* [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs
@ 2026-09-27 14:47 Jiale Yao
2026-09-27 14:47 ` [PATCH v2 1/7] net: macb: manage the netdev lifetime with devres Jiale Yao
` (7 more replies)
0 siblings, 8 replies; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Théo Lebrun, Conor Dooley, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Wei Fang, Frank Li,
Shenwei Wang, Jian Shen, Jijie Shao, Niklas Söderlund,
Paul Barker, Byungho An, Russell King, Nicolas Ferre,
Soren Brinkmann, Fabio Estevam, Arnd Bergmann, Zhangfei Gao,
dingtianhong, Jiancheng Xue, Dongpo Li, Mitsuhiro Kimura,
Sergei Shtylyov, Sergey Shtylyov, Claudiu Beznea, Vipul Pandya,
Girish K S, Siva Reddy, netdev, linux-kernel, imx,
linux-renesas-soc
Cc: Jiale Yao
Several Ethernet platform drivers request interrupts with
devm_request_irq() but allocate and free their netdevs manually.
Device-managed resources are released only after the driver's remove
callback returns, so these callbacks free the IRQ data while the interrupt
handlers can still be invoked. A late or shared interrupt in this window
can dereference freed memory.
For six drivers, make the netdev allocation device managed. Since each IRQ
is requested after its netdev is allocated, devres ordering releases the
IRQ before the netdev. SXGBE also keeps its hardware operations object
alive through the same ordering because its handlers dereference that
object directly.
RAVB takes a separate path because its ndo_stop() participates in runtime
PM teardown and its remove callback can encounter a resume failure before
unregister_netdev(). Keep its netdev manually managed, place its IRQs in a
dedicated devres group, and explicitly release that group after
unregistering the netdev. On a resume failure, continue the software
teardown without an unmatched runtime PM put.
Each patch handles one driver and is independently buildable.
Changes in v2:
- Keep commit message tags together without blank lines between them, as
requested by Francesco.
Jiale Yao (7):
net: macb: manage the netdev lifetime with devres
net: fec: manage the netdev lifetime with devres
net: hip04: manage the netdev lifetime with devres
net: hisi_femac: manage the netdev lifetime with devres
net: hix5hd2: manage the netdev lifetime with devres
net: ravb: fix resource teardown ordering
net: sxgbe: manage IRQ data lifetimes with devres
drivers/net/ethernet/cadence/macb_main.c | 17 +++++-------
drivers/net/ethernet/freescale/fec_main.c | 8 +++---
drivers/net/ethernet/hisilicon/hip04_eth.c | 4 +--
drivers/net/ethernet/hisilicon/hisi_femac.c | 15 +++++------
drivers/net/ethernet/hisilicon/hix5hd2_gmac.c | 15 +++++------
drivers/net/ethernet/renesas/ravb_main.c | 23 +++++++++++-----
.../net/ethernet/samsung/sxgbe/sxgbe_main.c | 26 +++++++------------
7 files changed, 49 insertions(+), 59 deletions(-)
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2 1/7] net: macb: manage the netdev lifetime with devres
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: " Jiale Yao
` (6 subsequent siblings)
7 siblings, 0 replies; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Théo Lebrun, Conor Dooley, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Russell King,
Nicolas Ferre, Soren Brinkmann, netdev, linux-kernel
Cc: Jiale Yao, stable
macb_remove() frees the netdev while its managed IRQs are only
released after the remove callback returns. An interrupt in that window
can dereference the freed netdev or queue data.
Allocate the netdev with devres as well. Since the IRQs are registered
later, devres releases them before freeing the netdev and closes the
lifetime gap.
Fixes: 0a4acf08ea62 ("net: macb: Use devm_request_irq()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/cadence/macb_main.c | 17 +++++++----------
1 file changed, 7 insertions(+), 10 deletions(-)
diff --git a/drivers/net/ethernet/cadence/macb_main.c b/drivers/net/ethernet/cadence/macb_main.c
index b8234ac4b602..ebf6ffb1cc4f 100644
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -5812,7 +5812,8 @@ static int macb_probe(struct platform_device *pdev)
goto err_disable_clocks;
}
- netdev = alloc_etherdev_mq(sizeof(*bp), num_queues);
+ netdev = devm_alloc_etherdev_mqs(&pdev->dev, sizeof(*bp),
+ num_queues, num_queues);
if (!netdev) {
err = -ENOMEM;
goto err_disable_clocks;
@@ -5859,7 +5860,7 @@ static int macb_probe(struct platform_device *pdev)
IS_ENABLED(CONFIG_MACB_USE_HWSTAMP)) {
dev_err(&pdev->dev, "Timer adjust mode is not supported\n");
err = -EINVAL;
- goto err_out_free_netdev;
+ goto err_disable_clocks;
}
/* By default we set to partial store and forward mode for zynqmp.
@@ -5893,7 +5894,7 @@ static int macb_probe(struct platform_device *pdev)
err = dma_set_mask_and_coherent(&pdev->dev, DMA_BIT_MASK(44));
if (err) {
dev_err(&pdev->dev, "failed to set DMA mask\n");
- goto err_out_free_netdev;
+ goto err_disable_clocks;
}
bp->caps |= MACB_CAPS_DMA_64B;
}
@@ -5903,7 +5904,7 @@ static int macb_probe(struct platform_device *pdev)
netdev->irq = platform_get_irq(pdev, 0);
if (netdev->irq < 0) {
err = netdev->irq;
- goto err_out_free_netdev;
+ goto err_disable_clocks;
}
/* MTU range: 68 - 1518 or 10240 */
@@ -5932,7 +5933,7 @@ static int macb_probe(struct platform_device *pdev)
err = of_get_ethdev_address(np, bp->netdev);
if (err == -EPROBE_DEFER)
- goto err_out_free_netdev;
+ goto err_disable_clocks;
else if (err)
macb_get_hwaddr(bp);
@@ -5946,7 +5947,7 @@ static int macb_probe(struct platform_device *pdev)
/* IP specific init */
err = macb_init(pdev, macb_config);
if (err)
- goto err_out_free_netdev;
+ goto err_disable_clocks;
err = macb_mii_init(bp);
if (err)
@@ -5988,9 +5989,6 @@ static int macb_probe(struct platform_device *pdev)
err_out_phy_exit:
phy_exit(bp->phy);
-err_out_free_netdev:
- free_netdev(netdev);
-
err_disable_clocks:
macb_clks_disable(pclk, hclk, tx_clk, rx_clk, tsu_clk);
pm_runtime_disable(&pdev->dev);
@@ -6024,7 +6022,6 @@ static void macb_remove(struct platform_device *pdev)
pm_runtime_dont_use_autosuspend(&pdev->dev);
pm_runtime_set_suspended(&pdev->dev);
phylink_destroy(bp->phylink);
- free_netdev(netdev);
}
}
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-09-27 14:47 ` [PATCH v2 1/7] net: macb: manage the netdev lifetime with devres Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-28 2:57 ` Wei Fang
2026-09-27 14:47 ` [PATCH v2 3/7] net: hip04: " Jiale Yao
` (5 subsequent siblings)
7 siblings, 1 reply; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Wei Fang, Frank Li, Shenwei Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Fabio Estevam, imx,
netdev, linux-kernel
Cc: Jiale Yao, stable
fec_drv_remove() frees the netdev before devres releases the managed
IRQs whose handlers use it as their data pointer. A late interrupt can
therefore access the freed netdev.
Allocate the netdev with devres so that the later IRQ registrations are
released first during teardown.
Fixes: 0d9b2ab1c376 ("fec: Use devm_request_irq()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/freescale/fec_main.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/freescale/fec_main.c b/drivers/net/ethernet/freescale/fec_main.c
index 794ec427b0ee..23e794a31ce8 100644
--- a/drivers/net/ethernet/freescale/fec_main.c
+++ b/drivers/net/ethernet/freescale/fec_main.c
@@ -5219,8 +5219,9 @@ fec_probe(struct platform_device *pdev)
fec_enet_get_queue_num(pdev, &num_tx_qs, &num_rx_qs);
/* Init network device */
- ndev = alloc_etherdev_mqs(sizeof(struct fec_enet_private) +
- FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
+ ndev = devm_alloc_etherdev_mqs(&pdev->dev,
+ sizeof(struct fec_enet_private) +
+ FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
if (!ndev)
return -ENOMEM;
@@ -5480,8 +5481,6 @@ fec_probe(struct platform_device *pdev)
failed_phy:
dev_id--;
failed_ioremap:
- free_netdev(ndev);
-
return ret;
}
@@ -5522,7 +5521,6 @@ fec_drv_remove(struct platform_device *pdev)
pm_runtime_disable(&pdev->dev);
fec_enet_deinit(ndev);
- free_netdev(ndev);
}
static int fec_suspend(struct device *dev)
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2 3/7] net: hip04: manage the netdev lifetime with devres
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-09-27 14:47 ` [PATCH v2 1/7] net: macb: manage the netdev lifetime with devres Jiale Yao
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: " Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-27 14:47 ` [PATCH v2 4/7] net: hisi_femac: " Jiale Yao
` (4 subsequent siblings)
7 siblings, 0 replies; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Jian Shen, Jijie Shao, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, dingtianhong,
Arnd Bergmann, Zhangfei Gao, netdev, linux-kernel
Cc: Jiale Yao, stable
hip04_remove() frees the netdev before the managed IRQ is released
after the remove callback. Since the IRQ handler receives the netdev as
its data pointer, a late interrupt can access freed memory.
