From patchwork Fri Aug 7 07:55:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5213 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:77c3:b0:87d:ab56:3700 with SMTP id r3csp8715366mau; Fri, 7 Aug 2026 00:56:24 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rpsluz7gHUuTVrOeaxYYy2A6bwACTy9sbQDAsFxhl+L0zFAmx+GjoICceWkN6fQ+P88ThATa1mIKgU=@openvpn.net X-Received: by 2002:a05:6830:3592:b0:7e9:e257:81cb with SMTP id 46e09a7af769-7f1e5d34abemr12396256a34.7.1786089384153; Fri, 07 Aug 2026 00:56:24 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1786089384; cv=none; d=google.com; s=arc-20260327; b=IPO8bxb9BjeIzEgt5sABqk2dKpSp2cyoHBMz35G0ahgOmowWgTHFU5bt4jDcoQbVWV qEI12KuFIBwNeil3kGY67zOz07IhxoigQPVQBc93gmtXa1phvEoDZKmcpxVW7PVAfKg0 SKdFQGINWqj6A/50j3PeIpgB5TlZL0eUdEcafZI6WRYFSy6TDf8lz33NQjQg4u3LhTB/ GRRQjcu8liLGL/FHXUTcmvG1/Y7IwB/VVbvOpggsSyRZPa3sv8RfeEAlhNN3he1hQ6/N ar4qvuai77ZSltA1hHP3t7JmqLbyCBh+nZiBsxMkiSvabKIzlolkw0uqyXN4sAuSbRnm PKaA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=xvYxb4BA5zqLDp41BtC5/hlYjWYQFjVRYWnukA9hgiA=; fh=yXAbqwSLX4AZy2IfjuXV6xw9sEGAlDO35mmlrsbkSnM=; b=OtHZybdJljT21SGKCHzvKQH9J/3gnqvKQIk/5xaaWpHSfXEvAZBr0X3D2kdGi852be UVQAcy65AFiF9bZAo1+RACS1z68Dwjulz5SVV3S2dCmRGz6Ggzq5CrODhsN0m8FgtVsI 9UvxNln4oTT6+TN1Klnxm1a6ilV03kXFHjAKVTtBR+P3xnXe33nD9NcIOs3Gxmhps/I7 59iRDifJnKfxOk6V3xubQRYqVueOD1Y01JJf8Grx0IRa8AswULdlAqoPEi05RJ4K2D+H o+qGinHUo5JRGrKywLkFX2NQ0RUFE7PtwZ/9gTMUYtcq5GJZQF+Zaf1hxf/atk2UbE+J K2Ow==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="f/LrcnOM"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=c0SmDwBB; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=hWlU6R13; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=v7ruLxPn; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f35b7a6a26si1060061a34.78.2026.08.07.00.56.23 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 07 Aug 2026 00:56:23 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="f/LrcnOM"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=c0SmDwBB; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=hWlU6R13; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=v7ruLxPn; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=xvYxb4BA5zqLDp41BtC5/hlYjWYQFjVRYWnukA9hgiA=; b=f/LrcnOM7n/cfaC5UjVwDmUbkP 6eQjCdLoiK5AN0nmAXbYYTEGftaarsWJJIf/m3iPfCLclhx5jWcPFzeZ5H9oLL31Nx1b4Y8Q539z6 /svHvzPfbjO+cs+Fp+1+ip8SWBTjRrLo5TKoMoOWr2nNTiea2Ja4vVcXq5XC3G+2Az6k=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wsFR6-000214-PZ; Fri, 07 Aug 2026 07:56:13 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wsFR4-00020w-DM for openvpn-devel@lists.sourceforge.net; Fri, 07 Aug 2026 07:56:12 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=mpYFlVX2ai5KAufKni9yKG+2/4ZkaPQh2+RcObfuaYM=; b=c0SmDwBB6yG22YUFtrYtrmbtCL 2cIEciwasmFQcbnh7RXJRSc2yIm3/h6RCLs6+k+aat2TcUJyhLUQTa5qe4HqJRWtaceXilw0vr+Ru fosX1PRCzftqDR1Zf/6//7SoADDxBxOcC1pOZTOOe8X79drWkyNX5b/qwCxtsHMDbTUc=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=mpYFlVX2ai5KAufKni9yKG+2/4ZkaPQh2+RcObfuaYM=; b=hWlU6R13wUMDQXz7W6poAkpmyb e09E7lDewK8NIqmvbiCLbqrEILe8S4SvUsh/f8U4gwsLZ7uMwh1nvWVEb6tLwaN2KhFvv2eWBoA64 KMKPgkpAq1AN8yOrWjrIIfpR1EmRgrxV3p73JJuiMyBYAa7NvFuWHQm7+jeBtPfe9qkc=; Received: from mout-b-206.mailbox.org ([195.10.208.51]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wsFR6-0007oi-By for openvpn-devel@lists.sourceforge.net; Fri, 07 Aug 2026 07:56:11 +0000 Received: from smtp2.mailbox.org (smtp2.mailbox.org [10.196.197.2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-206.mailbox.org (Postfix) with ESMTPS id 4hGc0J5bMqz8x; Fri, 07 Aug 2026 09:56:00 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1786089360; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mpYFlVX2ai5KAufKni9yKG+2/4ZkaPQh2+RcObfuaYM=; b=v7ruLxPnIukg+prjnazV1siRuJhmJ/5D0Q0XWh72nYaMKqK2dx2J1PbeJWttE4ABqHhmrA