All of lore.kernel.org
 help / color / mirror / Atom feed
* FAILED: patch "[PATCH] net: ravb: serialize PTP clock teardown" failed to apply to 5.10-stable tree
@ 2026-09-03 15:07 gregkh
  2026-09-09 17:55 ` [PATCH 5.10.y 1/4] net: ravb: Switch to SYSTEM_SLEEP_PM_OPS()/RUNTIME_PM_OPS() and pm_ptr() Sasha Levin
  0 siblings, 1 reply; 5+ messages in thread
From: gregkh @ 2026-09-03 15:07 UTC (permalink / raw)
  To: luoxuanqiang, kuba; +Cc: stable


The patch below does not apply to the 5.10-stable tree.
If someone wants it applied there, or to any other stable or longterm
tree, then please email the backport, including the original git commit
id to <stable@vger.kernel.org>.

To reproduce the conflict and resubmit, you may use the following commands:

git fetch https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/ linux-5.10.y
git checkout FETCH_HEAD
git cherry-pick -x 1cb9663789c5b7a12fcd419fcca6d6254c398252
# <resolve conflicts, build, test, etc.>
git commit -s
git send-email --to '<stable@vger.kernel.org>' --in-reply-to '2026090334-visor-renewed-f29f@gregkh' --subject-prefix 'PATCH 5.10.y' 'HEAD^..'

Possible dependencies:



thanks,

greg k-h

------------------ original commit in Linus's tree ------------------

From 1cb9663789c5b7a12fcd419fcca6d6254c398252 Mon Sep 17 00:00:00 2001
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Date: Tue, 11 Aug 2026 18:37:33 +0800
Subject: [PATCH] net: ravb: serialize PTP clock teardown

ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to
ptp_clock_event() while ptp_clock_unregister() is freeing it. This can
lead to a use-after-free.

Use READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer.
Atomically detach it with xchg() before disabling PTP interrupts, then
synchronize all IRQs which can invoke ravb_ptp_interrupt() before
unregistering the detached clock.

A handler which read the old pointer completes before the clock is
unregistered, while later handlers read NULL and skip the event.

Fixes: a0d2f20650e8 ("Renesas Ethernet AVB PTP clock driver")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260811103733.62599-3-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/drivers/net/ethernet/renesas/ravb.h b/drivers/net/ethernet/renesas/ravb.h
index 2a4fcb12a63c..3ee4c6108189 100644
--- a/drivers/net/ethernet/renesas/ravb.h
+++ b/drivers/net/ethernet/renesas/ravb.h
@@ -1124,6 +1124,8 @@ struct ravb_private {
 	int msg_enable;
 	int speed;
 	int emac_irq;
+	int err_irq;
+	int mgmt_irq;
 
 	unsigned no_avb_link:1;
 	unsigned avb_link_active_low:1;
diff --git a/drivers/net/ethernet/renesas/ravb_main.c b/drivers/net/ethernet/renesas/ravb_main.c
index db0229e00849..ea1c7e536791 100644
--- a/drivers/net/ethernet/renesas/ravb_main.c
+++ b/drivers/net/ethernet/renesas/ravb_main.c
@@ -2885,11 +2885,13 @@ static int ravb_setup_irqs(struct ravb_private *priv)
 		return error;
 
 	if (info->err_mgmt_irqs) {
-		error = ravb_setup_irq(priv, "err_a", "err_a", NULL, ravb_multi_interrupt);
+		error = ravb_setup_irq(priv, "err_a", "err_a", &priv->err_irq,
+				       ravb_multi_interrupt);
 		if (error)
 			return error;
 