Use a managed netdev allocation. Devres then releases the IRQ, which is
registered later, before releasing the netdev.
Fixes: a41ea46a9a12 ("net: hisilicon: new hip04 ethernet driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/hisilicon/hip04_eth.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/hisilicon/hip04_eth.c b/drivers/net/ethernet/hisilicon/hip04_eth.c
index fc2c47dcfaab..4a643dff22ab 100644
--- a/drivers/net/ethernet/hisilicon/hip04_eth.c
+++ b/drivers/net/ethernet/hisilicon/hip04_eth.c
@@ -905,7 +905,7 @@ static int hip04_mac_probe(struct platform_device *pdev)
int irq;
int ret;
- ndev = alloc_etherdev(sizeof(struct hip04_priv));
+ ndev = devm_alloc_etherdev(d, sizeof(struct hip04_priv));
if (!ndev)
return -ENOMEM;
@@ -1021,7 +1021,6 @@ static int hip04_mac_probe(struct platform_device *pdev)
hip04_free_ring(ndev, d);
init_fail:
of_node_put(priv->phy_node);
- free_netdev(ndev);
return ret;
}
@@ -1038,7 +1037,6 @@ static void hip04_remove(struct platform_device *pdev)
unregister_netdev(ndev);
of_node_put(priv->phy_node);
cancel_work_sync(&priv->tx_timeout_task);
- free_netdev(ndev);
}
static const struct of_device_id hip04_mac_match[] = {
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2 4/7] net: hisi_femac: manage the netdev lifetime with devres
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
` (2 preceding siblings ...)
2026-09-27 14:47 ` [PATCH v2 3/7] net: hip04: " Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-27 14:47 ` [PATCH v2 5/7] net: hix5hd2: " Jiale Yao
` (3 subsequent siblings)
7 siblings, 0 replies; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Jian Shen, Jijie Shao, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Jiancheng Xue,
Dongpo Li, netdev, linux-kernel
Cc: Jiale Yao, stable
hisi_femac_drv_remove() frees the netdev while the shared managed IRQ
remains registered until devres cleanup. Its handler uses the netdev as
private data, so an interrupt in this window can dereference freed
memory.
Manage the netdev allocation with devres so the later IRQ resource is
released before the netdev.
Fixes: 542ae60af24f ("net: hisilicon: Add Fast Ethernet MAC driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/hisilicon/hisi_femac.c | 15 ++++++---------
1 file changed, 6 insertions(+), 9 deletions(-)
diff --git a/drivers/net/ethernet/hisilicon/hisi_femac.c b/drivers/net/ethernet/hisilicon/hisi_femac.c
index d244a40df430..d369824fa4e8 100644
--- a/drivers/net/ethernet/hisilicon/hisi_femac.c
+++ b/drivers/net/ethernet/hisilicon/hisi_femac.c
@@ -774,7 +774,7 @@ static int hisi_femac_drv_probe(struct platform_device *pdev)
struct phy_device *phy;
int ret;
- ndev = alloc_etherdev(sizeof(*priv));
+ ndev = devm_alloc_etherdev(dev, sizeof(*priv));
if (!ndev)
return -ENOMEM;
@@ -788,26 +788,26 @@ static int hisi_femac_drv_probe(struct platform_device *pdev)
priv->port_base = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(priv->port_base)) {
ret = PTR_ERR(priv->port_base);
- goto out_free_netdev;
+ goto out_return;
}
priv->glb_base = devm_platform_ioremap_resource(pdev, 1);
if (IS_ERR(priv->glb_base)) {
ret = PTR_ERR(priv->glb_base);
- goto out_free_netdev;
+ goto out_return;
}
priv->clk = devm_clk_get(&pdev->dev, NULL);
if (IS_ERR(priv->clk)) {
dev_err(dev, "failed to get clk\n");
ret = -ENODEV;
- goto out_free_netdev;
+ goto out_return;
}
ret = clk_prepare_enable(priv->clk);
if (ret) {
dev_err(dev, "failed to enable clk %d\n", ret);
- goto out_free_netdev;
+ goto out_return;
}
priv->mac_rst = devm_reset_control_get(dev, "mac");
@@ -887,9 +887,7 @@ static int hisi_femac_drv_probe(struct platform_device *pdev)
phy_disconnect(phy);
out_disable_clk:
clk_disable_unprepare(priv->clk);
-out_free_netdev:
- free_netdev(ndev);
-
+out_return:
return ret;
}
@@ -903,7 +901,6 @@ static void hisi_femac_drv_remove(struct platform_device *pdev)
phy_disconnect(ndev->phydev);
clk_disable_unprepare(priv->clk);
- free_netdev(ndev);
}
#ifdef CONFIG_PM
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2 5/7] net: hix5hd2: manage the netdev lifetime with devres
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
` (3 preceding siblings ...)
