Re: [PATCH net] mac802154: hold an interface reference across the scan worker

Miquel Raynal <[email protected]> Fri, 17 Jul 2026 10:57:14 +0200
Newsgroups org.kernel.vger.linux-wpan,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <[email protected]>
Hi Ibrahim,

> +	/* From here on sdata->dev is dereferenced after rcu_read_unlock() and
> +	 * outside the rtnl: in the dev_err()/dev_dbg() traces below, in
> +	 * mac802154_transmit_beacon_req() (skb->dev =3D sdata->dev) and in the
> +	 * end_scan mac802154_scan_cleanup_locked() call. A concurrent teardown
> +	 * of that interface (NL802154_CMD_DEL_INTERFACE ->
> +	 * ieee802154_if_remove(), or a full PHY removal via
> +	 * ieee802154_unregister_hw()) can unregister the netdev; the actual
> +	 * free then runs asynchronously from netdev_run_todo() with the rtnl
> +	 * already dropped, so neither holding the rtnl nor the per-PHY
> +	 * IEEE802154_IS_SCANNING flag keeps sdata->dev alive here. Pin it with
> +	 * a reference taken while we still hold the RCU read lock (so the
> +	 * netdev cannot be freed before we bump the refcount) and drop it at
> +	 * every exit below. This blocks the teardown's netdev_run_todo() until
> +	 * this worker iteration is done; it cannot self-deadlock because the
> +	 * unregistering task claims the net_todo_list entry under the rtnl, so
> +	 * the blocking netdev_wait_allrefs_any() always runs on that task, not
> +	 * on this single-threaded worker.
> +	 */

The patch seems correct, the fix as well, but can we trim down this huge
comment please?

Thanks,
Miqu=C3=A8l