* [PATCH 0/3] Drain module-owned RCU callbacks during teardown
@ 2026-09-26 16:25 Jiale Yao
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
0 siblings, 1 reply; 5+ messages in thread
From: Jiale Yao @ 2026-09-26 16:25 UTC (permalink / raw)
To: Qiang Yu, Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann,
David Airlie, Simona Vetter, Willem de Bruijn, Jason Wang,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Alex Williamson, Kevin Tian, Jason Gunthorpe,
Ankit Agrawal, Leon Romanovsky, Farhan Ali, Matt Evans,
Vivek Kasireddy, Ritesh Harjani (IBM), Eric Anholt,
Vasily Khoruzhick, Andreas Baierl, Marek Vasut, Heiko Stuebner,
dri-devel, lima, linux-kernel, netdev, kvm
Cc: Jiale Yao
VFIO PCI core, TUN, and Lima each enqueue an RCU callback implemented in
module text. Their teardown paths can run after the callback producer has
stopped but before a previously queued callback has completed. Unloading
the module in that interval lets rcu_do_batch() invoke freed module text.
For Lima, the same window also allows the callback's slab cache to be
destroyed and its global pointer cleared before the callback frees the
fence.
Drain callbacks after their producers have stopped. The three changes are
independent and each patch remains buildable on its own.
The affected object files were built with CONFIG_TUN=m. The series was
also checked with checkpatch.pl. Runtime reproduction was not performed.
Jiale Yao (3):
vfio/pci: Drain eventfd RCU callbacks on module exit
tun: Drain eBPF RCU callbacks on module exit
drm/lima: Drain fence callbacks before destroying slab
drivers/gpu/drm/lima/lima_sched.c | 1 +
drivers/net/tun.c | 1 +
drivers/vfio/pci/vfio_pci_core.c | 1 +
3 files changed, 3 insertions(+)
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
2026-09-26 16:25 [PATCH 0/3] Drain module-owned RCU callbacks during teardown Jiale Yao
@ 2026-09-26 16:25 ` Jiale Yao
2026-09-28 18:51 ` Willem de Bruijn
2026-10-01 23:12 ` Jakub Kicinski
0 siblings, 2 replies; 5+ messages in thread
From: Jiale Yao @ 2026-09-26 16:25 UTC (permalink / raw)
To: Willem de Bruijn, Jason Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev, linux-kernel
Cc: Jiale Yao
Replacing or clearing a TUN eBPF program defers its destruction to
tun_prog_free(). In the device teardown path, tun_free_netdev() can queue
this callback as a private destructor. The rcu_barrier() in
netdev_run_todo() runs before private destructors, so it cannot drain the
new callback.
After the last file or persistent-device reference is released, tun can
therefore unload before the callback runs. Drain outstanding callbacks at
the end of module cleanup so they cannot execute from freed module text.
Fixes: 96f84061620c ("tun: add eBPF based queue selection method")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/tun.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index 5a302709a68a..bde5032bf4f4 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -3855,6 +3855,7 @@ static void __exit tun_cleanup(void)
misc_deregister(&tun_miscdev);
rtnl_link_unregister(&tun_link_ops);
unregister_netdevice_notifier(&tun_notifier_block);
+ rcu_barrier();
}
/* Get an underlying socket object from tun file. Returns error unless file is
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
@ 2026-09-28 18:51 ` Willem de Bruijn
2026-10-01 23:12 ` Jakub Kicinski
1 sibling, 0 replies; 5+ messages in thread
From: Willem de Bruijn @ 2026-09-28 18:51 UTC (permalink / raw)
To: Jiale Yao, Willem de Bruijn, Jason Wang, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
netdev, linux-kernel
Cc: Jiale Yao
Jiale Yao wrote:
> Replacing or clearing a TUN eBPF program defers its destruction to
> tun_prog_free(). In the device teardown path, tun_free_netdev() can queue
> this callback as a private destructor. The rcu_barrier() in
> netdev_run_todo() runs before private destructors, so it cannot drain the
> new callback.
>
> After the last file or persistent-device reference is released, tun can
> therefore unload before the callback runs. Drain outstanding callbacks at
> the end of module cleanup so they cannot execute from freed module text.
>
> Fixes: 96f84061620c ("tun: add eBPF based queue selection method")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
2026-09-28 18:51 ` Willem de Bruijn
@ 2026-10-01 23:12 ` Jakub Kicinski
2026-10-03 9:45 ` jiale yao
1 sibling, 1 reply; 5+ messages in thread
From: Jakub Kicinski @ 2026-10-01 23:12 UTC (permalink / raw)
To: Jiale Yao
Cc: Willem de Bruijn, Jason Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Paolo Abeni, netdev, linux-kernel
On Sun, 27 Sep 2026 00:25:51 +0800 Jiale Yao wrote:
> Subject: [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
please repost this if you expect networking to take the patch
patchwork will wait for the other emails that you did not cc us on
you shouldn't pointlessly make patches for different subsystems into
a series
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re:Re: [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
2026-10-01 23:12 ` Jakub Kicinski
@ 2026-10-03 9:45 ` jiale yao
0 siblings, 0 replies; 5+ messages in thread
From: jiale yao @ 2026-10-03 9:45 UTC (permalink / raw)
To: Jakub Kicinski
Cc: Willem de Bruijn, Jason Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Paolo Abeni, netdev, linux-kernel
Hi Jakub,
At 2026-10-02 07:12:09, "Jakub Kicinski" <kuba@kernel.org> wrote:
>On Sun, 27 Sep 2026 00:25:51 +0800 Jiale Yao wrote:
>> Subject: [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit
>
>please repost this if you expect networking to take the patch
>patchwork will wait for the other emails that you did not cc us on
>you shouldn't pointlessly make patches for different subsystems into
>a series
Thanks for pointing this out. I have split out the TUN change and
reposted it as a standalone patch,
in https://lore.kernel.org/all/20261003093822.544964-1-yaojiale02@163.com/
Jiale
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-10-03 9:45 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 16:25 [PATCH 0/3] Drain module-owned RCU callbacks during teardown Jiale Yao
2026-09-26 16:25 ` [PATCH 2/3] tun: Drain eBPF RCU callbacks on module exit Jiale Yao
2026-09-28 18:51 ` Willem de Bruijn
2026-10-01 23:12 ` Jakub Kicinski
2026-10-03 9:45 ` jiale yao
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox