* [PATCH net] tun: Drain eBPF RCU callbacks on module exit
@ 2026-10-03 9:38 Jiale Yao
2026-10-03 9:43 ` netdev-bot+sinfo
2026-10-03 18:42 ` Willem de Bruijn
0 siblings, 2 replies; 3+ messages in thread
From: Jiale Yao @ 2026-10-03 9:38 UTC (permalink / raw)
To: Willem de Bruijn, Jason Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev, linux-kernel
Cc: Jiale Yao
Replacing or clearing a TUN eBPF program defers its destruction to
tun_prog_free(). In the device teardown path, tun_free_netdev() can queue
this callback as a private destructor. The rcu_barrier() in
netdev_run_todo() runs before private destructors, so it cannot drain the
new callback.
After the last file or persistent-device reference is released, tun can
therefore unload before the callback runs. Drain outstanding callbacks at
the end of module cleanup so they cannot execute from freed module text.
Fixes: 96f84061620c ("tun: add eBPF based queue selection method")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/tun.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index 5a302709a68a..bde5032bf4f4 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -3855,6 +3855,7 @@ static void __exit tun_cleanup(void)
misc_deregister(&tun_miscdev);
rtnl_link_unregister(&tun_link_ops);
unregister_netdevice_notifier(&tun_notifier_block);
+ rcu_barrier();
}
/* Get an underlying socket object from tun file. Returns error unless file is
--
2.34.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] tun: Drain eBPF RCU callbacks on module exit
2026-10-03 9:38 [PATCH net] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
@ 2026-10-03 9:43 ` netdev-bot+sinfo
2026-10-03 18:42 ` Willem de Bruijn
1 sibling, 0 replies; 3+ messages in thread
From: netdev-bot+sinfo @ 2026-10-03 9:43 UTC (permalink / raw)
To: Jiale Yao
Cc: Willem de Bruijn, Jason Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev, linux-kernel
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] tun: Drain eBPF RCU callbacks on module exit
2026-10-03 9:38 [PATCH net] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
2026-10-03 9:43 ` netdev-bot+sinfo
@ 2026-10-03 18:42 ` Willem de Bruijn
1 sibling, 0 replies; 3+ messages in thread
From: Willem de Bruijn @ 2026-10-03 18:42 UTC (permalink / raw)
To: Jiale Yao, Willem de Bruijn, Jason Wang, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
netdev, linux-kernel
Cc: Jiale Yao
Jiale Yao wrote:
> Replacing or clearing a TUN eBPF program defers its destruction to
> tun_prog_free(). In the device teardown path, tun_free_netdev() can queue
> this callback as a private destructor. The rcu_barrier() in
> netdev_run_todo() runs before private destructors, so it cannot drain the
> new callback.
>
> After the last file or persistent-device reference is released, tun can
> therefore unload before the callback runs. Drain outstanding callbacks at
> the end of module cleanup so they cannot execute from freed module text.
>
> Fixes: 96f84061620c ("tun: add eBPF based queue selection method")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
In response to the bot, from the previous series's cover letter:
"These issues were found by a static analysis method"
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-03 18:42 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 9:38 [PATCH net] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
2026-10-03 9:43 ` netdev-bot+sinfo
2026-10-03 18:42 ` Willem de Bruijn
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®