mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net 0/2] net: cpsw: fix failed-probe cleanup
@ 2026-10-03 14:09 Karl Mehltretter
  2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:09 UTC (permalink / raw)
  To: netdev
  Cc: Karl Mehltretter, Siddharth Vadapalli, Roger Quadros,
	Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Keerthy, Kevin Hao, Alexander Sverdlin,
	Arnd Bergmann, linux-omap, linux-kernel, stable

The legacy CPSW driver registers its netdevs before requesting IRQs. A late
IRQ request failure leaves two lifetime problems in the probe error path:

  1. In dual-EMAC mode, the secondary netdev remains registered when devres
     calls free_netdev().
  2. A registered interface can queue rx_mode_work that survives the devm
     allocation holding its netdev and private data.

Patch 1 tracks successful secondary registration and unregisters the netdev
on the late error path. Patch 2 drains both interfaces' work after
unregistering them, as cpsw_remove() already does.

Runtime validation used a KASAN-enabled ARM kernel and a local QEMU
Arm virt CPSW probe stub. It provides one or two fixed-link ports. Its
device tree assigns the same non-shareable SPI to RX and TX. The TX request
therefore returns -EBUSY after registration. Test instrumentation opens the
relevant netdev and holds its real rx_mode_work until after the forced
failure.

Each result was reproduced twice:

  - Single EMAC, original cleanup: KASAN slab-use-after-free.
  - Single EMAC, work-cancel fix: clean poweroff.
  - Dual EMAC, original cleanup: free_netdev() reg_state BUG.
  - Dual EMAC, patch 1 only: KASAN slab-use-after-free in eth1's work.
  - Dual EMAC, both patches: clean poweroff.

Build testing used this series on the net tree at
6dc989ea46b96ce170840174b4a38c4a387fb005:

  make ARCH=arm LLVM=1 W=1 -j12 vmlinux modules

Clang/LLD 21.1.8 completed both ARM builds and all enabled modules with
configs derived from allyesconfig and allmodconfig. CONFIG_WERROR and
resource-heavy debug options (KASAN, UBSAN, KFENCE, KCOV/GCOV, KUnit,
kallsyms, KGDB/kmemleak, tracing, lock debugging, and allocation profiling)
were disabled. cpsw.c produced no warning. The literal allyesconfig build
first stopped on warnings in untouched files promoted by CONFIG_WERROR;
with WERROR disabled, its instrumented link exceeded the test host's memory.

Testing on real CPSW hardware would be welcome.

Karl Mehltretter (2):
  net: cpsw: unregister secondary netdev on probe failure
  net: cpsw: cancel RX mode work on probe failure

 drivers/net/ethernet/ti/cpsw.c | 10 ++++++++++
 1 file changed, 10 insertions(+)


base-commit: 6dc989ea46b96ce170840174b4a38c4a387fb005
-- 
2.53.0

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-03 14:29 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 2/2] net: cpsw: cancel RX mode work " Karl Mehltretter
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
2026-10-03 14:29   ` Karl Mehltretter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®