[PATCH 0/3] Drain module-owned RCU callbacks during teardown

From: Jiale Yao

Date: Sat Sep 26 2026 - 12:28:32 EST


VFIO PCI core, TUN, and Lima each enqueue an RCU callback implemented in
module text. Their teardown paths can run after the callback producer has
stopped but before a previously queued callback has completed. Unloading
the module in that interval lets rcu_do_batch() invoke freed module text.

For Lima, the same window also allows the callback's slab cache to be
destroyed and its global pointer cleared before the callback frees the
fence.

Drain callbacks after their producers have stopped. The three changes are
independent and each patch remains buildable on its own.

The affected object files were built with CONFIG_TUN=m. The series was
also checked with checkpatch.pl. Runtime reproduction was not performed.

Jiale Yao (3):
vfio/pci: Drain eventfd RCU callbacks on module exit
tun: Drain eBPF RCU callbacks on module exit
drm/lima: Drain fence callbacks before destroying slab

drivers/gpu/drm/lima/lima_sched.c | 1 +
drivers/net/tun.c | 1 +
drivers/vfio/pci/vfio_pci_core.c | 1 +
3 files changed, 3 insertions(+)

--
2.34.1