From patchwork Wed Jul 29 10:21:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5169 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746435mac; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rr9iBTyO3vQCTvUFzDANEk0+QPPyyBp2edkGxiPgF1+cAEUyp3GmOcnPIMIt6r7Nrd6wWSffwA9E+c=@openvpn.net X-Received: by 2002:a05:6871:680c:b0:456:b6b3:5b4f with SMTP id 586e51a60fabf-4586cc8aca5mr3510501fac.15.1785320545421; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=g+oHvik1zJkH205gKuhWKcRfKVUynF9iHF9fVAbHPnylVE5uJj+/Q1vGy/7jxLNJid ZR7yqxRycnlfKJ9YunOoNQbKptQ8WANEjzH6qMeQbHLEvh22HpuPBY46iyl2VL9dxKpu kTyRGZmixlVM6K+Hm1wYsWSOFYpr7nJmePAmURu3ukJq6sYTrWrmSQJLMrw9LwjJ2jAM J1urZ3SajKB774UnvT8XQRymqQ7QPyysz9nwlxvGWMiXYPEhcnlKZYLuMSGFsseGzkpG 9muAhBpMwUnzxKPK8/KfppRnvdICm/pT9NVFB16SKhz5c/ZplMJ4C/Zb2/FzIBMgDkQk QkCg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=VrxwItvEhFf40sVA8AsGqTMIdNR+EgsDh61u9lxhdZI=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=JtftEgwOQoyPBiah0W5jbd0P0pWB3E9Nj0d0eqhP/i93G+BE2fj0gRMkciBfVNqKVD RgSIhNoM8XBPHjQ+xUqbT/3xBYGWtvRcPzo6245/zODQ7U3muG7gqt4DEcPvZkKom/U7 9Jgkg7h/hEHrP56lUTV96nOeukoebETFtQ6NwmpVQsVBeYM29eRm0Hn2l0dc6fvt9z0L Mcn7WcJcPYad4yzq8yAJaGHxRW0ZulzMjYElOBNSmohLKw+aIAgQGHHGf5wU/gp/egGZ IDlxFROpY+VivsEQREdQYiGYBe8XF2UNJ+/o08eFdAcC349sYq3q7+Qyh0zpwEBblVWL Cs3w==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Yjl3HpIT; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=EhA82whe; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Q7OizojZ; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=nkeWkOvO; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-458863b6efbsi2189299fac.62.2026.07.29.03.22.25 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Yjl3HpIT; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=EhA82whe; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Q7OizojZ; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=nkeWkOvO; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=VrxwItvEhFf40sVA8AsGqTMIdNR+EgsDh61u9lxhdZI=; b=Yjl3HpITb8bZSfem5+vCAgOySP ZZgu3+x9/iXZ0PjFR7smVq8xksWrLIhtoLY+eH2toQqBjGUJ/a/QxjDoYhfbfHed+xLYCy4sdZKZz rNwuCpJqXvyGIp4KRbdlkV5J7DNrpxx+Qd1lx28BFKc91RxMykbXh41gM4I/kg4DOmaY=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1Qe-0002oK-MB; Wed, 29 Jul 2026 10:22:22 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QT-0002nk-VE for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:11 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=MKJoF6j+aK8nKirKr2ZQCdrxwKMQUsp7A7+a8+GHQcY=; b=EhA82wheEXIW2+CDym9fIJaAZH QgBWT9akhbLvzb6rgbpvXzCftRM3jUVfGaf9pARFJs2lgOl8yBNOBfswKvDV0mXvG/Nt6kVSUkAWd w3NJ/vJeMqwah8qPKxpMKE57t0VzYEtlkfmsy2EZ1jrHaqL+M0N3bt17xAsU+inhBDzA=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=MKJoF6j+aK8nKirKr2ZQCdrxwKMQUsp7A7+a8+GHQcY=; b=Q7OizojZY3TdT2u9r0D89/a2np eHqBcr4OwxxdNOUv++XYA7afDO97sRqd/TzVWw5EE1pRXKduRqeu6KfEaRhf8V3PMCiSMT2unTSlP sBjEJaXdI3sg/XkbRTflj+J88ySesosFcIiJPK5KwTo1Hiv8WHuoZpaSUzM4DAK2R/xI=; Received: from mout-b-105.mailbox.org ([195.10.208.50]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QN-0003Ug-66 for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:11 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-105.mailbox.org (Postfix) with ESMTPS id 4h97fv0S8xz9tcs; Wed, 29 Jul 2026 12:21:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320519; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=MKJoF6j+aK8nKirKr2ZQCdrxwKMQUsp7A7+a8+GHQcY=; b=nkeWkOvO8aStAJh8nGbOl97YF+HTZ/9jYGGf5QgIF4AHk9OCS/bPZKxEISYKhaDW7TeIvD Ify1PWW6G2PXXLdrPcIcB1ADsCN+qiEGOUNUzGTykauyb7kL0OGvpswIwEcqA9gwHiLjW8 fE/CT8qMFiAUkn4YYLsWggx6lY3kbQ9u5xObLayxv7W+DbFrHJqgKEaeFknxCTZzrWzSWH cyc0PhhxZQfYKXe9KebGINPO4DdPqb+bFpI4KEfjtdRJdMksYpGWDt48nZqyfQNKvDeGJD kWV6E6jz/gS/TMVG+kHkr7O0f+MC87iw4omMr2cLIueiCNCVWrQPGybal9waig== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:45 +0200 Message-ID: <51a8febf0da1fe17e5fc0b857e8d0a8797002ea2.1785318038.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h97fv0S8xz9tcs X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callba [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.50 listed in wl.mailspike.net] -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wp1QN-0003Ug-66 Subject: [Openvpn-devel] [PATCH ovpn net v6 5/6] ovpn: run deferred work on a module-owned workqueue X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044276575105185 X-GMAIL-MSGID: 1872044276575105185 ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callbacks have fully returned before the module text can be freed. Object references protect the objects used by the callbacks, but they do not prove that a workqueue function has returned. In particular, a worker can drop the final reference that unblocks device teardown while it is still executing ovpn code. Add a module-owned workqueue and queue all ovpn work items on it. During module exit, unregister rtnl and netlink first, flush the workqueue so ordinary ovpn workers finish, run the final RCU barrier, and destroy the workqueue last. This keeps the workqueue available for cleanup work queued from RCU callbacks, while ensuring no ovpn work item can outlive the module text. The per-device delayed keepalive work remains explicitly disabled during netdev teardown (disable_delayed_work_sync in ndo_uninit), since flush_workqueue does not flush delayed work that is still only pending on its timer. Fixes: 3ecfd9349f40 ("ovpn: implement keepalive mechanism") Fixes: 11851cbd60ea ("ovpn: implement TCP transport") Signed-off-by: Ralf Lici --- Changes since v5 https://lore.kernel.org/openvpn-devel/d530ecfc3719845075fbddd0cd7c34752bc2ce16.1783336121.git.ralf@mandelbit.com/ - Update the module-exit ordering for the queue_rcu_work-based key-slot release: flush ordinary ovpn work before rcu_barrier, then destroy the workqueue after RCU callbacks have queued their cleanup work. Changes since v4 https://lore.kernel.org/openvpn-devel/6edfcc51e0855bfd34286b86d4e7f26bb3bcd3f7.1783099626.git.ralf@mandelbit.com/ - Rebase on the pending keepalive and TCP deferred-work refcount fixes, preserving their hold-before-queue and queue-failure put handling when converting schedule_work to queue_work. Changes since v3 https://lore.kernel.org/openvpn-devel/49f38f89340e18ed30543d3990a7a7e20595b6af.1783080055.git.ralf@mandelbit.com/ - Replace the RCU-deferred peer netdev reference release with a module-owned workqueue that drains all ovpn work callbacks before module text can be freed. drivers/net/ovpn/main.c | 19 ++++++++++++++++++- drivers/net/ovpn/ovpnpriv.h | 4 ++++ drivers/net/ovpn/peer.c | 8 ++++---- drivers/net/ovpn/tcp.c | 9 ++++----- 4 files changed, 30 insertions(+), 10 deletions(-) diff --git a/drivers/net/ovpn/main.c b/drivers/net/ovpn/main.c index 5093a3b5aba6..80d10f9ef7d8 100644 --- a/drivers/net/ovpn/main.c +++ b/drivers/net/ovpn/main.c @@ -12,6 +12,7 @@ #include #include #include +#include #include #include #include @@ -26,6 +27,9 @@ #include "tcp.h" #include "udp.h" +/* module-owned workqueue on which all ovpn-specific work is queued */ +struct workqueue_struct *ovpn_wq; + static void ovpn_priv_free(struct net_device *net) { struct ovpn_priv *ovpn = netdev_priv(net); @@ -237,10 +241,16 @@ static int __init ovpn_init(void) ovpn_tcp_init(); + ovpn_wq = alloc_workqueue("ovpn", 0, 0); + if (!ovpn_wq) { + pr_err("ovpn: cannot allocate workqueue\n"); + return -ENOMEM; + } + err = rtnl_link_register(&ovpn_link_ops); if (err) { pr_err("ovpn: can't register rtnl link ops: %d\n", err); - return err; + goto destroy_wq; } err = ovpn_nl_register(); @@ -253,6 +263,9 @@ static int __init ovpn_init(void) unreg_rtnl: rtnl_link_unregister(&ovpn_link_ops); +destroy_wq: + destroy_workqueue(ovpn_wq); + ovpn_wq = NULL; return err; } @@ -261,7 +274,11 @@ static __exit void ovpn_cleanup(void) ovpn_nl_unregister(); rtnl_link_unregister(&ovpn_link_ops); + flush_workqueue(ovpn_wq); rcu_barrier(); + + destroy_workqueue(ovpn_wq); + ovpn_wq = NULL; } module_init(ovpn_init); diff --git a/drivers/net/ovpn/ovpnpriv.h b/drivers/net/ovpn/ovpnpriv.h index 5898f6adada7..84499140e4bd 100644 --- a/drivers/net/ovpn/ovpnpriv.h +++ b/drivers/net/ovpn/ovpnpriv.h @@ -15,6 +15,10 @@ #include #include +struct workqueue_struct; + +extern struct workqueue_struct *ovpn_wq; + /** * struct ovpn_peer_collection - container of peers for MultiPeer mode * @by_id: table of peers index by ID diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index a21d02ac715e..a80e85a62af5 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -62,7 +62,7 @@ void ovpn_peer_keepalive_set(struct ovpn_peer *peer, u32 interval, u32 timeout) /* now that interval and timeout have been changed, kick * off the worker so that the next delay can be recomputed */ - mod_delayed_work(system_percpu_wq, &peer->ovpn->keepalive_work, 0); + mod_delayed_work(ovpn_wq, &peer->ovpn->keepalive_work, 0); } /** @@ -1287,7 +1287,7 @@ static time64_t ovpn_peer_keepalive_work_single(struct ovpn_peer *peer, peer->id); if (WARN_ON(!ovpn_peer_hold(peer))) return 0; - if (!schedule_work(&peer->keepalive_work)) + if (!queue_work(ovpn_wq, &peer->keepalive_work)) ovpn_peer_put(peer); } @@ -1379,8 +1379,8 @@ void ovpn_peer_keepalive_work(struct work_struct *work) netdev_dbg(ovpn->dev, "scheduling keepalive work: now=%llu next_run=%llu delta=%llu\n", next_run, now, next_run - now); - schedule_delayed_work(&ovpn->keepalive_work, - (next_run - now) * HZ); + queue_delayed_work(ovpn_wq, &ovpn->keepalive_work, + (next_run - now) * HZ); } unlock_ovpn(ovpn, &release_list); } diff --git a/drivers/net/ovpn/tcp.c b/drivers/net/ovpn/tcp.c index 0af14055c39a..8fe8a8e750a4 100644 --- a/drivers/net/ovpn/tcp.c +++ b/drivers/net/ovpn/tcp.c @@ -151,7 +151,7 @@ static void ovpn_tcp_rcv(struct strparser *strp, struct sk_buff *skb) /* take reference for deferred peer deletion. should never fail */ if (WARN_ON(!ovpn_peer_hold(peer))) goto err_nopeer; - if (!schedule_work(&peer->tcp.defer_del_work)) + if (!queue_work(ovpn_wq, &peer->tcp.defer_del_work)) ovpn_peer_put(peer); ovpn_dev_dstats_rx_dropped(peer->ovpn->dev); err_nopeer: @@ -284,13 +284,12 @@ static void ovpn_tcp_send_sock(struct ovpn_peer *peer, struct sock *sk) * stream therefore we abort the connection */ ovpn_peer_hold(peer); - if (!schedule_work(&peer->tcp.defer_del_work)) + if (!queue_work(ovpn_wq, &peer->tcp.defer_del_work)) ovpn_peer_put(peer); /* we bail out immediately and keep tx_in_progress set * to true. This way we prevent more TX attempts - * which would lead to more invocations of - * schedule_work() + * which would lead to more invocations of queue_work() */ return; } @@ -487,7 +486,7 @@ static void ovpn_tcp_write_space(struct sock *sk) rcu_read_lock(); sock = rcu_dereference_sk_user_data(sk); if (likely(sock && sock->peer)) { - schedule_work(&sock->tcp_tx_work); + queue_work(ovpn_wq, &sock->tcp_tx_work); sock->peer->tcp.sk_cb.sk_write_space(sk); } rcu_read_unlock();