Re: [PATCH] KVM: Nullify irqfd->producer when add_producer() fails
From: leixiang <hidden>
Date: 2026-07-09 05:45:34
Also in:
kvm, lkml, stable
On 7/9/26 00:40, Sean Christopherson wrote:
On Mon, Jun 22, 2026, leixiang wrote:quoted
The x86 and powerpc add_producer() callbacks set irqfd->producer before the fallible setup and never clear it on error. The bypass manager doesn't register a producer whose add_producer() failed -- producer->eventfd is left NULL, so the later unregister early-returns and del_producer() is never called -- so nothing ever drops the pointer. For VFIO PCI the producer is embedded in struct vfio_pci_irq_ctx and freed when the vector is disabled, after which a routing update dereferences the dangling pointer via kvm_arch_update_irqfd_routing(). Nullify irqfd->producer on the error paths. Fixes: 77e1b8332d1d ("KVM: x86: Decouple device assignment from IRQ bypass") Fixes: c57875f5f9be ("KVM: PPC: Book3S HV: Enable IRQ bypass") Cc: stable@vger.kernel.org Signed-off-by: leixiang <redacted>Please post the PPC patch as a separate patch. x86 and PPC are separate maintainer domains and the backports will likely need to go to different LTS kernels. I'll grab/extract the x86 change from here (and I'll massage the changelog as appropriate).
Thank you for the review and guidance. I will submit a separate PPC patch.
quoted hunk ↗ jump to hunk
quoted
--- arch/powerpc/kvm/book3s_hv.c | 4 +++- arch/x86/kvm/irq.c | 4 +++- 2 files changed, 6 insertions(+), 2 deletions(-)diff --git a/arch/powerpc/kvm/book3s_hv.c b/arch/powerpc/kvm/book3s_hv.c index 61dbeea317f3..14919b76fb32 100644 --- a/arch/powerpc/kvm/book3s_hv.c +++ b/arch/powerpc/kvm/book3s_hv.c@@ -6114,9 +6114,11 @@ static int kvmppc_irq_bypass_add_producer_hv(struct irq_bypass_consumer *cons, irqfd->producer = prod; ret = kvmppc_set_passthru_irq(irqfd->kvm, prod->irq, irqfd->gsi); - if (ret) + if (ret) { pr_info("kvmppc_set_passthru_irq (irq %d, gsi %d) fails: %d\n", prod->irq, irqfd->gsi, ret); + irqfd->producer = NULL; + }Unlike x86, AFAICT there's no need to set irqfd->producer before configuring the passthru/bypass stuff. So I think that fix could be this?diff --git arch/powerpc/kvm/book3s_hv.c arch/powerpc/kvm/book3s_hv.c index 61dbeea317f3..ff7b25629125 100644 --- arch/powerpc/kvm/book3s_hv.c +++ arch/powerpc/kvm/book3s_hv.c@@ -6111,12 +6111,12 @@ static int kvmppc_irq_bypass_add_producer_hv(struct irq_bypass_consumer *cons, struct kvm_kernel_irqfd *irqfd = container_of(cons, struct kvm_kernel_irqfd, consumer); - irqfd->producer = prod; - ret = kvmppc_set_passthru_irq(irqfd->kvm, prod->irq, irqfd->gsi); if (ret) pr_info("kvmppc_set_passthru_irq (irq %d, gsi %d) fails: %d\n", prod->irq, irqfd->gsi, ret); + else + irqfd->producer = prod; return ret; }
Agreed. Your approach is cleaner.