Netdev List
 help / color / mirror / Atom feed
From: Jiale Yao <yaojiale02@163.com>
To: "Niklas Söderlund" <niklas.soderlund@ragnatech.se>,
	"Paul Barker" <paul@pbarker.dev>,
	"Andrew Lunn" <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	"Eric Dumazet" <edumazet@google.com>,
	"Jakub Kicinski" <kuba@kernel.org>,
	"Paolo Abeni" <pabeni@redhat.com>,
	"Sergey Shtylyov" <s.shtylyov@omp.ru>,
	"Claudiu Beznea" <claudiu.beznea.uj@bp.renesas.com>,
	netdev@vger.kernel.org, linux-renesas-soc@vger.kernel.org,
	linux-kernel@vger.kernel.org
Cc: Jiale Yao <yaojiale02@163.com>, stable@vger.kernel.org
Subject: [PATCH net v3 6/7] net: ravb: release managed IRQs before freeing netdev
Date: Sat,  3 Oct 2026 16:59:37 +0800	[thread overview]
Message-ID: <20261003085940.493951-7-yaojiale02@163.com> (raw)
In-Reply-To: <20261003085940.493951-1-yaojiale02@163.com>

ravb_remove() frees the netdev before devres releases the managed IRQs.
The handlers use the netdev as their data pointer, so an interrupt during
that window can access freed memory. Probe error paths have the same
ordering problem.

Keep the netdev manually managed and place only the IRQ resources in a
dedicated devres group. Release the group after unregistering the netdev
and before freeing it, and release it on probe failures as well. This
keeps the existing runtime PM error handling unchanged.

This issue was found by a static analysis method used in our research.

Fixes: 32f012b8c01c ("net: ravb: Move getting/requesting IRQs in the probe() method")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/net/ethernet/renesas/ravb_main.c | 18 ++++++++++++++----
 1 file changed, 14 insertions(+), 4 deletions(-)

diff --git a/drivers/net/ethernet/renesas/ravb_main.c b/drivers/net/ethernet/renesas/ravb_main.c
index ea1c7e536791..ab4703888778 100644
--- a/drivers/net/ethernet/renesas/ravb_main.c
+++ b/drivers/net/ethernet/renesas/ravb_main.c
@@ -2963,28 +2963,35 @@ static int ravb_probe(struct platform_device *pdev)
 		priv->num_rx_ring[RAVB_NC] = NC_RX_RING_SIZE;
 	}
 
+	if (!devres_open_group(&pdev->dev, priv, GFP_KERNEL)) {
+		error = -ENOMEM;
+		goto out_reset_assert;
+	}
+
 	error = ravb_setup_irqs(priv);
 	if (error)
-		goto out_reset_assert;
+		goto out_release_irq_group;
+
+	devres_close_group(&pdev->dev, priv);
 
 	priv->clk = devm_clk_get(&pdev->dev, NULL);
 	if (IS_ERR(priv->clk)) {
 		error = PTR_ERR(priv->clk);
-		goto out_reset_assert;
+		goto out_release_irq_group;
 	}
 
 	if (info->gptp_ref_clk) {
 		priv->gptp_clk = devm_clk_get(&pdev->dev, "gptp");
 		if (IS_ERR(priv->gptp_clk)) {
 			error = PTR_ERR(priv->gptp_clk);
-			goto out_reset_assert;
+			goto out_release_irq_group;
 		}
 	}
 
 	priv->refclk = devm_clk_get_optional(&pdev->dev, "refclk");
 	if (IS_ERR(priv->refclk)) {
 		error = PTR_ERR(priv->refclk);
-		goto out_reset_assert;
+		goto out_release_irq_group;
 	}
 	clk_prepare(priv->refclk);
 
@@ -3124,6 +3131,8 @@ static int ravb_probe(struct platform_device *pdev)
 	pm_runtime_disable(&pdev->dev);
 	pm_runtime_dont_use_autosuspend(&pdev->dev);
 	clk_unprepare(priv->refclk);
+out_release_irq_group:
+	devres_release_group(&pdev->dev, priv);
 out_reset_assert:
 	reset_control_assert(rstc);
 out_free_netdev:
@@ -3144,6 +3153,7 @@ static void ravb_remove(struct platform_device *pdev)
 		return;
 
 	unregister_netdev(ndev);
+	devres_release_group(dev, priv);
 	if (info->nc_queues)
 		netif_napi_del(&priv->napi[RAVB_NC]);
 	netif_napi_del(&priv->napi[RAVB_BE]);
-- 
2.34.1


  parent reply	other threads:[~2026-10-03  9:00 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03  8:59 [PATCH net v3 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-10-03  8:59 ` [PATCH net v3 1/7] net: macb: manage the netdev lifetime with devres Jiale Yao
2026-10-03  9:03   ` netdev-bot+sinfo
2026-10-04  8:45   ` Théo Lebrun
2026-10-04 12:14     ` jiale yao
2026-10-04 12:49       ` Théo Lebrun
2026-10-03  8:59 ` [PATCH net v3 2/7] net: fec: release IRQs before dependent resources Jiale Yao
2026-10-04  9:03   ` netdev-bot+sashiko
2026-10-03  8:59 ` [PATCH net v3 3/7] net: hip04: manage the netdev lifetime with devres Jiale Yao
2026-10-03  8:59 ` [PATCH net v3 4/7] net: hisi_femac: " Jiale Yao
2026-10-03  8:59 ` [PATCH net v3 5/7] net: hix5hd2: " Jiale Yao
2026-10-03  8:59 ` Jiale Yao [this message]
2026-10-03  9:59   ` [PATCH net v3 6/7] net: ravb: release managed IRQs before freeing netdev Niklas Söderlund
2026-10-03 10:04     ` jiale yao
2026-10-04  9:03   ` netdev-bot+sashiko
2026-10-03  8:59 ` [PATCH net v3 7/7] net: sxgbe: manage IRQ data lifetimes with devres Jiale Yao
2026-10-04  9:03   ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003085940.493951-7-yaojiale02@163.com \
    --to=yaojiale02@163.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=claudiu.beznea.uj@bp.renesas.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-renesas-soc@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=niklas.soderlund@ragnatech.se \
    --cc=pabeni@redhat.com \
    --cc=paul@pbarker.dev \
    --cc=s.shtylyov@omp.ru \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox