From: Myeonghun Pak <mhun512@gmail.com>
To: Tony Nguyen <anthony.l.nguyen@intel.com>,
Przemek Kitszel <przemyslaw.kitszel@intel.com>,
intel-wired-lan@lists.osuosl.org
Cc: Milena Olech <milena.olech@intel.com>,
Emil Tantilov <emil.s.tantilov@intel.com>,
Mina Almasry <almasrymina@google.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
Myeonghun Pak <mhun512@gmail.com>, Ijae Kim <ae878000@gmail.com>
Subject: [PATCH v3 net] idpf: disable PTM on probe failure and on remove
Date: Mon, 20 Jul 2026 23:35:10 +0900 [thread overview]
Message-ID: <20260720143511.43408-1-mhun512@gmail.com> (raw)
idpf_probe() enables PCIe Precision Time Measurement with
pci_enable_ptm(), which takes a reference on the device and on every
PTM-capable device up the path to the PTM Root.
Neither the probe error path nor idpf_remove() drops that reference, so
the PTM enable counts of this device and of its upstream path stay
elevated with no bound driver, and the device's PTM control bits remain
set. pcim_enable_device() only arranges for pci_disable_device() and
does not undo the PTM enable.
Add the matching pci_disable_ptm() to the common probe unwind and to
idpf_remove(). pci_enable_ptm() failure is not fatal here, so guard both
calls with pcie_ptm_enabled(): pci_disable_ptm() decrements
dev->ptm_enable_cnt unconditionally and then recurses upstream, so
calling it after a failed enable would drive this device's count negative
and wrongly decrement parents shared with other endpoints.
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: 8d5e12c5921c ("idpf: add initial PTP support")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
---
Changes in v3:
- Rebased; aa8671af0c38 ("PCI/PTM: Drop pci_enable_ptm() granularity
parameter") changed the call signature, so v2 no longer applied.
- Guard both pci_disable_ptm() calls with pcie_ptm_enabled(), as
pci_disable_ptm() is refcounted and recurses upstream since
e1092d5e15e6 ("PCI/PTM: Do not enable PTM automatically for Root and
Switch Upstream Ports"). Raised by Tony Nguyen.
- Dropped the v2 claim that pci_disable_ptm() is a no-op when PTM was not
enabled; that is no longer true.
Changes in v2:
- Disable PTM in the probe error path, as requested by Emil Tantilov.
drivers/net/ethernet/intel/idpf/idpf_main.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/intel/idpf/idpf_main.c b/drivers/net/ethernet/intel/idpf/idpf_main.c
index ab3c409..97bafeb 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_main.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_main.c
@@ -159,6 +159,8 @@ destroy_wqs:
mutex_destroy(&adapter->queue_lock);
mutex_destroy(&adapter->vc_buf_lock);
+ if (pcie_ptm_enabled(pdev))
+ pci_disable_ptm(pdev);
pci_set_drvdata(pdev, NULL);
kfree(adapter);
}
@@ -266,7 +268,7 @@ static int idpf_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
if (err) {
pci_err(pdev, "DMA configuration failed: %pe\n", ERR_PTR(err));
- goto err_free;
+ goto err_disable_ptm;
}
pci_set_master(pdev);
@@ -279,7 +281,7 @@ static int idpf_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
if (!adapter->init_wq) {
dev_err(dev, "Failed to allocate init workqueue\n");
err = -ENOMEM;
- goto err_free;
+ goto err_disable_ptm;
}
adapter->serv_wq = alloc_workqueue("%s-%s-service",
@@ -366,6 +368,9 @@ err_mbx_wq_alloc:
destroy_workqueue(adapter->serv_wq);
err_serv_wq_alloc:
destroy_workqueue(adapter->init_wq);
+err_disable_ptm:
+ if (pcie_ptm_enabled(pdev))
+ pci_disable_ptm(pdev);
err_free:
kfree(adapter);
return err;
--
2.47.1
WARNING: multiple messages have this Message-ID (diff)
From: Myeonghun Pak <mhun512@gmail.com>
To: Tony Nguyen <anthony.l.nguyen@intel.com>,
Przemek Kitszel <przemyslaw.kitszel@intel.com>,
intel-wired-lan@lists.osuosl.org
Cc: Milena Olech <milena.olech@intel.com>,
Emil Tantilov <emil.s.tantilov@intel.com>,
Mina Almasry <almasrymina@google.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
Myeonghun Pak <mhun512@gmail.com>, Ijae Kim <ae878000@gmail.com>
Subject: [Intel-wired-lan] [PATCH v3 net] idpf: disable PTM on probe failure and on remove
Date: Mon, 20 Jul 2026 23:35:10 +0900 [thread overview]
Message-ID: <20260720143511.43408-1-mhun512@gmail.com> (raw)
idpf_probe() enables PCIe Precision Time Measurement with
pci_enable_ptm(), which takes a reference on the device and on every
PTM-capable device up the path to the PTM Root.
