Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH net 00/10] net: Move setting of netops to fix crash
@ 2026-10-08  2:26 David Yang
  2026-10-08  2:26 ` [PATCH net 03/10] net: ethernet: actions: " David Yang
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: David Yang @ 2026-10-08  2:26 UTC (permalink / raw)
  To: netdev
  Cc: David Yang, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Andreas Färber,
	Manivannan Sadhasivam, Ciprian Regus, Andreas Larsson, Jian Shen,
	Jijie Shao, Sebastian Hesselbarth, Parthiban Veerasooran,
	MD Danish Anwar, Parvathi Pudi, Roger Quadros,
	Mohan Reddy Putluru, Runyu Xiao, Simon Horman, Jacob Keller,
	Stanislav Fomichev, Nicolai Buchwitz, Maxime Chevallier,
	linux-arm-kernel, linux-actions, linux-kernel

Commit ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev()
locking assertion") put a netdev_need_ops_lock() check on the
phy_attach_direct() path, in phy_link_topo_add_phy(). With
CONFIG_NET_SHAPER enabled netdev_need_ops_lock() reads
dev->netdev_ops->net_shaper_ops, so any driver that connects a PHY
before assigning ndev->netdev_ops now dies with a NULL pointer
dereference at probe time. The breakage showed up in v7.3-rc1.

ibm/emac was hit first and fixed by commit 7c9f391ec89c ("net: emac:
move setting of netops to fix crash"). These ten patches apply the
same one-line move to the remaining in-tree drivers whose probe path
attaches a PHY before filling in netdev_ops:

  1. hisilicon/hisi_femac   (crash reproduced on hardware)
  2. hisilicon/hip04
  3. actions/owl-emac
  4. adi/adin1140
  5. marvell/mv643xx_eth
  6. amd/au1000_eth
  7. ethoc
  8. aeroflex/greth
  9. ti/icssm-prueth
 10. microchip/lan865x      (attach happens inside oa_tc6_init())

Only patch 1 was reproduced and verified on hardware; patches 2-10
were found by source inspection and are neither build nor boot
tested.

Note that ti/netcp_ethss and cavium/thunder_bgx attach a PHY to
netdevs that never get a netdev_ops at all (dummy netdevs), so they
cannot be fixed by reordering and are not addressed here.

David Yang (10):
  net: hisilicon: hisi_femac: Move setting of netops to fix crash
  net: hisilicon: hip04_eth: Move setting of netops to fix crash
  net: ethernet: actions: Move setting of netops to fix crash
  net: ethernet: adi: Move setting of netops to fix crash
  net: mv643xx: move setting of netops to fix crash
  net: au1000: move setting of netops to fix crash
  net: ethoc: move setting of netops to fix crash
  net: ethernet: aeroflex: move setting of netops to fix crash
  net: ti: icssm-prueth: Move setting of netops to fix crash
  microchip: lan865x: move setting of netops to fix crash

 drivers/net/ethernet/actions/owl-emac.c          | 3 ++-
 drivers/net/ethernet/adi/adin1140.c              | 3 ++-
 drivers/net/ethernet/aeroflex/greth.c            | 3 ++-
 drivers/net/ethernet/amd/au1000_eth.c            | 3 ++-
 drivers/net/ethernet/ethoc.c                     | 3 ++-
 drivers/net/ethernet/hisilicon/hip04_eth.c       | 3 ++-
 drivers/net/ethernet/hisilicon/hisi_femac.c      | 3 ++-
 drivers/net/ethernet/marvell/mv643xx_eth.c       | 4 ++--
 drivers/net/ethernet/microchip/lan865x/lan865x.c | 3 ++-
 drivers/net/ethernet/ti/icssm/icssm_prueth.c     | 3 ++-
 10 files changed, 20 insertions(+), 11 deletions(-)

