Re: [PATCH RFC batadv] batman-adv: bla: fix report_work leak on backbone_gw purge
Simon Wunderlich <[email protected]>
| Newsgroups | org.open-mesh.lists.batman |
|---|---|
| Message-ID | <2317125.72vocr9iq0@prime> |
On Sunday, May 10, 2026 12:03:42 PM Central European Summer Time Sven
Eckelmann wrote:
> batadv_bla_purge_backbone_gw() removes stale backbone gateway entries,
> but fails to properly handle their associated report_work:
>
> - If report_work is running, the purge must wait for it to finish before
> freeing the backbone_gw, otherwise the worker may access freed memory
> (e.g. bat_priv).
> - If report_work is pending, the purge must cancel it and release the
> reference held for that pending work item.
>
> The previous implementation called hlist_for_each_entry_safe() inside a
> spin_lock_bh() section, but cancel_work_sync() may sleep and therefore
> cannot be called from within a spinlock-protected region.
>
> Restructure the loop to handle one entry per spinlock critical section:
> acquire the lock, find the next entry to purge, remove it from the hash
> list, then release the lock before calling cancel_work_sync() and
> dropping the hash_entry reference. Repeat until no more entries require
> purging.
>
> Fixes: a998bf5dfbd7 ("batman-adv: add detection for complex bridge loops")
> Signed-off-by: Sven Eckelmann <[email protected]>
This looks good, thank you!
Reviewed-by: Simon Wunderlich <[email protected]>
Cheers,
Simon