mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] net: winbond-840: release IRQ on alloc_ringdesc() error path
@ 2026-10-08 16:21 Haotian Zhang
  2026-10-08 16:23 ` netdev-bot+sinfo
  2026-10-08 19:17 ` Andrew Lunn
  0 siblings, 2 replies; 3+ messages in thread
From: Haotian Zhang @ 2026-10-08 16:21 UTC (permalink / raw)
  To: Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni
  Cc: netdev, linux-parisc, linux-kernel

netdev_open() registers the shared IRQ with request_irq() and then calls
alloc_ringdesc().  When alloc_ringdesc() fails, the error path jumps to
out_err, which only calls netif_device_attach() and returns.  The IRQ
handler stays registered forever: net/core/dev.c never calls ndo_stop
when ndo_open fails, so netdev_close(), the only place that frees the
IRQ, is never reached.  The leaked handler is also left enabled on an
uninitialised device.

Add a separate out_err_free_irq label that releases the IRQ before
returning the allocation error, mirroring the cleanup already used by
the sibling de2104x driver.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
 drivers/net/ethernet/dec/tulip/winbond-840.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/dec/tulip/winbond-840.c b/drivers/net/ethernet/dec/tulip/winbond-840.c
index a5581f1d0141..2ce05a63b289 100644
--- a/drivers/net/ethernet/dec/tulip/winbond-840.c
+++ b/drivers/net/ethernet/dec/tulip/winbond-840.c
@@ -639,7 +639,7 @@ static int netdev_open(struct net_device *dev)
 
 	i = alloc_ringdesc(dev);
 	if (i)
-		goto out_err;
+		goto out_err_free_irq;
 
 	spin_lock_irq(&np->lock);
 	netif_device_attach(dev);
@@ -655,6 +655,8 @@ static int netdev_open(struct net_device *dev)
 	np->timer.expires = jiffies + 1*HZ;
 	add_timer(&np->timer);
 	return 0;
+out_err_free_irq:
+	free_irq(irq, dev);
 out_err:
 	netif_device_attach(dev);
 	return i;
-- 
2.25.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] net: winbond-840: release IRQ on alloc_ringdesc() error path
  2026-10-08 16:21 [PATCH] net: winbond-840: release IRQ on alloc_ringdesc() error path Haotian Zhang
@ 2026-10-08 16:23 ` netdev-bot+sinfo
  2026-10-08 19:17 ` Andrew Lunn
  1 sibling, 0 replies; 3+ messages in thread
From: netdev-bot+sinfo @ 2026-10-08 16:23 UTC (permalink / raw)
  To: Haotian Zhang
  Cc: Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, netdev, linux-parisc, linux-kernel

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - How the issue was discovered, e.g. hit in production, hit during
   development, syzbot report, manual code inspection, LLM or static
   analysis tool scan.

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

 - What hardware the change was tested on. For driver fixes please
   mention the device (and if relevant firmware version) used for
   testing, or say that the change was not tested on real hardware.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] net: winbond-840: release IRQ on alloc_ringdesc() error path
  2026-10-08 16:21 [PATCH] net: winbond-840: release IRQ on alloc_ringdesc() error path Haotian Zhang
  2026-10-08 16:23 ` netdev-bot+sinfo
@ 2026-10-08 19:17 ` Andrew Lunn
  1 sibling, 0 replies; 3+ messages in thread
From: Andrew Lunn @ 2026-10-08 19:17 UTC (permalink / raw)
  To: Haotian Zhang
  Cc: Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, netdev, linux-parisc, linux-kernel

On Fri, Oct 09, 2026 at 12:21:09AM +0800, Haotian Zhang wrote:
> netdev_open() registers the shared IRQ with request_irq() and then calls
> alloc_ringdesc().  When alloc_ringdesc() fails, the error path jumps to
> out_err, which only calls netif_device_attach() and returns.  The IRQ
> handler stays registered forever: net/core/dev.c never calls ndo_stop
> when ndo_open fails, so netdev_close(), the only place that frees the
> IRQ, is never reached.  The leaked handler is also left enabled on an
> uninitialised device.
> 
> Add a separate out_err_free_irq label that releases the IRQ before
> returning the allocation error, mirroring the cleanup already used by
> the sibling de2104x driver.

Please set the subject line correctly:

https://www.kernel.org/doc/html/latest/process/maintainer-netdev.html

> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")

This obviously does not bother anybody, or it would of been fixed by
now. Please post this to net-next.

You might want to concentrate on drivers from the last decade?

    Andrew

---
pw-bot: cr

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-08 19:17 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 16:21 [PATCH] net: winbond-840: release IRQ on alloc_ringdesc() error path Haotian Zhang
2026-10-08 16:23 ` netdev-bot+sinfo
2026-10-08 19:17 ` Andrew Lunn

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®