* [PATCH net 0/2] net: cpsw: fix failed-probe cleanup
@ 2026-10-03 14:09 Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
` (2 more replies)
0 siblings, 3 replies; 7+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:09 UTC (permalink / raw)
To: netdev
Cc: Karl Mehltretter, Siddharth Vadapalli, Roger Quadros,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Keerthy, Kevin Hao, Alexander Sverdlin,
Arnd Bergmann, linux-omap, linux-kernel, stable
The legacy CPSW driver registers its netdevs before requesting IRQs. A late
IRQ request failure leaves two lifetime problems in the probe error path:
1. In dual-EMAC mode, the secondary netdev remains registered when devres
calls free_netdev().
2. A registered interface can queue rx_mode_work that survives the devm
allocation holding its netdev and private data.
Patch 1 tracks successful secondary registration and unregisters the netdev
on the late error path. Patch 2 drains both interfaces' work after
unregistering them, as cpsw_remove() already does.
Runtime validation used a KASAN-enabled ARM kernel and a local QEMU
Arm virt CPSW probe stub. It provides one or two fixed-link ports. Its
device tree assigns the same non-shareable SPI to RX and TX. The TX request
therefore returns -EBUSY after registration. Test instrumentation opens the
relevant netdev and holds its real rx_mode_work until after the forced
failure.
Each result was reproduced twice:
- Single EMAC, original cleanup: KASAN slab-use-after-free.
- Single EMAC, work-cancel fix: clean poweroff.
- Dual EMAC, original cleanup: free_netdev() reg_state BUG.
- Dual EMAC, patch 1 only: KASAN slab-use-after-free in eth1's work.
- Dual EMAC, both patches: clean poweroff.
Build testing used this series on the net tree at
6dc989ea46b96ce170840174b4a38c4a387fb005:
make ARCH=arm LLVM=1 W=1 -j12 vmlinux modules
Clang/LLD 21.1.8 completed both ARM builds and all enabled modules with
configs derived from allyesconfig and allmodconfig. CONFIG_WERROR and
resource-heavy debug options (KASAN, UBSAN, KFENCE, KCOV/GCOV, KUnit,
kallsyms, KGDB/kmemleak, tracing, lock debugging, and allocation profiling)
were disabled. cpsw.c produced no warning. The literal allyesconfig build
first stopped on warnings in untouched files promoted by CONFIG_WERROR;
with WERROR disabled, its instrumented link exceeded the test host's memory.
Testing on real CPSW hardware would be welcome.
Karl Mehltretter (2):
net: cpsw: unregister secondary netdev on probe failure
net: cpsw: cancel RX mode work on probe failure
drivers/net/ethernet/ti/cpsw.c | 10 ++++++++++
1 file changed, 10 insertions(+)
base-commit: 6dc989ea46b96ce170840174b4a38c4a387fb005
--
2.53.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
@ 2026-10-03 14:09 ` Karl Mehltretter
2026-10-07 0:57 ` Jakub Kicinski
2026-10-03 14:09 ` [PATCH net 2/2] net: cpsw: cancel RX mode work " Karl Mehltretter
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
2 siblings, 1 reply; 7+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:09 UTC (permalink / raw)
To: netdev
Cc: Karl Mehltretter, Siddharth Vadapalli, Roger Quadros,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Keerthy, Kevin Hao, Alexander Sverdlin,
Arnd Bergmann, linux-omap, linux-kernel, stable
The legacy CPSW driver registers both netdevs in dual-EMAC mode before
requesting its IRQs. If a later IRQ request fails, the probe error path
unregisters only the primary netdev. Driver-core devres cleanup then calls
free_netdev() for the still-registered secondary netdev, triggering the
reg_state BUG_ON.
Track successful secondary registration and unregister that netdev before
the primary on this error path. The pointer cannot indicate registration:
cpsw_probe_dual_emac() sets cpsw->slaves[1].ndev before it calls
register_netdev().
Reproduced with QEMU fault injection by forcing the TX IRQ request to fail
with -EBUSY in dual-EMAC mode; real hardware was not tested.
