batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by
timer_delete() to guard against the timer handler re-arming itself between
the two calls. This double-deletion hack relied on the sending status being
set to 0 to suppress re-arming.

Replace both calls with a single timer_shutdown_sync(). This function both
waits for any running timer callback to complete (like timer_delete_sync())
and permanently disarms the timer so it cannot be re-armed afterwards,
making re-arming prevention unconditional and self-documenting.

Signed-off-by: Sven Eckelmann <[email protected]>
---
 net/batman-adv/tp_meter.c | 8 +-------
 1 file changed, 1 insertion(+), 7 deletions(-)

diff --git a/net/batman-adv/tp_meter.c b/net/batman-adv/tp_meter.c
index 759ae923..d27c3da9 100644
--- a/net/batman-adv/tp_meter.c
+++ b/net/batman-adv/tp_meter.c
@@ -401,13 +401,7 @@ static void batadv_tp_sender_cleanup(struct batadv_tp_vars 
*tp_vars)
        batadv_tp_list_detach(tp_vars);
 
        /* kill the timer and remove its reference */
-       timer_delete_sync(&tp_vars->timer);
-       /* the worker might have rearmed itself therefore we kill it again. Note
-        * that if the worker should run again before invoking the following
-        * timer_delete(), it would not re-arm itself once again because the 
status
-        * is OFF now
-        */
-       timer_delete(&tp_vars->timer);
+       timer_shutdown_sync(&tp_vars->timer);
        batadv_tp_vars_put(tp_vars);
 }
 

---
base-commit: f876964b732393119a036ff1ce7a1c94290b09ed
change-id: 20260510-tp-shutdown-f327c0bc0343

Best regards,
--  
Sven Eckelmann <[email protected]>

Reply via email to