-		error = ravb_setup_irq(priv, "mgmt_a", "mgmt_a", NULL, ravb_multi_interrupt);
+		error = ravb_setup_irq(priv, "mgmt_a", "mgmt_a", &priv->mgmt_irq,
+				       ravb_multi_interrupt);
 		if (error)
 			return error;
 	}
diff --git a/drivers/net/ethernet/renesas/ravb_ptp.c b/drivers/net/ethernet/renesas/ravb_ptp.c
index cbec7c057d71..43218bc15b15 100644
--- a/drivers/net/ethernet/renesas/ravb_ptp.c
+++ b/drivers/net/ethernet/renesas/ravb_ptp.c
@@ -289,16 +289,17 @@ static const struct ptp_clock_info ravb_ptp_info = {
 void ravb_ptp_interrupt(struct net_device *ndev)
 {
 	struct ravb_private *priv = netdev_priv(ndev);
+	struct ptp_clock *clock = READ_ONCE(priv->ptp.clock);
 	u32 gis = ravb_read(ndev, GIS);
 
 	gis &= ravb_read(ndev, GIC);
-	if (gis & GIS_PTCF) {
+	if ((gis & GIS_PTCF) && clock) {
 		struct ptp_clock_event event;
 
 		event.type = PTP_CLOCK_EXTTS;
 		event.index = 0;
 		event.timestamp = ravb_read(ndev, GCPT);
-		ptp_clock_event(priv->ptp.clock, &event);
+		ptp_clock_event(clock, &event);
 	}
 	if (gis & GIS_PTMF) {
 		struct ravb_ptp_perout *perout = priv->ptp.perout;
@@ -334,19 +335,39 @@ void ravb_ptp_init(struct net_device *ndev, struct platform_device *pdev)
 		clock = NULL;
 	}
 
-	priv->ptp.clock = clock;
+	WRITE_ONCE(priv->ptp.clock, clock);
 	if (clock)
 		WRITE_ONCE(priv->ptp.phc_index, ptp_clock_index(clock));
 }
 
+static void ravb_ptp_disable(struct net_device *ndev)
+{
+	ravb_write(ndev, 0, GIC);
+	ravb_write(ndev, 0, GIS);
+}
+
+static void ravb_ptp_sync_irqs(struct net_device *ndev)
+{
+	struct ravb_private *priv = netdev_priv(ndev);
+
+	synchronize_irq(ndev->irq);
+	if (priv->info->err_mgmt_irqs) {
+		synchronize_irq(priv->err_irq);
+		synchronize_irq(priv->mgmt_irq);
+	}
+}
+
 void ravb_ptp_stop(struct net_device *ndev)
 {
 	struct ravb_private *priv = netdev_priv(ndev);
-
-	ravb_write(ndev, 0, GIC);
-	ravb_write(ndev, 0, GIS);
+	struct ptp_clock *clock;
 
 	WRITE_ONCE(priv->ptp.phc_index, -1);
-	if (priv->ptp.clock)
-		ptp_clock_unregister(priv->ptp.clock);
+	clock = xchg(&priv->ptp.clock, NULL);
+
+	ravb_ptp_disable(ndev);
+	ravb_ptp_sync_irqs(ndev);
+
+	if (clock)
+		ptp_clock_unregister(clock);
 }


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 5.10.y 1/4] net: ravb: Switch to SYSTEM_SLEEP_PM_OPS()/RUNTIME_PM_OPS() and pm_ptr()
  2026-09-03 15:07 FAILED: patch "[PATCH] net: ravb: serialize PTP clock teardown" failed to apply to 5.10-stable tree gregkh
@ 2026-09-09 17:55 ` Sasha Levin
  2026-09-09 17:55   ` [PATCH 5.10.y 2/4] net: ravb: avoid dereferencing an invalid PTP clock Sasha Levin
                     ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Sasha Levin @ 2026-09-09 17:55 UTC (permalink / raw)
  To: stable
  Cc: Claudiu Beznea, Sergey Shtylyov, Geert Uytterhoeven, Paolo Abeni,
	Sasha Levin

From: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>

[ Upstream commit 6ccc22a5afcbac46d55866d72eaba22f43491c00 ]

SET_SYSTEM_SLEEP_PM_OPS() and SET_RUNTIME_PM_OPS() are deprecated now
and require __maybe_unused protection against unused function warnings.
The usage of pm_ptr() and SYSTEM_SLEEP_PM_OPS()/RUNTIME_PM_OPS() allows
the compiler to see the functions, thus suppressing the warning. Thus
drop the __maybe_unused markings.

Signed-off-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
Reviewed-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Stable-dep-of: 1cb9663789c5 ("net: ravb: serialize PTP clock teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/renesas/ravb_main.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/drivers/net/ethernet/renesas/ravb_main.c b/drivers/net/ethernet/renesas/ravb_main.c
index 3e131788a4a3c..172b05b7f594b 100644
--- a/drivers/net/ethernet/renesas/ravb_main.c
+++ b/drivers/net/ethernet/renesas/ravb_main.c
@@ -2341,7 +2341,7 @@ static int ravb_wol_restore(struct net_device *ndev)
 	return disable_irq_wake(priv->emac_irq);
 }
 
-static int __maybe_unused ravb_suspend(struct device *dev)
+static int ravb_suspend(struct device *dev)
 {
 	struct net_device *ndev = dev_get_drvdata(dev);
 	struct ravb_private *priv = netdev_priv(ndev);
@@ -2360,7 +2360,7 @@ static int __maybe_unused ravb_suspend(struct device *dev)
 	return ret;
 }
 
-static int __maybe_unused ravb_resume(struct device *dev)
+static int ravb_resume(struct device *dev)
 {
 	struct net_device *ndev = dev_get_drvdata(dev);
 	struct ravb_private *priv = netdev_priv(ndev);
@@ -2408,7 +2408,7 @@ static int __maybe_unused ravb_resume(struct device *dev)
 	return ret;
 }
 
-static int __maybe_unused ravb_runtime_nop(struct device *dev)
+static int ravb_runtime_nop(struct device *dev)
 {
 	/* Runtime PM callback shared between ->runtime_suspend()
 	 * and ->runtime_resume(). Simply returns success.
@@ -2421,8 +2421,8 @@ static int __maybe_unused ravb_runtime_nop(struct device *dev)
 }
 
 static const struct dev_pm_ops ravb_dev_pm_ops = {
-	SET_SYSTEM_SLEEP_PM_OPS(ravb_suspend, ravb_resume)
-	SET_RUNTIME_PM_OPS(ravb_runtime_nop, ravb_runtime_nop, NULL)
+	SYSTEM_SLEEP_PM_OPS(ravb_suspend, ravb_resume)
+	RUNTIME_PM_OPS(ravb_runtime_nop, ravb_runtime_nop, NULL)
 };
 
 static struct platform_driver ravb_driver = {
@@ -2430,7 +2430,7 @@ static struct platform_driver ravb_driver = {
 	.remove		= ravb_remove,
 	.driver = {
 		.name	= "ravb",
-		.pm	= &ravb_dev_pm_ops,
+		.pm	= pm_ptr(&ravb_dev_pm_ops),
 		.of_match_table = ravb_match_table,
 	},
 };
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 5.10.y 2/4] net: ravb: avoid dereferencing an invalid PTP clock
  2026-09-09 17:55 ` [PATCH 5.10.y 1/4] net: ravb: Switch to SYSTEM_SLEEP_PM_OPS()/RUNTIME_PM_OPS() and pm_ptr() Sasha Levin
@ 2026-09-09 17:55   ` Sasha Levin
  2026-09-09 17:55   ` [PATCH 5.10.y 3/4] net: ravb: serialize PTP clock teardown Sasha Levin
  2026-09-09 17:55   ` [PATCH 5.10.y 4/4] [AUTOMATED CONFLICT RESOLUTION] Documentation for 1cb9663789c5b7a12fcd419fcca6d6254c398252 Sasha Levin
  2 siblings, 0 replies; 5+ messages in thread
From: Sasha Levin @ 2026-09-09 17:55 UTC (permalink / raw)
  To: stable; +Cc: Xuanqiang Luo, Vadim Fedorenko, Jakub Kicinski

From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>

The PTP clock is unavailable before the first open, so querying its
index can dereference a NULL pointer. Registration failures can also
leave an error pointer in priv->ptp.clock.

Cache the PHC index separately and report -1 while no clock is
registered. Normalize registration errors to NULL and preserve the
static timestamping capabilities.