-- 
2.53.0



^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH net 03/10] net: ethernet: actions: Move setting of netops to fix crash
  2026-10-08  2:26 [PATCH net 00/10] net: Move setting of netops to fix crash David Yang
@ 2026-10-08  2:26 ` David Yang
  2026-10-08  8:30   ` Maxime Chevallier
  2026-10-08  2:26 ` [PATCH net 09/10] net: ti: icssm-prueth: " David Yang
  2026-10-08 12:10 ` [PATCH net 00/10] net: " Jijie Shao
  2 siblings, 1 reply; 6+ messages in thread
From: David Yang @ 2026-10-08  2:26 UTC (permalink / raw)
  To: netdev
  Cc: David Yang, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Andreas Färber,
	Manivannan Sadhasivam, Stanislav Fomichev, Maxime Chevallier,
	Nicolai Buchwitz, Jacob Keller, linux-arm-kernel, linux-actions,
	linux-kernel

owl_emac_probe() calls owl_emac_phy_init(), which connects the PHY,
before netdev->netdev_ops is assigned. phy_attach_direct() ->
phy_link_topo_add_phy() reads dev->netdev_ops through
netdev_need_ops_lock() since the commit in question, so probing crashes
with a NULL pointer dereference when CONFIG_NET_SHAPER is enabled.

Assign netdev_ops before the PHY attach, as was done for emac in commit
7c9f391ec89c ("net: emac: move setting of netops to fix crash").

Fixes: ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev() locking assertion")
Signed-off-by: David Yang <mmyangfl@gmail.com>
---
 drivers/net/ethernet/actions/owl-emac.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/actions/owl-emac.c b/drivers/net/ethernet/actions/owl-emac.c
index 0a08da799255..2538275a1e57 100644
--- a/drivers/net/ethernet/actions/owl-emac.c
+++ b/drivers/net/ethernet/actions/owl-emac.c
@@ -1552,6 +1552,8 @@ static int owl_emac_probe(struct platform_device *pdev)
 		return ret;
 	}
 
+	netdev->netdev_ops = &owl_emac_netdev_ops;
+
 	ret = owl_emac_phy_init(netdev);
 	if (ret) {
 		dev_err(dev, "failed to initialize PHY\n");
@@ -1563,7 +1565,6 @@ static int owl_emac_probe(struct platform_device *pdev)
 	netdev->min_mtu = OWL_EMAC_MTU_MIN;
 	netdev->max_mtu = OWL_EMAC_MTU_MAX;
 	netdev->watchdog_timeo = OWL_EMAC_TX_TIMEOUT;
-	netdev->netdev_ops = &owl_emac_netdev_ops;
 	netdev->ethtool_ops = &owl_emac_ethtool_ops;
 	netif_napi_add(netdev, &priv->napi, owl_emac_poll);
 
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH net 09/10] net: ti: icssm-prueth: Move setting of netops to fix crash
  2026-10-08  2:26 [PATCH net 00/10] net: Move setting of netops to fix crash David Yang
  2026-10-08  2:26 ` [PATCH net 03/10] net: ethernet: actions: " David Yang
@ 2026-10-08  2:26 ` David Yang
  2026-10-08  8:32   ` Maxime Chevallier
  2026-10-08 12:10 ` [PATCH net 00/10] net: " Jijie Shao
  2 siblings, 1 reply; 6+ messages in thread
From: David Yang @ 2026-10-08  2:26 UTC (permalink / raw)
  To: netdev
  Cc: David Yang, MD Danish Anwar, Parvathi Pudi, Roger Quadros,
	Mohan Reddy Putluru, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Jacob Keller, Stanislav Fomichev,
	Nicolai Buchwitz, Maxime Chevallier, linux-arm-kernel,
	linux-kernel

icssm_prueth_netdev_init() calls of_phy_get_and_connect() before
ndev->netdev_ops is assigned. phy_attach_direct() ->
phy_link_topo_add_phy() reads dev->netdev_ops through
netdev_need_ops_lock() since the commit in question, so probing crashes
with a NULL pointer dereference when CONFIG_NET_SHAPER is enabled.

