From: Jiale Yao <yaojiale02@163.com>
To: Qiang Yu <yuq825@gmail.com>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>,
Willem de Bruijn <willemdebruijn.kernel@gmail.com>,
Jason Wang <jasowangio@gmail.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Alex Williamson <alex@shazbot.org>,
Kevin Tian <kevin.tian@intel.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Ankit Agrawal <ankita@nvidia.com>,
Leon Romanovsky <leon@kernel.org>,
Farhan Ali <alifm@linux.ibm.com>, Matt Evans <mattev@meta.com>,
Vivek Kasireddy <vivek.kasireddy@intel.com>,
"Ritesh Harjani (IBM)" <ritesh.list@gmail.com>,
Eric Anholt <eric@anholt.net>,
Vasily Khoruzhick <anarsoul@gmail.com>,
Andreas Baierl <ichgeh@imkreisrum.de>,
Marek Vasut <marex@denx.de>, Heiko Stuebner <heiko@sntech.de>,
dri-devel@lists.freedesktop.org, lima@lists.freedesktop.org,
linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
kvm@vger.kernel.org
Cc: Jiale Yao <yaojiale02@163.com>
Subject: [PATCH 0/3] Drain module-owned RCU callbacks during teardown
Date: Sun, 27 Sep 2026 00:25:49 +0800 [thread overview]
Message-ID: <20260926162554.163197-1-yaojiale02@163.com> (raw)
VFIO PCI core, TUN, and Lima each enqueue an RCU callback implemented in
module text. Their teardown paths can run after the callback producer has
stopped but before a previously queued callback has completed. Unloading
the module in that interval lets rcu_do_batch() invoke freed module text.
For Lima, the same window also allows the callback's slab cache to be
destroyed and its global pointer cleared before the callback frees the
fence.
Drain callbacks after their producers have stopped. The three changes are
independent and each patch remains buildable on its own.
The affected object files were built with CONFIG_TUN=m. The series was
also checked with checkpatch.pl. Runtime reproduction was not performed.
Jiale Yao (3):
vfio/pci: Drain eventfd RCU callbacks on module exit
tun: Drain eBPF RCU callbacks on module exit
drm/lima: Drain fence callbacks before destroying slab
drivers/gpu/drm/lima/lima_sched.c | 1 +
drivers/net/tun.c | 1 +
drivers/vfio/pci/vfio_pci_core.c | 1 +
3 files changed, 3 insertions(+)
--
2.34.1
next reply other threads:[~2026-09-26 16:28 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 16:25 Jiale Yao [this message]
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
2026-09-28 18:51 ` Willem de Bruijn
2026-10-01 23:12 ` Jakub Kicinski
2026-10-03 9:45 ` jiale yao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926162554.163197-1-yaojiale02@163.com \
--to=yaojiale02@163.com \
--cc=airlied@gmail.com \
--cc=alex@shazbot.org \
--cc=alifm@linux.ibm.com \
--cc=anarsoul@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=ankita@nvidia.com \
--cc=davem@davemloft.net \
--cc=dri-devel@lists.freedesktop.org \
--cc=edumazet@google.com \
--cc=eric@anholt.net \
--cc=heiko@sntech.de \
--cc=ichgeh@imkreisrum.de \
--cc=jasowangio@gmail.com \
--cc=jgg@ziepe.ca \
--cc=kevin.tian@intel.com \
--cc=kuba@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=leon@kernel.org \
--cc=lima@lists.freedesktop.org \
--cc=linux-kernel@vger.kernel.org \
--cc=maarten.lankhorst@linux.intel.com \
--cc=marex@denx.de \
--cc=mattev@meta.com \
--cc=mripard@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=ritesh.list@gmail.com \
--cc=simona@ffwll.ch \
--cc=tzimmermann@suse.de \
--cc=vivek.kasireddy@intel.com \
--cc=willemdebruijn.kernel@gmail.com \
--cc=yuq825@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).