From: "Théo Lebrun" <theo.lebrun@bootlin.com>
To: "Jiale Yao" <yaojiale02@163.com>,
"Conor Dooley" <conor.dooley@microchip.com>,
"Andrew Lunn" <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
"Eric Dumazet" <edumazet@google.com>,
"Jakub Kicinski" <kuba@kernel.org>,
"Paolo Abeni" <pabeni@redhat.com>,
"Russell King" <linux@armlinux.org.uk>,
"Nicolas Ferre" <nicolas.ferre@microchip.com>,
"Soren Brinkmann" <soren.brinkmann@xilinx.com>,
<netdev@vger.kernel.org>, <linux-kernel@vger.kernel.org>
Cc: <stable@vger.kernel.org>
Subject: Re: [PATCH net v3 1/7] net: macb: manage the netdev lifetime with devres
Date: Sun, 04 Oct 2026 10:45:58 +0200 [thread overview]
Message-ID: <DLVX7ZLU4GOM.1WCL74N0U7PUP@bootlin.com> (raw)
In-Reply-To: <20261003085940.493951-2-yaojiale02@163.com>
Hello Jiale,
Those LLM bugs are code churn, that's why you are seeing pushback.
Please don't ignore the pushback. For example on V2 you got asked to
reply to an automated message, which you didn't do.
https://lore.kernel.org/netdev/20260927153020.5311dba6@kernel.org/
On Sat Oct 3, 2026 at 10:59 AM CEST, Jiale Yao wrote:
> macb_remove() frees the netdev while its managed IRQs are only
> released after the remove callback returns. An interrupt in that window
> can dereference the freed netdev or queue data.
Please indicate how an interrupt could land in that window.
Thinking about it for a brief instant, I cannot think of one.
> Allocate the netdev with devres as well. Since the IRQs are registered
> later, devres releases them before freeing the netdev and closes the
> lifetime gap.
>
> This issue was found by a static analysis method used in our research.
>
> Fixes: 0a4acf08ea62 ("net: macb: Use devm_request_irq()")
> Cc: stable@vger.kernel.org
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/ethernet/cadence/macb_main.c | 17 +++++++----------
> 1 file changed, 7 insertions(+), 10 deletions(-)
Reviewed-by: Théo Lebrun <theo.lebrun@bootlin.com>
I still give my Rb because the patch is valid. The wasted time is on net
maintainers though; they'll decide if they want it or not.
For this MACB patch, it could land in net-next as I don't see a
practical bug here (in light of the recent pushback about the # of
fixes in net).
Thanks,
--
Théo Lebrun, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
next prev parent reply other threads:[~2026-10-04 8:46 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 8:59 [PATCH net v3 0/7] net: ethernet: release managed IRQs before freeing netdevs Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 1/7] net: macb: manage the netdev lifetime with devres Jiale Yao
2026-10-03 9:03 ` netdev-bot+sinfo
2026-10-04 8:45 ` Théo Lebrun [this message]
2026-10-04 12:14 ` jiale yao
2026-10-04 12:49 ` Théo Lebrun
2026-10-03 8:59 ` [PATCH net v3 2/7] net: fec: release IRQs before dependent resources Jiale Yao
2026-10-04 9:03 ` netdev-bot+sashiko
2026-10-03 8:59 ` [PATCH net v3 3/7] net: hip04: manage the netdev lifetime with devres Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 4/7] net: hisi_femac: " Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 5/7] net: hix5hd2: " Jiale Yao
2026-10-03 8:59 ` [PATCH net v3 6/7] net: ravb: release managed IRQs before freeing netdev Jiale Yao
2026-10-03 9:59 ` Niklas Söderlund
2026-10-03 10:04 ` jiale yao
2026-10-04 9:03 ` netdev-bot+sashiko
2026-10-03 8:59 ` [PATCH net v3 7/7] net: sxgbe: manage IRQ data lifetimes with devres Jiale Yao
2026-10-04 9:03 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLVX7ZLU4GOM.1WCL74N0U7PUP@bootlin.com \
--to=theo.lebrun@bootlin.com \
--cc=andrew+netdev@lunn.ch \
--cc=conor.dooley@microchip.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=netdev@vger.kernel.org \
--cc=nicolas.ferre@microchip.com \
--cc=pabeni@redhat.com \
--cc=soren.brinkmann@xilinx.com \
--cc=stable@vger.kernel.org \
--cc=yaojiale02@163.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®