Netdev List
 help / color / mirror / Atom feed
From: "Björn Töpel" <bjorn@kernel.org>
To: Stanislav Fomichev <sdf.kernel@gmail.com>,
	James Hilliard <james.hilliard1@gmail.com>
Cc: netdev@vger.kernel.org, Paolo Abeni <pabeni@redhat.com>,
	Jakub Kicinski <kuba@kernel.org>,
	Magnus Karlsson <magnus.karlsson@intel.com>,
	Maciej Fijalkowski <maciej.fijalkowski@intel.com>,
	Stanislav Fomichev <sdf@fomichev.me>,
	Simon Horman <horms@kernel.org>,
	Alexei Starovoitov <ast@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	Jesper Dangaard Brouer <hawk@kernel.org>,
	John Fastabend <john.fastabend@gmail.com>,
	Eric Dumazet <edumazet@kernel.org>,
	"David S. Miller" <davem@davemloft.net>,
	bpf@vger.kernel.org, linux-kernel@vger.kernel.org,
	Andrew Lunn <andrew+netdev@lunn.ch>
Subject: Re: [PATCH net v2] xsk: freeze deferred pool teardown without blocking unregister
Date: Thu, 08 Oct 2026 15:13:24 +0200	[thread overview]
Message-ID: <8733ug2v4b.fsf@all.your.base.are.belong.to.us> (raw)
In-Reply-To: <asaTvPO05EpmUEgN@devvm7509.cco0.facebook.com>

Stanislav Fomichev <sdf.kernel@gmail.com> writes:

> On 10/05, James Hilliard wrote:
>> Deferred pool destruction calls ndo_bpf() under RTNL. system_wq is
>> not frozen during system sleep, so that callback can run after a
>> device has suspended and gated its clocks. Use system_freezable_wq
>> so running destruction finishes before device suspend and new work
>> waits until process thaw.

...more PM suspend/resume issues...

I'd say this a bad smell/poor XSK contract that we need to use wq
freezable here. XSK capable drivers (and the core) should tolerate
calling the pool-removal path on suspended hardware and failed
resume/unregister.

Now that poor design leaks into net_device. :/

>> Keep assigned pools visible to NETDEV_UNREGISTER independently of
>> the socket list. A released socket has already left that list, but
>> its final pool put can queue destruction after workqueues freeze.
>> A resume-time unregister would then wait for a device reference
>> whose release cannot run until the resume completes.
>> 
>> Track assigned pools per netdev under RTNL and detach remaining pools
>> after the notifier socket walk, including copy-mode pools. This also
>> covers leased queues without scanning pools from unrelated devices or
>> network namespaces. Remove the entry on assignment failure and normal
>> teardown. The deferred worker still owns the pool and later observes
>> the cleared device pointer, avoiding a second driver detach or put.
>> 
>> The lifetime problem was identified by code inspection of the deferred
>> release and system-sleep paths.
>> 
>> Fixes: 1c1efc2af158 ("xsk: Create and free buffer pool independently from umem")
>> Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
>> ---
>> Changes in v2:
>> - Track assigned pools per netdev instead of scanning a global pool list.
>> - Keep deferred releases visible across queue changes and queue leases.
>> - Rebase onto current net.
>> - Link to v1: https://patch.msgid.link/20260930-xsk-suspend-teardown-v1-1-a6cac8c030be@gmail.com
>> 
>> To: "David S. Miller" <davem@davemloft.net>
>> To: Eric Dumazet <edumazet@kernel.org>
>> To: Jakub Kicinski <kuba@kernel.org>
>> To: Paolo Abeni <pabeni@redhat.com>
>> To: Simon Horman <horms@kernel.org>
>> To: Andrew Lunn <andrew+netdev@lunn.ch>
>> To: Magnus Karlsson <magnus.karlsson@intel.com>
>> To: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
>> To: Stanislav Fomichev <sdf@fomichev.me>
>> To: Alexei Starovoitov <ast@kernel.org>
>> To: Daniel Borkmann <daniel@iogearbox.net>
>> To: Jesper Dangaard Brouer <hawk@kernel.org>
>> To: John Fastabend <john.fastabend@gmail.com>
>> To: Björn Töpel <bjorn@kernel.org>
>> Cc: netdev@vger.kernel.org
>> Cc: linux-kernel@vger.kernel.org
>> Cc: bpf@vger.kernel.org
>> ---
>>  include/linux/netdevice.h   |  5 +++++
>>  include/net/xsk_buff_pool.h |  3 +++
>>  net/xdp/xsk.c               |  5 +++++
>>  net/xdp/xsk_buff_pool.c     | 25 ++++++++++++++++++++++++-
>>  4 files changed, 37 insertions(+), 1 deletion(-)
>> 
>> diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
>> index 3cff2174dc03..72091938f6e6 100644
>> --- a/include/linux/netdevice.h
>> +++ b/include/linux/netdevice.h
>> @@ -2545,6 +2545,11 @@ struct net_device {
>>  	/* protected by rtnl_lock */
>>  	struct bpf_xdp_entity	xdp_state[__MAX_XDP_MODE];
>>  
>> +#ifdef CONFIG_XDP_SOCKETS
>> +	/** @xsk_pools: assigned AF_XDP pools, protected by rtnl_lock */
>
>
> Can we mark this as being ops protected (net_device::lock) ?

+1

> xp_clear_dev calls netdev_lock_ops, but xp_assign_dev
> has netdev_assert_locked_ops_compat, so maybe there needs to be a bit more
> care. We don't want to add new ASSERT_RTNL if possible (and extend new
> netdev lock semantics).
>
> The rest looks good.

+1

I've made a mental note to try to improve this, and hopefully the we can
get rid of this in the future.


Björn

      reply	other threads:[~2026-10-08 13:13 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 18:17 [PATCH net v2] xsk: freeze deferred pool teardown without blocking unregister James Hilliard
2026-10-07 18:51 ` Stanislav Fomichev
2026-10-08 13:13   ` Björn Töpel [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8733ug2v4b.fsf@all.your.base.are.belong.to.us \
    --to=bjorn@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=davem@davemloft.net \
    --cc=edumazet@kernel.org \
    --cc=hawk@kernel.org \
    --cc=horms@kernel.org \
    --cc=james.hilliard1@gmail.com \
    --cc=john.fastabend@gmail.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=maciej.fijalkowski@intel.com \
    --cc=magnus.karlsson@intel.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=sdf.kernel@gmail.com \
    --cc=sdf@fomichev.me \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox