mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net v5] net: e1000: fix warning in iounmap on probe failure
@ 2026-09-28 12:38 Svyatoslav Nikolenko
  2026-09-28 12:39 ` netdev-bot+sinfo
  2026-09-28 15:17 ` Loktionov, Aleksandr
  0 siblings, 2 replies; 3+ messages in thread
From: Svyatoslav Nikolenko @ 2026-09-28 12:38 UTC (permalink / raw)
  To: anthony.l.nguyen, przemyslaw.kitszel, andrew+netdev, davem,
	edumazet, kuba, pabeni
  Cc: intel-wired-lan, netdev, linux-kernel, Svyatoslav Nikolenko,
	syzbot+ca1ef9e2e234b8d3599b, stable

In e1000_probe(), the error unwinding path at err_sw_init unconditionally
calls iounmap(hw->ce4100_gbe_mdio_base_virt). On non-CE4100 hardware,
hw->ce4100_gbe_mdio_base_virt remains NULL.
Passing NULL to iounmap() triggers a WARN_ON_ONCE on x86 architectures.
Furthermore, on CE4100 hardware, if probe fails before or during
MDIO mapping, ce4100_gbe_mdio_base_virt is also NULL.

Fix this by adding a NULL pointer check before calling iounmap() on
hw->ce4100_gbe_mdio_base_virt. iounmap(hw->hw_addr) remains unconditional
because every code path reaching err_sw_init occurs after hw->hw_addr has
been successfully mapped.

Reported-by: syzbot+ca1ef9e2e234b8d3599b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ca1ef9e2e234b8d3599b
Fixes: 13acde8fffc0 ("e1000: cleanup CE4100 MDIO registers access")
Cc: stable@vger.kernel.org
Signed-off-by: Svyatoslav Nikolenko <nsvatoslav515@gmail.com>
---
v5:
  - Updated commit message and changelog to accurately describe the NULL pointer
    check implemented in the diff.
  - Fixed subject string in the Fixes: tag to match commit 13acde8fffc0.
v4:
  - Actually include the code changes (v3 was sent un-staged by mistake)
v3:
  - Switched from pointer null-checks to checking hw->mac_type == e1000_ce4100
  - Removed redundant check for hw->hw_addr since it cannot be NULL here
  - Added missing Cc: stable tag and Closes tag
v2:
  - Expanded commit message to answer reviewer questions (reproduction details)
  - Added appropriate Fixes tags

 drivers/net/ethernet/intel/e1000/e1000_main.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/e1000/e1000_main.c b/drivers/net/ethernet/intel/e1000/e1000_main.c
index d7f5c6f16142..d7e279b739b8 100644
--- a/drivers/net/ethernet/intel/e1000/e1000_main.c
+++ b/drivers/net/ethernet/intel/e1000/e1000_main.c
@@ -1227,7 +1227,8 @@ static int e1000_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
 	kfree(adapter->rx_ring);
 err_dma:
 err_sw_init:
-	iounmap(hw->ce4100_gbe_mdio_base_virt);
+	if (hw->ce4100_gbe_mdio_base_virt)
+		iounmap(hw->ce4100_gbe_mdio_base_virt);
 	iounmap(hw->hw_addr);
 err_ioremap:
 	disable_dev = !test_and_set_bit(__E1000_DISABLED, &adapter->flags);
-- 
2.47.3


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net v5] net: e1000: fix warning in iounmap on probe failure
  2026-09-28 12:38 [PATCH net v5] net: e1000: fix warning in iounmap on probe failure Svyatoslav Nikolenko
@ 2026-09-28 12:39 ` netdev-bot+sinfo
  2026-09-28 15:17 ` Loktionov, Aleksandr
  1 sibling, 0 replies; 3+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28 12:39 UTC (permalink / raw)
  To: Svyatoslav Nikolenko
  Cc: anthony.l.nguyen, przemyslaw.kitszel, andrew+netdev, davem,
	edumazet, kuba, pabeni, intel-wired-lan, netdev, linux-kernel,
	syzbot+ca1ef9e2e234b8d3599b, stable

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - What hardware the change was tested on. For driver fixes please
   mention the device (and if relevant firmware version) used for
   testing, or say that the change was not tested on real hardware.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 3+ messages in thread

* RE: [PATCH net v5] net: e1000: fix warning in iounmap on probe failure
  2026-09-28 12:38 [PATCH net v5] net: e1000: fix warning in iounmap on probe failure Svyatoslav Nikolenko
  2026-09-28 12:39 ` netdev-bot+sinfo
@ 2026-09-28 15:17 ` Loktionov, Aleksandr
  1 sibling, 0 replies; 3+ messages in thread
From: Loktionov, Aleksandr @ 2026-09-28 15:17 UTC (permalink / raw)
  To: Svyatoslav Nikolenko, Nguyen, Anthony L, Kitszel, Przemyslaw,
	andrew+netdev, davem, edumazet, kuba, pabeni
  Cc: intel-wired-lan, netdev, linux-kernel,
	syzbot+ca1ef9e2e234b8d3599b, stable



> -----Original Message-----
> From: Svyatoslav Nikolenko <nsvatoslav515@gmail.com>
> Sent: Monday, September 28, 2026 2:38 PM
> To: Nguyen, Anthony L <anthony.l.nguyen@intel.com>; Kitszel,
> Przemyslaw <przemyslaw.kitszel@intel.com>; andrew+netdev@lunn.ch;
> davem@davemloft.net; edumazet@google.com; kuba@kernel.org;
> pabeni@redhat.com
> Cc: intel-wired-lan@lists.osuosl.org; netdev@vger.kernel.org; linux-
> kernel@vger.kernel.org; Svyatoslav Nikolenko
> <nsvatoslav515@gmail.com>;
> syzbot+ca1ef9e2e234b8d3599b@syzkaller.appspotmail.com;
> stable@vger.kernel.org
> Subject: [PATCH net v5] net: e1000: fix warning in iounmap on probe
> failure
> 
> In e1000_probe(), the error unwinding path at err_sw_init
> unconditionally calls iounmap(hw->ce4100_gbe_mdio_base_virt). On non-
> CE4100 hardware,
> hw->ce4100_gbe_mdio_base_virt remains NULL.
> Passing NULL to iounmap() triggers a WARN_ON_ONCE on x86
> architectures.
> Furthermore, on CE4100 hardware, if probe fails before or during MDIO
> mapping, ce4100_gbe_mdio_base_virt is also NULL.
> 
> Fix this by adding a NULL pointer check before calling iounmap() on
> hw->ce4100_gbe_mdio_base_virt. iounmap(hw->hw_addr) remains
> hw->unconditional
> because every code path reaching err_sw_init occurs after hw->hw_addr
> has been successfully mapped.
> 
> Reported-by: syzbot+ca1ef9e2e234b8d3599b@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=ca1ef9e2e234b8d3599b
> Fixes: 13acde8fffc0 ("e1000: cleanup CE4100 MDIO registers access")
> Cc: stable@vger.kernel.org
> Signed-off-by: Svyatoslav Nikolenko <nsvatoslav515@gmail.com>
> ---
> v5:
>   - Updated commit message and changelog to accurately describe the
> NULL pointer
>     check implemented in the diff.
>   - Fixed subject string in the Fixes: tag to match commit
> 13acde8fffc0.
> v4:
>   - Actually include the code changes (v3 was sent un-staged by
> mistake)
> v3:
>   - Switched from pointer null-checks to checking hw->mac_type ==
> e1000_ce4100
>   - Removed redundant check for hw->hw_addr since it cannot be NULL
> here
>   - Added missing Cc: stable tag and Closes tag
> v2:
>   - Expanded commit message to answer reviewer questions (reproduction
> details)
>   - Added appropriate Fixes tags
> 
>  drivers/net/ethernet/intel/e1000/e1000_main.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/net/ethernet/intel/e1000/e1000_main.c
> b/drivers/net/ethernet/intel/e1000/e1000_main.c
> index d7f5c6f16142..d7e279b739b8 100644
> --- a/drivers/net/ethernet/intel/e1000/e1000_main.c
> +++ b/drivers/net/ethernet/intel/e1000/e1000_main.c
> @@ -1227,7 +1227,8 @@ static int e1000_probe(struct pci_dev *pdev,
> const struct pci_device_id *ent)
>  	kfree(adapter->rx_ring);
>  err_dma:
>  err_sw_init:
> -	iounmap(hw->ce4100_gbe_mdio_base_virt);
> +	if (hw->ce4100_gbe_mdio_base_virt)
> +		iounmap(hw->ce4100_gbe_mdio_base_virt);
>  	iounmap(hw->hw_addr);
>  err_ioremap:
>  	disable_dev = !test_and_set_bit(__E1000_DISABLED, &adapter-
> >flags);
> --
> 2.47.3

Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-28 15:18 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 12:38 [PATCH net v5] net: e1000: fix warning in iounmap on probe failure Svyatoslav Nikolenko
2026-09-28 12:39 ` netdev-bot+sinfo
2026-09-28 15:17 ` Loktionov, Aleksandr

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®