2026-09-27 14:47 ` [PATCH v2 4/7] net: hisi_femac: " Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-27 14:47 ` [PATCH v2 6/7] net: ravb: fix resource teardown ordering Jiale Yao
` (2 subsequent siblings)
7 siblings, 0 replies; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Jian Shen, Jijie Shao, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Zhangfei Gao, netdev,
linux-kernel
Cc: Jiale Yao, stable
hix5hd2_dev_remove() manually frees the netdev before devres releases
the IRQ. The interrupt handler receives that netdev as its data pointer
and can access it during this teardown window.
Allocate the netdev through devres so its later registered IRQ is
released first.
Fixes: 57c5bc9ad7d7 ("net: hisilicon: add hix5hd2 mac driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/hisilicon/hix5hd2_gmac.c | 15 ++++++---------
1 file changed, 6 insertions(+), 9 deletions(-)
diff --git a/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c b/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
index 02282dc86faf..ffcb281230eb 100644
--- a/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
+++ b/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
@@ -1100,7 +1100,7 @@ static int hix5hd2_dev_probe(struct platform_device *pdev)
struct mii_bus *bus;
int ret;
- ndev = alloc_etherdev(sizeof(struct hix5hd2_priv));
+ ndev = devm_alloc_etherdev(dev, sizeof(struct hix5hd2_priv));
if (!ndev)
return -ENOMEM;
@@ -1115,26 +1115,26 @@ static int hix5hd2_dev_probe(struct platform_device *pdev)
priv->base = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(priv->base)) {
ret = PTR_ERR(priv->base);
- goto out_free_netdev;
+ goto out_return;
}
priv->ctrl_base = devm_platform_ioremap_resource(pdev, 1);
if (IS_ERR(priv->ctrl_base)) {
ret = PTR_ERR(priv->ctrl_base);
- goto out_free_netdev;
+ goto out_return;
}
priv->mac_core_clk = devm_clk_get(&pdev->dev, "mac_core");
if (IS_ERR(priv->mac_core_clk)) {
netdev_err(ndev, "failed to get mac core clk\n");
ret = -ENODEV;
- goto out_free_netdev;
+ goto out_return;
}
ret = clk_prepare_enable(priv->mac_core_clk);
if (ret < 0) {
netdev_err(ndev, "failed to enable mac core clk %d\n", ret);
- goto out_free_netdev;
+ goto out_return;
}
priv->mac_ifc_clk = devm_clk_get(&pdev->dev, "mac_ifc");
@@ -1271,9 +1271,7 @@ static int hix5hd2_dev_probe(struct platform_device *pdev)
clk_disable_unprepare(priv->mac_ifc_clk);
out_disable_mac_core_clk:
clk_disable_unprepare(priv->mac_core_clk);
-out_free_netdev:
- free_netdev(ndev);
-
+out_return:
return ret;
}
@@ -1291,7 +1289,6 @@ static void hix5hd2_dev_remove(struct platform_device *pdev)
hix5hd2_destroy_hw_desc_queue(priv);
of_node_put(priv->phy_node);
cancel_work_sync(&priv->tx_timeout_task);
- free_netdev(ndev);
}
static const struct of_device_id hix5hd2_of_match[] = {
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2 6/7] net: ravb: fix resource teardown ordering
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
` (4 preceding siblings ...)
2026-09-27 14:47 ` [PATCH v2 5/7] net: hix5hd2: " Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-27 16:01 ` Niklas Söderlund
2026-09-27 14:47 ` [PATCH v2 7/7] net: sxgbe: manage IRQ data lifetimes with devres Jiale Yao
2026-09-27 22:30 ` [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jakub Kicinski
7 siblings, 1 reply; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Niklas Söderlund, Paul Barker, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Sergei Shtylyov,
Mitsuhiro Kimura, Claudiu Beznea, Sergey Shtylyov, netdev,
linux-renesas-soc, linux-kernel
Cc: Jiale Yao, stable
ravb_remove() frees the netdev before devres releases the managed IRQs.
The handlers use the netdev as their data pointer, so an interrupt during
that window can access freed memory. Probe error paths have the same
ordering problem.
The remove callback also returns when runtime resume fails. That leaves
the netdev registered while the driver core still releases its managed
resources. A running interface already holds a runtime PM reference, so
the extra get cannot invoke a failing resume. A resume failure therefore
occurs while the interface is down and ndo_stop() will not be called.
Place the IRQ resources in a dedicated devres group and release it before
freeing the netdev. Continue unregistering and freeing software resources
when runtime resume fails, but skip the unmatched runtime PM put.
