From nobody Mon Sep 28 09:58:16 2026 Received: from mta0.migadu.com (out-193.mta0.migadu.com [91.218.175.193]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AEEC73988E2 for ; Mon, 24 Aug 2026 07:42:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.193 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557379; cv=none; b=rOeGLqRaLG6RywSHRG1sW/2MJy199qJXAhafCj/i/aUQ7ITdxLF1dMQJSjZCY3+BrJUJygj2jqzHGjwp/v8Y2m4BllH1TXxFO6dBxLnEfBqK0bQWHLL88i1EfCZXaXFDXIrl1h8xtZrnpE7aAieKophaLMEHyn/Es7ahDMxPKtE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557379; c=relaxed/simple; bh=tLmq2HrjLCESAVz5nI7NICH8bUrsH/OHxKa8Tyxl6MQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=HfNxxoP8iskmhAmiKxQF9GlJZU+mbz80Tztb3LMTjswt0eYbij6iSXrzspg6Q0ZUkCd0+RFw6cO+y5J2FMDpFyp81AMXA6yTvmzpR+fT++98axkClxO3F6ubWVmXVwlslfsvV38hs5xt+ZV75GDFeL5OKZvhMMthXWHxYvqy1ew= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=PI0/2que; arc=none smtp.client-ip=91.218.175.193 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="PI0/2que" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=tLmq2HrjLCESAVz5nI7NICH8bUrsH/OHxKa8Tyxl6MQ=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787557374; v=1; x=1788162174; b=PI0/2queFP1BFyhexZd22gK3sOHqq0VELAuKvXWES71xMDk/34bn2RXN9qzA9hDCBUJdf2aR mWOaGtVAFo6FVKLOwWoY5PVKRYtf3/Jz32ZK4Aiyn4qR0Lu0UvQfVlYS1FQxniiKFOZQWh5rgUa Y3TfBdAP3uBhn/i6DF+E6xT0= X-Envelope-To: linux-kernel@vger.kernel.org Received: from claudy.local (2a01:4b00:ad36:1d00:3a05:25ff:fe33:35a9) by smtp.migadu.com with ESMTPS id 02e1aa68f1a3f532; Mon, 24 Aug 2026 07:42:54 +0000 X-Mizu-Trace-ID: 02e1aa68f1a3f532 X-Migadu-Flow: FLOW_OUT From: Fuad Tabba To: Marc Zyngier , Oliver Upton Cc: Thomas Gleixner , Eric Auger , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Will Deacon , Sascha Bischoff , Sebastian Ene , Fuad Tabba , kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 1/4] irqchip/gic-v4: Clear the domain and fwnode pointers after freeing them Date: Mon, 24 Aug 2026 08:42:42 +0100 Message-Id: <20260824074245.710955-2-fuad.tabba@linux.dev> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260824074245.710955-1-fuad.tabba@linux.dev> References: <20260824074245.710955-1-fuad.tabba@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The GICv4 allocation and teardown paths free their irq domains and fwnodes but leave the pointers set, and the allocation error paths test those pointers before removing them. struct its_vm and struct its_vpe are embedded in KVM's per-VM and per-vCPU state, so nothing re-zeroes them between two attempts, and an error path taken after an earlier one already freed the domain calls irq_domain_remove() on freed memory. Reaching this takes two allocation failures, one to leave the stale pointer behind and one to send the next attempt down the error path. Fixes: 7de5c0af9c7c ("irqchip/gic-v4: Add per-VM VPE domain creation") Fixes: 6d31b6ff985d ("irqchip/gic-v4.1: Add VSGI allocation/teardown") Signed-off-by: Fuad Tabba Reviewed-by: Yuan Yao --- drivers/irqchip/irq-gic-v4.c | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/drivers/irqchip/irq-gic-v4.c b/drivers/irqchip/irq-gic-v4.c index 8455b4a5fbb0d..754839e409f88 100644 --- a/drivers/irqchip/irq-gic-v4.c +++ b/drivers/irqchip/irq-gic-v4.c @@ -147,10 +147,14 @@ static