Netdev List
 help / color / mirror / Atom feed
* [PATCH net v2 0/2] mac802154: fix queued RX descriptor lifetime
@ 2026-09-03 12:32 Xuanqiang Luo
  2026-09-03 12:32 ` [PATCH net v2 1/2] mac802154: serialize and drain queued RX descriptors Xuanqiang Luo
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Xuanqiang Luo @ 2026-09-03 12:32 UTC (permalink / raw)
  To: linux-wpan
  Cc: netdev, linux-kernel, alex.aring, stefan, miquel.raynal,
	david.girault, davem, edumazet, kuba, pabeni, horms, stable,
	Xuanqiang Luo

From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>

mac802154 queues one descriptor per received beacon or MAC command, but
each worker invocation dequeues only one. Since queue_work() coalesces
attempts to queue the same pending work item, a burst can add more
descriptors than scheduled invocations. A later frame may schedule another
invocation, but also adds a descriptor, so it does not necessarily reduce
the backlog. Descriptors can therefore remain queued indefinitely once
reception stops. The RX path, workers, and scan cleanup also access the
descriptor lists without common synchronization.

A queued descriptor carries its receiving interface beyond the RCU
read-side critical section without holding a netdev reference. If the
interface is removed first, the worker can dereference freed memory.

Protect the descriptor lists with a spinlock and keep the workers running
until the queues are empty. Then hold the netdev for the lifetime of each
queued descriptor to prevent it from being freed too early.

This ordering is required. Without the queue-draining fix, a descriptor
stranded by queue_work() coalescing would also strand its netdev reference,
as netdev_put() runs only when the descriptor is released, leaving the
netdev pinned indefinitely.

---
Changes:
v2:
  Patch 1 (new):
  - Serialize descriptor list access and requeue each worker while another
    descriptor remains.
  - Detach queued beacons under the same lock before scan cleanup frees
    them.

  Patch 2:
  - Replace the v1 drain_workqueue() approach, which does not cover work
    queued after the drain or the DEL_INTERFACE path, with a netdev
    reference held by each queued descriptor. (Sashiko.)

v1: https://lore.kernel.org/all/20260828101905.26865-1-xuanqiang.luo@linux.dev/

Xuanqiang Luo (2):
  mac802154: serialize and drain queued RX descriptors
  mac802154: pin netdevs for queued RX descriptors

 include/net/cfg802154.h      |  2 ++
 net/mac802154/ieee802154_i.h |  2 ++
 net/mac802154/main.c         |  1 +
 net/mac802154/rx.c           | 36 ++++++++++++++++++++++++++++++------
 net/mac802154/scan.c         |  8 +++++++-
 5 files changed, 42 insertions(+), 7 deletions(-)


base-commit: dc4b95b8fee95113587e93ca116356032d271371
-- 
2.43.0

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-05  6:02 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 12:32 [PATCH net v2 0/2] mac802154: fix queued RX descriptor lifetime Xuanqiang Luo
2026-09-03 12:32 ` [PATCH net v2 1/2] mac802154: serialize and drain queued RX descriptors Xuanqiang Luo
2026-09-04 16:27   ` Miquel Raynal
2026-09-03 12:32 ` [PATCH net v2 2/2] mac802154: pin netdevs for " Xuanqiang Luo
2026-09-04 16:27   ` Miquel Raynal
2026-09-05  6:02 ` [PATCH net v2 0/2] mac802154: fix queued RX descriptor lifetime Xuanqiang Luo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox