From: James Hilliard <james.hilliard1@gmail.com>
To: netdev@vger.kernel.org, Paolo Abeni <pabeni@redhat.com>,
Jakub Kicinski <kuba@kernel.org>,
Richard Cochran <richardcochran@gmail.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
Yangbo Lu <yangbo.lu@nxp.com>
Cc: Eric Dumazet <edumazet@kernel.org>,
"David S. Miller" <davem@davemloft.net>,
linux-kernel@vger.kernel.org,
James Hilliard <james.hilliard1@gmail.com>
Subject: [PATCH net v2 1/2] ptp: drain virtual clock sysfs operations before unregistering children
Date: Mon, 05 Oct 2026 12:45:33 -0600 [thread overview]
Message-ID: <20261005-ptp-vclock-sampling-v2-1-8ed12d4d10af@gmail.com> (raw)
In-Reply-To: <20261005-ptp-vclock-sampling-v2-0-8ed12d4d10af@gmail.com>
Parent clock removal walks its virtual clocks before removing the
n_vclocks sysfs attribute. The mutex taken by ptp_vclock_in_use() is
released before that walk, so a concurrent sysfs deletion can pick the
same child and unregister and free its ptp_vclock a second time. A
reference held by the device iterator does not protect that separately
allocated virtual clock.
Remove n_vclocks before walking the children. Removing the attribute
prevents new stores and drains stores already running, without holding
n_vclocks_mux across a callback that needs that mutex. Virtual clocks
have no such attribute and must not remove the parent attribute when
being deleted by its active store.
This race was found by code inspection of virtual-clock registration
failure cleanup and parent removal.
Fixes: 5d43f951b1ac ("ptp: add ptp virtual clock driver framework")
Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
---
drivers/ptp/ptp_clock.c | 5 +++++
drivers/ptp/ptp_private.h | 1 +
drivers/ptp/ptp_sysfs.c | 6 ++++++
3 files changed, 12 insertions(+)
diff --git a/drivers/ptp/ptp_clock.c b/drivers/ptp/ptp_clock.c
index 4111342d64f0..47ffc773065a 100644
--- a/drivers/ptp/ptp_clock.c
+++ b/drivers/ptp/ptp_clock.c
@@ -508,6 +508,11 @@ static int unregister_vclock(struct device *dev, void *data)
int ptp_clock_unregister(struct ptp_clock *ptp)
{
+ /*
+ * Stop and drain virtual-clock creation and deletion before walking the
+ * children. Do not hold n_vclocks_mux while waiting for sysfs callbacks.
+ */
+ ptp_vclock_remove_sysfs(ptp);
if (ptp_vclock_in_use(ptp)) {
device_for_each_child(&ptp->dev, NULL, unregister_vclock);
}
diff --git a/drivers/ptp/ptp_private.h b/drivers/ptp/ptp_private.h
index db4039d642b4..ec8633126d6b 100644
--- a/drivers/ptp/ptp_private.h
+++ b/drivers/ptp/ptp_private.h
@@ -169,6 +169,7 @@ extern const struct attribute_group *ptp_groups[];
int ptp_populate_pin_groups(struct ptp_clock *ptp);
void ptp_cleanup_pin_groups(struct ptp_clock *ptp);
+void ptp_vclock_remove_sysfs(struct ptp_clock *ptp);
struct ptp_vclock *ptp_vclock_register(struct ptp_clock *pclock);
void ptp_vclock_unregister(struct ptp_vclock *vclock);
diff --git a/drivers/ptp/ptp_sysfs.c b/drivers/ptp/ptp_sysfs.c
index dc398c6b7528..53388b123198 100644
--- a/drivers/ptp/ptp_sysfs.c
+++ b/drivers/ptp/ptp_sysfs.c
@@ -263,6 +263,12 @@ static ssize_t n_vclocks_store(struct device *dev,
}
static DEVICE_ATTR_RW(n_vclocks);
+void ptp_vclock_remove_sysfs(struct ptp_clock *ptp)
+{
+ if (!ptp->is_virtual_clock)
+ device_remove_file(&ptp->dev, &dev_attr_n_vclocks);
+}
+
static ssize_t max_vclocks_show(struct device *dev,
struct device_attribute *attr, char *page)
{
--
2.53.0
next prev parent reply other threads:[~2026-10-05 18:45 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 18:45 [PATCH net v2 0/2] ptp: make virtual clock sampling and teardown failure-safe James Hilliard
2026-10-05 18:45 ` James Hilliard [this message]
2026-10-05 18:45 ` [PATCH net v2 2/2] ptp: vclock: preserve time across failed physical clock samples James Hilliard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005-ptp-vclock-sampling-v2-1-8ed12d4d10af@gmail.com \
--to=james.hilliard1@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=richardcochran@gmail.com \
--cc=yangbo.lu@nxp.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®