Re: [PATCH] cuse: wait for pending RCU callbacks on module exit
From: Baokun Li
Date: Tue Aug 18 2026 - 04:00:23 EST
Hi Miklos,
On 2026/8/18 15:33, Miklos Szeredi wrote:
> On Fri, 14 Aug 2026 at 15:40, Baokun Li <libaokun@xxxxxxxxxxxxxxxxx> wrote:
>> Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"),
>> fuse_conn_put() frees the fuse_conn through call_rcu() rather than
>> synchronously. For cuse, fc->release is cuse_fc_release(), which
>> lives in the cuse module. If the module is removed before the RCU
>> grace period ends, the callback jumps into freed module memory:
> free_module() calls synchronize_rcu(), so this should not be an issue.
synchronize_rcu() only waits for pre-existing RCU read-side critical
sections to complete. It does not wait for pending call_rcu() callbacks
to execute. The callback can still be queued when module text is freed.
The rcu_barrier() is needed to flush them.
Many modules (including fuse itself) already call rcu_barrier() on exit
for exactly this reason. Documentation/RCU/rcubarrier.rst also explicitly
states that synchronize_rcu() does not wait for callbacks and cannot
replace rcu_barrier().
Thanks,
Baokun