[RFC net-next 08/15] xsk: Handle a detached FILL ring in RX wakeup
From: Björn Töpel
Date: Fri Oct 02 2026 - 15:02:23 EST
A buffer pool used as a memory provider can live longer than its
FILL ring, while an old page pool finishes a deferred destroy. The
RX need-wakeup helpers use pool->fq without a NULL check.
Read pool->fq once and return if it is NULL. A normal pool always
has a FILL ring here, so nothing changes for it.
Signed-off-by: Björn Töpel <bjorn@xxxxxxxxxx>
---
net/xdp/xsk.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/net/xdp/xsk.c b/net/xdp/xsk.c
index 33475b180ea6..b68dda9c37d1 100644
--- a/net/xdp/xsk.c
+++ b/net/xdp/xsk.c
@@ -50,10 +50,15 @@ static struct kmem_cache *xsk_tx_generic_cache;
void xsk_set_rx_need_wakeup(struct xsk_buff_pool *pool)
{
+ struct xsk_queue *fq = READ_ONCE(pool->fq);
+
+ if (!fq)
+ return;
+
if (pool->cached_need_wakeup & XDP_WAKEUP_RX)
return;
- pool->fq->ring->flags |= XDP_RING_NEED_WAKEUP;
+ fq->ring->flags |= XDP_RING_NEED_WAKEUP;
pool->cached_need_wakeup |= XDP_WAKEUP_RX;
}
EXPORT_SYMBOL(xsk_set_rx_need_wakeup);
@@ -77,10 +82,15 @@ EXPORT_SYMBOL(xsk_set_tx_need_wakeup);
void xsk_clear_rx_need_wakeup(struct xsk_buff_pool *pool)
{
+ struct xsk_queue *fq = READ_ONCE(pool->fq);
+
+ if (!fq)
+ return;
+
if (!(pool->cached_need_wakeup & XDP_WAKEUP_RX))
return;
- pool->fq->ring->flags &= ~XDP_RING_NEED_WAKEUP;
+ fq->ring->flags &= ~XDP_RING_NEED_WAKEUP;
pool->cached_need_wakeup &= ~XDP_WAKEUP_RX;
}
EXPORT_SYMBOL(xsk_clear_rx_need_wakeup);
--
2.55.0