X7QNVm2m7W3Qhyc5aA70pNtAxLdtBotbVhXDDLp6QYRdBCDFHQUB5f2YWTIBBhffX8+e4e M9u7Ol4aTxPLw6LMxTLkXJ+JobsIPEqpCAk3RcmVC+WKQa5TV/f1dcYhH2+B7rVOOmYaN/ ApBkX+IFApzHrR1M/EuWQrXJGx1XmMqeQqgaxjcYrYwQRh0E6BRBvhtVdRRdKKq+w+n1V3 izvmNk7C6f1zi8vb7RHehARok6XumKFi/8NQgnhQJN9E0xzm45JfmhPfh4A7vw== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Fri, 7 Aug 2026 09:55:43 +0200 Message-ID: <1ece7178e4ddce746c4dfc972e7bf51ff56ed625.1786088883.git.ralf@mandelbit.com> In-Reply-To: <20260807065253.73909-1-ralf@mandelbit.com> References: <20260807065253.73909-1-ralf@mandelbit.com> MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callba [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.51 listed in wl.mailspike.net] X-Headers-End: 1wsFR6-0007oi-By Subject: [Openvpn-devel] [PATCH ovpn net v7] ovpn: run deferred work on a module-owned workqueue X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044276575105185 X-GMAIL-MSGID: 1872850462116600508 ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callbacks have fully returned before the module text can be freed. Object references protect the objects used by the callbacks, but they do not prove that a workqueue function has returned. In particular, a worker can drop the final reference that unblocks device teardown while it is still executing ovpn code. Add a module-owned workqueue and queue all ovpn work items on it. During module exit, unregister rtnl and netlink first, flush the workqueue so ordinary ovpn workers finish, run the final RCU barrier, and destroy the workqueue last. This keeps the workqueue available for cleanup work queued from RCU callbacks, while ensuring no ovpn work item can outlive the module text. The per-device delayed keepalive work remains explicitly disabled during netdev teardown (disable_delayed_work_sync in ndo_uninit), since flush_workqueue does not flush delayed work that is still only pending on its timer. Fixes: 3ecfd9349f40 ("ovpn: implement keepalive mechanism") Fixes: 11851cbd60ea ("ovpn: implement TCP transport") Signed-off-by: Ralf Lici --- Changes since v6 https://lore.kernel.org/openvpn-devel/51a8febf0da1fe17e5fc0b857e8d0a8797002ea2.1785318038.git.ralf@mandelbit.com/ - Pass WQ_PERCPU to alloc_workqueue to satisfy the new workqueue API contract (syzbot). Changes since v5 https://lore.kernel.org/openvpn-devel/d530ecfc3719845075fbddd0cd7c34752bc2ce16.1783336121.git.ralf@mandelbit.com/ - Update the module-exit ordering for the queue_rcu_work-based key-slot release: flush ordinary ovpn work before rcu_barrier, then destroy the workqueue after RCU callbacks have queued their cleanup work. Changes since v4 https://lore.kernel.org/openvpn-devel/6edfcc51e0855bfd34286b86d4e7f26bb3bcd3f7.1783099626.git.ralf@mandelbit.com/ - Rebase on the pending keepalive and TCP deferred-work refcount fixes, preserving their hold-before-queue and queue-failure put handling when converting schedule_work to queue_work. Changes since v3 https://lore.kernel.org/openvpn-devel/49f38f89340e18ed30543d3990a7a7e20595b6af.1783080055.git.ralf@mandelbit.com/ - Replace the RCU-deferred peer netdev reference release with a module-owned workqueue that drains all ovpn work callbacks before module text can be freed. drivers/net/ovpn/main.c | 19 ++++++++++++++++++- drivers/net/ovpn/ovpnpriv.h | 4 ++++ drivers/net/ovpn/peer.c | 8 ++++---- drivers/net/ovpn/tcp.c | 9 ++++----- 4 files changed, 30 insertions(+), 10 deletions(-) diff --git a/drivers/net/ovpn/main.c b/drivers/net/ovpn/main.c index 168cfe9b59a9..0708249e9607 100644 --- a/drivers/net/ovpn/main.c +++ b/drivers/net/ovpn/main.c @@ -12,6 +12,7 @@ #include #include #include +#include #include #include #include @@ -26,6 +27,9 @@ #include "tcp.h" #include "udp.h" +/* module-owned workqueue on which all ovpn-specific work is queued */ +struct workqueue_struct *ovpn_wq; + static void ovpn_priv_free(struct net_device *net) { struct ovpn_priv *ovpn = netdev_priv(net); @@ -264,10 +268,16 @@ static int __init ovpn_init(void) ovpn_tcp_init(); + ovpn_wq = alloc_workqueue("ovpn", WQ_PERCPU, 0); + if (!ovpn_wq) { + pr_err("ovpn: cannot allocate workqueue\n"); + return -ENOMEM; + } + err = rtnl_link_register(&ovpn_link_ops); if (err) { pr_err("ovpn: can't register rtnl link ops: %d\n", err); - return err; + goto destroy_wq; } err = ovpn_nl_register(); @@ -280,6 +290,9 @@ static int __init ovpn_init(void) unreg_rtnl: rtnl_link_unregister(&ovpn_link_ops); +destroy_wq: + destroy_workqueue(ovpn_wq); + ovpn_wq = NULL; return err; } @@ -288,7 +301,11 @@ static __exit void ovpn_cleanup(void) ovpn_nl_unregister(); rtnl_link_unregister(&ovpn_link_ops); + flush_workqueue(ovpn_wq); rcu_barrier(); + + destroy_workqueue(ovpn_wq); + ovpn_wq = NULL; } module_init(ovpn_init); diff --git a/drivers/net/ovpn/ovpnpriv.h b/drivers/net/ovpn/ovpnpriv.h index 5898f6adada7..84499140e4bd 100644 --- a/drivers/net/ovpn/ovpnpriv.h +++ b/drivers/net/ovpn/ovpnpriv.h @@ -15,6 +15,10 @@ #include #include +struct workqueue_struct; + +extern struct workqueue_struct *ovpn_wq; + /** * struct ovpn_peer_collection - container of peers for MultiPeer mode * @by_id: table of peers index by ID diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index b0519f9840d8..c95656ca7c35 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -62,7 +62,7 @@ void ovpn_peer_keepalive_set(struct ovpn_peer *peer, u32 interval, u32 timeout) /* now that interval and timeout have been changed, kick * off the worker so that the next delay can be recomputed */ - mod_delayed_work(system_percpu_wq, &peer->ovpn->keepalive_work, 0); + mod_delayed_work(ovpn_wq, &peer->ovpn->keepalive_work, 0); } /** @@ -1371,7 +1371,7 @@ static time64_t ovpn_peer_keepalive_work_single(struct ovpn_peer *peer, peer->id); if (WARN_ON(!ovpn_peer_hold(peer))) return 0; - if (!schedule_work(&peer->keepalive_work)) + if (!queue_work(ovpn_wq, &peer->keepalive_work)) ovpn_peer_put(peer); } @@ -1463,8 +1463,8 @@ void ovpn_peer_keepalive_work(struct work_struct *work) netdev_dbg(ovpn->dev, "scheduling keepalive work: now=%llu next_run=%llu delta=%llu\n", next_run, now, next_run - now); - schedule_delayed_work(&ovpn->keepalive_work, - (next_run - now) * HZ); + queue_delayed_work(ovpn_wq, &ovpn->keepalive_work, + (next_run - now) * HZ); } unlock_ovpn(ovpn, &release_list); } diff --git a/drivers/net/ovpn/tcp.c b/drivers/net/ovpn/tcp.c index 0af14055c39a..8fe8a8e750a4 100644 --- a/drivers/net/ovpn/tcp.c +++ b/drivers/net/ovpn/tcp.c @@ -151,7 +151,7 @@ static void ovpn_tcp_rcv(struct strparser *strp, struct sk_buff *skb) /* take reference for deferred peer deletion. should never fail */ if (WARN_ON(!ovpn_peer_hold(peer))) goto err_nopeer; - if (!schedule_work(&peer->tcp.defer_del_work)) + if (!queue_work(ovpn_wq, &peer->tcp.defer_del_work)) ovpn_peer_put(peer); ovpn_dev_dstats_rx_dropped(peer->ovpn->dev); err_nopeer: @@ -284,13 +284,12 @@ static void ovpn_tcp_send_sock(struct ovpn_peer *peer, struct sock *sk) * stream therefore we abort the connection */ ovpn_peer_hold(peer); - if (!schedule_work(&peer->tcp.defer_del_work)) + if (!queue_work(ovpn_wq, &peer->tcp.defer_del_work)) ovpn_peer_put(peer); /* we bail out immediately and keep tx_in_progress set * to true. This way we prevent more TX attempts - * which would lead to more invocations of - * schedule_work() + * which would lead to more invocations of queue_work() */ return; } @@ -487,7 +486,7 @@ static void ovpn_tcp_write_space(struct sock *sk) rcu_read_lock(); sock = rcu_dereference_sk_user_data(sk); if (likely(sock && sock->peer)) { - schedule_work(&sock->tcp_tx_work); + queue_work(ovpn_wq, &sock->tcp_tx_work); sock->peer->tcp.sk_cb.sk_write_space(sk); } rcu_read_unlock();