Neither the probe error path nor idpf_remove() drops that reference, so
the PTM enable counts of this device and of its upstream path stay
elevated with no bound driver, and the device's PTM control bits remain
set. pcim_enable_device() only arranges for pci_disable_device() and
does not undo the PTM enable.
Add the matching pci_disable_ptm() to the common probe unwind and to
idpf_remove(). pci_enable_ptm() failure is not fatal here, so guard both
calls with pcie_ptm_enabled(): pci_disable_ptm() decrements
dev->ptm_enable_cnt unconditionally and then recurses upstream, so
calling it after a failed enable would drive this device's count negative
and wrongly decrement parents shared with other endpoints.
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: 8d5e12c5921c ("idpf: add initial PTP support")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
---
Changes in v3:
- Rebased; aa8671af0c38 ("PCI/PTM: Drop pci_enable_ptm() granularity
parameter") changed the call signature, so v2 no longer applied.
- Guard both pci_disable_ptm() calls with pcie_ptm_enabled(), as
pci_disable_ptm() is refcounted and recurses upstream since
e1092d5e15e6 ("PCI/PTM: Do not enable PTM automatically for Root and
Switch Upstream Ports"). Raised by Tony Nguyen.
- Dropped the v2 claim that pci_disable_ptm() is a no-op when PTM was not
enabled; that is no longer true.
Changes in v2:
- Disable PTM in the probe error path, as requested by Emil Tantilov.
drivers/net/ethernet/intel/idpf/idpf_main.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/intel/idpf/idpf_main.c b/drivers/net/ethernet/intel/idpf/idpf_main.c
index ab3c409..97bafeb 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_main.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_main.c
@@ -159,6 +159,8 @@ destroy_wqs:
mutex_destroy(&adapter->queue_lock);
mutex_destroy(&adapter->vc_buf_lock);
+ if (pcie_ptm_enabled(pdev))
+ pci_disable_ptm(pdev);
pci_set_drvdata(pdev, NULL);
kfree(adapter);
}
@@ -266,7 +268,7 @@ static int idpf_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
if (err) {
pci_err(pdev, "DMA configuration failed: %pe\n", ERR_PTR(err));
- goto err_free;
+ goto err_disable_ptm;
}
pci_set_master(pdev);
@@ -279,7 +281,7 @@ static int idpf_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
if (!adapter->init_wq) {
dev_err(dev, "Failed to allocate init workqueue\n");
err = -ENOMEM;
- goto err_free;
+ goto err_disable_ptm;
}
adapter->serv_wq = alloc_workqueue("%s-%s-service",
@@ -366,6 +368,9 @@ err_mbx_wq_alloc:
destroy_workqueue(adapter->serv_wq);
err_serv_wq_alloc:
destroy_workqueue(adapter->init_wq);
+err_disable_ptm:
+ if (pcie_ptm_enabled(pdev))
+ pci_disable_ptm(pdev);
err_free:
kfree(adapter);
return err;
--
2.47.1
next reply other threads:[~2026-07-20 14:35 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 14:35 Myeonghun Pak [this message]
2026-07-20 14:35 ` [Intel-wired-lan] [PATCH v3 net] idpf: disable PTM on probe failure and on remove Myeonghun Pak
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720143511.43408-1-mhun512@gmail.com \
--to=mhun512@gmail.com \
--cc=ae878000@gmail.com \
--cc=almasrymina@google.com \
--cc=andrew+netdev@lunn.ch \
--cc=anthony.l.nguyen@intel.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=emil.s.tantilov@intel.com \
--cc=intel-wired-lan@lists.osuosl.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=milena.olech@intel.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=przemyslaw.kitszel@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.