Fixes: c156633f1353 ("Renesas Ethernet AVB driver proper")
Fixes: 48f894ab07c4 ("net: ravb: Add runtime PM support")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/ethernet/renesas/ravb_main.c | 23 +++++++++++++++++------
1 file changed, 17 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/renesas/ravb_main.c b/drivers/net/ethernet/renesas/ravb_main.c
index ea1c7e536791..a25f5ac7062f 100644
--- a/drivers/net/ethernet/renesas/ravb_main.c
+++ b/drivers/net/ethernet/renesas/ravb_main.c
@@ -2963,28 +2963,35 @@ static int ravb_probe(struct platform_device *pdev)
priv->num_rx_ring[RAVB_NC] = NC_RX_RING_SIZE;
}
+ if (!devres_open_group(&pdev->dev, priv, GFP_KERNEL)) {
+ error = -ENOMEM;
+ goto out_reset_assert;
+ }
+
error = ravb_setup_irqs(priv);
if (error)
- goto out_reset_assert;
+ goto out_release_irqs;
+
+ devres_close_group(&pdev->dev, priv);
priv->clk = devm_clk_get(&pdev->dev, NULL);
if (IS_ERR(priv->clk)) {
error = PTR_ERR(priv->clk);
- goto out_reset_assert;
+ goto out_release_irqs;
}
if (info->gptp_ref_clk) {
priv->gptp_clk = devm_clk_get(&pdev->dev, "gptp");
if (IS_ERR(priv->gptp_clk)) {
error = PTR_ERR(priv->gptp_clk);
- goto out_reset_assert;
+ goto out_release_irqs;
}
}
priv->refclk = devm_clk_get_optional(&pdev->dev, "refclk");
if (IS_ERR(priv->refclk)) {
error = PTR_ERR(priv->refclk);
- goto out_reset_assert;
+ goto out_release_irqs;
}
clk_prepare(priv->refclk);
@@ -3124,6 +3131,8 @@ static int ravb_probe(struct platform_device *pdev)
pm_runtime_disable(&pdev->dev);
pm_runtime_dont_use_autosuspend(&pdev->dev);
clk_unprepare(priv->refclk);
+out_release_irqs:
+ devres_release_group(&pdev->dev, priv);
out_reset_assert:
reset_control_assert(rstc);
out_free_netdev:
@@ -3141,9 +3150,10 @@ static void ravb_remove(struct platform_device *pdev)
error = pm_runtime_resume_and_get(dev);
if (error < 0)
- return;
+ dev_warn(dev, "failed to resume device: %d\n", error);
unregister_netdev(ndev);
+ devres_release_group(dev, priv);
if (info->nc_queues)
netif_napi_del(&priv->napi[RAVB_NC]);
netif_napi_del(&priv->napi[RAVB_BE]);
@@ -3153,7 +3163,8 @@ static void ravb_remove(struct platform_device *pdev)
dma_free_coherent(ndev->dev.parent, priv->desc_bat_size, priv->desc_bat,
priv->desc_bat_dma);
- pm_runtime_put_sync_suspend(&pdev->dev);
+ if (error >= 0)
+ pm_runtime_put_sync_suspend(&pdev->dev);
pm_runtime_disable(&pdev->dev);
pm_runtime_dont_use_autosuspend(dev);
clk_unprepare(priv->refclk);
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2 7/7] net: sxgbe: manage IRQ data lifetimes with devres
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
` (5 preceding siblings ...)
2026-09-27 14:47 ` [PATCH v2 6/7] net: ravb: fix resource teardown ordering Jiale Yao
@ 2026-09-27 14:47 ` Jiale Yao
2026-09-27 22:30 ` [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jakub Kicinski
7 siblings, 0 replies; 11+ messages in thread
From: Jiale Yao @ 2026-09-27 14:47 UTC (permalink / raw)
To: Byungho An, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Siva Reddy, Vipul Pandya,
Girish K S, netdev, linux-kernel
Cc: Jiale Yao, stable
sxgbe_drv_remove() frees the netdev and hardware operations while
managed IRQs remain registered until the remove callback returns. The
handlers dereference these objects, so an interrupt in that window can
access freed memory.
Allocate both objects with devres. They are acquired before the IRQs and
are consequently released only after the IRQ resources have been
removed.
Fixes: 1edb9ca69e8a ("net: sxgbe: add basic framework for Samsung 10Gb ethernet driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
.../net/ethernet/samsung/sxgbe/sxgbe_main.c | 26 +++++++------------
1 file changed, 9 insertions(+), 17 deletions(-)
diff --git a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
index 70cf3619555f..ada851477302 100644
--- a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
+++ b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
@@ -2007,7 +2007,7 @@ static int sxgbe_hw_init(struct sxgbe_priv_data * const priv)
{
u32 ctrl_ids;
- priv->hw = kmalloc_obj(*priv->hw);
+ priv->hw = devm_kmalloc(priv->device, sizeof(*priv->hw), GFP_KERNEL);
if(!priv->hw)
return -ENOMEM;
@@ -2058,7 +2058,7 @@ static int sxgbe_sw_reset(void __iomem *addr)
* @plat_dat: platform data pointer
* @addr: iobase memory address
* Description: this is the main probe function used to
- * call the alloc_etherdev, allocate the priv structure.
+ * allocate the netdev and priv structure.
*/
struct sxgbe_priv_data *sxgbe_drv_probe(struct device *device,
struct sxgbe_plat_data *plat_dat,
@@ -2069,8 +2069,8 @@ struct sxgbe_priv_data *sxgbe_drv_probe(struct device *device,
int ret;
u8 queue_num;
- ndev = alloc_etherdev_mqs(sizeof(struct sxgbe_priv_data),
- SXGBE_TX_QUEUES, SXGBE_RX_QUEUES);
+ ndev = devm_alloc_etherdev_mqs(device, sizeof(struct sxgbe_priv_data),
+ SXGBE_TX_QUEUES, SXGBE_RX_QUEUES);
if (!ndev)
return NULL;
@@ -2086,7 +2086,7 @@ struct sxgbe_priv_data *sxgbe_drv_probe(struct device *device,
ret = sxgbe_sw_reset(priv->ioaddr);
if (ret)
- goto error_free_netdev;
+ goto error_return;
/* Verify driver arguments */
sxgbe_verify_args();
@@ -2094,16 +2094,16 @@ struct sxgbe_priv_data *sxgbe_drv_probe(struct device *device,
/* Init MAC and get the capabilities */
ret = sxgbe_hw_init(priv);
if (ret)
- goto error_free_netdev;
+ goto error_return;
/* allocate memory resources for Descriptor rings */
ret = txring_mem_alloc(priv);
if (ret)
- goto error_free_hw;
+ goto error_return;
ret = rxring_mem_alloc(priv);
if (ret)
- goto error_free_hw;
+ goto error_return;
ndev->netdev_ops = &sxgbe_netdev_ops;
@@ -2191,11 +2191,7 @@ struct sxgbe_priv_data *sxgbe_drv_probe(struct device *device,
clk_put(priv->sxgbe_clk);
error_napi_del:
netif_napi_del(&priv->napi);
-error_free_hw:
- kfree(priv->hw);
-error_free_netdev:
- free_netdev(ndev);
-
+error_return:
return NULL;
}
@@ -2229,10 +2225,6 @@ void sxgbe_drv_remove(struct net_device *ndev)
clk_put(priv->sxgbe_clk);
netif_napi_del(&priv->napi);
-
- kfree(priv->hw);
-
- free_netdev(ndev);
}
#ifdef CONFIG_PM
--
2.34.1
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v2 6/7] net: ravb: fix resource teardown ordering
2026-09-27 14:47 ` [PATCH v2 6/7] net: ravb: fix resource teardown ordering Jiale Yao
@ 2026-09-27 16:01 ` Niklas Söderlund
0 siblings, 0 replies; 11+ messages in thread
From: Niklas Söderlund @ 2026-09-27 16:01 UTC (permalink / raw)
To: Jiale Yao
Cc: Paul Barker, Andrew Lunn, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Sergei Shtylyov, Mitsuhiro Kimura,
Claudiu Beznea, Sergey Shtylyov, netdev, linux-renesas-soc,
linux-kernel, stable
Hi Jiale,
On 2026-09-27 22:47:39 +0800, Jiale Yao wrote:
> ravb_remove() frees the netdev before devres releases the managed IRQs.
> The handlers use the netdev as their data pointer, so an interrupt during
> that window can access freed memory. Probe error paths have the same
> ordering problem.
>
> The remove callback also returns when runtime resume fails. That leaves
> the netdev registered while the driver core still releases its managed
> resources. A running interface already holds a runtime PM reference, so
> the extra get cannot invoke a failing resume. A resume failure therefore
> occurs while the interface is down and ndo_stop() will not be called.
>
> Place the IRQ resources in a dedicated devres group and release it before
> freeing the netdev. Continue unregistering and freeing software resources
> when runtime resume fails, but skip the unmatched runtime PM put.
Would it not make more sens to rework the driver to allocate the ndev
using devm too instead of adding a complex devres group? AFIK
s/alloc_etherdev_mqs/devm_alloc_etherdev_mqs/ would allocate the ndev
with devm too?
>
> Fixes: c156633f1353 ("Renesas Ethernet AVB driver proper")
> Fixes: 48f894ab07c4 ("net: ravb: Add runtime PM support")
> Cc: stable@vger.kernel.org
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/ethernet/renesas/ravb_main.c | 23 +++++++++++++++++------
> 1 file changed, 17 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/net/ethernet/renesas/ravb_main.c b/drivers/net/ethernet/renesas/ravb_main.c
> index ea1c7e536791..a25f5ac7062f 100644
> --- a/drivers/net/ethernet/renesas/ravb_main.c
> +++ b/drivers/net/ethernet/renesas/ravb_main.c
> @@ -2963,28 +2963,35 @@ static int ravb_probe(struct platform_device *pdev)
> priv->num_rx_ring[RAVB_NC] = NC_RX_RING_SIZE;
> }
>
> + if (!devres_open_group(&pdev->dev, priv, GFP_KERNEL)) {
> + error = -ENOMEM;
> + goto out_reset_assert;
> + }
> +
> error = ravb_setup_irqs(priv);
> if (error)
> - goto out_reset_assert;
> + goto out_release_irqs;
> +
> + devres_close_group(&pdev->dev, priv);
>
> priv->clk = devm_clk_get(&pdev->dev, NULL);
> if (IS_ERR(priv->clk)) {
> error = PTR_ERR(priv->clk);
> - goto out_reset_assert;
> + goto out_release_irqs;
> }
>
> if (info->gptp_ref_clk) {
> priv->gptp_clk = devm_clk_get(&pdev->dev, "gptp");
> if (IS_ERR(priv->gptp_clk)) {
> error = PTR_ERR(priv->gptp_clk);
> - goto out_reset_assert;
> + goto out_release_irqs;
> }
> }
>
> priv->refclk = devm_clk_get_optional(&pdev->dev, "refclk");
> if (IS_ERR(priv->refclk)) {
> error = PTR_ERR(priv->refclk);
> - goto out_reset_assert;
> + goto out_release_irqs;
> }
> clk_prepare(priv->refclk);
>
> @@ -3124,6 +3131,8 @@ static int ravb_probe(struct platform_device *pdev)
> pm_runtime_disable(&pdev->dev);
> pm_runtime_dont_use_autosuspend(&pdev->dev);
> clk_unprepare(priv->refclk);
> +out_release_irqs:
> + devres_release_group(&pdev->dev, priv);
> out_reset_assert:
> reset_control_assert(rstc);
> out_free_netdev:
> @@ -3141,9 +3150,10 @@ static void ravb_remove(struct platform_device *pdev)
>
> error = pm_runtime_resume_and_get(dev);
> if (error < 0)
> - return;
> + dev_warn(dev, "failed to resume device: %d\n", error);
>
> unregister_netdev(ndev);
> + devres_release_group(dev, priv);
> if (info->nc_queues)
> netif_napi_del(&priv->napi[RAVB_NC]);
> netif_napi_del(&priv->napi[RAVB_BE]);
> @@ -3153,7 +3163,8 @@ static void ravb_remove(struct platform_device *pdev)
> dma_free_coherent(ndev->dev.parent, priv->desc_bat_size, priv->desc_bat,
> priv->desc_bat_dma);
>
> - pm_runtime_put_sync_suspend(&pdev->dev);
> + if (error >= 0)
> + pm_runtime_put_sync_suspend(&pdev->dev);
> pm_runtime_disable(&pdev->dev);
> pm_runtime_dont_use_autosuspend(dev);
> clk_unprepare(priv->refclk);
> --
> 2.34.1
>
--
Kind Regards,
Niklas Söderlund
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
` (6 preceding siblings ...)
2026-09-27 14:47 ` [PATCH v2 7/7] net: sxgbe: manage IRQ data lifetimes with devres Jiale Yao
@ 2026-09-27 22:30 ` Jakub Kicinski
7 siblings, 0 replies; 11+ messages in thread
From: Jakub Kicinski @ 2026-09-27 22:30 UTC (permalink / raw)
To: Jiale Yao
Cc: Théo Lebrun, Conor Dooley, Andrew Lunn, David S. Miller,
Eric Dumazet, Paolo Abeni, Wei Fang, Frank Li, Shenwei Wang,
Jian Shen, Jijie Shao, Niklas Söderlund, Paul Barker,
Byungho An, Russell King, Nicolas Ferre, Soren Brinkmann,
Fabio Estevam, Arnd Bergmann, Zhangfei Gao, dingtianhong,
Jiancheng Xue, Dongpo Li, Mitsuhiro Kimura, Sergei Shtylyov,
Sergey Shtylyov, Claudiu Beznea, Vipul Pandya, Girish K S,
Siva Reddy, netdev, linux-kernel, imx, linux-renesas-soc
On Sun, 27 Sep 2026 22:47:33 +0800 Jiale Yao wrote:
> Several Ethernet platform drivers request interrupts with
> devm_request_irq() but allocate and free their netdevs manually.
> Device-managed resources are released only after the driver's remove
> callback returns, so these callbacks free the IRQ data while the interrupt
> handlers can still be invoked. A late or shared interrupt in this window
> can dereference freed memory.
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
- What hardware the change was tested on. For driver fixes please
mention the device (and if relevant firmware version) used for
testing, or say that the change was not tested on real hardware.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
^ permalink raw reply [flat|nested] 11+ messages in thread
* RE: [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: " Jiale Yao
@ 2026-09-28 2:57 ` Wei Fang
0 siblings, 0 replies; 11+ messages in thread
From: Wei Fang @ 2026-09-28 2:57 UTC (permalink / raw)
To: Jiale Yao
Cc: stable, Frank Li, Shenwei Wang, Andrew Lunn, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, Fabio Estevam, imx,
netdev, linux-kernel
> Subject: [PATCH v2 2/7] net: fec: manage the netdev lifetime with devres
Please add target tree to the subject. Since this is a fix, the target tree should be net.
>
> fec_drv_remove() frees the netdev before devres releases the managed
> IRQs whose handlers use it as their data pointer. A late interrupt can
> therefore access the freed netdev.
>
> Allocate the netdev with devres so that the later IRQ registrations are
> released first during teardown.
>
> Fixes: 0d9b2ab1c376 ("fec: Use devm_request_irq()")
> Cc: stable@vger.kernel.org
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/ethernet/freescale/fec_main.c | 8 +++-----
> 1 file changed, 3 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/net/ethernet/freescale/fec_main.c
> b/drivers/net/ethernet/freescale/fec_main.c
> index 794ec427b0ee..23e794a31ce8 100644
> --- a/drivers/net/ethernet/freescale/fec_main.c
> +++ b/drivers/net/ethernet/freescale/fec_main.c
> @@ -5219,8 +5219,9 @@ fec_probe(struct platform_device *pdev)
> fec_enet_get_queue_num(pdev, &num_tx_qs, &num_rx_qs);
>
> /* Init network device */
> - ndev = alloc_etherdev_mqs(sizeof(struct fec_enet_private) +
> - FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
> + ndev = devm_alloc_etherdev_mqs(&pdev->dev,
> + sizeof(struct fec_enet_private) +
> + FEC_STATS_SIZE, num_tx_qs, num_rx_qs);
> if (!ndev)
> return -ENOMEM;
>
> @@ -5480,8 +5481,6 @@ fec_probe(struct platform_device *pdev)
> failed_phy:
> dev_id--;
> failed_ioremap:
failed_ioremap is no longer needed, please remove it.
> - free_netdev(ndev);
> -
> return ret;
> }
>
> @@ -5522,7 +5521,6 @@ fec_drv_remove(struct platform_device *pdev)
> pm_runtime_disable(&pdev->dev);
>
> fec_enet_deinit(ndev);
> - free_netdev(ndev);
> }
>
> static int fec_suspend(struct device *dev)
> --
> 2.34.1
This patch just prevents the netdev from being freed in fec_drv_remove(),
but fec_enet_interrupt() could still be called after the removal, and
fec_enet_collect_events() will be called to access the registers, however,
the ipg clk has been disabled, the registers are not accessible at that point,
that is a problem.
I think the hardware interrupts should be disabled on the removal path
and disable_irq() should be called to disable the irqs.
BTW, do not repost a new version within 24 hours.
https://elixir.bootlin.com/linux/v7.3-rc4/source/Documentation/process/maintainer-netdev.rst#L15
There are other upstream rules in maintainer-netdev.rst, please
refer to them.
^ permalink raw reply [flat|nested] 11+ messages in thread
end of thread, other threads:[~2026-09-28 2:57 UTC | newest]
Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-27 14:47 [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-09-27 14:47 ` [PATCH v2 1/7] net: macb: manage the netdev lifetime with devres Jiale Yao
2026-09-27 14:47 ` [PATCH v2 2/7] net: fec: " Jiale Yao
2026-09-28 2:57 ` Wei Fang
2026-09-27 14:47 ` [PATCH v2 3/7] net: hip04: " Jiale Yao
2026-09-27 14:47 ` [PATCH v2 4/7] net: hisi_femac: " Jiale Yao
2026-09-27 14:47 ` [PATCH v2 5/7] net: hix5hd2: " Jiale Yao
2026-09-27 14:47 ` [PATCH v2 6/7] net: ravb: fix resource teardown ordering Jiale Yao
2026-09-27 16:01 ` Niklas Söderlund
2026-09-27 14:47 ` [PATCH v2 7/7] net: sxgbe: manage IRQ data lifetimes with devres Jiale Yao
2026-09-27 22:30 ` [PATCH v2 0/7] net: ethernet: release managed IRQs before freeing netdevs Jakub Kicinski
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®