Fixes: a0d2f20650e8 ("Renesas Ethernet AVB PTP clock driver")
Cc: stable@vger.kernel.org
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260811103733.62599-2-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
 drivers/net/ethernet/renesas/ravb.h      |  1 +
 drivers/net/ethernet/renesas/ravb_main.c |  3 ++-
 drivers/net/ethernet/renesas/ravb_ptp.c  | 15 +++++++++++++--
 3 files changed, 16 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/renesas/ravb.h b/drivers/net/ethernet/renesas/ravb.h
index 7453b17a37a2c..e41e25cdbffea 100644
--- a/drivers/net/ethernet/renesas/ravb.h
+++ b/drivers/net/ethernet/renesas/ravb.h
@@ -978,6 +978,7 @@ struct ravb_ptp_perout {
 struct ravb_ptp {
 	struct ptp_clock *clock;
 	struct ptp_clock_info info;
+	int phc_index;
 	u32 default_addend;
 	u32 current_addend;
 	int extts[N_EXT_TS];
diff --git a/drivers/net/ethernet/renesas/ravb_main.c b/drivers/net/ethernet/renesas/ravb_main.c
index 172b05b7f594b..0cb339359f995 100644
--- a/drivers/net/ethernet/renesas/ravb_main.c
+++ b/drivers/net/ethernet/renesas/ravb_main.c
@@ -1270,7 +1270,7 @@ static int ravb_get_ts_info(struct net_device *ndev,
 		(1 << HWTSTAMP_FILTER_NONE) |
 		(1 << HWTSTAMP_FILTER_PTP_V2_L2_EVENT) |
 		(1 << HWTSTAMP_FILTER_ALL);
-	info->phc_index = ptp_clock_index(priv->ptp.clock);
+	info->phc_index = READ_ONCE(priv->ptp.phc_index);
 
 	return 0;
 }
@@ -2119,6 +2119,7 @@ static int ravb_probe(struct platform_device *pdev)
 	priv = netdev_priv(ndev);
 	priv->ndev = ndev;
 	priv->pdev = pdev;
+	priv->ptp.phc_index = -1;
 	priv->num_tx_ring[RAVB_BE] = BE_TX_RING_SIZE;
 	priv->num_rx_ring[RAVB_BE] = BE_RX_RING_SIZE;
 	priv->num_tx_ring[RAVB_NC] = NC_TX_RING_SIZE;
diff --git a/drivers/net/ethernet/renesas/ravb_ptp.c b/drivers/net/ethernet/renesas/ravb_ptp.c
index 6984bd5b7da91..66cd690af54b0 100644
--- a/drivers/net/ethernet/renesas/ravb_ptp.c
+++ b/drivers/net/ethernet/renesas/ravb_ptp.c
@@ -330,6 +330,7 @@ void ravb_ptp_interrupt(struct net_device *ndev)
 void ravb_ptp_init(struct net_device *ndev, struct platform_device *pdev)
 {
 	struct ravb_private *priv = netdev_priv(ndev);
+	struct ptp_clock *clock;
 	unsigned long flags;
 
 	priv->ptp.info = ravb_ptp_info;
@@ -342,7 +343,15 @@ void ravb_ptp_init(struct net_device *ndev, struct platform_device *pdev)
 	ravb_modify(ndev, GCCR, GCCR_TCSS, GCCR_TCSS_ADJGPTP);
 	spin_unlock_irqrestore(&priv->lock, flags);
 
-	priv->ptp.clock = ptp_clock_register(&priv->ptp.info, &pdev->dev);
+	clock = ptp_clock_register(&priv->ptp.info, &pdev->dev);
+	if (IS_ERR(clock)) {
+		netdev_err(ndev, "failed to register PTP clock: %pe\n", clock);
+		clock = NULL;
+	}
+
+	priv->ptp.clock = clock;
+	if (clock)
+		WRITE_ONCE(priv->ptp.phc_index, ptp_clock_index(clock));
 }
 
 void ravb_ptp_stop(struct net_device *ndev)
@@ -352,5 +361,7 @@ void ravb_ptp_stop(struct net_device *ndev)
 	ravb_write(ndev, 0, GIC);
 	ravb_write(ndev, 0, GIS);
 
-	ptp_clock_unregister(priv->ptp.clock);
+	WRITE_ONCE(priv->ptp.phc_index, -1);
+	if (priv->ptp.clock)
+		ptp_clock_unregister(priv->ptp.clock);
 }
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 5.10.y 3/4] net: ravb: serialize PTP clock teardown
  2026-09-09 17:55 ` [PATCH 5.10.y 1/4] net: ravb: Switch to SYSTEM_SLEEP_PM_OPS()/RUNTIME_PM_OPS() and pm_ptr() Sasha Levin
  2026-09-09 17:55   ` [PATCH 5.10.y 2/4] net: ravb: avoid dereferencing an invalid PTP clock Sasha Levin
@ 2026-09-09 17:55   ` Sasha Levin
  2026-09-09 17:55   ` [PATCH 5.10.y 4/4] [AUTOMATED CONFLICT RESOLUTION] Documentation for 1cb9663789c5b7a12fcd419fcca6d6254c398252 Sasha Levin
  2 siblings, 0 replies; 5+ messages in thread
From: Sasha Levin @ 2026-09-09 17:55 UTC (permalink / raw)
  To: stable; +Cc: Xuanqiang Luo, Jakub Kicinski, Sasha Levin

From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>

[ Upstream commit 1cb9663789c5b7a12fcd419fcca6d6254c398252 ]

ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to
ptp_clock_event() while ptp_clock_unregister() is freeing it. This can
lead to a use-after-free.

Use READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer.
Atomically detach it with xchg() before disabling PTP interrupts, then
synchronize all IRQs which can invoke ravb_ptp_interrupt() before
unregistering the detached clock.

A handler which read the old pointer completes before the clock is
unregistered, while later handlers read NULL and skip the event.

Fixes: a0d2f20650e8 ("Renesas Ethernet AVB PTP clock driver")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260811103733.62599-3-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ adapted IRQ synchronization to use only ndev->irq within the existing ravb_ptp_stop(). ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/renesas/ravb_ptp.c | 17 +++++++++++------
 1 file changed, 11 insertions(+), 6 deletions(-)

diff --git a/drivers/net/ethernet/renesas/ravb_ptp.c b/drivers/net/ethernet/renesas/ravb_ptp.c
index 66cd690af54b0..bcbcce4a0ee5f 100644
--- a/drivers/net/ethernet/renesas/ravb_ptp.c
+++ b/drivers/net/ethernet/renesas/ravb_ptp.c
@@ -304,16 +304,17 @@ static const struct ptp_clock_info ravb_ptp_info = {
 void ravb_ptp_interrupt(struct net_device *ndev)
 {
 	struct ravb_private *priv = netdev_priv(ndev);
+	struct ptp_clock *clock = READ_ONCE(priv->ptp.clock);
 	u32 gis = ravb_read(ndev, GIS);
 
 	gis &= ravb_read(ndev, GIC);
-	if (gis & GIS_PTCF) {
+	if ((gis & GIS_PTCF) && clock) {
 		struct ptp_clock_event event;
 
 		event.type = PTP_CLOCK_EXTTS;
 		event.index = 0;
 		event.timestamp = ravb_read(ndev, GCPT);
-		ptp_clock_event(priv->ptp.clock, &event);
+		ptp_clock_event(clock, &event);
 	}
 	if (gis & GIS_PTMF) {
 		struct ravb_ptp_perout *perout = priv->ptp.perout;
@@ -349,7 +350,7 @@ void ravb_ptp_init(struct net_device *ndev, struct platform_device *pdev)
 		clock = NULL;
 	}
 
-	priv->ptp.clock = clock;
+	WRITE_ONCE(priv->ptp.clock, clock);
 	if (clock)
 		WRITE_ONCE(priv->ptp.phc_index, ptp_clock_index(clock));
 }
@@ -357,11 +358,15 @@ void ravb_ptp_init(struct net_device *ndev, struct platform_device *pdev)
 void ravb_ptp_stop(struct net_device *ndev)
 {
 	struct ravb_private *priv = netdev_priv(ndev);
+	struct ptp_clock *clock;
+
+	WRITE_ONCE(priv->ptp.phc_index, -1);
+	clock = xchg(&priv->ptp.clock, NULL);
 
 	ravb_write(ndev, 0, GIC);
 	ravb_write(ndev, 0, GIS);
+	synchronize_irq(ndev->irq);
 
-	WRITE_ONCE(priv->ptp.phc_index, -1);
-	if (priv->ptp.clock)
-		ptp_clock_unregister(priv->ptp.clock);
+	if (clock)
+		ptp_clock_unregister(clock);
 }
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 5.10.y 4/4] [AUTOMATED CONFLICT RESOLUTION] Documentation for 1cb9663789c5b7a12fcd419fcca6d6254c398252
  2026-09-09 17:55 ` [PATCH 5.10.y 1/4] net: ravb: Switch to SYSTEM_SLEEP_PM_OPS()/RUNTIME_PM_OPS() and pm_ptr() Sasha Levin
  2026-09-09 17:55   ` [PATCH 5.10.y 2/4] net: ravb: avoid dereferencing an invalid PTP clock Sasha Levin
  2026-09-09 17:55   ` [PATCH 5.10.y 3/4] net: ravb: serialize PTP clock teardown Sasha Levin
@ 2026-09-09 17:55   ` Sasha Levin
  2 siblings, 0 replies; 5+ messages in thread
From: Sasha Levin @ 2026-09-09 17:55 UTC (permalink / raw)
  To: stable; +Cc: Sasha Levin

This commit documents the automated conflict resolution performed by codex
for upstream commit 1cb9663789c5b7a12fcd419fcca6d6254c398252.

codex's resolution process:
================================================================================
Resolved and committed as **`12b10225f2d26`** — `net: ravb: serialize PTP clock teardown`.

The conflicts came from upstream driver infrastructure absent in Linux 5.10:

- **IRQ handling:** This branch has no separate error/management IRQs or `ravb_setup_irqs()`. Both PTP interrupt paths use `ndev->irq`, so synchronizing that IRQ covers them. The newer IRQ fields and setup changes were unnecessary.
- **Helper functions:** Kept interrupt disabling and synchronization inside the existing `ravb_ptp_stop()`. No functions were added.
- **Clock-index prerequisite:** Backported upstream `1f77af0aaf27` as **`f9b9c59b95a72`**, with minor context adjustments. It caches the PHC index and handles registration errors, preventing ethtool from dereferencing the clock pointer after teardown clears it.

The teardown preserves upstream’s sequence: atomically detach the clock, disable PTP interrupts, wait for existing handlers, then unregister the saved clock. Later handlers see `NULL` and skip clock events. The teardown commit itself changes one file, with 11 insertions and 6 deletions.

Both commits retain their **exact original messages, authors, and author dates**. No custom fixup commits were created.

After committing, I ran **`stable build log` and waited for completion**. Both x86_64 and arm64 builds passed with **zero warnings and errors**. The working tree is clean.

[Build log](/home/sasha/tmp/stable-parse-fail-5.10-1788974275-build.log)
================================================================================

Backport verification analysis (via codex):
================================================================================
**The backport is correct for this branch. I found no code defects introduced by the conflict resolution and would accept `107f357e539c9f6787ec17d543d74b4d65e5fb4a` together with its prerequisite, `f9b9c59b95a72`.** The omitted IRQ changes are justified by the older driver’s actual interrupt wiring.

I compared the committed sources, inspected every caller of `ravb_ptp_interrupt()` and `ravb_ptp_stop()`, checked the prerequisite against upstream, and reviewed the supplied build log. There are a few documentation and validation qualifications described below.

The upstream fix’s lifetime protection is preserved completely. The backport’s [teardown implementation](/home/sasha/tmp/stable-parse-fail-5.10-1788974275/drivers/net/ethernet/renesas/ravb_ptp.c:358) performs these operations in order:

1. Set the cached PHC index to `-1`.
2. Atomically replace `priv->ptp.clock` with `NULL`, retaining the previous pointer locally.
3. Disable PTP interrupts and clear their status using the existing `GIC` and `GIS` writes.
4. Wait for handlers on `ndev->irq` to finish.
5. Unregister the saved clock, if present.

That sequence closes both sides of the reported race. A handler that already obtained the old pointer finishes before unregistration can free the clock. A later handler obtains `NULL` and skips `ptp_clock_event()`.

The [interrupt handler](/home/sasha/tmp/stable-parse-fail-5.10-1788974275/drivers/net/ethernet/renesas/ravb_ptp.c:304) reads the pointer once with `READ_ONCE()`, checks that local value, and passes that same value to `ptp_clock_event()`. This avoids checking one pointer value and subsequently using another. Initialization publishes the pointer with `WRITE_ONCE()`.

The synchronization is essential: `READ_ONCE()`, `WRITE_ONCE()`, and pointer detachment alone would not protect a handler that had already captured the old pointer. The backport includes the required wait before unregistration.

I also compared the resulting function bodies mechanically: `ravb_ptp_interrupt()` and `ravb_ptp_init()` are identical to upstream. After expanding upstream’s two helpers and removing the unsupported additional IRQ branch, `ravb_ptp_stop()` is equivalent apart from whitespace.

The differences shown by the comparison script are justified as follows:

| Difference | Assessment |
|---|---|
| Omission of `err_irq` and `mgmt_irq` fields | Correct. This branch has no separately registered error/management IRQs that need these fields. |
| Omission of changes to `ravb_setup_irqs()` | Correct. This branch requests interrupts through `ravb_open()` and `ravb_hook_irq()` instead. |
| Synchronizing only `ndev->irq` | Sufficient for every current caller of `ravb_ptp_interrupt()` in this tree. |
| Keeping disabling and synchronization inside `ravb_ptp_stop()` | Behaviorally equivalent. The upstream helpers do not provide additional locking or lifetime protection themselves. |
| Separate PHC-index prerequisite | Appropriate and necessary to preserve safe handling of clock availability and registration failures. |

The IRQ conclusion is supported by both the handler bodies and their [registration sites](/home/sasha/tmp/stable-parse-fail-5.10-1788974275/drivers/net/ethernet/renesas/ravb_main.c:1334):

| Driver path | Handler that invokes PTP processing | Registered IRQ |
|---|---|---|
| R-Car Gen2 | `ravb_interrupt()` | `ndev->irq`, requested with `IRQF_SHARED` |
| R-Car Gen3 | `ravb_multi_interrupt()` | `ndev->irq`, obtained from the `"ch22"` resource |

These are the only two callers of `ravb_ptp_interrupt()`. The separately registered E-MAC and RX/TX queue handlers do not invoke it or access the PTP clock pointer. Upstream additionally registers `ravb_multi_interrupt()` on `"err_a"` and `"mgmt_a"` for hardware supporting that arrangement; this older branch does not.

Therefore, the backport synchronizes **all relevant IRQ handlers**, despite synchronizing fewer IRQ numbers than upstream. Adding unused fields would not improve coverage.

The prerequisite was also resolved correctly. Comparing `f9b9c59b95a72` against upstream `1f77af0aaf27`, the added and removed lines match after accounting for indentation; the surrounding older-driver context explains the differences.

Its effects are preserved:

- The cached `phc_index` starts at `-1`.
- Successful registration publishes the clock’s index.
- Registration errors are logged and normalized to `NULL`.
- Teardown resets the index to `-1`.
- [The ethtool query](/home/sasha/tmp/stable-parse-fail-5.10-1788974275/drivers/net/ethernet/renesas/ravb_main.c:1256) reads the cached index without dereferencing the clock.
- Existing timestamping capability flags remain unchanged.

This prerequisite matters because clearing the clock pointer would otherwise leave ethtool’s old `ptp_clock_index(priv->ptp.clock)` call unsafe. Error normalization also ensures that teardown cannot treat an `ERR_PTR()` as a successfully registered clock. The configuration where PTP registration returns `NULL` is handled correctly too.

