, u32 type)
 		}
 
 		kvm->arch.vgic.vgic_model = 0;
+		kvm->arch.vgic.in_kernel = false;
 		goto out_unlock;
 	}
 

base-commit: f5098b6bae761e346ebcd9da7f95622c04733cff
-- 
2.39.5
Re: [PATCH v1] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure
Posted by Oliver Upton 1 month, 2 weeks ago
On Sun, 02 Aug 2026 16:08:45 +0100, Fuad Tabba wrote:
> kvm_vgic_create() sets vgic.in_kernel before allocating the per-vCPU
> private IRQs, but the allocation-failure path resets only vgic_model and
> leaves in_kernel set. As irqchip_in_kernel() is !!in_kernel, the VM is
> left with an in-kernel irqchip but no model, and the -EEXIST guard at the
> top of kvm_vgic_create() rejects every retry, so userspace cannot recover
> from a transient -ENOMEM.
> 
> [...]

Applied to next, thanks!

[1/1] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure
      https://git.kernel.org/kvmarm/kvmarm/c/43347154e7ab

--
Best,
Oliver
Re: [PATCH v1] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure
Posted by Marc Zyngier 2 months ago
On Sun, 02 Aug 2026 16:08:45 +0100,
Fuad Tabba <fuad.tabba@linux.dev> wrote:
> 
> kvm_vgic_create() sets vgic.in_kernel before allocating the per-vCPU
> private IRQs, but the allocation-failure path resets only vgic_model and
> leaves in_kernel set. As irqchip_in_kernel() is !!in_kernel, the VM is
> left with an in-kernel irqchip but no model, and the -EEXIST guard at the
> top of kvm_vgic_create() rejects every retry, so userspace cannot recover
> from a transient -ENOMEM.
> 
> Reset in_kernel alongside vgic_model on the failure path.
> 
> Fixes: 9435c1e1431003 ("KVM: arm64: gic: Set vgic_model before initing private IRQs")
> Cc: stable@vger.kernel.org
> Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
> ---
>  arch/arm64/kvm/vgic/vgic-init.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/arch/arm64/kvm/vgic/vgic-init.c b/arch/arm64/kvm/vgic/vgic-init.c
> index 907057881b26a..fdac6e24762da 100644
> --- a/arch/arm64/kvm/vgic/vgic-init.c
> +++ b/arch/arm64/kvm/vgic/vgic-init.c
> @@ -176,6 +176,7 @@ int kvm_vgic_create(struct kvm *kvm, u32 type)
>  		}
>  
>  		kvm->arch.vgic.vgic_model = 0;
> +		kvm->arch.vgic.in_kernel = false;
>  		goto out_unlock;
>  	}
>  
> 

Acked-by: Marc Zyngier <maz@kernel.org>

	M.

-- 
Jazz isn't dead. It just smells funny.