• S
    batman-adv: Avoid recursive call_rcu for batadv_nc_node · 44e8e7e9
    Sven Eckelmann 提交于
    The batadv_nc_node_free_ref function uses call_rcu to delay the free of the
    batadv_nc_node object until no (already started) rcu_read_lock is enabled
    anymore. This makes sure that no context is still trying to access the
    object which should be removed. But batadv_nc_node also contains a
    reference to orig_node which must be removed.
    
    The reference drop of orig_node was done in the call_rcu function
    batadv_nc_node_free_rcu but should actually be done in the
    batadv_nc_node_release function to avoid nested call_rcus. This is
    important because rcu_barrier (e.g. batadv_softif_free or batadv_exit) will
    not detect the inner call_rcu as relevant for its execution. Otherwise this
    barrier will most likely be inserted in the queue before the callback of
    the first call_rcu was executed. The caller of rcu_barrier will therefore
    continue to run before the inner call_rcu callback finished.
    
    Fixes: d56b1705 ("batman-adv: network coding - detect coding nodes and remove these after timeout")
    Signed-off-by: NSven Eckelmann <sven@narfation.org>
    Signed-off-by: NMarek Lindner <mareklindner@neomailbox.ch>
    Signed-off-by: NAntonio Quartulli <a@unstable.cc>
    44e8e7e9
network-coding.c 57.9 KB