Assign netdev_ops before the PHY attach, as was done for emac in commit
7c9f391ec89c ("net: emac: move setting of netops to fix crash").

Fixes: ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev() locking assertion")
Signed-off-by: David Yang <mmyangfl@gmail.com>
---
 drivers/net/ethernet/ti/icssm/icssm_prueth.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/ti/icssm/icssm_prueth.c b/drivers/net/ethernet/ti/icssm/icssm_prueth.c
index b7e94244355a..b42c98e861e0 100644
--- a/drivers/net/ethernet/ti/icssm/icssm_prueth.c
+++ b/drivers/net/ethernet/ti/icssm/icssm_prueth.c
@@ -1563,6 +1563,8 @@ static int icssm_prueth_netdev_init(struct prueth *prueth,
 	}
 	ether_addr_copy(emac->mac_addr, ndev->dev_addr);
 
+	ndev->netdev_ops = &emac_netdev_ops;
+
 	/* connect PHY */
 	emac->phydev = of_phy_get_and_connect(ndev, eth_node,
 					      icssm_emac_adjust_link);
@@ -1590,7 +1592,6 @@ static int icssm_prueth_netdev_init(struct prueth *prueth,
 	}
 
 	ndev->dev.of_node = eth_node;
-	ndev->netdev_ops = &emac_netdev_ops;
 
 	netif_napi_add(ndev, &emac->napi, icssm_emac_napi_poll);
 
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH net 03/10] net: ethernet: actions: Move setting of netops to fix crash
  2026-10-08  2:26 ` [PATCH net 03/10] net: ethernet: actions: " David Yang
@ 2026-10-08  8:30   ` Maxime Chevallier
  0 siblings, 0 replies; 6+ messages in thread
From: Maxime Chevallier @ 2026-10-08  8:30 UTC (permalink / raw)
  To: David Yang, netdev
  Cc: Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Andreas Färber, Manivannan Sadhasivam,
	Stanislav Fomichev, Nicolai Buchwitz, Jacob Keller,
	linux-arm-kernel, linux-actions, linux-kernel



On 10/8/26 04:26, David Yang wrote:
> owl_emac_probe() calls owl_emac_phy_init(), which connects the PHY,
> before netdev->netdev_ops is assigned. phy_attach_direct() ->
> phy_link_topo_add_phy() reads dev->netdev_ops through
> netdev_need_ops_lock() since the commit in question, so probing crashes
> with a NULL pointer dereference when CONFIG_NET_SHAPER is enabled.
> 
> Assign netdev_ops before the PHY attach, as was done for emac in commit
> 7c9f391ec89c ("net: emac: move setting of netops to fix crash").
> 
> Fixes: ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev() locking assertion")
> Signed-off-by: David Yang <mmyangfl@gmail.com>

Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>

Thanks,

Maxime

> ---
>  drivers/net/ethernet/actions/owl-emac.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/net/ethernet/actions/owl-emac.c b/drivers/net/ethernet/actions/owl-emac.c
> index 0a08da799255..2538275a1e57 100644
> --- a/drivers/net/ethernet/actions/owl-emac.c
> +++ b/drivers/net/ethernet/actions/owl-emac.c
> @@ -1552,6 +1552,8 @@ static int owl_emac_probe(struct platform_device *pdev)
>  		return ret;
>  	}
>  
> +	netdev->netdev_ops = &owl_emac_netdev_ops;
> +
>  	ret = owl_emac_phy_init(netdev);
>  	if (ret) {
>  		dev_err(dev, "failed to initialize PHY\n");
> @@ -1563,7 +1565,6 @@ static int owl_emac_probe(struct platform_device *pdev)
>  	netdev->min_mtu = OWL_EMAC_MTU_MIN;
>  	netdev->max_mtu = OWL_EMAC_MTU_MAX;
>  	netdev->watchdog_timeo = OWL_EMAC_TX_TIMEOUT;
> -	netdev->netdev_ops = &owl_emac_netdev_ops;
>  	netdev->ethtool_ops = &owl_emac_ethtool_ops;
>  	netif_napi_add(netdev, &priv->napi, owl_emac_poll);
>  



