mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit
@ 2026-10-03  9:38 Jiale Yao
  2026-10-09 21:57 ` Alex Williamson
  0 siblings, 1 reply; 2+ messages in thread
From: Jiale Yao @ 2026-10-03  9:38 UTC (permalink / raw)
  To: Alex Williamson, Jason Gunthorpe, kvm, linux-kernel; +Cc: Jiale Yao

vfio_pci_eventfd_replace_locked() defers freeing replaced eventfds to
vfio_pci_eventfd_rcu_free(). A callback can remain queued after
close_device() returns and the device driver module reference is dropped.
Once the dependent driver is removed, vfio-pci-core can be unloaded while
the callback still points into its module text.

Wait for outstanding RCU callbacks before vfio-pci-core exits.

Fixes: 98693e0897f7 ("vfio/pci: Use RCU for error/request triggers to avoid circular locking")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/vfio/pci/vfio_pci_core.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_core.c
index 6757054e9d87..9bce419c52c8 100644
--- a/drivers/vfio/pci/vfio_pci_core.c
+++ b/drivers/vfio/pci/vfio_pci_core.c
@@ -2675,6 +2675,7 @@ static void vfio_pci_dev_set_try_reset(struct vfio_device_set *dev_set)
 static void vfio_pci_core_cleanup(void)
 {
 	vfio_pci_uninit_perm_bits();
+	rcu_barrier();
 }
 
 static int __init vfio_pci_core_init(void)
-- 
2.34.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit
  2026-10-03  9:38 [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
@ 2026-10-09 21:57 ` Alex Williamson
  0 siblings, 0 replies; 2+ messages in thread
From: Alex Williamson @ 2026-10-09 21:57 UTC (permalink / raw)
  To: Jiale Yao; +Cc: Jason Gunthorpe, kvm, linux-kernel, alex

On Sat,  3 Oct 2026 17:38:06 +0800
Jiale Yao <yaojiale02@163.com> wrote:

> vfio_pci_eventfd_replace_locked() defers freeing replaced eventfds to
> vfio_pci_eventfd_rcu_free(). A callback can remain queued after
> close_device() returns and the device driver module reference is dropped.
> Once the dependent driver is removed, vfio-pci-core can be unloaded while
> the callback still points into its module text.
> 
> Wait for outstanding RCU callbacks before vfio-pci-core exits.
> 
> Fixes: 98693e0897f7 ("vfio/pci: Use RCU for error/request triggers to avoid circular locking")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
>  drivers/vfio/pci/vfio_pci_core.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_core.c
> index 6757054e9d87..9bce419c52c8 100644
> --- a/drivers/vfio/pci/vfio_pci_core.c
> +++ b/drivers/vfio/pci/vfio_pci_core.c
> @@ -2675,6 +2675,7 @@ static void vfio_pci_dev_set_try_reset(struct vfio_device_set *dev_set)
>  static void vfio_pci_core_cleanup(void)
>  {
>  	vfio_pci_uninit_perm_bits();
> +	rcu_barrier();
>  }
>  
>  static int __init vfio_pci_core_init(void)

Applied to vfio next branch for v7.4.  Thanks,

Alex

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-09 21:57 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03  9:38 [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
2026-10-09 21:57 ` Alex Williamson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®