* [PATCH net] net: phy: clear phydev->devlink when the link is deleted
@ 2025-05-22 6:42 Wei Fang
2025-05-22 12:33 ` Andrew Lunn
0 siblings, 1 reply; 4+ messages in thread
From: Wei Fang @ 2025-05-22 6:42 UTC (permalink / raw)
To: andrew, hkallweit1, linux, davem, edumazet, kuba, pabeni,
f.fainelli, xiaolei.wang
Cc: netdev, linux-kernel, imx
The phydev->devlink is not cleared when the link is deleted, so calling
phy_detach() again will cause a crash. For example, the link is deleted
when the network interface is set to down, then re-enable the network
interface and phy_attach_direct() will be called, but an error occurs
and jump to the error path, so phy_detach() is called again and cause a
crash, the crash log is as follows.
[ 24.702421] Call trace:
[ 24.704856] device_link_put_kref+0x20/0x120
[ 24.709124] device_link_del+0x30/0x48
[ 24.712864] phy_detach+0x24/0x168
[ 24.716261] phy_attach_direct+0x168/0x3a4
[ 24.720352] phylink_fwnode_phy_connect+0xc8/0x14c
[ 24.725140] phylink_of_phy_connect+0x1c/0x34
Fixes: bc66fa87d4fd ("net: phy: Add link between phy dev and mac dev")
Signed-off-by: Wei Fang <wei.fang@nxp.com>
---
drivers/net/phy/phy_device.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c
index cc1bfd22fb81..7d5e76a3db0e 100644
--- a/drivers/net/phy/phy_device.c
+++ b/drivers/net/phy/phy_device.c
@@ -1727,8 +1727,10 @@ void phy_detach(struct phy_device *phydev)
struct module *ndev_owner = NULL;
struct mii_bus *bus;
- if (phydev->devlink)
+ if (phydev->devlink) {
device_link_del(phydev->devlink);
+ phydev->devlink = NULL;
+ }
if (phydev->sysfs_links) {
if (dev)
--
2.34.1
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH net] net: phy: clear phydev->devlink when the link is deleted 2025-05-22 6:42 [PATCH net] net: phy: clear phydev->devlink when the link is deleted Wei Fang @ 2025-05-22 12:33 ` Andrew Lunn 2025-05-22 13:57 ` Wei Fang 0 siblings, 1 reply; 4+ messages in thread From: Andrew Lunn @ 2025-05-22 12:33 UTC (permalink / raw) To: Wei Fang Cc: hkallweit1, linux, davem, edumazet, kuba, pabeni, f.fainelli, xiaolei.wang, netdev, linux-kernel, imx On Thu, May 22, 2025 at 02:42:53PM +0800, Wei Fang wrote: > The phydev->devlink is not cleared when the link is deleted, so calling > phy_detach() again will cause a crash. I would say crashing is correct. You have done something you should not do, and the crash helped you find it. phy_attach() and phy_detach() should always be in pairs. Andrew --- pw-bot: cr ^ permalink raw reply [flat|nested] 4+ messages in thread
* RE: [PATCH net] net: phy: clear phydev->devlink when the link is deleted 2025-05-22 12:33 ` Andrew Lunn @ 2025-05-22 13:57 ` Wei Fang 2025-05-22 16:19 ` Andrew Lunn 0 siblings, 1 reply; 4+ messages in thread From: Wei Fang @ 2025-05-22 13:57 UTC (permalink / raw) To: Andrew Lunn Cc: hkallweit1@gmail.com, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, f.fainelli@gmail.com, xiaolei.wang@windriver.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, imx@lists.linux.dev > On Thu, May 22, 2025 at 02:42:53PM +0800, Wei Fang wrote: > > The phydev->devlink is not cleared when the link is deleted, so calling > > phy_detach() again will cause a crash. > > I would say crashing is correct. You have done something you should > not do, and the crash helped you find it. phy_attach() and > phy_detach() should always be in pairs. > phy_attach() and phy_detach() are called in pairs in my case. When re-enabling the network port, if an error occurs in the phy_attach_direct(), For example, if phy_init_hw() returns an error, it will jump to the error path and call phy_detach(). Because phy_detach() did not clear the phydev->devlink pointer when the network port was disabled, device_link_del() will access a NULL pointer and cause a crash. And this crash may cause the CPU to hang. I don't think it is reasonable to cause the CPU to hang. ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] net: phy: clear phydev->devlink when the link is deleted 2025-05-22 13:57 ` Wei Fang @ 2025-05-22 16:19 ` Andrew Lunn 0 siblings, 0 replies; 4+ messages in thread From: Andrew Lunn @ 2025-05-22 16:19 UTC (permalink / raw) To: Wei Fang Cc: hkallweit1@gmail.com, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, f.fainelli@gmail.com, xiaolei.wang@windriver.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, imx@lists.linux.dev On Thu, May 22, 2025 at 01:57:20PM +0000, Wei Fang wrote: > > On Thu, May 22, 2025 at 02:42:53PM +0800, Wei Fang wrote: > > > The phydev->devlink is not cleared when the link is deleted, so calling > > > phy_detach() again will cause a crash. > > > > I would say crashing is correct. You have done something you should > > not do, and the crash helped you find it. phy_attach() and > > phy_detach() should always be in pairs. > > > > phy_attach() and phy_detach() are called in pairs in my case. When > re-enabling the network port, if an error occurs in the phy_attach_direct(), > For example, if phy_init_hw() returns an error, it will jump to the error > path and call phy_detach(). Because phy_detach() did not clear the > phydev->devlink pointer when the network port was disabled, > device_link_del() will access a NULL pointer and cause a crash. And this > crash may cause the CPU to hang. I don't think it is reasonable to cause > the CPU to hang. Ah, now i get it... phy_attach_direct() runs, but fails early, before the call to: phydev->devlink = device_link_add(dev->dev.parent, &phydev->mdio.dev, DL_FLAG_PM_RUNTIME | DL_FLAG_STATELESS); So it has its old value, from a previous attach/detach cycle. At the error: label, it calls phy_detach(phydev), which does a device_link_del(), using the old value... Please improve your changelog message, add more details. Andrew --- pw-bot: cr ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2025-05-22 16:19 UTC | newest] Thread overview: 4+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2025-05-22 6:42 [PATCH net] net: phy: clear phydev->devlink when the link is deleted Wei Fang 2025-05-22 12:33 ` Andrew Lunn 2025-05-22 13:57 ` Wei Fang 2025-05-22 16:19 ` Andrew Lunn
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox