* [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs
@ 2026-09-27 14:47 Jiale Yao
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres Jiale Yao
2026-09-27 22:30 ` [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jakub Kicinski
0 siblings, 2 replies; 4+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Théo Lebrun, Conor Dooley, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Wei Fang, Frank Li,
Shenwei Wang, Jian Shen, Jijie Shao, Niklas Söderlund,
Paul Barker, Byungho An, Russell King, Nicolas Ferre,
Soren Brinkmann, Fabio Estevam, Arnd Bergmann, Zhangfei Gao,
dingtianhong, Jiancheng Xue, Dongpo Li, Mitsuhiro Kimura,
Sergei Shtylyov, Sergey Shtylyov, Claudiu Beznea, Vipul Pandya,
Girish K S, Siva Reddy, netdev, linux-kernel, imx,
linux-renesas-soc
Cc: Jiale Yao
Several Ethernet platform drivers request interrupts with
devm_request_irq() but allocate and free their netdevs manually.
Device-managed resources are released only after the driver's remove
callback returns, so these callbacks free the IRQ data while the interrupt
handlers can still be invoked. A late or shared interrupt in this window
can dereference freed memory.
For six drivers, make the netdev allocation device managed. Since each IRQ
is requested after its netdev is allocated, devres ordering releases the
IRQ before the netdev. SXGBE also keeps its hardware operations object
alive through the same ordering because its handlers dereference that
object directly.
RAVB takes a separate path because its ndo_stop() participates in runtime
PM teardown and its remove callback can encounter a resume failure before
unregister_netdev(). Keep its netdev manually managed, place its IRQs in a
dedicated devres group, and explicitly release that group after
unregistering the netdev. On a resume failure, continue the software
teardown without an unmatched runtime PM put.
Each patch handles one driver and is independently buildable.
Changes in v2:
- Keep commit message tags together without blank lines between them, as
requested by Francesco.
Jiale Yao (7):
net: macb: manage the netdev lifetime with devres
net: fec: manage the netdev lifetime with devres
net: hip04: manage the netdev lifetime with devres
net: hisi_femac: manage the netdev lifetime with devres
net: hix5hd2: manage the netdev lifetime with devres
net: ravb: fix resource teardown ordering
net: sxgbe: manage IRQ data lifetimes with devres
drivers/net/ethernet/cadence/macb_main.c | 17 +++++-------
drivers/net/ethernet/freescale/fec_main.c | 8 +++---
drivers/net/ethernet/hisilicon/hip04_eth.c | 4 +--
drivers/net/ethernet/hisilicon/hisi_femac.c | 15 +++++------
drivers/net/ethernet/hisilicon/hix5hd2_gmac.c | 15 +++++------
drivers/net/ethernet/renesas/ravb_main.c | 23 +++++++++++-----
.../net/ethernet/samsung/sxgbe/sxgbe_main.c | 26 +++++++------------
7 files changed, 49 insertions(+), 59 deletions(-)
--
2.34.1
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-28 2:57 ` Wei Fang
2026-09-27 22:30 ` [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jakub Kicinski
1 sibling, 1 reply; 4+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Wei Fang, Frank Li, Shenwei Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Fabio Estevam, imx,
netdev, linux-kernel
Cc: Jiale Yao, stable
fec_drv_remove() frees the netdev before devres releases the managed
IRQs whose handlers use it as their data pointer. A late interrupt can
therefore access the freed netdev.
Allocate the netdev with devres so that the later IRQ registrations are
released first during teardown.
Fixes: 0d9b2ab1c376 ("fec: Use devm_request_irq()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/freescale/fec_main.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/freescale/fec_main.c b/drivers/net/ethernet/freescale/fec_main.c
index 794ec427b0ee..23e794a31ce8 100644
--- a/drivers/net/ethernet/freescale/fec_main.c
+++ b/drivers/net/ethernet/freescale/fec_main.c
@@ -5219,8 +5219,9 @@ fec_probe(struct platform_device *pdev)
fec_enet_get_queue_num(pdev, &num_tx_qs, &num_rx_qs);
/* Init network device */
- ndev = alloc_etherdev_mqs(sizeof(struct fec_enet_private) +
- FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
+ ndev = devm_alloc_etherdev_mqs(&pdev->dev,
+ sizeof(struct fec_enet_private) +
+ FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
if (!ndev)
return -ENOMEM;
@@ -5480,8 +5481,6 @@ fec_probe(struct platform_device *pdev)
failed_phy:
dev_id--;
failed_ioremap:
- free_netdev(ndev);
-
return ret;
}
@@ -5522,7 +5521,6 @@ fec_drv_remove(struct platform_device *pdev)
pm_runtime_disable(&pdev->dev);
fec_enet_deinit(ndev);
- free_netdev(ndev);
}
static int fec_suspend(struct device *dev)
--
2.34.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres Jiale Yao
@ 2026-09-27 22:30 ` Jakub Kicinski
1 sibling, 0 replies; 4+ messages in thread
From: Jakub Kicinski @ 2026-09-27 22:30 UTC (permalink / raw)
To: Jiale Yao
Cc: Théo Lebrun, Conor Dooley, Andrew Lunn, David S. Miller,
Eric Dumazet, Paolo Abeni, Wei Fang, Frank Li, Shenwei Wang,
Jian Shen, Jijie Shao, Niklas Söderlund, Paul Barker,
Byungho An, Russell King, Nicolas Ferre, Soren Brinkmann,
Fabio Estevam, Arnd Bergmann, Zhangfei Gao, dingtianhong,
Jiancheng Xue, Dongpo Li, Mitsuhiro Kimura, Sergei Shtylyov,
Sergey Shtylyov, Claudiu Beznea, Vipul Pandya, Girish K S,
Siva Reddy, netdev, linux-kernel, imx, linux-renesas-soc
On Sun, 27 Sep 2026 22:47:33 +0800 Jiale Yao wrote:
> Several Ethernet platform drivers request interrupts with
> devm_request_irq() but allocate and free their netdevs manually.
