* [PATCH net v3] net: emac: mal: replace devm_request_irq with request_irq to fix probe error race
@ 2026-10-07 18:38 Rosen Penev
2026-10-07 18:44 ` netdev-bot+sinfo
0 siblings, 1 reply; 3+ messages in thread
From: Rosen Penev @ 2026-10-07 18:38 UTC (permalink / raw)
To: netdev
Cc: Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Rosen Penev, open list
devm_request_irq() is a managed resource: the IRQ is not freed until
devres_release_all() runs after the probe function returns. In the
probe error path, free_netdev(mal->dummy_dev) and dcr_unmap() execute
while the IRQ is still live. If the shared IRQ fires during cleanup,
the handler accesses unmapped DCR registers (crash) or the already-
freed dummy_dev (use-after-free).
Switch to plain request_irq() with per-IRQ error labels that tear down
only the IRQs that were successfully registered, and add the matching
free_irq() calls in mal_remove().
Fixes: 14f59154ff0b ("net: ibm: emac: mal: use devm for request_irq")
Assisted-by: LLM
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
---
v3: add Reviewed-by and fix Assisted-by.
v2: rebase and add tested comment
drivers/net/ethernet/ibm/emac/mal.c | 43 +++++++++++++++++++----------
1 file changed, 29 insertions(+), 14 deletions(-)
diff --git a/drivers/net/ethernet/ibm/emac/mal.c b/drivers/net/ethernet/ibm/emac/mal.c
index 42027665f2a9..236603a381bc 100644
--- a/drivers/net/ethernet/ibm/emac/mal.c
+++ b/drivers/net/ethernet/ibm/emac/mal.c
@@ -665,26 +665,26 @@ static int mal_probe(struct platform_device *ofdev)
hdlr_rxde = mal_rxde;
}
- err = devm_request_irq(&ofdev->dev, mal->serr_irq, hdlr_serr, irqflags,
- "MAL SERR", mal);
+ err = request_irq(mal->serr_irq, hdlr_serr, irqflags,
+ "MAL SERR", mal);
if (err)
goto fail2;
- err = devm_request_irq(&ofdev->dev, mal->txde_irq, hdlr_txde, irqflags,
- "MAL TX DE", mal);
+ err = request_irq(mal->txde_irq, hdlr_txde, irqflags,
+ "MAL TX DE", mal);
if (err)
- goto fail2;
- err = devm_request_irq(&ofdev->dev, mal->txeob_irq, mal_txeob, 0,
- "MAL TX EOB", mal);
+ goto fail_serr_irq;
+ err = request_irq(mal->txeob_irq, mal_txeob, 0,
+ "MAL TX EOB", mal);
if (err)
- goto fail2;
- err = devm_request_irq(&ofdev->dev, mal->rxde_irq, hdlr_rxde, irqflags,
- "MAL RX DE", mal);
+ goto fail_txde_irq;
+ err = request_irq(mal->rxde_irq, hdlr_rxde, irqflags,
+ "MAL RX DE", mal);
if (err)
- goto fail2;
- err = devm_request_irq(&ofdev->dev, mal->rxeob_irq, mal_rxeob, 0,
- "MAL RX EOB", mal);
+ goto fail_txeob_irq;
+ err = request_irq(mal->rxeob_irq, mal_rxeob, 0,
+ "MAL RX EOB", mal);
if (err)
- goto fail2;
+ goto fail_rxde_irq;
/* Enable all MAL SERR interrupt sources */
set_mal_dcrn(mal, MAL_IER, MAL_IER_EVENTS);
@@ -703,6 +703,14 @@ static int mal_probe(struct platform_device *ofdev)
return 0;
+ fail_rxde_irq:
+ free_irq(mal->rxde_irq, mal);
+ fail_txeob_irq:
+ free_irq(mal->txeob_irq, mal);
+ fail_txde_irq:
+ free_irq(mal->txde_irq, mal);
+ fail_serr_irq:
+ free_irq(mal->serr_irq, mal);
fail2:
dma_free_coherent(&ofdev->dev, bd_size, mal->bd_virt, mal->bd_dma);
fail_dummy:
@@ -729,6 +737,13 @@ static void mal_remove(struct platform_device *ofdev)
mal_reset(mal);
+ /* Free IRQs before freeing resources they access */
+ free_irq(mal->serr_irq, mal);
+ free_irq(mal->txde_irq, mal);
+ free_irq(mal->txeob_irq, mal);
+ free_irq(mal->rxde_irq, mal);
+ free_irq(mal->rxeob_irq, mal);
+
free_netdev(mal->dummy_dev);
dcr_unmap(mal->dcr_host, 0x100);
--
2.56.0
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH net v3] net: emac: mal: replace devm_request_irq with request_irq to fix probe error race
2026-10-07 18:38 [PATCH net v3] net: emac: mal: replace devm_request_irq with request_irq to fix probe error race Rosen Penev
@ 2026-10-07 18:44 ` netdev-bot+sinfo
2026-10-07 19:20 ` Rosen Penev
0 siblings, 1 reply; 3+ messages in thread
From: netdev-bot+sinfo @ 2026-10-07 18:44 UTC (permalink / raw)
To: Rosen Penev
Cc: netdev, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, linux-kernel
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
- What hardware the change was tested on. For driver fixes please
mention the device (and if relevant firmware version) used for
testing, or say that the change was not tested on real hardware.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net v3] net: emac: mal: replace devm_request_irq with request_irq to fix probe error race
2026-10-07 18:44 ` netdev-bot+sinfo
@ 2026-10-07 19:20 ` Rosen Penev
0 siblings, 0 replies; 3+ messages in thread
From: Rosen Penev @ 2026-10-07 19:20 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, linux-kernel
On Wed, Oct 7, 2026 at 11:44 AM <netdev-bot+sinfo@kernel.org> wrote:
>
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
LLM tool scan probably.
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> - What hardware the change was tested on. For driver fixes please
> mention the device (and if relevant firmware version) used for
> testing, or say that the change was not tested on real hardware.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-07 19:20 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 18:38 [PATCH net v3] net: emac: mal: replace devm_request_irq with request_irq to fix probe error race Rosen Penev
2026-10-07 18:44 ` netdev-bot+sinfo
2026-10-07 19:20 ` Rosen Penev
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®