mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: David Howells <dhowells@redhat.com>
To: netdev@vger.kernel.org
Cc: David Howells <dhowells@redhat.com>,
	Marc Dionne <marc.dionne@auristor.com>,
	Jakub Kicinski <kuba@kernel.org>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Paolo Abeni <pabeni@redhat.com>, Simon Horman <horms@kernel.org>,
	linux-afs@lists.infradead.org, linux-kernel@vger.kernel.org,
	Jeffrey Altman <jaltman@auristor.com>,
	stable@vger.kernel.org
Subject: [PATCH net v12 10/15] rxrpc: Fix the cleanup of service calls when socket shut down
Date: Tue,  6 Oct 2026 14:30:02 +0100	[thread overview]
Message-ID: <20261006133011.531806-11-dhowells@redhat.com> (raw)
In-Reply-To: <20261006133011.531806-1-dhowells@redhat.com>

When a kernel AF_RXRPC socket is shut down, rxrpc_release_call() detaches
each outstanding service call from the socket, but doesn't send the app a
notification for each call that the socket to end the linkage from the app
side, assuming that the app will do this - but neither afs nor rxperf do.
The notification is prevented by rxrpc_notify_socket() rejecting the
notification if the socket in the CLOSE state.  This could lead to calls
not being cleaned up and rmmod of rxrpc stalling indefinitely.

Fix this by:

 (1) Making rxrpc_release_calls_on_socket() wait for the call to be
     transitioned to the completed state when the I/O thread processes the
     abort proposal.  This prevents the call from having the RELEASED flag
     set before rxrpc_notify_socket() runs (which would otherwise cause the
     notification to be skipped).

 (2) Making rxrpc_notify_socket() call ->notify_rx() even if the socket is
     in the RXRPC_CLOSE state.  The wait added in (1) makes sure that the
     notification is done before the call is released from the socket.

Note that this isn't relevant to userspace as the userspace app doesn't
have its own structures in the kernel that need to be cleaned up.

Fixes: 248f219cb8bc ("rxrpc: Rewrite the data and ack handling code")
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Eric Dumazet <edumazet@google.com>
cc: "David S. Miller" <davem@davemloft.net>
cc: Jakub Kicinski <kuba@kernel.org>
cc: Paolo Abeni <pabeni@redhat.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@vger.kernel.org
---
 net/rxrpc/call_object.c |  1 +
 net/rxrpc/recvmsg.c     | 12 ++++++------
 2 files changed, 7 insertions(+), 6 deletions(-)

diff --git a/net/rxrpc/call_object.c b/net/rxrpc/call_object.c
index 817ed9acb91e..68d4096994bd 100644
--- a/net/rxrpc/call_object.c
+++ b/net/rxrpc/call_object.c
@@ -628,6 +628,7 @@ void rxrpc_release_calls_on_socket(struct rxrpc_sock *rx)
 		rxrpc_get_call(call, rxrpc_call_get_release_sock);
 		rxrpc_propose_abort(call, RX_CALL_DEAD, -ECONNRESET,
 				    rxrpc_abort_call_sock_release);
+		wait_event(call->waitq, rxrpc_call_is_complete(call));
 		rxrpc_release_call(rx, call);
 		rxrpc_put_call(call, rxrpc_call_put_release_sock);
 	}
diff --git a/net/rxrpc/recvmsg.c b/net/rxrpc/recvmsg.c
index 0c960f13b5fc..214eea04b1c2 100644
--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@ -37,12 +37,12 @@ void rxrpc_notify_socket(struct rxrpc_call *call)
 
 	rx = rcu_dereference(call->socket);
 	sk = &rx->sk;
-	if (rx && sk->sk_state < RXRPC_CLOSE) {
-		if (call->notify_rx) {
-			spin_lock_irqsave(&call->notify_lock, flags);
-			call->notify_rx(sk, call, call->user_call_ID);
-			spin_unlock_irqrestore(&call->notify_lock, flags);
-		} else {
+	if (call->notify_rx) {
+		spin_lock_irqsave(&call->notify_lock, flags);
+		call->notify_rx(sk, call, call->user_call_ID);
+		spin_unlock_irqrestore(&call->notify_lock, flags);
+	} else {
+		if (rx && sk->sk_state < RXRPC_CLOSE) {
 			spin_lock_irqsave(&rx->recvmsg_lock, flags);
 			if (list_empty(&call->recvmsg_link)) {
 				rxrpc_get_call(call, rxrpc_call_get_notify_socket);


  parent reply	other threads:[~2026-10-06 13:31 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 13:29 [PATCH net v12 00/15] rxrpc: Miscellaneous fixes David Howells
2026-10-06 13:29 ` [PATCH net v12 01/15] rxrpc: Revert "rxrpc: rxperf: Fix missing decoding of terminal magic cookie" David Howells
2026-10-06 13:29 ` [PATCH net v12 02/15] rxrpc: Fix rxperf test rxgk key kvno to be 0 David Howells
2026-10-06 13:29 ` [PATCH net v12 03/15] rxrpc: Fix update of call->tx_pending without holding lock David Howells
2026-10-06 13:29 ` [PATCH net v12 04/15] rxrpc: Fix lack of short-send handling in rxrpc_kernel_send_data() David Howells
2026-10-06 13:29 ` [PATCH net v12 05/15] afs: Fix afs to abort the rxrpc call on send error David Howells
2026-10-06 13:29 ` [PATCH net v12 06/15] rxrpc: Fix aborting in rxperf test server David Howells
2026-10-06 13:29 ` [PATCH net v12 07/15] rxrpc: Fix sendmsg length David Howells
2026-10-06 13:30 ` [PATCH net v12 08/15] rxrpc: Fix double IRQ enablement David Howells
2026-10-06 13:30 ` [PATCH net v12 09/15] rxrpc: Fix return in rxrpc_recvmsg_data() for service calls David Howells
2026-10-06 13:30 ` David Howells [this message]
2026-10-06 13:30 ` [PATCH net v12 11/15] rxrpc: Fix error handling in rxrpc_send_data() David Howells
2026-10-06 13:30 ` [PATCH net v12 12/15] rxrpc: Fix packet encryption error handling David Howells
2026-10-06 13:30 ` [PATCH net v12 13/15] rxrpc: Fix generation of notifications after call completion David Howells
2026-10-06 13:30 ` [PATCH net v12 14/15] rxrpc: Fix RxGK key parser to check enctype is supported David Howells
2026-10-06 13:30 ` [PATCH net v12 15/15] rxrpc: fix use-after-free in rxrpc_poke_conn() David Howells
2026-10-06 13:35 ` [PATCH net v12 00/15] rxrpc: Miscellaneous fixes netdev-bot+sinfo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006133011.531806-11-dhowells@redhat.com \
    --to=dhowells@redhat.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=jaltman@auristor.com \
    --cc=kuba@kernel.org \
    --cc=linux-afs@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=marc.dionne@auristor.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®