From: Ruijie Li <[email protected]>

batadv_gw_node_free() removes the gateway list entries during mesh teardown,
but it does not clear the currently selected gateway. This leaves stale
gateway state behind across cleanup and can break a later mesh recreation.

Clear bat_priv->gw.curr_gw before walking the gateway list so the selected
gateway reference is dropped as part of teardown.

Fixes: 2265c1410864 ("batman-adv: gateway election code refactoring")
Cc: [email protected]
Reported-by: Yuan Tan <[email protected]>
Reported-by: Yifan Wu <[email protected]>
Reported-by: Juefei Pu <[email protected]>
Reported-by: Xin Liu <[email protected]>
Signed-off-by: Ruijie Li <[email protected]>
Signed-off-by: Zhanpeng Li <[email protected]>
Signed-off-by: Ren Wei <[email protected]>
---
 net/batman-adv/gateway_client.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/net/batman-adv/gateway_client.c b/net/batman-adv/gateway_client.c
index 51e9c081a2a4..a9d0346e8332 100644
--- a/net/batman-adv/gateway_client.c
+++ b/net/batman-adv/gateway_client.c
@@ -478,10 +478,14 @@ void batadv_gw_node_delete(struct batadv_priv *bat_priv,
  */
 void batadv_gw_node_free(struct batadv_priv *bat_priv)
 {
+       struct batadv_gw_node *curr_gw;
        struct batadv_gw_node *gw_node;
        struct hlist_node *node_tmp;
 
        spin_lock_bh(&bat_priv->gw.list_lock);
+       curr_gw = rcu_replace_pointer(bat_priv->gw.curr_gw, NULL, true);
+       batadv_gw_node_put(curr_gw);
+
        hlist_for_each_entry_safe(gw_node, node_tmp,
                                  &bat_priv->gw.gateway_list, list) {
                hlist_del_init_rcu(&gw_node->list);
-- 
2.34.1

Reply via email to