I checked the main potential failure modes introduced by adding an IRQ wait:

- **Deadlock or invalid calling context:** The direct teardown callers cover ring reconfiguration, open-error cleanup, timeout recovery, interface close, probe-error cleanup, and removal. None holds `priv->lock` around `ravb_ptp_stop()`. Timeout recovery calls it from workqueue context. This satisfies the relevant requirement that `synchronize_irq()` may sleep and must not run while holding a resource needed by the handler. Both the [local implementation](/home/sasha/tmp/stable-parse-fail-5.10-1788974275/kernel/irq/manage.c:112) and [Linux 5.10 IRQ documentation](https://www.kernel.org/doc/html/v5.10/core-api/genericirq.html#c.synchronize_irq) establish that requirement.
- **Dependence on later IRQ release:** In close and open-error cleanup, `free_irq()` occurs after PTP teardown. Previously, that later synchronization could not protect a clock already unregistered. The new wait is placed before unregistration, where it is needed.
- **Different Gen2/Gen3 clock lifecycles:** Gen2 registers its clock during open; Gen3 registers during probe and unregisters during removal or probe cleanup. The backport retains those lifecycles. `ndev->irq` is assigned before either initialization path.
- **Missing pointer consumers:** The remaining clock-pointer accesses are the interrupt snapshot, initialization publication, and teardown exchange. Etthool no longer dereferences it.
- **Changes to other PTP interrupt behavior:** The null check guards external timestamp event delivery. Periodic-output processing and interrupt acknowledgement remain unchanged, matching upstream.
- **Repeated teardown:** After detachment, a subsequent teardown obtains `NULL` and skips unregistration, preventing another unregister of the saved pointer. This does not make arbitrary concurrent initialization and teardown safe; the fix retains the driver’s existing lifecycle assumptions.

I found no missing dependency or additional code adjustment required for this fix.

The available validation supports compilation success, with limits. `git diff --check HEAD~2 HEAD` passed. The supplied [build log](/home/sasha/tmp/stable-parse-fail-5.10-1788974275-build.log:5) reports successful x86_64 and arm64 builds with `rc=0` and `W=0`. I reviewed that existing log; I did not rerun those builds or perform hardware testing. The abbreviated log does not include configurations or compilation commands, so it does not independently establish whether `CONFIG_RAVB` was enabled in each build. It also cannot demonstrate the runtime race fix. External timestamp activity during repeated Gen2 open/close and Gen3 removal would provide useful additional runtime coverage.

For the historical record, three details in the conflict-resolution report need qualification:

- **Commit identity:** The report names `12b10225f2d26`, whereas current HEAD is `107f357e539c9`. Both commits have the same parent and identical Git tree IDs. The hash discrepancy therefore reflects metadata changes, not different source code.
- **“Exact original messages”:** Both backports preserve upstream authors and author dates. The prerequisite preserves its original message exactly. Current HEAD adds the upstream-commit reference and Sasha Levin’s sign-off, so its message is no longer byte-for-byte identical to upstream. Those additions do not affect correctness.
- **“Working tree is clean”:** Tracked files and the index are unchanged, but the current checkout contains an untracked `tmp.cmt`. That does not affect the committed backport; the clean-tree statement does not describe the current checkout exactly.

The implementation is minimal, preserves upstream’s protection against the reported use-after-free, and adapts the IRQ synchronization correctly to this branch. No code revision is warranted by this review.
================================================================================

This is an empty commit for documentation purposes only.
-- 
2.53.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-09 17:56 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 15:07 FAILED: patch "[PATCH] net: ravb: serialize PTP clock teardown" failed to apply to 5.10-stable tree gregkh
2026-09-09 17:55 ` [PATCH 5.10.y 1/4] net: ravb: Switch to SYSTEM_SLEEP_PM_OPS()/RUNTIME_PM_OPS() and pm_ptr() Sasha Levin
2026-09-09 17:55   ` [PATCH 5.10.y 2/4] net: ravb: avoid dereferencing an invalid PTP clock Sasha Levin
2026-09-09 17:55   ` [PATCH 5.10.y 3/4] net: ravb: serialize PTP clock teardown Sasha Levin
2026-09-09 17:55   ` [PATCH 5.10.y 4/4] [AUTOMATED CONFLICT RESOLUTION] Documentation for 1cb9663789c5b7a12fcd419fcca6d6254c398252 Sasha Levin

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.