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH net 09/10] net: ti: icssm-prueth: Move setting of netops to fix crash
  2026-10-08  2:26 ` [PATCH net 09/10] net: ti: icssm-prueth: " David Yang
@ 2026-10-08  8:32   ` Maxime Chevallier
  0 siblings, 0 replies; 6+ messages in thread
From: Maxime Chevallier @ 2026-10-08  8:32 UTC (permalink / raw)
  To: David Yang, netdev
  Cc: MD Danish Anwar, Parvathi Pudi, Roger Quadros,
	Mohan Reddy Putluru, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Jacob Keller, Stanislav Fomichev,
	Nicolai Buchwitz, linux-arm-kernel, linux-kernel



On 10/8/26 04:26, David Yang wrote:
> icssm_prueth_netdev_init() calls of_phy_get_and_connect() before
> ndev->netdev_ops is assigned. phy_attach_direct() ->
> phy_link_topo_add_phy() reads dev->netdev_ops through
> netdev_need_ops_lock() since the commit in question, so probing crashes
> with a NULL pointer dereference when CONFIG_NET_SHAPER is enabled.
> 
> Assign netdev_ops before the PHY attach, as was done for emac in commit
> 7c9f391ec89c ("net: emac: move setting of netops to fix crash").
> 
> Fixes: ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev() locking assertion")
> Signed-off-by: David Yang <mmyangfl@gmail.com>

Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>

Thanks,

Maxime

> ---
>  drivers/net/ethernet/ti/icssm/icssm_prueth.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/net/ethernet/ti/icssm/icssm_prueth.c b/drivers/net/ethernet/ti/icssm/icssm_prueth.c
> index b7e94244355a..b42c98e861e0 100644
> --- a/drivers/net/ethernet/ti/icssm/icssm_prueth.c
> +++ b/drivers/net/ethernet/ti/icssm/icssm_prueth.c
> @@ -1563,6 +1563,8 @@ static int icssm_prueth_netdev_init(struct prueth *prueth,
>  	}
>  	ether_addr_copy(emac->mac_addr, ndev->dev_addr);
>  
> +	ndev->netdev_ops = &emac_netdev_ops;
> +
>  	/* connect PHY */
>  	emac->phydev = of_phy_get_and_connect(ndev, eth_node,
>  					      icssm_emac_adjust_link);
> @@ -1590,7 +1592,6 @@ static int icssm_prueth_netdev_init(struct prueth *prueth,
>  	}
>  
>  	ndev->dev.of_node = eth_node;
> -	ndev->netdev_ops = &emac_netdev_ops;
>  
>  	netif_napi_add(ndev, &emac->napi, icssm_emac_napi_poll);
>  



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH net 00/10] net: Move setting of netops to fix crash
  2026-10-08  2:26 [PATCH net 00/10] net: Move setting of netops to fix crash David Yang
  2026-10-08  2:26 ` [PATCH net 03/10] net: ethernet: actions: " David Yang
  2026-10-08  2:26 ` [PATCH net 09/10] net: ti: icssm-prueth: " David Yang
@ 2026-10-08 12:10 ` Jijie Shao
  2 siblings, 0 replies; 6+ messages in thread
From: Jijie Shao @ 2026-10-08 12:10 UTC (permalink / raw)
  To: David Yang, netdev
  Cc: shaojijie, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Andreas Färber,
	Manivannan Sadhasivam, Ciprian Regus, Andreas Larsson, Jian Shen,
	Sebastian Hesselbarth, Parthiban Veerasooran, MD Danish Anwar,
	Parvathi Pudi, Roger Quadros, Mohan Reddy Putluru, Runyu Xiao,
	Simon Horman, Jacob Keller, Stanislav Fomichev, Nicolai Buchwitz,
	Maxime Chevallier, linux-arm-kernel, linux-actions, linux-kernel


