[PATCH net v2 0/2] net/smc: fix link group teardown races
From: Chengfeng Ye
Date: Sat Oct 03 2026 - 14:33:09 EST
These two fixes were posted separately, but both change the link group's
freeing protocol. Resend them together so scheduling and early cleanup
use the same locked teardown transition.
Patch 1 serializes the freeing check and delayed-work rearm with teardown.
It gives freeing its own storage and sets it under the list lock during
early cleanup, so another connection cannot rearm after cancellation.
It also corrects the cancellation comment: cancel_delayed_work() cancels
pending work but does not synchronize with an already-running callback.
Patch 2 excludes competing early teardown and pins both early-cleanup
callers through their ownership checks, including failed registration of
a new link group. Each patch retains its original KASAN evidence and
Fixes tag. The evidence comes from earlier instrumented runs.
The separate pre-existing race in which an already-running free_work
callback outlives the group is outside this series. The callback reference
and cancellation mechanisms are unchanged. The socket-lock versus
abort-work wait cycle also remains separate.
The series is based on net/main 71a77ab76e74. Local validation results are
recorded alongside the exported patches; no runtime test is claimed.
Chengfeng Ye (2):
net/smc: serialize link group free work scheduling
net/smc: serialize early link group cleanup with termination
net/smc/af_smc.c | 8 ++++++--
net/smc/smc_core.c | 16 +++++++++++++++-
net/smc/smc_core.h | 2 +-
3 files changed, 22 insertions(+), 4 deletions(-)
base-commit: 71a77ab76e74131a101f4d2d2afb0dcbf81b4e3c
--
2.43.0