mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net v2 0/2] net/smc: fix link group teardown races
@ 2026-10-03 18:32 Chengfeng Ye
  2026-10-03 18:32 ` [PATCH net v2 1/2] net/smc: serialize link group free work scheduling Chengfeng Ye
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Chengfeng Ye @ 2026-10-03 18:32 UTC (permalink / raw)
  To: alibuda, dust.li, sidraya, mjambigi, davem, edumazet, kuba, pabeni
  Cc: tonylu, guwen, horms, linux-rdma, linux-s390, netdev,
	linux-kernel, stable

These two fixes were posted separately, but both change the link group's
freeing protocol. Resend them together so scheduling and early cleanup
use the same locked teardown transition.

Patch 1 serializes the freeing check and delayed-work rearm with teardown.
It gives freeing its own storage and sets it under the list lock during
early cleanup, so another connection cannot rearm after cancellation.
It also corrects the cancellation comment: cancel_delayed_work() cancels
pending work but does not synchronize with an already-running callback.

Patch 2 excludes competing early teardown and pins both early-cleanup
callers through their ownership checks, including failed registration of
a new link group. Each patch retains its original KASAN evidence and
Fixes tag. The evidence comes from earlier instrumented runs.

The separate pre-existing race in which an already-running free_work
callback outlives the group is outside this series. The callback reference
and cancellation mechanisms are unchanged. The socket-lock versus
abort-work wait cycle also remains separate.

The series is based on net/main 71a77ab76e74. Local validation results are
recorded alongside the exported patches; no runtime test is claimed.

Chengfeng Ye (2):
  net/smc: serialize link group free work scheduling
  net/smc: serialize early link group cleanup with termination

 net/smc/af_smc.c   |  8 ++++++--
 net/smc/smc_core.c | 16 +++++++++++++++-
 net/smc/smc_core.h |  2 +-
 3 files changed, 22 insertions(+), 4 deletions(-)


base-commit: 71a77ab76e74131a101f4d2d2afb0dcbf81b4e3c
-- 
2.43.0

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-03 18:39 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 18:32 [PATCH net v2 0/2] net/smc: fix link group teardown races Chengfeng Ye
2026-10-03 18:32 ` [PATCH net v2 1/2] net/smc: serialize link group free work scheduling Chengfeng Ye
2026-10-03 18:32 ` [PATCH net v2 2/2] net/smc: serialize early link group cleanup with termination Chengfeng Ye
2026-10-03 18:39 ` [PATCH net v2 0/2] net/smc: fix link group teardown races netdev-bot+sinfo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®