Re: [PATCH net] tun: Drain eBPF RCU callbacks on module exit
From: Willem de Bruijn
Date: Sat Oct 03 2026 - 14:42:36 EST
Jiale Yao wrote:
> Replacing or clearing a TUN eBPF program defers its destruction to
> tun_prog_free(). In the device teardown path, tun_free_netdev() can queue
> this callback as a private destructor. The rcu_barrier() in
> netdev_run_todo() runs before private destructors, so it cannot drain the
> new callback.
>
> After the last file or persistent-device reference is released, tun can
> therefore unload before the callback runs. Drain outstanding callbacks at
> the end of module cleanup so they cannot execute from freed module text.
>
> Fixes: 96f84061620c ("tun: add eBPF based queue selection method")
> Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
Reviewed-by: Willem de Bruijn <willemb@xxxxxxxxxx>
In response to the bot, from the previous series's cover letter:
"These issues were found by a static analysis method"