)]}'
{
  "commit": "fbd97dd1d3ce32d32fb7be86acc3fdb7c04fa043",
  "tree": "f41257f69266bb67c1070253c9c36d7a8f9eaa9c",
  "parents": [
    "47f4f695cec1eb82d961fdb466cd7c99d2865b7c"
  ],
  "author": {
    "name": "Alexei Starovoitov",
    "email": "ast@kernel.org",
    "time": "Wed Sep 30 09:59:19 2026 +0000"
  },
  "committer": {
    "name": "Kumar Kartikeya Dwivedi",
    "email": "memxor@gmail.com",
    "time": "Thu Oct 01 18:40:04 2026 +0200"
  },
  "message": "bpf: Fix objects stuck in free_by_rcu_ttrace\n\ndo_call_rcu_ttrace() returns early when call_rcu_ttrace_in_progress is set\nand leaves the objects in free_by_rcu_ttrace. __free_rcu() frees\nwaiting_for_gp_ttrace only and clears the flag. Hence the objects that\nfree_bulk() or __free_by_rcu() added while RCU tasks trace GP was in flight\nstay in free_by_rcu_ttrace until free_bulk() or alloc_bulk() is called for\nthe same bpf_mem_cache again, which may never happen. The number of such\nobjects is not bounded.\n\nTurn call_rcu_ttrace_in_progress into three states:\n0 - idle\n1 - __free_rcu() is queued\n2 - __free_rcu() is queued and free_by_rcu_ttrace got more objects since\n\ndo_call_rcu_ttrace() sets 2. __free_rcu() does cmpxchg(1 -\u003e 0) and starts\nthe next GP when it fails. It cannot clear the flag first and check\nfree_by_rcu_ttrace later, since bpf_mem_alloc_destroy() frees bpf_mem_cache\nwithout waiting for RCU callbacks when the flag is zero.\n\nNow __free_rcu() queues itself, so the one that didn\u0027t see \u0027draining\u0027 may\ndo call_rcu_tasks_trace() after rcu_barrier_tasks_trace() in\nfree_mem_alloc(). Queue it under rcu_read_lock() and do synchronize_rcu()\nbefore the barriers. Calling rcu_barrier_tasks_trace() twice works too, but\ncreating and destroying hash maps in a loop on many cpus slows down to one\nfree_mem_alloc() per GP and kworkers pile up.\n\nFixes: 8d5a8011b35d (\"bpf: Batch call_rcu callbacks instead of SLAB_TYPESAFE_BY_RCU.\")\nSigned-off-by: Alexei Starovoitov \u003cast@kernel.org\u003e\nLink: https://lore.kernel.org/bpf/20260930095920.601738-3-alexei.starovoitov@gmail.com\nSigned-off-by: Kumar Kartikeya Dwivedi \u003cmemxor@gmail.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "08e4dde66cd5283c229636ca33f9689a92106f6f",
      "old_mode": 33188,
      "old_path": "kernel/bpf/memalloc.c",
      "new_id": "15684d0fc883b7048abad0d40e0fa0c728150a7c",
      "new_mode": 33188,
      "new_path": "kernel/bpf/memalloc.c"
    }
  ]
}
