* [PATCH net 0/2] net: cpsw: fix failed-probe cleanup
@ 2026-10-03 14:09 Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
` (2 more replies)
0 siblings, 3 replies; 5+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:09 UTC (permalink / raw)
To: netdev
Cc: Karl Mehltretter, Siddharth Vadapalli, Roger Quadros,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Keerthy, Kevin Hao, Alexander Sverdlin,
Arnd Bergmann, linux-omap, linux-kernel, stable
The legacy CPSW driver registers its netdevs before requesting IRQs. A late
IRQ request failure leaves two lifetime problems in the probe error path:
1. In dual-EMAC mode, the secondary netdev remains registered when devres
calls free_netdev().
2. A registered interface can queue rx_mode_work that survives the devm
allocation holding its netdev and private data.
Patch 1 tracks successful secondary registration and unregisters the netdev
on the late error path. Patch 2 drains both interfaces' work after
unregistering them, as cpsw_remove() already does.
Runtime validation used a KASAN-enabled ARM kernel and a local QEMU
Arm virt CPSW probe stub. It provides one or two fixed-link ports. Its
device tree assigns the same non-shareable SPI to RX and TX. The TX request
therefore returns -EBUSY after registration. Test instrumentation opens the
relevant netdev and holds its real rx_mode_work until after the forced
failure.
Each result was reproduced twice:
- Single EMAC, original cleanup: KASAN slab-use-after-free.
- Single EMAC, work-cancel fix: clean poweroff.
- Dual EMAC, original cleanup: free_netdev() reg_state BUG.
- Dual EMAC, patch 1 only: KASAN slab-use-after-free in eth1's work.
- Dual EMAC, both patches: clean poweroff.
Build testing used this series on the net tree at
6dc989ea46b96ce170840174b4a38c4a387fb005:
make ARCH=arm LLVM=1 W=1 -j12 vmlinux modules
Clang/LLD 21.1.8 completed both ARM builds and all enabled modules with
configs derived from allyesconfig and allmodconfig. CONFIG_WERROR and
resource-heavy debug options (KASAN, UBSAN, KFENCE, KCOV/GCOV, KUnit,
kallsyms, KGDB/kmemleak, tracing, lock debugging, and allocation profiling)
were disabled. cpsw.c produced no warning. The literal allyesconfig build
first stopped on warnings in untouched files promoted by CONFIG_WERROR;
with WERROR disabled, its instrumented link exceeded the test host's memory.
Testing on real CPSW hardware would be welcome.
Karl Mehltretter (2):
net: cpsw: unregister secondary netdev on probe failure
net: cpsw: cancel RX mode work on probe failure
drivers/net/ethernet/ti/cpsw.c | 10 ++++++++++
1 file changed, 10 insertions(+)
base-commit: 6dc989ea46b96ce170840174b4a38c4a387fb005
--
2.53.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
@ 2026-10-03 14:09 ` Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 2/2] net: cpsw: cancel RX mode work " Karl Mehltretter
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
2 siblings, 0 replies; 5+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:09 UTC (permalink / raw)
To: netdev
Cc: Karl Mehltretter, Siddharth Vadapalli, Roger Quadros,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Keerthy, Kevin Hao, Alexander Sverdlin,
Arnd Bergmann, linux-omap, linux-kernel, stable
The legacy CPSW driver registers both netdevs in dual-EMAC mode before
requesting its IRQs. If a later IRQ request fails, the probe error path
unregisters only the primary netdev. Driver-core devres cleanup then calls
free_netdev() for the still-registered secondary netdev, triggering the
reg_state BUG_ON.
Track successful secondary registration and unregister that netdev before
the primary on this error path. The pointer cannot indicate registration:
cpsw_probe_dual_emac() sets cpsw->slaves[1].ndev before it calls
register_netdev().
Reproduced with QEMU fault injection by forcing the TX IRQ request to fail
with -EBUSY in dual-EMAC mode; real hardware was not tested.
Fixes: 070f9c658a59 ("net: ethernet: ti: cpsw: Push the request_irq function to the end of probe")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
drivers/net/ethernet/ti/cpsw.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
index aa3531e844e8..4fc59f9f23fc 100644
--- a/drivers/net/ethernet/ti/cpsw.c
+++ b/drivers/net/ethernet/ti/cpsw.c
@@ -1550,6 +1550,7 @@ static int cpsw_probe(struct platform_device *pdev)
struct gpio_descs *mode;
const struct soc_device_attribute *soc;
struct cpsw_common *cpsw;
+ bool secondary_registered = false;
int ret = 0, ch;
int irq;
@@ -1717,6 +1718,7 @@ static int cpsw_probe(struct platform_device *pdev)
cpsw_err(priv, probe, "error probe slave 2 emac interface\n");
goto clean_unregister_netdev_ret;
}
+ secondary_registered = true;
}
/* Grab RX and TX IRQs. Note that we also have RX_THRESHOLD and
@@ -1764,6 +1766,8 @@ static int cpsw_probe(struct platform_device *pdev)
return 0;
clean_unregister_netdev_ret:
+ if (secondary_registered)
+ unregister_netdev(cpsw->slaves[1].ndev);
unregister_netdev(ndev);
clean_cpts:
cpts_release(cpsw->cpts);
--
2.53.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net 2/2] net: cpsw: cancel RX mode work on probe failure
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
@ 2026-10-03 14:09 ` Karl Mehltretter
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
2 siblings, 0 replies; 5+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:09 UTC (permalink / raw)
To: netdev
Cc: Karl Mehltretter, Siddharth Vadapalli, Roger Quadros,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Keerthy, Kevin Hao, Alexander Sverdlin,
Arnd Bergmann, linux-omap, linux-kernel, stable
The legacy CPSW driver registers its netdevs before requesting their IRQs.
Once registered, an interface can be opened and dev_set_rx_mode() can queue
its rx_mode_work. If a later IRQ request fails, the probe error path
unregisters the interfaces but does not drain their work before returning.
Driver core then releases the devm-allocated netdevs and private data,
allowing a worker to dereference freed memory.
Call disable_work_sync() after unregistering each registered netdev. This
matches cpsw_remove(). It drains the work before the error path releases
the remaining resources.
Without this change, a QEMU stub test reproduced a use-after-free
after an IRQ request failure with rx_mode_work pending. KASAN reported:
BUG: KASAN: slab-use-after-free in cpsw_ndo_set_rx_mode_work+0x28/0x174
Workqueue: events cpsw_ndo_set_rx_mode_work
Call trace:
kasan_report from cpsw_ndo_set_rx_mode_work+0x28/0x174
cpsw_ndo_set_rx_mode_work from process_scheduled_works+0x4ac/0x790
process_scheduled_works from worker_thread+0x49c/0x5b0
Real hardware was not tested.
Fixes: 0b8c878d1173 ("net: cpsw: Execute ndo_set_rx_mode callback in a work queue")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
drivers/net/ethernet/ti/cpsw.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
index 4fc59f9f23fc..d93d94eaac2d 100644
--- a/drivers/net/ethernet/ti/cpsw.c
+++ b/drivers/net/ethernet/ti/cpsw.c
@@ -1766,9 +1766,15 @@ static int cpsw_probe(struct platform_device *pdev)
return 0;
clean_unregister_netdev_ret:
- if (secondary_registered)
+ if (secondary_registered) {
+ struct cpsw_priv *priv_sl2;
+
+ priv_sl2 = netdev_priv(cpsw->slaves[1].ndev);
unregister_netdev(cpsw->slaves[1].ndev);
+ disable_work_sync(&priv_sl2->rx_mode_work);
+ }
unregister_netdev(ndev);
+ disable_work_sync(&priv->rx_mode_work);
clean_cpts:
cpts_release(cpsw->cpts);
cpdma_ctlr_destroy(cpsw->dma);
--
2.53.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH net 0/2] net: cpsw: fix failed-probe cleanup
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 2/2] net: cpsw: cancel RX mode work " Karl Mehltretter
@ 2026-10-03 14:13 ` netdev-bot+sinfo
2026-10-03 14:29 ` Karl Mehltretter
2 siblings, 1 reply; 5+ messages in thread
From: netdev-bot+sinfo @ 2026-10-03 14:13 UTC (permalink / raw)
To: Karl Mehltretter
Cc: netdev, Siddharth Vadapalli, Roger Quadros, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Keerthy, Kevin Hao, Alexander Sverdlin, Arnd Bergmann,
linux-omap, linux-kernel, stable
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH net 0/2] net: cpsw: fix failed-probe cleanup
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
@ 2026-10-03 14:29 ` Karl Mehltretter
0 siblings, 0 replies; 5+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:29 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, Siddharth Vadapalli, Roger Quadros, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Keerthy, Kevin Hao, Alexander Sverdlin, Arnd Bergmann,
linux-omap, linux-kernel, stable
On Sat, Oct 03, 2026 at 02:13:26PM +0100, netdev-bot+sinfo@kernel.org wrote:
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
The rx_mode_work lifetime issue was found during an LLM-assisted review
of the 6.12.112-rc1 stable series.
Reviewing the same probe error path in dual-EMAC mode then exposed the
older secondary-netdev cleanup bug.
Thanks,
Karl
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-10-03 14:29 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 2/2] net: cpsw: cancel RX mode work " Karl Mehltretter
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
2026-10-03 14:29 ` Karl Mehltretter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®