From: Myeonghun Pak <mhun512@gmail.com>
To: Wei Fang <wei.fang@nxp.com>, netdev@vger.kernel.org
Cc: Myeonghun Pak <mhun512@gmail.com>, Frank Li <frank.li@nxp.com>,
Shenwei Wang <shenwei.wang@nxp.com>,
Richard Cochran <richardcochran@gmail.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
imx@lists.linux.dev, linux-kernel@vger.kernel.org,
Simon Horman <horms@kernel.org>,
stable@vger.kernel.org, Ijae Kim <ae878000@gmail.com>
Subject: [PATCH net RESEND] net: fec: drain PEROUT requests before canceling the timer
Date: Thu, 1 Oct 2026 14:02:58 -0400 [thread overview]
Message-ID: <20261001180258.4054391-1-mhun512@gmail.com> (raw)
fec_ptp_stop() cancels perout_timer before unregistering the PTP clock.
A PEROUT ioctl can set perout_enable, release the driver's locks and
then be preempted before hrtimer_start(). The unregister path waits for
that ioctl, which can rearm the timer after it was canceled. Removal
then frees the netdev containing the still-armed timer.
Unregister the PTP clock first so all in-flight ioctls have returned
before canceling the timer. Clear the PEROUT state and compare channel
afterward, then disable PPS. Serialize the channel write with PTP clock
shutdown and skip it when that clock is off.
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: 350749b909bf ("net: fec: Add support for periodic output signal of PPS")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
---
Resend notes:
- Send via git send-email over SMTP to preserve diff and hunk headers.
- No code changes from the previous submission.
Previous submission:
https://lore.kernel.org/netdev/CAGEsz8EYe=gBFr_hEYFLUeiJMRtau=eV3cDUUmHJOQkC0qvfqw@mail.gmail.com/
drivers/net/ethernet/freescale/fec_ptp.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/freescale/fec_ptp.c b/drivers/net/ethernet/freescale/fec_ptp.c
index 56801c2009d5..67901e036ac3 100644
--- a/drivers/net/ethernet/freescale/fec_ptp.c
+++ b/drivers/net/ethernet/freescale/fec_ptp.c
@@ -506,10 +506,13 @@ static int fec_ptp_pps_disable(struct fec_enet_private *fep, uint channel)
hrtimer_cancel(&fep->perout_timer);
+ mutex_lock(&fep->ptp_clk_mutex);
spin_lock_irqsave(&fep->tmreg_lock, flags);
fep->perout_enable = false;
- writel(0, fep->hwp + FEC_TCSR(channel));
+ if (fep->ptp_clk_on)
+ writel(0, fep->hwp + FEC_TCSR(channel));
spin_unlock_irqrestore(&fep->tmreg_lock, flags);
+ mutex_unlock(&fep->ptp_clk_mutex);
return 0;
}
@@ -856,11 +859,12 @@ void fec_ptp_stop(struct platform_device *pdev)
struct net_device *ndev = platform_get_drvdata(pdev);
struct fec_enet_private *fep = netdev_priv(ndev);
- if (fep->pps_enable)
- fec_ptp_enable_pps(fep, 0);
-
cancel_delayed_work_sync(&fep->time_keep);
- hrtimer_cancel(&fep->perout_timer);
if (fep->ptp_clock)
ptp_clock_unregister(fep->ptp_clock);
+
+ /* An in-flight PEROUT ioctl can arm the timer until unregister returns. */
+ fec_ptp_pps_disable(fep, fep->pps_channel);
+ if (fep->pps_enable)
+ fec_ptp_enable_pps(fep, 0);
}
--
2.53.0
next reply other threads:[~2026-10-01 18:03 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 18:02 Myeonghun Pak [this message]
2026-10-01 18:09 ` netdev-bot+sinfo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001180258.4054391-1-mhun512@gmail.com \
--to=mhun512@gmail.com \
--cc=ae878000@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=frank.li@nxp.com \
--cc=horms@kernel.org \
--cc=imx@lists.linux.dev \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=richardcochran@gmail.com \
--cc=shenwei.wang@nxp.com \
--cc=stable@vger.kernel.org \
--cc=wei.fang@nxp.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®