int its_alloc_vcpu_sgis(struct its_vpe *vpe, i= nt idx) return 0; =20 err: - if (vpe->sgi_domain) + if (vpe->sgi_domain) { irq_domain_remove(vpe->sgi_domain); - if (vpe->fwnode) + vpe->sgi_domain =3D NULL; + } + if (vpe->fwnode) { irq_domain_free_fwnode(vpe->fwnode); + vpe->fwnode =3D NULL; + } kfree(name); return -ENOMEM; } @@ -191,10 +195,14 @@ int its_alloc_vcpu_irqs(struct its_vm *vm) return 0; =20 err: - if (vm->domain) + if (vm->domain) { irq_domain_remove(vm->domain); - if (vm->fwnode) + vm->domain =3D NULL; + } + if (vm->fwnode) { irq_domain_free_fwnode(vm->fwnode); + vm->fwnode =3D NULL; + } =20 return -ENOMEM; } @@ -215,6 +223,8 @@ static void its_free_sgi_irqs(struct its_vm *vm) irq_domain_free_irqs(irq, 16); irq_domain_remove(vm->vpes[i]->sgi_domain); irq_domain_free_fwnode(vm->vpes[i]->fwnode); + vm->vpes[i]->sgi_domain =3D NULL; + vm->vpes[i]->fwnode =3D NULL; } } =20 @@ -224,6 +234,8 @@ void its_free_vcpu_irqs(struct its_vm *vm) irq_domain_free_irqs(vm->vpes[0]->irq, vm->nr_vpes); irq_domain_remove(vm->domain); irq_domain_free_fwnode(vm->fwnode); + vm->domain =3D NULL; + vm->fwnode =3D NULL; } =20 static int its_send_vpe_cmd(struct its_vpe *vpe, struct its_cmd_info *info) --=20 2.39.5 From nobody Mon Sep 28 09:58:16 2026 Received: from mta1.migadu.com (out-41.mta1.migadu.com [95.215.58.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ADA9439EF14 for ; Mon, 24 Aug 2026 07:43:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557385; cv=none; b=EvDm821k0ztANZLfQnb/aoLZ6WyAEiQohbO8GRr909j8iGX2reI94L/8fqf80FMctz1MmAH8Sy/zdf7xmjXyvMWPlXzN5aBuYkk9KU/+KMeq83kECeDXb9T+BY6ImiNCzSM2e0JCla7tUciNctmQZZQdwuivZTSVTC1+rDg0tGk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557385; c=relaxed/simple; bh=DMAf1c7UHhlCupwZA/0QkeFewyx6PmcAOPgc7+1CLxc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=dFZjRB01pvb6HZdjCk8rLb8Te3jPTK2XLmIi393lLH70ECT6IhTB5EIGi7SXWDbdM6anOBMTdp9BQn3dexplfhpwmtW5EkeHl9uttNzJTFnFPp8E8Zzj02UBiGG3iJQe1wjYuecJzP9kB/DHsb0L1CZ21WxNs+gkaVUbl3g37P0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=Uf0DEm+X; arc=none smtp.client-ip=95.215.58.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="Uf0DEm+X" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=DMAf1c7UHhlCupwZA/0QkeFewyx6PmcAOPgc7+1CLxc=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787557379; v=1; x=1788162179; b=Uf0DEm+XnIXlEOFOoPd2/ZOLLV6osBajla7iUPqXZHn3779pbmXxIc/LxUHjuNHK6rs/PnMU LPxFqzh6R+wM55dUwDjX1Q1mVPpmqicl1l8CkEiaDpGItElLZkOF1mWFNMuJzS5pbVlxPuilHdB qST+9hU+BHpAY25w9smieD4Y= X-Envelope-To: linux-kernel@vger.kernel.org Received: from claudy.local (2a01:4b00:ad36:1d00:3a05:25ff:fe33:35a9) by smtp.migadu.com with ESMTPS id 3a916f8011f966dc; Mon, 24 Aug 2026 07:42:59 +0000 X-Mizu-Trace-ID: 3a916f8011f966dc X-Migadu-Flow: FLOW_OUT From: Fuad Tabba To: Marc Zyngier , Oliver Upton Cc: Thomas Gleixner , Eric Auger , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Will Deacon , Sascha Bischoff , Sebastian Ene , Fuad Tabba , kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 2/4] irqchip/gic-v4: Unwind what its_alloc_vcpu_irqs() allocated on failure Date: Mon, 24 Aug 2026 08:42:43 +0100 Message-Id: <20260824074245.710955-3-fuad.tabba@linux.dev> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260824074245.710955-1-fuad.tabba@linux.dev> References: <20260824074245.710955-1-fuad.tabba@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A failure in the its_alloc_vcpu_sgis() loop leaves behind both the SGI domains created for the vPEs below the failing index and the vPE irqs allocated before the loop, since irq_domain_remove() frees neither. Each leaked vPE takes its ITS state with it, a vpe_id and an LPI pending table. Free both from a second label before the existing unwind. With the freed pointers now cleared, its_free_sgi_irqs() can skip a vPE with no SGI domain and be reused there. The check has to precede the lookup: irq_find_mapping(NULL, 0) falls back to irq_default_domain, and the live irq it returns would then be freed. Fixes: 6d31b6ff985d ("irqchip/gic-v4.1: Add VSGI allocation/teardown") Signed-off-by: Fuad Tabba Reviewed-by: Yuan Yao --- drivers/irqchip/irq-gic-v4.c | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/drivers/irqchip/irq-gic-v4.c b/drivers/irqchip/irq-gic-v4.c index 754839e409f88..f707a3cb281aa 100644 --- a/drivers/irqchip/irq-gic-v4.c +++ b/drivers/irqchip/irq-gic-v4.c @@ -159,6 +159,8 @@ static int its_alloc_vcpu_sgis(struct its_vpe *vpe, int= idx) return -ENOMEM; } =20 +static void its_free_sgi_irqs(struct its_vm *vm); + int its_alloc_vcpu_irqs(struct its_vm *vm) { int vpe_base_irq, i; @@ -189,11 +191,14 @@ int its_alloc_vcpu_irqs(struct its_vm *vm) vm->vpes[i]->irq =3D vpe_base_irq + i; ret =3D its_alloc_vcpu_sgis(vm->vpes[i], i); if (ret) - goto err; + goto err_free_irqs; } =20 return 0; =20 +err_free_irqs: + its_free_sgi_irqs(vm); + irq_domain_free_irqs(vpe_base_irq, vm->nr_vpes); err: if (vm->domain) { irq_domain_remove(vm->domain); @@ -215,8 +220,13 @@ static void its_free_sgi_irqs(struct its_vm *vm) return; =20 for (i =3D 0; i < vm->nr_vpes; i++) { - unsigned int irq =3D irq_find_mapping(vm->vpes[i]->sgi_domain, 0); + unsigned int irq; =20 + /* irq_find_mapping() falls back to the default domain on NULL. */ + if (!vm->vpes[i]->sgi_domain) + continue; + + irq =3D irq_find_mapping(vm->vpes[i]->sgi_domain, 0); if (WARN_ON(!irq)) continue; =20 --=20 2.39.5 From nobody Mon Sep 28 09:58:16 2026 Received: from mta0.migadu.com (out-205.mta0.migadu.com [91.218.175.205]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E94333A4F47 for ; Mon, 24 Aug 2026 07:43:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.205 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557395; cv=none; b=Oh9WB0mHYSpdtalpERgBFaf6MAcl5R1C/zF/eXJUsaffnZHnRhNEyy/4TAsS4x8d6d0Jq6TlK/Y30Giiy2dMrM5Xr47HsXkUpWb3KA3zvdSqdskTRRlc4+lBIVk74TDWWC1uLkcRjaJRLCdQibFkkcW3jwdY987i5860+AlSv0c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557395; c=relaxed/simple; bh=9SM9EZpFWctk2TqtGWCIMwkbHqGpteu/BtNVjcuXB8k=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=KN6pcnInd2xNbQuiS1Afd0O52h5bw1HOEUygCuDJaMUCh3glYJaEFDxediSBxEJSIpuLoa2fEniMZSt5pSV2D74djgfh6m9RYlZ4LqyyWwwdmpsYL1dfylnW56m7O9Fuv5OvApeOx6sDQ+LQq5EhoNFrcOyHFQy+lK2Sk9pL2KM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=vAQiKIT0; arc=none smtp.client-ip=91.218.175.205 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="vAQiKIT0" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=9SM9EZpFWctk2TqtGWCIMwkbHqGpteu/BtNVjcuXB8k=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787557384; v=1; x=1788162184; b=vAQiKIT0UOWNY9Mw7xmNPO4xArsPj47tElYH+KKwb9ZZt9hiakbENrM7pjY0blzzBksXH+RQ nwNUAANQ6l7qoPxgeZfEQII1hWx2vV2Lg5ROHqo0AcIeYqsk7gFKg+Ai7gHdlU2Rn1rl4mkGWqV QHWHTOXwev36YuMZJ+JgdgoY= X-Envelope-To: linux-kernel@vger.kernel.org Received: from claudy.local (2a01:4b00:ad36:1d00:3a05:25ff:fe33:35a9) by smtp.migadu.com with ESMTPS id ff7716c927965831; Mon, 24 Aug 2026 07:43:03 +0000 X-Mizu-Trace-ID: ff7716c927965831 X-Migadu-Flow: FLOW_OUT From: Fuad Tabba To: Marc Zyngier , Oliver Upton Cc: Thomas Gleixner , Eric Auger , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Will Deacon , Sascha Bischoff , Sebastian Ene , Fuad Tabba , kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 3/4] KVM: arm64: vgic: Tear down what vgic_init() created when it fails Date: Mon, 24 Aug 2026 08:42:44 +0100 Message-Id: <20260824074245.710955-4-fuad.tabba@linux.dev> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260824074245.710955-1-fuad.tabba@linux.dev> References: <20260824074245.710955-1-fuad.tabba@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Once kvm_vgic_dist_init() has succeeded, every later failure in vgic_init() returns with the SPI array still allocated. A failure after vgic_v4_init() has also succeeded, which today means only kvm_vgic_setup_default_irq_routing(), leaves the vPE array behind as well. A failed vgic_init() leaves kvm_arch_vcpu_precreate() admitting new vCPUs, so a retry of KVM_DEV_ARM_VGIC_CTRL_INIT reaches vgic_v4_init()'s early return with an array that no longer covers every vCPU, and vgic_v3_load()'s WARN_ON(vgic_v4_load()) fires on the first one it misses. Release both on the two paths that can reach them, so the ioctl is all or nothing and a retry starts from scratch. dist->nr_spis stays frozen, since the SPI count cannot change once vgic_init() has supplied it. Fixes: 180ae7b11823 ("KVM: arm/arm64: Enable irqchip routing") Fixes: 74fe55dc9ab7 ("KVM: arm/arm64: GICv4: Add init/teardown of the per-V= M vPE irq domain") Reported-by: Sashiko Closes: https://lore.kernel.org/all/20260807105558.73D701F000E9@smtp.kernel= .org/ Signed-off-by: Fuad Tabba --- arch/arm64/kvm/vgic/vgic-init.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/arch/arm64/kvm/vgic/vgic-init.c b/arch/arm64/kvm/vgic/vgic-ini= t.c index 4012df6002ea6..7493fded53acc 100644 --- a/arch/arm64/kvm/vgic/vgic-init.c +++ b/arch/arm64/kvm/vgic/vgic-init.c @@ -462,7 +462,7 @@ int vgic_init(struct kvm *kvm) if (vgic_supports_direct_irqs(kvm)) { ret =3D vgic_v4_init(kvm); if (ret) - return ret; + goto out_teardown; } } else { ret =3D vgic_v5_init(kvm); @@ -475,12 +475,19 @@ int vgic_init(struct kvm *kvm) =20 ret =3D kvm_vgic_setup_default_irq_routing(kvm); if (ret) - return ret; + goto out_teardown; =20 vgic_debug_init(kvm); dist->initialized =3D true; =20 return 0; + +out_teardown: + vgic_v4_teardown(kvm); + kfree(dist->spis); + dist->spis =3D NULL; + + return ret; } =20 static void kvm_vgic_dist_destroy(struct kvm *kvm) --=20 2.39.5 From nobody Mon Sep 28 09:58:16 2026 Received: from mta0.migadu.com (out-211.mta0.migadu.com [91.218.175.211]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1338539A048 for ; Mon, 24 Aug 2026 07:43:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.211 