Intel-Wired-Lan Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Sergey Temerkhanov <sergey.temerkhanov@intel.com>
To: intel-wired-lan@lists.osuosl.org
Cc: netdev@vger.kernel.org
Subject: [PATCH iwl-net v5 1/8] ice: Unlink the PTP port before destroying its ps_lock
Date: Thu, 24 Sep 2026 12:59:09 +0000	[thread overview]
Message-ID: <20260924125916.2796499-2-sergey.temerkhanov@intel.com> (raw)
In-Reply-To: <20260924125916.2796499-1-sergey.temerkhanov@intel.com>

err_clean_pf destroys ptp->port.ps_lock before ice_ptp_cleanup_pf()
removes the port from adapter->ports.list and drains the outstanding
references, so while the mutex is being destroyed the port is still
reachable by every other PF on the adapter:

ice_ptp_settime64()
  ice_ptp_restart_all_phy()
    list_for_each_entry_rcu(port, &pf->adapter->ports.list, list_node)
      ice_ptp_port_phy_restart(port)
        mutex_lock(&ptp_port->ps_lock);

ice_ptp_setup_pf() publishes the port before ice_ptp_init_port() runs,
and a link event can set port.link_up at any point after that, so the
walk does not necessarily skip it.

Call ice_ptp_cleanup_pf() first and destroy the mutex once no other PF
can reach the port, matching the order already used by the
ICE_PTP_READY path in ice_ptp_release().

Release the Tx timestamp tracker here as well, so the label frees
everything the port owns. ice_ptp_init_port() allocates it through
ice_ptp_alloc_tx_tracker(), and any failure unwinding through
err_clean_pf after that point would otherwise leak tx->tstamps,
tx->in_use and tx->stale. The tx.init guard is needed because
err_clean_pf is also reached when ice_ptp_init_port() itself fails, and
ice_ptp_alloc_tx_tracker() leaves tx->lock uninitialized in that case.

Fixes: 23a5b9b12de9 ("ice: fix PTP cleanup on driver removal in error path")
Signed-off-by: Sergey Temerkhanov <sergey.temerkhanov@intel.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
---
 drivers/net/ethernet/intel/ice/ice_ptp.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/ice/ice_ptp.c b/drivers/net/ethernet/intel/ice/ice_ptp.c
index a735dfa2b03e..5104ccc70d4c 100644
--- a/drivers/net/ethernet/intel/ice/ice_ptp.c
+++ b/drivers/net/ethernet/intel/ice/ice_ptp.c
@@ -3587,8 +3587,14 @@ void ice_ptp_init(struct ice_pf *pf)
 	return;
 
 err_clean_pf:
-	mutex_destroy(&ptp->port.ps_lock);
+	/* Unlink the port before tearing down anything it still shares with
+	 * the other PFs on the adapter: ice_ptp_restart_all_phy() can be
+	 * walking adapter->ports.list and taking ps_lock until this returns.
+	 */
 	ice_ptp_cleanup_pf(pf);
+	if (ptp->port.tx.init)
+		ice_ptp_release_tx_tracker(pf, &ptp->port.tx);
+	mutex_destroy(&ptp->port.ps_lock);
 err_exit:
 	/* If we registered a PTP clock, release it */
 	if (pf->ptp.clock) {
-- 
2.53.0


  reply	other threads:[~2026-09-24 12:59 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 12:59 [PATCH iwl-net v5 0/8] Rework usage of the control PF pointer in struct ice_adapter Sergey Temerkhanov
2026-09-24 12:59 ` Sergey Temerkhanov [this message]
2026-09-24 12:59 ` [PATCH iwl-net v5 2/8] ice: Protect the control PF pointer with RCU and a rwsem Sergey Temerkhanov
2026-09-24 12:59 ` [PATCH iwl-net v5 3/8] ice: Cache struct ice_hw pointer for split register reads Sergey Temerkhanov
2026-09-24 12:59 ` [PATCH iwl-net v5 4/8] ice: Reject PTP access without a control PF Sergey Temerkhanov
2026-09-24 12:59 ` [PATCH iwl-net v5 5/8] ice: Clear the control PF pointer when the control PF is removed Sergey Temerkhanov
2026-09-24 12:59 ` [PATCH iwl-net v5 6/8] ice: Document control PF lock ordering Sergey Temerkhanov
2026-09-24 12:59 ` [PATCH iwl-net v5 7/8] ice: Annotate PTP control PF lock handoff Sergey Temerkhanov
2026-09-25 20:36   ` Nathan Chancellor
2026-09-24 12:59 ` [PATCH iwl-net v5 8/8] ice: Release control PF lock before RCU wait Sergey Temerkhanov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924125916.2796499-2-sergey.temerkhanov@intel.com \
    --to=sergey.temerkhanov@intel.com \
    --cc=intel-wired-lan@lists.osuosl.org \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox