* [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit
@ 2026-10-03 9:38 Jiale Yao
2026-10-09 21:57 ` Alex Williamson
0 siblings, 1 reply; 2+ messages in thread
From: Jiale Yao @ 2026-10-03 9:38 UTC (permalink / raw)
To: Alex Williamson, Jason Gunthorpe, kvm, linux-kernel; +Cc: Jiale Yao
vfio_pci_eventfd_replace_locked() defers freeing replaced eventfds to
vfio_pci_eventfd_rcu_free(). A callback can remain queued after
close_device() returns and the device driver module reference is dropped.
Once the dependent driver is removed, vfio-pci-core can be unloaded while
the callback still points into its module text.
Wait for outstanding RCU callbacks before vfio-pci-core exits.
Fixes: 98693e0897f7 ("vfio/pci: Use RCU for error/request triggers to avoid circular locking")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/vfio/pci/vfio_pci_core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_core.c
index 6757054e9d87..9bce419c52c8 100644
--- a/drivers/vfio/pci/vfio_pci_core.c
+++ b/drivers/vfio/pci/vfio_pci_core.c
@@ -2675,6 +2675,7 @@ static void vfio_pci_dev_set_try_reset(struct vfio_device_set *dev_set)
static void vfio_pci_core_cleanup(void)
{
vfio_pci_uninit_perm_bits();
+ rcu_barrier();
}
static int __init vfio_pci_core_init(void)
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit
2026-10-03 9:38 [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
@ 2026-10-09 21:57 ` Alex Williamson
0 siblings, 0 replies; 2+ messages in thread
From: Alex Williamson @ 2026-10-09 21:57 UTC (permalink / raw)
To: Jiale Yao; +Cc: Jason Gunthorpe, kvm, linux-kernel, alex
On Sat, 3 Oct 2026 17:38:06 +0800
Jiale Yao <yaojiale02@163.com> wrote:
> vfio_pci_eventfd_replace_locked() defers freeing replaced eventfds to
> vfio_pci_eventfd_rcu_free(). A callback can remain queued after
> close_device() returns and the device driver module reference is dropped.
> Once the dependent driver is removed, vfio-pci-core can be unloaded while
> the callback still points into its module text.
>
> Wait for outstanding RCU callbacks before vfio-pci-core exits.
>
> Fixes: 98693e0897f7 ("vfio/pci: Use RCU for error/request triggers to avoid circular locking")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/vfio/pci/vfio_pci_core.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_core.c
> index 6757054e9d87..9bce419c52c8 100644
> --- a/drivers/vfio/pci/vfio_pci_core.c
> +++ b/drivers/vfio/pci/vfio_pci_core.c
> @@ -2675,6 +2675,7 @@ static void vfio_pci_dev_set_try_reset(struct vfio_device_set *dev_set)
> static void vfio_pci_core_cleanup(void)
> {
> vfio_pci_uninit_perm_bits();
> + rcu_barrier();
> }
>
> static int __init vfio_pci_core_init(void)
Applied to vfio next branch for v7.4. Thanks,
Alex
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-09 21:57 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 9:38 [PATCH] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
2026-10-09 21:57 ` Alex Williamson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®