On Tue, 2012-05-22 at 23:23 -0400, David Miller wrote:
From: Yanmin Zhang <redacted>
Date: Wed, 23 May 2012 11:02:03 +0800
quoted
1) Why does free_fib_info call call_rcu instead of releasing fi directly?
I assume other cpu might be accessing it. nexthop_nh->nh_dev is in fi.
If other cpu are accessing it, here resetting to NULL would cause other
cpu panic.
Because fib trie lookups are done with RCU locking, therefore we must
use RCU freeing to release the object.
What I was trying to impart to you is that removing the NULL
assignment is wrong and that an alternative fix is warranted (hint:
consider moving something into the RCU release).
--
Its more than that I'm afraid.
fi->fib_dev (aka fib_nh[0].nh_dev) need full RCU protection.
Also the "fib_info_cnt--;" must stay in free_fib_info() (so that it is
protected by RTNL)