Re: [PATCH net] net: emac: mal: replace devm_request_irq with request_irq to fix probe error race
From: Andrew Lunn
Date: Fri Jul 03 2026 - 12:45:37 EST
On Thu, Jul 02, 2026 at 04:50:45PM -0700, Rosen Penev wrote:
> devm_request_irq() is a managed resource: the IRQ is not freed until
> devres_release_all() runs after the probe function returns. In the
> probe error path, free_netdev(mal->dummy_dev) and dcr_unmap() execute
> while the IRQ is still live. If the shared IRQ fires during cleanup,
> the handler accesses unmapped DCR registers (crash) or the already-
> freed dummy_dev (use-after-free).
>
> Switch to plain request_irq() with per-IRQ error labels that tear down
> only the IRQs that were successfully registered, and add the matching
> free_irq() calls in mal_remove().
>
> Fixes: 14f59154ff0b ("net: ibm: emac: mal: use devm for request_irq")
> Assisted-by: opencode:big-pickle
> Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
You seemed to of sent the same patch within 24 hours. Please don't do
that.
https://www.kernel.org/doc/html/latest/process/maintainer-netdev.html
Send a self NACK to the broken version, wait 24 hours, and send v2.
Andrew
---
pw-bot: cr