From: sashiko-bot@kernel.org
To: "Arthur Crépin Leblond" <arthur@marmottus.net>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH net-next v3 1/3] dt-bindings: net: wiznet,w5100: convert to DT schema
Date: Fri, 07 Aug 2026 15:00:33 +0000 [thread overview]
Message-ID: <20260807150034.4EEF61F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260806-wiznet-link-gpio-v3-1-532d4a143805@marmottus.net>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] Preexisting module removal race condition: `unregister_netdev()` is called after `destroy_workqueue()`, leading to potential use-after-free.
- [High] Preexisting probe race condition: `register_netdev()` is called too early, exposing the device to userspace before hardware and structures are initialized.
--
--- Patch [1]: [PATCH net-next v3 1/3] dt-bindings: net: wiznet,w5100: convert to DT schema ---
commit 6b1d871923a8b7c229c0db289868ab706e3e28d1
Author: Arthur Crépin Leblond <arthur@marmottus.net>
dt-bindings: net: wiznet,w5100: convert to DT schema
Convert the Wiznet w5x00 SPI Ethernet controller binding from
plain text to DT schema.
> diff --git a/Documentation/devicetree/bindings/net/wiznet,w5100.yaml b/Documentation/devicetree/bindings/net/wiznet,w5100.yaml
> new file mode 100644
> index 0000000000000..641c9ddbde9e7
> --- /dev/null
> +++ b/Documentation/devicetree/bindings/net/wiznet,w5100.yaml
[ ... ]
While reviewing this dt-bindings change, I noticed a couple of pre-existing
issues in the related driver code (drivers/net/ethernet/wiznet/w5100.c)
that might be worth addressing.
drivers/net/ethernet/wiznet/w5100.c:w5100_probe() {
...
err = register_netdev(ndev);
if (err < 0)
goto err_register;
priv->xfer_wq = alloc_workqueue("%s", WQ_MEM_RECLAIM | WQ_PERCPU, 0,
netdev_name(ndev));
...
}
[Severity: High]
This isn't a bug introduced by this patch, but is it safe to call
register_netdev() before fully initializing the device?
If userspace automation brings the interface up immediately after
registration, it could trigger a packet transmission. This would call
w5100_start_tx(), which attempts to queue work to priv->xfer_wq.
Since the workqueue and other hardware structures are initialized after
registration, could this result in a NULL pointer dereference?
drivers/net/ethernet/wiznet/w5100.c:w5100_remove() {
...
flush_work(&priv->setrx_work);
flush_work(&priv->restart_work);
destroy_workqueue(priv->xfer_wq);
unregister_netdev(ndev);
...
}
[Severity: High]
This is a pre-existing issue, but does destroying the workqueue before
calling unregister_netdev() create a race condition during module removal?
The unregister_netdev() function is responsible for safely stopping the
transmission queue and tearing down device visibility. If the workqueue is
destroyed first, there is a window where the network stack can concurrently
call ndo_start_xmit (w5100_start_tx()).
Can this lead to a use-after-free when w5100_start_tx() attempts to queue
work to the destroyed workqueue?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-wiznet-link-gpio-v3-0-532d4a143805@marmottus.net?part=1
next prev parent reply other threads:[~2026-08-07 15:00 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 14:59 [PATCH net-next v3 0/3] w5100: restore GPIO-based link detection Arthur Crépin Leblond
2026-08-06 15:00 ` [PATCH net-next v3 1/3] dt-bindings: net: wiznet,w5100: convert to DT schema Arthur Crépin Leblond
2026-08-07 15:00 ` sashiko-bot [this message]
2026-08-10 7:40 ` Krzysztof Kozlowski
2026-08-06 15:00 ` [PATCH net-next v3 2/3] dt-bindings: net: wiznet,w5100: add link-gpios Arthur Crépin Leblond
2026-08-10 7:43 ` Krzysztof Kozlowski
2026-08-10 7:50 ` Arthur Crépin Leblond
2026-08-10 7:53 ` Arnd Bergmann
2026-08-10 7:59 ` Krzysztof Kozlowski
2026-08-10 8:12 ` Arthur Crépin Leblond
2026-08-10 8:21 ` Krzysztof Kozlowski
2026-08-10 8:25 ` Arnd Bergmann
2026-08-10 8:31 ` Krzysztof Kozlowski
2026-08-10 14:46 ` Arthur Crépin Leblond
2026-08-10 7:55 ` Krzysztof Kozlowski
2026-08-06 15:00 ` [PATCH net-next v3 3/3] w5100: detect carrier state using link status bit Arthur Crépin Leblond
2026-08-07 15:00 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260807150034.4EEF61F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=arthur@marmottus.net \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.