The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH net 1/2] fjes: unregister the netdev before destroying the workqueues
@ 2026-08-05  1:14 Fan Wu
  2026-08-05  1:23 ` [PATCH net 2/2] fjes: cancel force_close_task in fjes_remove() Fan Wu
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Fan Wu @ 2026-08-05  1:14 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, edumazet, pabeni, andrew+netdev, linux-kernel,
	stable, Fan Wu

fjes_remove() destroys the driver workqueues before unregistering the
netdev. The interrupt handler queues work on them, but the IRQ is only
freed from fjes_close() under unregister_netdev(), so an interrupt in that
window can queue work once the workqueues are gone.

Unregister the netdev first so fjes_close() frees the IRQ and cancels the
workers before the workqueues are destroyed. force_close_task, which the
workers arm on the system workqueue, is handled in the next patch.

This issue was found by an in-house static analysis tool.

Fixes: 658d439b2292 ("fjes: Introduce FUJITSU Extended Socket Network Device driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
---
 drivers/net/fjes/fjes_main.c | 9 +++------
 1 file changed, 3 insertions(+), 6 deletions(-)

diff --git a/drivers/net/fjes/fjes_main.c b/drivers/net/fjes/fjes_main.c
index 1f0f38980..cddabc965 100644
--- a/drivers/net/fjes/fjes_main.c
+++ b/drivers/net/fjes/fjes_main.c
@@ -1394,17 +1394,14 @@ static void fjes_remove(struct platform_device *plat_dev)
 
 	fjes_dbg_adapter_exit(adapter);
 
-	cancel_delayed_work_sync(&adapter->interrupt_watch_task);
-	cancel_work_sync(&adapter->unshare_watch_task);
-	cancel_work_sync(&adapter->raise_intr_rxdata_task);
-	cancel_work_sync(&adapter->tx_stall_task);
+	/* Unregister first: .ndo_stop frees the IRQ and cancels the workers. */
+	unregister_netdev(netdev);
+
 	if (adapter->control_wq)
 		destroy_workqueue(adapter->control_wq);
 	if (adapter->txrx_wq)
 		destroy_workqueue(adapter->txrx_wq);
 
-	unregister_netdev(netdev);
-
 	fjes_hw_exit(hw);
 
 	netif_napi_del(&adapter->napi);
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-08-06 16:51 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-05  1:14 [PATCH net 1/2] fjes: unregister the netdev before destroying the workqueues Fan Wu
2026-08-05  1:23 ` [PATCH net 2/2] fjes: cancel force_close_task in fjes_remove() Fan Wu
2026-08-06 14:19   ` Simon Horman
2026-08-06 14:19 ` [PATCH net 1/2] fjes: unregister the netdev before destroying the workqueues Simon Horman
2026-08-06 16:50 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox