Re: [PATCH] KVM: Remove the kvm debugfs directory if kvm_init() fails
Sean Christopherson <[email protected]>
| Newsgroups | org.kernel.vger.kvm,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Aug 07, 2026, Zeng Chi wrote: > From: zengchi <[email protected]> > > kvm_init_debug() creates the "kvm" debugfs directory along with all of > the VM/vCPU stat files, but none of kvm_init()'s error paths removes it. > If kvm_vfio_ops_init(), kvm_gmem_init(), kvm_init_virtualization() or > misc_register() fails, the directory is leaked, and none of kvm_init()'s > callers invokes kvm_exit() on failure, i.e. nothing papers over the > leak. > > The stale /sys/kernel/debug/kvm directory isn't just cosmetic: a > subsequent attempt to load KVM makes debugfs_create_dir() fail with > -EEXIST, after which kvm_debugfs_dir holds an ERR_PTR and all stat > files are silently never created again. Worse, the leaked stat files > reference file_operations and stat data that live in the KVM module; if > the module is unloaded after the failed initialization, reading the > stale files is a use-after-free. > > Remove the debugfs directory in the error path, mirroring kvm_exit(). > > Fixes: 2b0128127373 ("KVM: Register /dev/kvm as the _very_ last thing during initialization") > Cc: [email protected] > Signed-off-by: zengchi <[email protected]> > --- > virt/kvm/kvm_main.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c > index 45e784462ec6..8a503ac1adbd 100644 > --- a/virt/kvm/kvm_main.c > +++ b/virt/kvm/kvm_main.c > @@ -6553,6 +6553,7 @@ int kvm_init(unsigned vcpu_size, unsigned vcpu_align, struct module *module) > err_gmem: > kvm_vfio_ops_exit(); > err_vfio: > + debugfs_remove_recursive(kvm_debugfs_dir); > kvm_async_pf_deinit(); > err_async_pf: > kvm_irqfd_exit(); > -- Already posted (twice) and applied: https://lore.kernel.org/all/[email protected]