在 2026/9/3 20:32, Xuanqiang Luo 写道:
From: Xuanqiang Luo<[email protected]> mac802154 queues one descriptor per received beacon or MAC command, but each worker invocation dequeues only one. Since queue_work() coalesces attempts to queue the same pending work item, a burst can add more descriptors than scheduled invocations. A later frame may schedule another invocation, but also adds a descriptor, so it does not necessarily reduce the backlog. Descriptors can therefore remain queued indefinitely once reception stops. The RX path, workers, and scan cleanup also access the descriptor lists without common synchronization. A queued descriptor carries its receiving interface beyond the RCU read-side critical section without holding a netdev reference. If the interface is removed first, the worker can dereference freed memory. Protect the descriptor lists with a spinlock and keep the workers running until the queues are empty. Then hold the netdev for the lifetime of each queued descriptor to prevent it from being freed too early. This ordering is required. Without the queue-draining fix, a descriptor stranded by queue_work() coalescing would also strand its netdev reference, as netdev_put() runs only when the descriptor is released, leaving the netdev pinned indefinitely. --- Changes: v2: Patch 1 (new): - Serialize descriptor list access and requeue each worker while another descriptor remains. - Detach queued beacons under the same lock before scan cleanup frees them. Patch 2: - Replace the v1 drain_workqueue() approach, which does not cover work queued after the drain or the DEL_INTERFACE path, with a netdev reference held by each queued descriptor. (Sashiko.) v1:https://lore.kernel.org/all/[email protected]/ Xuanqiang Luo (2): mac802154: serialize and drain queued RX descriptors mac802154: pin netdevs for queued RX descriptors include/net/cfg802154.h | 2 ++ net/mac802154/ieee802154_i.h | 2 ++ net/mac802154/main.c | 1 + net/mac802154/rx.c | 36 ++++++++++++++++++++++++++++++------ net/mac802154/scan.c | 8 +++++++- 5 files changed, 42 insertions(+), 7 deletions(-) base-commit: dc4b95b8fee95113587e93ca116356032d271371
I realized that the issues addressed by this series appear to have already been fixed by: https://lore.kernel.org/all/[email protected]/ I missed that, so please disregard this one. Thanks, pw-bot: rejected

