* [PATCH 0/3] Drain module-owned RCU callbacks during teardown
@ 2026-09-26 16:25 Jiale Yao
2026-09-26 16:25 ` [PATCH 1/3] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
` (2 more replies)
0 siblings, 3 replies; 5+ messages in thread
From: Jiale Yao @ 2026-09-26 16:25 UTC (permalink / raw)
To: Qiang Yu, Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann,
David Airlie, Simona Vetter, Willem de Bruijn, Jason Wang,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Alex Williamson, Kevin Tian, Jason Gunthorpe,
Ankit Agrawal, Leon Romanovsky, Farhan Ali, Matt Evans,
Vivek Kasireddy, Ritesh Harjani (IBM),
Eric Anholt, Vasily Khoruzhick, Andreas Baierl, Marek Vasut,
Heiko Stuebner, dri-devel, lima, linux-kernel, netdev, kvm
Cc: Jiale Yao
VFIO PCI core, TUN, and Lima each enqueue an RCU callback implemented in
module text. Their teardown paths can run after the callback producer has
stopped but before a previously queued callback has completed. Unloading
the module in that interval lets rcu_do_batch() invoke freed module text.
For Lima, the same window also allows the callback's slab cache to be
destroyed and its global pointer cleared before the callback frees the
fence.
Drain callbacks after their producers have stopped. The three changes are
independent and each patch remains buildable on its own.
The affected object files were built with CONFIG_TUN=m. The series was
also checked with checkpatch.pl. Runtime reproduction was not performed.
Jiale Yao (3):
vfio/pci: Drain eventfd RCU callbacks on module exit
tun: Drain eBPF RCU callbacks on module exit
drm/lima: Drain fence callbacks before destroying slab
drivers/gpu/drm/lima/lima_sched.c | 1 +
drivers/net/tun.c | 1 +
drivers/vfio/pci/vfio_pci_core.c | 1 +
3 files changed, 3 insertions(+)
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 1/3] vfio/pci: Drain eventfd RCU callbacks on module exit
2026-09-26 16:25 [PATCH 0/3] Drain module-owned RCU callbacks during teardown Jiale Yao
@ 2026-09-26 16:25 ` Jiale Yao
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF " Jiale Yao
2026-09-26 16:25 ` [PATCH 3/3] drm/lima: Drain fence callbacks before destroying slab Jiale Yao
2 siblings, 0 replies; 5+ messages in thread
From: Jiale Yao @ 2026-09-26 16:25 UTC (permalink / raw)
To: Alex Williamson, Kevin Tian, Jason Gunthorpe, Ankit Agrawal,
Leon Romanovsky, Matt Evans, Farhan Ali, Vivek Kasireddy,
Ritesh Harjani (IBM),
kvm, linux-kernel
Cc: Jiale Yao
vfio_pci_eventfd_replace_locked() defers freeing replaced eventfds to
vfio_pci_eventfd_rcu_free(). A callback can remain queued after
close_device() returns and the device driver module reference is dropped.
Once the dependent driver is removed, vfio-pci-core can be unloaded while
the callback still points into its module text.
Wait for outstanding RCU callbacks before vfio-pci-core exits.
Fixes: 98693e0897f7 ("vfio/pci: Use RCU for error/request triggers to avoid circular locking")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/vfio/pci/vfio_pci_core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_core.c
index 6757054e9d87..9bce419c52c8 100644
--- a/drivers/vfio/pci/vfio_pci_core.c
+++ b/drivers/vfio/pci/vfio_pci_core.c
@@ -2675,6 +2675,7 @@ static void vfio_pci_dev_set_try_reset(struct vfio_device_set *dev_set)
static void vfio_pci_core_cleanup(void)
{
vfio_pci_uninit_perm_bits();
+ rcu_barrier();
}
static int __init vfio_pci_core_init(void)
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
2026-09-26 16:25 [PATCH 0/3] Drain module-owned RCU callbacks during teardown Jiale Yao
2026-09-26 16:25 ` [PATCH 1/3] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
@ 2026-09-26 16:25 ` Jiale Yao
2026-09-28 18:51 ` Willem de Bruijn
2026-09-26 16:25 ` [PATCH 3/3] drm/lima: Drain fence callbacks before destroying slab Jiale Yao
2 siblings, 1 reply; 5+ messages in thread
From: Jiale Yao @ 2026-09-26 16:25 UTC (permalink / raw)
To: Willem de Bruijn, Jason Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev, linux-kernel
Cc: Jiale Yao
Replacing or clearing a TUN eBPF program defers its destruction to
tun_prog_free(). In the device teardown path, tun_free_netdev() can queue
this callback as a private destructor. The rcu_barrier() in
netdev_run_todo() runs before private destructors, so it cannot drain the
new callback.
After the last file or persistent-device reference is released, tun can
therefore unload before the callback runs. Drain outstanding callbacks at
the end of module cleanup so they cannot execute from freed module text.
Fixes: 96f84061620c ("tun: add eBPF based queue selection method")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/tun.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index 5a302709a68a..bde5032bf4f4 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -3855,6 +3855,7 @@ static void __exit tun_cleanup(void)
misc_deregister(&tun_miscdev);
rtnl_link_unregister(&tun_link_ops);
unregister_netdevice_notifier(&tun_notifier_block);
+ rcu_barrier();
}
/* Get an underlying socket object from tun file. Returns error unless file is
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 3/3] drm/lima: Drain fence callbacks before destroying slab
2026-09-26 16:25 [PATCH 0/3] Drain module-owned RCU callbacks during teardown Jiale Yao
2026-09-26 16:25 ` [PATCH 1/3] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF " Jiale Yao
@ 2026-09-26 16:25 ` Jiale Yao
2 siblings, 0 replies; 5+ messages in thread
From: Jiale Yao @ 2026-09-26 16:25 UTC (permalink / raw)
To: Qiang Yu, Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann,
David Airlie, Simona Vetter, Eric Anholt, Erico Nunes,
Rob Herring, Neil Armstrong, Andreas Baierl, dri-devel, lima,
linux-kernel
Cc: Jiale Yao
lima_fence_release() defers freeing fences from lima_fence_slab to an
RCU callback. The last lima_sched_slab_fini() can destroy the slab and
clear its pointer while a release callback is still queued. Module removal
can also free lima_fence_release_rcu() before that callback runs.
Drain outstanding callbacks before destroying the last fence slab.
Fixes: a1d2a6339961 ("drm/lima: driver for ARM Mali4xx GPUs")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/gpu/drm/lima/lima_sched.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/gpu/drm/lima/lima_sched.c b/drivers/gpu/drm/lima/lima_sched.c
index 9a1e6b9ecbe5..9c5ff1929d3e 100644
--- a/drivers/gpu/drm/lima/lima_sched.c
+++ b/drivers/gpu/drm/lima/lima_sched.c
@@ -44,6 +44,7 @@ int lima_sched_slab_init(void)
void lima_sched_slab_fini(void)
{
if (!--lima_fence_slab_refcnt) {
+ rcu_barrier();
kmem_cache_destroy(lima_fence_slab);
lima_fence_slab = NULL;
}
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF " Jiale Yao
@ 2026-09-28 18:51 ` Willem de Bruijn
0 siblings, 0 replies; 5+ messages in thread
From: Willem de Bruijn @ 2026-09-28 18:51 UTC (permalink / raw)
To: Jiale Yao, Willem de Bruijn, Jason Wang, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
netdev, linux-kernel
Cc: Jiale Yao
Jiale Yao wrote:
> Replacing or clearing a TUN eBPF program defers its destruction to
> tun_prog_free(). In the device teardown path, tun_free_netdev() can queue
> this callback as a private destructor. The rcu_barrier() in
> netdev_run_todo() runs before private destructors, so it cannot drain the
> new callback.
>
> After the last file or persistent-device reference is released, tun can
> therefore unload before the callback runs. Drain outstanding callbacks at
> the end of module cleanup so they cannot execute from freed module text.
>
> Fixes: 96f84061620c ("tun: add eBPF based queue selection method")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-28 18:51 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-26 16:25 [PATCH 0/3] Drain module-owned RCU callbacks during teardown Jiale Yao
2026-09-26 16:25 ` [PATCH 1/3] vfio/pci: Drain eventfd RCU callbacks on module exit Jiale Yao
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF " Jiale Yao
2026-09-28 18:51 ` Willem de Bruijn
2026-09-26 16:25 ` [PATCH 3/3] drm/lima: Drain fence callbacks before destroying slab Jiale Yao
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®