From: Jakub Kicinski Date: Wed, 5 Aug 2026 01:15:35 +0000 (-0700) Subject: Merge branch 'net-atlantic-fix-two-ring-teardown-leaks' X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=6310aaadbf405363eba338dfb5568673be11318d;p=thirdparty%2Fkernel%2Flinux.git Merge branch 'net-atlantic-fix-two-ring-teardown-leaks' Yangyu Chen says: ==================== net: atlantic: fix two ring teardown leaks These are the two fixes from the page_pool conversion series [1], resent against net as requested in the review of that series. The page_pool conversion itself stays in net-next and is not part of this posting; it depends on these fixes, but they stand on their own. Both patches are unchanged from [1] apart from the collected Reviewed-by tags, and each carries a Fixes tag and a Cc: stable with the affected range (patch 1: v4.11+, patch 2: v5.2+). They apply and were build- and runtime-tested independently of each other and of the conversion. Patch 1: aq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean() call, which is capped at AQ_CFG_TX_CLEAN_BUDGET descriptors and stops at hw_head, frozen once the hardware and NAPI have been stopped. Everything beyond that keeps its skb or xdp_frame when the interface goes down and is lost when the buffer ring is freed. Patch 2: aq_ring_rx_deinit() only walks [sw_head, sw_tail). Since the page reuse strategy was added, a cleaned RX buffer keeps its page for reuse and refill is batched, so consumed but not yet reposted slots accumulate in the [sw_tail, sw_head) gap and their pages and DMA mappings are never released. Reproduction logs for both leaks (as page_pool stalled shutdowns, which is how they become visible) are in the notes of the respective patches. [1] https://lore.kernel.org/lkml/tencent_1F173E0FC1606D2AC704DC9C98AF10984607@qq.com/ ==================== Link: https://patch.msgid.link/tencent_29B860317921D68DE77C718242DA418EB608@qq.com Signed-off-by: Jakub Kicinski --- 6310aaadbf405363eba338dfb5568673be11318d