on 2026/10/8 10:26, David Yang wrote:
> Commit ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev()
> locking assertion") put a netdev_need_ops_lock() check on the
> phy_attach_direct() path, in phy_link_topo_add_phy(). With
> CONFIG_NET_SHAPER enabled netdev_need_ops_lock() reads
> dev->netdev_ops->net_shaper_ops, so any driver that connects a PHY
> before assigning ndev->netdev_ops now dies with a NULL pointer
> dereference at probe time. The breakage showed up in v7.3-rc1.
>
> ibm/emac was hit first and fixed by commit 7c9f391ec89c ("net: emac:
> move setting of netops to fix crash"). These ten patches apply the
> same one-line move to the remaining in-tree drivers whose probe path
> attaches a PHY before filling in netdev_ops:
>
>    1. hisilicon/hisi_femac   (crash reproduced on hardware)
>    2. hisilicon/hip04
>    3. actions/owl-emac
>    4. adi/adin1140
>    5. marvell/mv643xx_eth
>    6. amd/au1000_eth
>    7. ethoc
>    8. aeroflex/greth
>    9. ti/icssm-prueth
>   10. microchip/lan865x      (attach happens inside oa_tc6_init())
>
> Only patch 1 was reproduced and verified on hardware; patches 2-10
> were found by source inspection and are neither build nor boot
> tested.
>
> Note that ti/netcp_ethss and cavium/thunder_bgx attach a PHY to
> netdevs that never get a netdev_ops at all (dummy netdevs), so they
> cannot be fixed by reordering and are not addressed here.
>
> David Yang (10):
>    net: hisilicon: hisi_femac: Move setting of netops to fix crash
>    net: hisilicon: hip04_eth: Move setting of netops to fix crash
>    net: ethernet: actions: Move setting of netops to fix crash
>    net: ethernet: adi: Move setting of netops to fix crash
>    net: mv643xx: move setting of netops to fix crash
>    net: au1000: move setting of netops to fix crash
>    net: ethoc: move setting of netops to fix crash
>    net: ethernet: aeroflex: move setting of netops to fix crash
>    net: ti: icssm-prueth: Move setting of netops to fix crash
>    microchip: lan865x: move setting of netops to fix crash

Why isn't the subject of the last patch "net: microchip: lan865x..."
But overall, it's okay.

Reviewed-by: Jijie Shao <shaojijie@huawei.com>


>
>   drivers/net/ethernet/actions/owl-emac.c          | 3 ++-
>   drivers/net/ethernet/adi/adin1140.c              | 3 ++-
>   drivers/net/ethernet/aeroflex/greth.c            | 3 ++-
>   drivers/net/ethernet/amd/au1000_eth.c            | 3 ++-
>   drivers/net/ethernet/ethoc.c                     | 3 ++-
>   drivers/net/ethernet/hisilicon/hip04_eth.c       | 3 ++-
>   drivers/net/ethernet/hisilicon/hisi_femac.c      | 3 ++-
>   drivers/net/ethernet/marvell/mv643xx_eth.c       | 4 ++--
>   drivers/net/ethernet/microchip/lan865x/lan865x.c | 3 ++-
>   drivers/net/ethernet/ti/icssm/icssm_prueth.c     | 3 ++-
>   10 files changed, 20 insertions(+), 11 deletions(-)
>


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-08 12:11 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-08  2:26 [PATCH net 00/10] net: Move setting of netops to fix crash David Yang
2026-10-08  2:26 ` [PATCH net 03/10] net: ethernet: actions: " David Yang
2026-10-08  8:30   ` Maxime Chevallier
2026-10-08  2:26 ` [PATCH net 09/10] net: ti: icssm-prueth: " David Yang
2026-10-08  8:32   ` Maxime Chevallier
2026-10-08 12:10 ` [PATCH net 00/10] net: " Jijie Shao

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox