From: Vineeth Karumanchi <vineeth.karumanchi@amd.com>
To: <git@amd.com>, <netdev@vger.kernel.org>
Cc: <vineeth.karumanchi@amd.com>, Andrew Lunn <andrew@lunn.ch>,
"Heiner Kallweit" <hkallweit1@gmail.com>,
Russell King <linux@armlinux.org.uk>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@kernel.org>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
"Michal Simek" <michal.simek@amd.com>,
Florian Fainelli <f.fainelli@gmail.com>,
Harini Katakam <harini.katakam@amd.com>,
Kedareswara rao Appana <appanad@amd.com>,
<linux-arm-kernel@lists.infradead.org>,
<linux-kernel@vger.kernel.org>
Subject: [PATCH net 2/2] net: phy: xilinx-gmii2rgmii: Restore PHY driver on remove
Date: Thu, 1 Oct 2026 13:17:18 +0530 [thread overview]
Message-ID: <20261001074718.3944521-3-vineeth.karumanchi@amd.com> (raw)
In-Reply-To: <20261001074718.3944521-1-vineeth.karumanchi@amd.com>
The GMII-to-RGMII converter replaces phydev->drv with a modified copy
of the attached PHY driver. This copied driver is embedded in the
converter's private data and is released when the converter is
removed.
Without a remove callback, phydev->drv continues to point to the freed
copy after the converter is unbound. A subsequent PHY operation can
dereference this stale pointer and result in a use-after-free.
With Generic KASAN enabled, unbinding only the converter while the
external PHY remains active produces the following report (abridged):
BUG: KASAN: slab-use-after-free in phy_check_link_status+0x2d8/0x338
Read of size 8 at addr ffff000006c359b0 by task kworker/2:0/27
Workqueue: events_power_efficient phy_state_machine
Call trace:
phy_check_link_status+0x2d8/0x338
_phy_state_machine+0xdc/0xa4c
phy_state_machine+0x2c/0x70
process_one_work+0x554/0xe44
worker_thread+0x6d0/0x1180
kthread+0x2e8/0x5d4
ret_from_fork+0x10/0x20
Allocated by task 55:
...
devm_kmalloc+0xac/0x2ac
xgmiitorgmii_probe+0xa0/0x37c
mdio_probe+0x68/0xb4
...
Freed by task 642:
...
kfree+0x14c/0x38c
release_nodes+0xb4/0x1e0
devres_release_all+0x140/0x1f4
device_unbind_cleanup+0x20/0x190
device_release_driver_internal+0x344/0x460
device_driver_detach+0x3c/0x54
unbind_store+0xe0/0xf8
...
Store the converter private data in its own MDIO device and add a
remove callback. Restore the attached PHY's original driver while
holding phydev->lock so that the update cannot race with an active PHY
callback.
Also release the device reference acquired by of_phy_find_device().
Fixes: f411a6160bd4 ("net: phy: Add gmiitorgmii converter support")
Signed-off-by: Vineeth Karumanchi <vineeth.karumanchi@amd.com>
---
drivers/net/phy/xilinx_gmii2rgmii.c | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)
diff --git a/drivers/net/phy/xilinx_gmii2rgmii.c b/drivers/net/phy/xilinx_gmii2rgmii.c
index 61f71e977a57..b9aa5515577b 100644
--- a/drivers/net/phy/xilinx_gmii2rgmii.c
+++ b/drivers/net/phy/xilinx_gmii2rgmii.c
@@ -128,10 +128,29 @@ static int xgmiitorgmii_probe(struct mdio_device *mdiodev)
priv->conv_phy_drv.read_status = xgmiitorgmii_read_status;
priv->conv_phy_drv.set_loopback = xgmiitorgmii_set_loopback;
priv->phy_dev->drv = &priv->conv_phy_drv;
+ mdiodev_set_drvdata(mdiodev, priv);
return 0;
}
+static void xgmiitorgmii_remove(struct mdio_device *mdiodev)
+{
+ struct gmii2rgmii *priv = mdiodev_get_drvdata(mdiodev);
+
+ /*
+ * The attached PHY is a separate, still-bound device whose state
+ * machine keeps running and dispatches ->read_status / ->set_loopback
+ * under phydev->lock. Restore its original driver under that lock so
+ * the swap cannot race an in-flight dispatch; the restored driver is
+ * the PHY's own static phy_driver, not the devres-freed conv_phy_drv.
+ */
+ mutex_lock(&priv->phy_dev->lock);
+ priv->phy_dev->drv = priv->phy_drv;
+ mutex_unlock(&priv->phy_dev->lock);
+
+ put_device(&priv->phy_dev->mdio.dev);
+}
+
static const struct of_device_id xgmiitorgmii_of_match[] = {
{ .compatible = "xlnx,gmii-to-rgmii-1.0" },
{},
@@ -140,6 +159,7 @@ MODULE_DEVICE_TABLE(of, xgmiitorgmii_of_match);
static struct mdio_driver xgmiitorgmii_driver = {
.probe = xgmiitorgmii_probe,
+ .remove = xgmiitorgmii_remove,
.mdiodrv.driver = {
.name = "xgmiitorgmii",
.of_match_table = xgmiitorgmii_of_match,
--
2.43.0
next prev parent reply other threads:[~2026-10-01 7:48 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 7:47 [PATCH net 0/2] net: phy: xilinx-gmii2rgmii: Fix PHY data ownership and removal Vineeth Karumanchi
2026-10-01 7:47 ` [PATCH net 1/2] net: phy: xilinx-gmii2rgmii: Avoid overwriting PHY drvdata Vineeth Karumanchi
2026-10-01 7:47 ` Vineeth Karumanchi [this message]
2026-10-05 8:07 ` [PATCH net 2/2] net: phy: xilinx-gmii2rgmii: Restore PHY driver on remove netdev-bot+sashiko
2026-10-06 6:56 ` Karumanchi, Vineeth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001074718.3944521-3-vineeth.karumanchi@amd.com \
--to=vineeth.karumanchi@amd.com \
--cc=andrew@lunn.ch \
--cc=appanad@amd.com \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=f.fainelli@gmail.com \
--cc=git@amd.com \
--cc=harini.katakam@amd.com \
--cc=hkallweit1@gmail.com \
--cc=kuba@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=michal.simek@amd.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®