[RFC net-next 08/15] xsk: Handle a detached FILL ring in RX wakeup

From: Björn Töpel

Date: Fri Oct 02 2026 - 15:02:23 EST


A buffer pool used as a memory provider can live longer than its
FILL ring, while an old page pool finishes a deferred destroy. The
RX need-wakeup helpers use pool->fq without a NULL check.

Read pool->fq once and return if it is NULL. A normal pool always
has a FILL ring here, so nothing changes for it.

Signed-off-by: Björn Töpel <bjorn@xxxxxxxxxx>
---
net/xdp/xsk.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)

diff --git a/net/xdp/xsk.c b/net/xdp/xsk.c
index 33475b180ea6..b68dda9c37d1 100644
--- a/net/xdp/xsk.c
+++ b/net/xdp/xsk.c
@@ -50,10 +50,15 @@ static struct kmem_cache *xsk_tx_generic_cache;

void xsk_set_rx_need_wakeup(struct xsk_buff_pool *pool)
{
+ struct xsk_queue *fq = READ_ONCE(pool->fq);
+
+ if (!fq)
+ return;
+
if (pool->cached_need_wakeup & XDP_WAKEUP_RX)
return;

- pool->fq->ring->flags |= XDP_RING_NEED_WAKEUP;
+ fq->ring->flags |= XDP_RING_NEED_WAKEUP;
pool->cached_need_wakeup |= XDP_WAKEUP_RX;
}
EXPORT_SYMBOL(xsk_set_rx_need_wakeup);
@@ -77,10 +82,15 @@ EXPORT_SYMBOL(xsk_set_tx_need_wakeup);

void xsk_clear_rx_need_wakeup(struct xsk_buff_pool *pool)
{
+ struct xsk_queue *fq = READ_ONCE(pool->fq);
+
+ if (!fq)
+ return;
+
if (!(pool->cached_need_wakeup & XDP_WAKEUP_RX))
return;

- pool->fq->ring->flags &= ~XDP_RING_NEED_WAKEUP;
+ fq->ring->flags &= ~XDP_RING_NEED_WAKEUP;
pool->cached_need_wakeup &= ~XDP_WAKEUP_RX;
}
EXPORT_SYMBOL(xsk_clear_rx_need_wakeup);
--
2.55.0