> Device-managed resources are released only after the driver's remove
> callback returns, so these callbacks free the IRQ data while the interrupt
> handlers can still be invoked. A late or shared interrupt in this window
> can dereference freed memory.
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
- What hardware the change was tested on. For driver fixes please
mention the device (and if relevant firmware version) used for
testing, or say that the change was not tested on real hardware.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
^ permalink raw reply [flat|nested] 4+ messages in thread
* RE: [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres Jiale Yao
@ 2026-09-28 2:57 ` Wei Fang
0 siblings, 0 replies; 4+ messages in thread
From: Wei Fang @ 2026-09-28 2:57 UTC (permalink / raw)
To: Jiale Yao
Cc: stable@vger.kernel.org, Frank Li, Shenwei Wang, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Fabio Estevam, imx@lists.linux.dev, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org
> Subject: [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres
Please add target tree to the subject. Since this is a fix, the target tree should be net.
>
> fec_drv_remove() frees the netdev before devres releases the managed
> IRQs whose handlers use it as their data pointer. A late interrupt can
> therefore access the freed netdev.
>
> Allocate the netdev with devres so that the later IRQ registrations are
> released first during teardown.
>
> Fixes: 0d9b2ab1c376 ("fec: Use devm_request_irq()")
> Cc: stable@vger.kernel.org
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/ethernet/freescale/fec_main.c | 8 +++-----
> 1 file changed, 3 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/net/ethernet/freescale/fec_main.c
> b/drivers/net/ethernet/freescale/fec_main.c
> index 794ec427b0ee..23e794a31ce8 100644
> --- a/drivers/net/ethernet/freescale/fec_main.c
> +++ b/drivers/net/ethernet/freescale/fec_main.c
> @@ -5219,8 +5219,9 @@ fec_probe(struct platform_device *pdev)
> fec_enet_get_queue_num(pdev, &num_tx_qs, &num_rx_qs);
>
> /* Init network device */
> - ndev = alloc_etherdev_mqs(sizeof(struct fec_enet_private) +
> - FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
> + ndev = devm_alloc_etherdev_mqs(&pdev->dev,
> + sizeof(struct fec_enet_private) +
> + FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
> if (!ndev)
> return -ENOMEM;
>
> @@ -5480,8 +5481,6 @@ fec_probe(struct platform_device *pdev)
> failed_phy:
> dev_id--;
> failed_ioremap:
failed_ioremap is no longer needed, please remove it.
> - free_netdev(ndev);
> -
> return ret;
> }
>
> @@ -5522,7 +5521,6 @@ fec_drv_remove(struct platform_device *pdev)
> pm_runtime_disable(&pdev->dev);
>
> fec_enet_deinit(ndev);
> - free_netdev(ndev);
> }
>
> static int fec_suspend(struct device *dev)
> --
> 2.34.1
This patch just prevents the netdev from being freed in fec_drv_remove(),
but fec_enet_interrupt() could still be called after the removal, and
fec_enet_collect_events() will be called to access the registers, however,
the ipg clk has been disabled, the registers are not accessible at that point,
that is a problem.
I think the hardware interrupts should be disabled on the removal path
and disable_irq() should be called to disable the irqs.
BTW, do not repost a new version within 24 hours.
https://elixir.bootlin.com/linux/v7.3-rc4/source/Documentation/process/maintainer-netdev.rst#L15
There are other upstream rules in maintainer-netdev.rst, please
refer to them.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-28 2:57 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres Jiale Yao
2026-09-28 2:57 ` Wei Fang
2026-09-27 22:30 ` [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jakub Kicinski
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox