* [PATCH net] net: calxeda: cancel timeout work before freeing rings
@ 2026-09-28 13:41 Hongyan Xu
2026-09-28 13:45 ` netdev-bot+sinfo
0 siblings, 1 reply; 2+ messages in thread
From: Hongyan Xu @ 2026-09-28 13:41 UTC (permalink / raw)
To: andrew+netdev, davem
Cc: edumazet, kuba, pabeni, o-takashi, kees, u.kleine-koenig,
bhelgaas, netdev, linux-kernel, jianhao.xu, Hongyan Xu
The transmit timeout paths queue tx_timeout_work, which accesses the DMA
rings and NAPI state. xgmac_stop() can free the rings without waiting
for a queued timeout worker, so the worker may subsequently use freed
storage.
Stop transmit and interrupt publication, cancel the timeout work, and
only then disable NAPI and release the rings.
Fixes: 85c10f282861 ("net: add calxeda xgmac ethernet driver")
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
---
drivers/net/ethernet/calxeda/xgmac.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/calxeda/xgmac.c b/drivers/net/ethernet/calxeda/xgmac.c
index a2410fba6be2..63296469bd85 100644
--- a/drivers/net/ethernet/calxeda/xgmac.c
+++ b/drivers/net/ethernet/calxeda/xgmac.c
@@ -1046,12 +1046,10 @@ static int xgmac_stop(struct net_device *dev)
{
struct xgmac_priv *priv = netdev_priv(dev);
- if (readl(priv->base + XGMAC_DMA_INTR_ENA))
- napi_disable(&priv->napi);
-
- writel(0, priv->base + XGMAC_DMA_INTR_ENA);
-
netif_tx_disable(dev);
+ writel(0, priv->base + XGMAC_DMA_INTR_ENA);
+ cancel_work_sync(&priv->tx_timeout_work);
+ napi_disable(&priv->napi);
/* Disable the MAC core */
xgmac_mac_disable(priv->base);
--
2.50.1.windows.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH net] net: calxeda: cancel timeout work before freeing rings
2026-09-28 13:41 [PATCH net] net: calxeda: cancel timeout work before freeing rings Hongyan Xu
@ 2026-09-28 13:45 ` netdev-bot+sinfo
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28 13:45 UTC (permalink / raw)
To: Hongyan Xu
Cc: andrew+netdev, davem, edumazet, kuba, pabeni, o-takashi, kees,
u.kleine-koenig, bhelgaas, netdev, linux-kernel, jianhao.xu
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
- What hardware the change was tested on. For driver fixes please
mention the device (and if relevant firmware version) used for
testing, or say that the change was not tested on real hardware.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-28 13:45 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 13:41 [PATCH net] net: calxeda: cancel timeout work before freeing rings Hongyan Xu
2026-09-28 13:45 ` netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®