Fixes: 070f9c658a59 ("net: ethernet: ti: cpsw: Push the request_irq function to the end of probe")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
drivers/net/ethernet/ti/cpsw.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
index aa3531e844e8..4fc59f9f23fc 100644
--- a/drivers/net/ethernet/ti/cpsw.c
+++ b/drivers/net/ethernet/ti/cpsw.c
@@ -1550,6 +1550,7 @@ static int cpsw_probe(struct platform_device *pdev)
struct gpio_descs *mode;
const struct soc_device_attribute *soc;
struct cpsw_common *cpsw;
+ bool secondary_registered = false;
int ret = 0, ch;
int irq;
@@ -1717,6 +1718,7 @@ static int cpsw_probe(struct platform_device *pdev)
cpsw_err(priv, probe, "error probe slave 2 emac interface\n");
goto clean_unregister_netdev_ret;
}
+ secondary_registered = true;
}
/* Grab RX and TX IRQs. Note that we also have RX_THRESHOLD and
@@ -1764,6 +1766,8 @@ static int cpsw_probe(struct platform_device *pdev)
return 0;
clean_unregister_netdev_ret:
+ if (secondary_registered)
+ unregister_netdev(cpsw->slaves[1].ndev);
unregister_netdev(ndev);
clean_cpts:
cpts_release(cpsw->cpts);
--
2.53.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH net 2/2] net: cpsw: cancel RX mode work on probe failure
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
@ 2026-10-03 14:09 ` Karl Mehltretter
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
2 siblings, 0 replies; 7+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:09 UTC (permalink / raw)
To: netdev
Cc: Karl Mehltretter, Siddharth Vadapalli, Roger Quadros,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Keerthy, Kevin Hao, Alexander Sverdlin,
Arnd Bergmann, linux-omap, linux-kernel, stable
The legacy CPSW driver registers its netdevs before requesting their IRQs.
Once registered, an interface can be opened and dev_set_rx_mode() can queue
its rx_mode_work. If a later IRQ request fails, the probe error path
unregisters the interfaces but does not drain their work before returning.
Driver core then releases the devm-allocated netdevs and private data,
allowing a worker to dereference freed memory.
Call disable_work_sync() after unregistering each registered netdev. This
matches cpsw_remove(). It drains the work before the error path releases
the remaining resources.
Without this change, a QEMU stub test reproduced a use-after-free
after an IRQ request failure with rx_mode_work pending. KASAN reported:
BUG: KASAN: slab-use-after-free in cpsw_ndo_set_rx_mode_work+0x28/0x174
Workqueue: events cpsw_ndo_set_rx_mode_work
Call trace:
kasan_report from cpsw_ndo_set_rx_mode_work+0x28/0x174
cpsw_ndo_set_rx_mode_work from process_scheduled_works+0x4ac/0x790
process_scheduled_works from worker_thread+0x49c/0x5b0
Real hardware was not tested.
Fixes: 0b8c878d1173 ("net: cpsw: Execute ndo_set_rx_mode callback in a work queue")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
drivers/net/ethernet/ti/cpsw.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
index 4fc59f9f23fc..d93d94eaac2d 100644
--- a/drivers/net/ethernet/ti/cpsw.c
+++ b/drivers/net/ethernet/ti/cpsw.c
@@ -1766,9 +1766,15 @@ static int cpsw_probe(struct platform_device *pdev)
return 0;
clean_unregister_netdev_ret:
- if (secondary_registered)
+ if (secondary_registered) {
+ struct cpsw_priv *priv_sl2;
+
+ priv_sl2 = netdev_priv(cpsw->slaves[1].ndev);
unregister_netdev(cpsw->slaves[1].ndev);
+ disable_work_sync(&priv_sl2->rx_mode_work);
+ }
unregister_netdev(ndev);
+ disable_work_sync(&priv->rx_mode_work);
clean_cpts:
cpts_release(cpsw->cpts);
cpdma_ctlr_destroy(cpsw->dma);
--
2.53.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH net 0/2] net: cpsw: fix failed-probe cleanup
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 2/2] net: cpsw: cancel RX mode work " Karl Mehltretter
@ 2026-10-03 14:13 ` netdev-bot+sinfo
2026-10-03 14:29 ` Karl Mehltretter
2 siblings, 1 reply; 7+ messages in thread
From: netdev-bot+sinfo @ 2026-10-03 14:13 UTC (permalink / raw)
To: Karl Mehltretter
Cc: netdev, Siddharth Vadapalli, Roger Quadros, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Keerthy, Kevin Hao, Alexander Sverdlin, Arnd Bergmann,
linux-omap, linux-kernel, stable
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH net 0/2] net: cpsw: fix failed-probe cleanup
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
@ 2026-10-03 14:29 ` Karl Mehltretter
0 siblings, 0 replies; 7+ messages in thread
From: Karl Mehltretter @ 2026-10-03 14:29 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, Siddharth Vadapalli, Roger Quadros, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Keerthy, Kevin Hao, Alexander Sverdlin, Arnd Bergmann,
linux-omap, linux-kernel, stable
On Sat, Oct 03, 2026 at 02:13:26PM +0100, netdev-bot+sinfo@kernel.org wrote:
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
The rx_mode_work lifetime issue was found during an LLM-assisted review
of the 6.12.112-rc1 stable series.
Reviewing the same probe error path in dual-EMAC mode then exposed the
older secondary-netdev cleanup bug.
Thanks,
Karl
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
@ 2026-10-07 0:57 ` Jakub Kicinski
0 siblings, 0 replies; 7+ messages in thread
From: Jakub Kicinski @ 2026-10-07 0:57 UTC (permalink / raw)
To: Karl Mehltretter
Cc: netdev, Siddharth Vadapalli, Roger Quadros, Andrew Lunn,
David S. Miller, Eric Dumazet, Paolo Abeni, Keerthy, Kevin Hao,
Alexander Sverdlin, Arnd Bergmann, linux-omap, linux-kernel,
stable
On Sat, 3 Oct 2026 16:09:14 +0200 Karl Mehltretter wrote:
> + bool secondary_registered = false;
the rule of thumb is that error unwind should match the remove()
If not possible match the condition of the code, don't add local vars
Sashiko is right to suggest to fold the two fixes together.
--
pw-bot: cr
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure
@ 2026-10-04 14:10 netdev-bot+sashiko
0 siblings, 0 replies; 7+ messages in thread
From: netdev-bot+sashiko @ 2026-10-04 14:10 UTC (permalink / raw)
To: kmehltretter
Cc: netdev, s-vadapalli, rogerq, andrew+netdev, davem, edumazet,
kuba, pabeni, j-keerthy, haokexin, alex, arnd, linux-omap,
linux-kernel, stable
Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider.
Critical: 0 · High: 1 · Medium: 0 · Low: 0
If you believe none of the issues are legitimate, please reply to each
issue of Medium severity or higher and explain why the AI is wrong.
If any of them are legitimate and you plan to respin, please let patchwork
know by including "pw-bot: cr" as a separate line at the end of your reply
(one such reply per series is enough).
- [High] In this patch, the cpsw_probe() error label
clean_unregister_netdev_ret in drivers/net/ethernet/ti/cpsw.c now…
--
net: cpsw: unregister secondary netdev on probe failure
This patch records whether cpsw_probe() registered the secondary
dual-EMAC netdev. If it did, the clean_unregister_netdev_ret error path
now unregisters it before the primary netdev. This avoids the reg_state
BUG_ON in free_netdev() when devres frees a netdev that is still
registered after a late IRQ request failure.
> diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
> index aa3531e844e87..4fc59f9f23fcb 100644
> --- a/drivers/net/ethernet/ti/cpsw.c
> +++ b/drivers/net/ethernet/ti/cpsw.c
[ ... ]
> @@ -1764,6 +1766,8 @@ static int cpsw_probe(struct platform_device *pdev)
> return 0;
>
> clean_unregister_netdev_ret:
> + if (secondary_registered)
> + unregister_netdev(cpsw->slaves[1].ndev);
> unregister_netdev(ndev);
[Severity: High]
Can rx_mode_work still be pending on either netdev when devres frees it?
Both netdevs are registered before the devm_request_irq() calls, so an
interface can be brought up during that window. Bringing it up, or
changing its address lists, reaches cpsw_ndo_set_rx_mode(), which does:
schedule_work(&priv->rx_mode_work);
cpsw_ndo_stop() does not cancel this work.
cpsw_remove() follows each unregister with a disable:
priv = netdev_priv(ndev);
unregister_netdev(ndev);
disable_work_sync(&priv->rx_mode_work);
This error path does not. After probe returns the error, devres calls
free_netdev() on the devm-allocated netdevs. A queued or rtnl-blocked
cpsw_ndo_set_rx_mode_work() would then dereference the freed priv,
priv->cpsw and priv->ndev. The workqueue core would also touch the freed
work_struct.
The primary netdev already had this gap. For the secondary netdev, the
free_netdev() BUG_ON used to fire first. This patch removes that BUG_ON,
so the use-after-free on the secondary netdev can now be reached.
The next patch in the series, "net: cpsw: cancel RX mode work on probe
failure", appears to fix this. It adds disable_work_sync() after both
unregister_netdev() calls here, which matches cpsw_remove(). Its commit
message quotes a KASAN report of "slab-use-after-free in
cpsw_ndo_set_rx_mode_work".
Could that change be folded into this patch, so the two are not applied
separately?
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/cover.1791035789.git.kmehltretter%40gmail.com
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-10-07 0:57 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 14:09 [PATCH net 0/2] net: cpsw: fix failed-probe cleanup Karl Mehltretter
2026-10-03 14:09 ` [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure Karl Mehltretter
2026-10-07 0:57 ` Jakub Kicinski
2026-10-03 14:09 ` [PATCH net 2/2] net: cpsw: cancel RX mode work " Karl Mehltretter
2026-10-03 14:13 ` [PATCH net 0/2] net: cpsw: fix failed-probe cleanup netdev-bot+sinfo
2026-10-03 14:29 ` Karl Mehltretter
2026-10-04 14:10 [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure netdev-bot+sashiko
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®