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557397; cv=none; b=cRTXzMXoeSULVGw97k7ciywfAec63fnBXFBAFDGM0CS49TGAw/m9gfMH/3mgAN5burTLwY7t/Cvc1o4eVZo6A0nCfwyEFRb128AM25X8W625hUyA8T6UdYHqapP3Ea4EoTwotRkI3AsORztGDgJNZUpzaJpggHrCvQV2MKRYssk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787557397; c=relaxed/simple; bh=0njPdbaKLdmcvhV4JMlTlxwDuJcfUS+uR9TLYY7nzIc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=sYWY+smymMgqlkEDC39VqaQSPVI60vKk45As2tptfkIPcoFXqFOSCKYwVnU+VWTOP3RINnSGGcvmypmp37mDr/ABWTUzSnAQ83YaW5GgG0FEgReCr42TGQdVSH4YXBVY+rFSjsHHjeKhfehlVTbfHXsTeqC4amPB/8X+9CMwBVE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=JJAdsQy+; arc=none smtp.client-ip=91.218.175.211 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="JJAdsQy+" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=0njPdbaKLdmcvhV4JMlTlxwDuJcfUS+uR9TLYY7nzIc=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787557388; v=1; x=1788162188; b=JJAdsQy+YavOzIDLH65HB/iZm0vza4sNVTZIQ8N1RP0GjcSD7shL3/kJfU/e7rwJ4jYURSsI 3OBPJmbLhzIcBUKzzwV2eBORQ5CUPuM4yWqPbpklc2/KteiczFnsvIGoIusHaDZYLrHwnT/BVkQ 0ScXddug5zKf31ayZjvgWx1g= X-Envelope-To: linux-kernel@vger.kernel.org Received: from claudy.local (2a01:4b00:ad36:1d00:3a05:25ff:fe33:35a9) by smtp.migadu.com with ESMTPS id 599f795f6d738f63; Mon, 24 Aug 2026 07:43:08 +0000 X-Mizu-Trace-ID: 599f795f6d738f63 X-Migadu-Flow: FLOW_OUT From: Fuad Tabba To: Marc Zyngier , Oliver Upton Cc: Thomas Gleixner , Eric Auger , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Will Deacon , Sascha Bischoff , Sebastian Ene , Fuad Tabba , kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 4/4] KVM: arm64: vgic-v4: Restore nr_vpes before freeing the vPE resources Date: Mon, 24 Aug 2026 08:42:45 +0100 Message-Id: <20260824074245.710955-5-fuad.tabba@linux.dev> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260824074245.710955-1-fuad.tabba@linux.dev> References: <20260824074245.710955-1-fuad.tabba@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" vgic_v4_init() truncates its_vm.nr_vpes to the failing index to bound vgic_v4_teardown()'s free_irq() loop, but its_free_vcpu_irqs() reads the same field: the vPE irqs and the v4.1 SGI domains at or above that index are never freed, each one leaking a vpe_id and an LPI pending table. Restore the count from online_vcpus before that call. This depends on the previous patch: a failed vgic_init() keeps admitting vCPUs, so without that patch's teardown the vPE array outlives the failure while online_vcpus grows past the size it was allocated with. Fixes: bdb2d2ccac65 ("KVM: arm/arm64: GICv4: Add doorbell interrupt handlin= g") Reported-by: Sashiko Closes: https://lore.kernel.org/all/20260820130616.1A7241F000E9@smtp.kernel= .org/ Suggested-by: Marc Zyngier Signed-off-by: Fuad Tabba --- arch/arm64/kvm/vgic/vgic-v4.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/arch/arm64/kvm/vgic/vgic-v4.c b/arch/arm64/kvm/vgic/vgic-v4.c index ed236f083f0d7..30e1de3fc7d9d 100644 --- a/arch/arm64/kvm/vgic/vgic-v4.c +++ b/arch/arm64/kvm/vgic/vgic-v4.c @@ -333,6 +333,9 @@ void vgic_v4_teardown(struct kvm *kvm) free_irq(irq, vcpu); } =20 + /* Make sure we free all VM-wide, per-CPU resources */ + its_vm->nr_vpes =3D atomic_read(&kvm->online_vcpus); + its_free_vcpu_irqs(its_vm); kfree(its_vm->vpes); its_vm->nr_vpes =3D 0; --=20 2.39.5