Re: [PATCH RFC batadv] batman-adv: bla: fix report_work leak on backbone_gw purge

Simon Wunderlich <[email protected]>
Newsgroups org.open-mesh.lists.batman
Message-ID <2317125.72vocr9iq0@prime>
On Sunday, May 10, 2026 12:03:42 PM Central European Summer Time Sven 
Eckelmann wrote:
> batadv_bla_purge_backbone_gw() removes stale backbone gateway entries,
> but fails to properly handle their associated report_work:
> 
> - If report_work is running, the purge must wait for it to finish before
>   freeing the backbone_gw, otherwise the worker may access freed memory
>   (e.g. bat_priv).
> - If report_work is pending, the purge must cancel it and release the
>   reference held for that pending work item.
> 
> The previous implementation called hlist_for_each_entry_safe() inside a
> spin_lock_bh() section, but cancel_work_sync() may sleep and therefore
> cannot be called from within a spinlock-protected region.
> 
> Restructure the loop to handle one entry per spinlock critical section:
> acquire the lock, find the next entry to purge, remove it from the hash
> list, then release the lock before calling cancel_work_sync() and
> dropping the hash_entry reference. Repeat until no more entries require
> purging.
> 
> Fixes: a998bf5dfbd7 ("batman-adv: add detection for complex bridge loops")
> Signed-off-by: Sven Eckelmann <[email protected]>

This looks good, thank you!

Reviewed-by: Simon Wunderlich <[email protected]>

Cheers,
       Simon
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.