From: Jiale Yao <yaojiale02@163.com>
To: Wei Fang <wei.fang@nxp.com>, Frank Li <frank.li@nxp.com>,
Shenwei Wang <shenwei.wang@nxp.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Fabio Estevam <fabio.estevam@freescale.com>,
imx@lists.linux.dev, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org
Cc: Jiale Yao <yaojiale02@163.com>, stable@vger.kernel.org
Subject: [PATCH net v3 2/7] net: fec: release IRQs before dependent resources
Date: Sat, 3 Oct 2026 16:59:33 +0800 [thread overview]
Message-ID: <20261003085940.493951-3-yaojiale02@163.com> (raw)
In-Reply-To: <20261003085940.493951-1-yaojiale02@163.com>
fec_drv_remove() leaves the managed IRQs active until after the remove
callback returns. The handler can then run after the device has been
unregistered, its clocks have been disabled, and its other resources have
been torn down.
Mask the hardware interrupt sources and disable each IRQ before
unregistering the netdev. Mask the sources again afterwards because
fec_stop() restores the default interrupt mask. Also perform the same
cleanup on probe failures, and manage the netdev with devres so it remains
alive until the IRQ resources are released.
This issue was found by a static analysis method used in our research.
Fixes: 0d9b2ab1c376 ("fec: Use devm_request_irq()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/freescale/fec_main.c | 28 ++++++++++++++---------
1 file changed, 17 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/freescale/fec_main.c b/drivers/net/ethernet/freescale/fec_main.c
index 794ec427b0ee..b0fc5b39c748 100644
--- a/drivers/net/ethernet/freescale/fec_main.c
+++ b/drivers/net/ethernet/freescale/fec_main.c
@@ -5219,8 +5219,9 @@ fec_probe(struct platform_device *pdev)
fec_enet_get_queue_num(pdev, &num_tx_qs, &num_rx_qs);
/* Init network device */
- ndev = alloc_etherdev_mqs(sizeof(struct fec_enet_private) +
- FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
+ ndev = devm_alloc_etherdev_mqs(&pdev->dev,
+ sizeof(struct fec_enet_private) +
+ FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
if (!ndev)
return -ENOMEM;
@@ -5247,10 +5248,8 @@ fec_probe(struct platform_device *pdev)
pinctrl_pm_select_default_state(&pdev->dev);
fep->hwp = devm_platform_ioremap_resource(pdev, 0);
- if (IS_ERR(fep->hwp)) {
- ret = PTR_ERR(fep->hwp);
- goto failed_ioremap;
- }
+ if (IS_ERR(fep->hwp))
+ return PTR_ERR(fep->hwp);
fep->pdev = pdev;
fep->dev_id = dev_id++;
@@ -5455,6 +5454,9 @@ fec_probe(struct platform_device *pdev)
fec_enet_mii_remove(fep);
failed_mii_init:
failed_irq:
+ fec_irqs_disable(ndev);
+ while (i--)
+ disable_irq(fep->irq[i]);
fec_enet_deinit(ndev);
failed_init:
if (fep->bufdesc_ex)
@@ -5479,9 +5481,6 @@ fec_probe(struct platform_device *pdev)
failed_ipc_init:
failed_phy:
dev_id--;
-failed_ioremap:
- free_netdev(ndev);
-
return ret;
}
@@ -5491,7 +5490,7 @@ fec_drv_remove(struct platform_device *pdev)
struct net_device *ndev = platform_get_drvdata(pdev);
struct fec_enet_private *fep = netdev_priv(ndev);
struct device_node *np = pdev->dev.of_node;
- int ret;
+ int i, irq_cnt, ret;
ret = pm_runtime_get_sync(&pdev->dev);
if (ret < 0)
@@ -5502,7 +5501,15 @@ fec_drv_remove(struct platform_device *pdev)
cancel_work_sync(&fep->tx_timeout_work);
if (fep->bufdesc_ex)
fec_ptp_stop(pdev);
+ if (ret >= 0)
+ fec_irqs_disable(ndev);
+ irq_cnt = fec_enet_get_irq_cnt(pdev);
+ for (i = 0; i < irq_cnt; i++)
+ disable_irq(fep->irq[i]);
unregister_netdev(ndev);
+ /* fec_stop() enables the default interrupt mask. */
+ if (ret >= 0)
+ fec_irqs_disable(ndev);
fec_enet_mii_remove(fep);
if (fep->reg_phy)
regulator_disable(fep->reg_phy);
@@ -5522,7 +5529,6 @@ fec_drv_remove(struct platform_device *pdev)
pm_runtime_disable(&pdev->dev);
fec_enet_deinit(ndev);
- free_netdev(ndev);
}
static int fec_suspend(struct device *dev)
--
2.34.1
next prev parent reply other threads:[~2026-10-03 9:01 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 8:59 [PATCH net v3 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 1/7] net: macb: manage the netdev lifetime with devres Jiale Yao
2026-10-03 9:03 ` netdev-bot+sinfo
2026-10-04 8:45 ` Théo Lebrun
2026-10-04 12:14 ` jiale yao
2026-10-04 12:49 ` Théo Lebrun
2026-10-03 8:59 ` Jiale Yao [this message]
2026-10-04 9:03 ` [PATCH net v3 2/7] net: fec: release IRQs before dependent resources netdev-bot+sashiko
2026-10-03 8:59 ` [PATCH net v3 3/7] net: hip04: manage the netdev lifetime with devres Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 4/7] net: hisi_femac: " Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 5/7] net: hix5hd2: " Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 6/7] net: ravb: release managed IRQs before freeing netdev Jiale Yao
2026-10-03 9:59 ` Niklas Söderlund
2026-10-03 10:04 ` jiale yao
2026-10-04 9:03 ` netdev-bot+sashiko
2026-10-03 8:59 ` [PATCH net v3 7/7] net: sxgbe: manage IRQ data lifetimes with devres Jiale Yao
2026-10-04 9:03 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003085940.493951-3-yaojiale02@163.com \
--to=yaojiale02@163.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fabio.estevam@freescale.com \
--cc=frank.li@nxp.com \
--cc=imx@lists.linux.dev \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=shenwei.wang@nxp.com \
--cc=stable@vger.kernel.org \
--cc=wei.fang@nxp.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox